Install Steam
login
|
language
简体中文 (Simplified Chinese)
繁體中文 (Traditional Chinese)
日本語 (Japanese)
한국어 (Korean)
ไทย (Thai)
Български (Bulgarian)
Čeština (Czech)
Dansk (Danish)
Deutsch (German)
Español - España (Spanish - Spain)
Español - Latinoamérica (Spanish - Latin America)
Ελληνικά (Greek)
Français (French)
Italiano (Italian)
Bahasa Indonesia (Indonesian)
Magyar (Hungarian)
Nederlands (Dutch)
Norsk (Norwegian)
Polski (Polish)
Português (Portuguese - Portugal)
Português - Brasil (Portuguese - Brazil)
Română (Romanian)
Русский (Russian)
Suomi (Finnish)
Svenska (Swedish)
Türkçe (Turkish)
Tiếng Việt (Vietnamese)
Українська (Ukrainian)
Report a translation problem
This can lead to some really nasty situation if SE won't react properly, people will abuse the opening and will push it further and further. Especially now after lackluster response.
I don't think that is true at all considering the amount of cheap companies that exists.
I have no doubts that some, a relatively low number of companies compared to the total amount, would do that, but nowhere near my mind is the thought that the majority would do this.
If you put your credit card online, no matter if it's Square Enix, Amazon, Google, or a random chinese company, you have the same risks. This is the world we live in.
Tho about the game security in general. FFXIV doesn't require any heavy permissions and everything runs within the user mode with admin access only required for patching and installing the game and parts of the game that use user input like chat/pf listings are sanitized as well. Your IP address and your account credentials that are being sent to the server are also encrypted using TLS 1.2
Speaking of Mods/cheats including malware is basically user error and this is why Dalamud warns the user about using addons from non official repos. You can play games like Valorant with the most aggressive kernel level anti cheat but infect yourself by using a random "free cheat" that had a crypto miner/keylogger whatever in it
You in general should keep your OS updated at all times, do not run everything as administrator for "better performance" and be mindful of what are you running
Better yet, don't send sensitive information to the client at all. There is no reason for the client to have access to the account ID, even obfuscated. Account blacklisting should have been processed entirely on the server side, and if there is a performance hit to the servers, SE should just accept it and get stronger hardware if necessary.
SE isn't some cheap company, they have money and I assume basic knowledge of cybersecurity, this stuff isn't some rocket science, you're learning this pretty early in cybersecurity studies.
What this is in my opinion is lack of senior devs at the wheel, DT was given to new batch of developers and writers to potentially learn and improve, and this are the result. Hole in security and mostly negative reviews.
You can use all of the tech and standards and still mess up due to terrible implementation which is what happened in this case
But overall, when you log in to the game. you go through the authentication in a different server which returns you a valid SID (token) in order to log in into the game
So no, no one will actually steal your log in credentials even if they have your account ID of FFXIV and if you feel concern then I strongly suggest (and you should have done it anyway) but enable 2FA on your SE account
I agree, Blacklisting should be done differently and SE should be called out for messing up but I highly doubt that the game has RCEs and etc in there
Well not so old. CBU3 did "fix" the issue that allowed the leaking of account IDs within the game but turns out it wasn't fixed properly and the issue happens again.
The reaction to the plugin is completely overblown. So what if they have my character ID and know the names of my retainers? They are blacklisted and disappear from my screen so what does it matter? They can't do anything with that information and I can't see their character or read their chat messages. They don't exist anymore.
There are gaps in every online service out there, including the very one we are using right now to comment on. no security is perfect and it all depends which measures the service takes to protect its data in terms of how they store the data and what mitigations there are
Yes, I know about PlayerScope and how people did fork the Github repo before it went down and created versions that offer more features to track more character specific data. it sucks and you ain't wrong but I don't expect to see RCEs or anything critical all of the sudden popping off as you log in through an issued token/SID, the game doesn't expose your IP addresses, user Inputs are sanitized and the set of permissions to launch the game is very limited and everything is done on user mode + the game doesn't host any other service on your machine.
I would argue that other games like League of Legends have a much larger attack surface area compared to FFXIV for example.
But just as I mentioned before. Don't launch the game as administrator, keep your OS updated and be mindful of what you execute on your computer. if you use addons by any chances then stick to Dalamud's official ones and if you decide to use a custom repo then be sure to know what are you exactly doing