Jump to content

No more "keychain" authenticators? BIG problem


HollyUSEC

Recommended Posts

Okay so I'm not a new player, but I don't know where else to post this, and this message may be important to anyone that never played the game before, but is interested in trying it out.

 

I've been told that the old "keychain" style authenticator is no longer available-- cell phone app or nothing.

 

My authenticator has been in use since launch and I'm concerned about the battery going out. I wanted to replace it.

 

I don't have a cell phone.

 

Anyone who wants to scream at me over that, get off this thread, okay? I do NOT have a cell phone. I will not defend this to anyone, in any way.

 

Is it true that BIoware has stopped making the keychain models?

 

If this is true, then once the battery goes, I'm locked out of my account. I understand that there's a way to get the authenticator serial number removed, but then my account is unsecured. I hope Bioware doesn't expect me to get a cell phone for the sole purpose of using its authenticator app?

 

And what about the fact that cell phones can be hacked, or stolen by a mugger, AND software updates (especially mandatory ones) can screw the app all up (a friend of mine lost her account for this reason, Bioware refused to help her in any way other than saying to start a whole new account), while the keychain authenticator never leaves my computer desk in my apartment and is worth diddly-squat outside of authenticating my account? Oh yes, the cell phone app sounds MUCH more secure to me. (/sarcasm)

 

Again, if you're going to scream flames at me for this, just do everyone a favor and log out of the internet for a little bit? I'm looking for constructive solutions here.

 

If the keychain authenticator is still available, please post a link.

Edited by HollyUSEC
Link to comment
Share on other sites

I believe they aren't being released any more, but you can still find them kicking about eBay and Amazon.

 

Additionally, although you'll have to test it, I believe any token-style authenticator should work. I don't know, because I have both a phone and tablet, and use much more than SWTOR with 2FA.

 

Phones are no less secure than physical authenticators; the latter can be just as easily stolen, and leaving them in your desk is a major security risk (but if the attacker has physical access to your computer, you are screwed anyway).\

 

I'm not gonna convince you to go one way or another, but I would highly recommend conducting more thorough research into your arguments before being arguably antagonistic with them.

Link to comment
Share on other sites

I'd be curious to take a look at a "keychain" authenticator and see how hard it is to change the battery. If it's easy enough to open it up, you could plug it into a USB port (through an extension so you can get at it) while you change the battery (so it doesn't lose power.). But that's all just speculation. :)

In any case, how long should the battery last?

Edited by JediQuaker
Link to comment
Share on other sites

I am not going to criticize but I am genuinely curious...in this day and age why do you not have a cellphone?

 

I get the sense you are worried about it being hacked, and yes if someone is truly intent on hacking your mobile device they will get in, but what makes you think that you are going to be targeted in such a fashion? Potential hackers/thieves are far more likely to see reasonable security in place and move on...there are plenty of unsecured devices out there /shudder.

 

I am NOT saying, "get into the 21st century and go buy a smartphone *******." What I am saying is that if I am reading you right, your concerns are unfounded.

 

P.S. I quite recently had to have my authenticator removed from my account because I replaced my smartphone without disabling the security code feature first and BW was very helpful. Yes I had to jump through some (reasonable and understandable) hoops - mostly to prove I was who I said I was - to get them to remove it, but it happened within 24 hours. I do not know why your friend would be denied so vehemently.

Link to comment
Share on other sites

I'd be curious to take a look at a "keychain" authenticator and see how hard it is to change the battery. If it's easy enough to open it up, you could plug it into a USB port (through an extension so you can get at it) while you change the battery (so it doesn't lose power.). But that's all just speculation. :)

It is entirely possible that the device will have some anti-tampering stuff inside. The simplest is to have a sort of loose-knit wire 'sock' around the electronics (including the battery holder) and some "potting" resin in and around that. Any attempt to access the battery pack will involve removing the resin, and that will break the 'sock', disabling the electronics.

 

I've seen this done, some years ago, on a crypto-enabled 56K PCMCIA card modem. Sure, it's all speculation, but given the sorts of things that similar tokens are used to protect, it may well be a reasonable thing to include.

Link to comment
Share on other sites

I am not going to criticize but I am genuinely curious...in this day and age why do you not have a cellphone?

 

I can't answer for the OP but in my case i had one and i just threw it away. The thing is that while i had it i just couldn't have a time for myself and i felt like i was a slave to the phone. So i threw it away. Best decision of my life. Now all communication is through email( yes, i cancelled my facebook account too). No more BS like someone calling me just because he's bored. My free time is for myself unless i choose otherwise.

Link to comment
Share on other sites

I can't answer for the OP but in my case i had one and i just threw it away. The thing is that while i had it i just couldn't have a time for myself and i felt like i was a slave to the phone. So i threw it away. Best decision of my life. Now all communication is through email( yes, i cancelled my facebook account too). No more BS like someone calling me just because he's bored. My free time is for myself unless i choose otherwise.

 

I completely understand that feeling, but - just my opinion - there are less extreme ways to "detach.";)

Link to comment
Share on other sites

It is entirely possible that the device will have some anti-tampering stuff inside. .

I assume there would be some sort of anti-tampering features in the "key", such as potting of the main chip, etc, but it is "possible" that the battery is replaceable. I wouldn't suggest anyone try to replace the battery as long as the device is still working, though. :)

 

Actually, that brings up another question. Does it even have a battery? I can visualize a device that simply has some protected flash RAM and is only powered by the USB socket when it's plugged in. Anyone out there know any such details? Do they say anything about a battery in any documentation that comes with it?

(It could even have the passcode permanently embedded in a small EPROM, so you don't even need to be concerned about flash losing it's contents.)

 

In any case, from what one poster said about WoW authenticators lasting 6 or 7 years, it doesn't sound like it will be a problem for another couple of years anyway.

 

P.S. Better to have a cellphone and turn it off when not needed than to have no cellphone at all. :)

Edited by JediQuaker
Link to comment
Share on other sites

Actually, that brings up another question. Does it even have a battery? I can visualize a device that simply has some protected flash RAM and is only powered by the USB socket when it's plugged in. Anyone out there know any such details? Do they say anything about a battery in any documentation that comes with it?)

It most definitely has a battery. There's no connector of any kind on it, USB or otherwise. So no external power source. The poster who mentioned USB was talking about rigging something up so you could keep it powered while pulling out the old battery and putting in a new one.

 

The device is a version of the Digipass Go 6, made by Vasco. Basically that device with SWTOR art on it. They make (or made) versions of it for several games. Google turns up a number of images showing the device with the Blizzard name plastered across it. Nothing that looks like the SWTOR one, though. According to their spec sheet, the battery is non-replaceable, and has a life expectancy of 7 years.

Link to comment
Share on other sites

i was just starting to wonder about this myself. my keychain requires a loooong press of the button to get my code to come up.

 

i do have a smartphone, but i just like the keychain.

 

This is the same case with mine. Had Mine since they came out from launch. and as long as i hold the button down oddly longer then normal, the numbers will pop up. As long is it still working i wont worry about a alternative.

But i would like to know if there is more then one app out there for this. Do to i got one on my Android and it wont work at all. So is there more then one app out there, if so? Please Link. Thanks........

Link to comment
Share on other sites

×
×
  • Create New...