Yoshi P's Response to FFXIV's Blacklist Exploit – Unacceptable?



I feel like Square Enix has been dropping the ball a lot with FFXIV lately, but this one annoyed me enough that I decided to make a video about it. Basically the new black list system was implemented with such incompetence that it facilitates more harassment. Even though the new features are a good idea, the way they are designed adds a major privacy vulnerability.

Yoshi P’s statement: https://forum.square-enix.com/ffxiv/threads/515102-Regarding-the-Use-of-Third-Party-Programs-and-Player-Safety

source

30 thoughts on “Yoshi P's Response to FFXIV's Blacklist Exploit – Unacceptable?”

  1. While it is a concern, for the vast majority of players this is a non issue.

    If anything, those found exploiting this problem while also harassing others should be dealt with zero tolerance, resulting in a permanent ban while also contacting local authorities of their actions.

    Reply
  2. Sorry, since FFXIV probably makes calls to excel spreadsheets for its marketboard system, this is likely exactly the same for the friendlist and blacklist system. Small indie dev, please understand.

    Reply
  3. Too much focus on plugins; this account ID is also visible in the network traffic and FFXIV network traffic is NOT encrypted. So you could still sniff this data out without the use of plugins. Could easily have a 3rd party listening in on your wifi sniffing out your account info for example. This is an exploit in the game itself that needs to be fixed in the game.

    Reply
  4. Man all signs are pointing to to FF14 crashing to the ground. Such a shame to see but since DT or arguably further back the retention of success seems to be diminishing. I wish it wasn't happening and I'm sure there are ways to come out of this but with every update they inch towards the game's failure

    Reply
  5. Hello from Japan.
    A few hours before this statement by Yoshi P, there was a post from overseas on the FF14 forum in Japan.
    He/she said that "Square Enix is violating the GDPR – General Data Protection Regulation (from the European Union)" and he/she made a formal complaint to the German data protection authority regarding this issue. That post has already been removed by a moderator.
    Do you think this will work?
    Does the fact that the blacklist feature is not fixed violate the GDPR?

    Reply
  6. I have been stalked across multiple data centers/server in game, by different people, but I have one consistent stalker. i have repeatedly reported said person for it too, and nothing was ever done, so frankly, I'm not surprised.

    Reply
  7. So the only way to completely starve this plugin and make players' data safe again would be to roll back the blacklist change, I assume? I'd almost rather just prefer that than…this mess. I'm not in programming or game dev or anything like that, so I don't really know what it's like on their side but to continue to have this data available for this plugin just seems like the absolute WORST idea, full stop.

    Reply
  8. Before you get all the pitchforks out, a reminder that this drastic of a backend data configuration change is NOT as simple as most are making it out to be, whatsoever. It's disingenuous at best while they explore potential larger fixes.

    Reply
  9. It's gonna get worse if Square doesn't do something. I'm not just talking about this incident. More exploits of the game will pop up to be used for bullying, harassment, and even account theft. The same thing happened to WOW. The devs were lazy and did little. Now account theft is quite common in the game. Happened to me once and two of my friends. All within one year. I never clicked on anything or downloaded anything.

    Reply
  10. Legal action? What a bunch of Japanese clowns, doing the only thing they know. đŸ€Ą
    This is just such a completely insignificant drama that doesn't actually affect anyone. It's just a game. Just block someone if you don't want to deal with them, and let's go. No need to yap about this like it has any real-life consequences. XIV players seriously so fragile, yet completely clueless, it's mind-boggling.

    Reply
  11. I imagine they don't wanna show their hand early, they definitely can't leave this as is…getting the mod nuked from orbit is a good start but given it was on the internet it means I'm sure someone took down the database info for it meaning it can be easily replicated…this isn't gonna go away now

    Reply
  12. As someone who has been stalked in this game to the point of having to take a haitus from the game at the end of HW, leaving behind my house, FC, beloved friends, and even swapping worlds upon my return – this is NOT enough!
    Yoshi-P "please don't use this" is a massive f-you in the face to anyone who's had to face these issues.

    Reply
  13. Haven't touched 14 since August because I wasn't really vibing with the direction the game went with regards to class design, specifically with my favorite job

    Been thinking about how much time I'd spent in endwalker and whether id be willing to commit to the possibility that I could get pulled into the game the same way if I went back.

    Thought this whole situation was hilarious but I expected some sort of patch

    But naah, I think I'm done. Not gonna give them money if he's gonna put his fingers in his ears and go "lalalalalalala not listening don't use mods"

    Reply
  14. They seem to be consistently reluctant to devote more server side data to players. They make claims that giving people more inventory will break the game (while also selling more inventory as retainers). Gear sets and hud setup are client side, among other things. The recent update to the glamour dresser seems to have keep the server side data the same by repurposing dye data.

    Seems this stinginess is biting them in the butt.

    Reply
  15. Shoulda coulda woulda is only a fair response from the player base till we get denuvo'd and everyone loses. The protection that sounds like people are advocating for is quickly answered by anti-cheat making it impossible to exploit in the first place if they didn't care about us, and trust me you don't want that route, it leads to the death of expression and accessibility. Watching VRChat go through this exact thing 2 years ago was a joke, I'VE PLAYED THESE GAMES BEFORE. I do not think they're looking at this situation like "none of this is the fault of the blacklist", I think its just reasonable to not have an answer to something you just learned about, they have to do their own research to make sure its directly the black list causing this and not something else (even if we've been doing the research for months, we've basically made the hypothesis and they as DEVS have to prove its true or not before they make an official statement)

    Reply
  16. Its not a great PR moment for Yoshi P and the dev team, but i suspect there is something else at play here we're not privy to.

    What i mean is that the solution may not be that easy to fix. Possibly there could be issues due to engine, or proposed solutions create server side issues, like security or lag.

    The devs implemented this with the effect of dealing with harrassment. Oversight, sure, but Yoshi P has been fairly transparent and on the players' side. So i am willing to give him and their team trust that they will resolve the issue in some form. Time, like most things, is probably required.

    Reply
  17. Your title is clickbait 
 If you read his statement, he clearly says that it is illegal to use plugins. Don’t use the plugin or interact with anyone who uses the plugins or advocates the use of plugins. This video itself may also be a violation of the ToS because it is disseminating information about the use of plugins, which is specifically called out as a prohibited activity in the ToS.

    Reply

Leave a Comment