How to not lose your divines to session ID thieves
Relog after every trade to reset session ID tokens.
Kick people sitting in a corner in your hideout by swapping the hideout.
Don't trade with sketchy people.
Don't trade with non ascendancy level 25's
Relog after a party failure, i.e: you invite person for trade, they insta join and leave
This crap happened in PoE 1 5-6 years ago and was later solved but it took forever. It's back now in full force and effect.
This isn't a 2FA problem.
This isn't a data breach issue like other posts.
This isn't a extension or 3rd party software issue.
They can simply log in to your characters under your session ID and swipe your stash.
Here is a post from when this was happening 6 years ago: https://www.reddit.com/r/pathofexile/comments/a0h1qv/log_into_someone_else_account_by_accident/
Stay safe out there <3
Comments
It’s easy for me, only 1 step.
Don’t have divines :)
if i trade in public spaces can they still get into my acc? like if i only trade in ziggurat refuge for example
wow man, I just had a trade with a lv2 account earlier today,
and you get me checking my account immediately as I arrived home, thank god my one and only divine still intact!
i'll get another hideout (I only got Canal atm) to insta kick people who don't immediately leave after trade :D
Provide any proof that someone can get a session id from a trade otherwise this is complete bs.
Which it is.
My strat is to have multiple folders upon folders hiding the goods :)
I don’t think this is a session hijack exploit and either way initiating a relogin won’t do much.
Do i have to relog website AND game, or just relog game
It's funny just how many problems one can avoid by simply playing ssf
lol
The bug 6 years ago was a people going to char select at exactly the same time and getting their sessions mixed up. That had nothing to do with trade at all.
Here is the statement from GGG:
https://www.pathofexile.com/forum/view-thread/2253250
All that session id stealing stuff going around is mostly people repeating things they dont understand without any proof.
Guaranteed third party issue
brb making hackingaftertrade char name
Blood mage may not want to ascend at 25 you know.
I dont understand how they get your sessionid just by trading. And then, with that, login to your account 🤔
Do i have to wait till the person leaves my hideout to relog? or just relog right after the trade
Don't allow people to your hideout, sweet