Fewer than 100 Steam users had the games installed, but Valve is adding a new SMS verification step for all developers to try to prevent it from happening again.
JackGreenEarth
link
fedilink
English
141Y

It’s not a confirmation via SMS, it’s a verification via SMS, so the attacker has to have your phone number as well as your steam account to attack it, which makes it harder.

TWeaK
link
fedilink
English
10
edit-2
1Y

They’re saying the people who bought the game from the original devs may have been the ones to upload the malware. In that case, they could confirm the SMS very easily.

ahriboy
link
fedilink
31Y

And SMS messages can be intercepted. Not a good option, use physical security keys instead!

TWeaK
link
fedilink
English
71Y

Even authenticator apps are generally better than SMS.

One thing no one talks about with SMS verifications, though, is that it frequently confirms your phone number to the business you’re giving it to. If they’re in the habit of trading user data, this makes the data much more valuable. I think this is the real reason for many businesses that push for it, when normally they could hardly care less about user security.

@[email protected]
link
fedilink
English
41Y

Seriously, while 2FA via SMS is generally much better than nothing, it has zero security so might even make things worse in some cases by providing a false sense of security!

LoafyLemon
link
fedilink
1
edit-2
1Y

RCS messages are encrypted using TLS.

@[email protected]
link
fedilink
English
61Y

RCS isn’t SMS though, nobody mentioned RCS!

LoafyLemon
link
fedilink
11Y

RCS is a replacement for SMS, used by the majority of mobile carriers in Europe, Northern America, and Asia. It is used by default in all supported regions.

@[email protected]
link
fedilink
English
21Y

I know what it is, but it’s got nothing to do with this discussion. What company provides 2FA codes via RCS instead of SMS?

LoafyLemon
link
fedilink
2
edit-2
1Y

Most of them do, because as you have noted before, SMS protocol is not secure.

@[email protected]
link
fedilink
English
51Y

Do they? I’ve never seen this as an option. In fact, I’ve never even seen RCS mentioned anywhere outside Android enthusiast forums!

LoafyLemon
link
fedilink
21Y

Only if you have the access to the same mast, otherwise no. This vastly reduces the number of attack vectors.

@[email protected]
link
fedilink
English
151Y

That’s why I was saying that this is “working as intended” and that more than likely this was perpetrated by less-than-savory devs who purposefully sold out the people who bought their games. There were no “hackers” only shitty devs that claimed they were hacked after they got caught distributing malware. Again, I may just be overly cynical.

Create a post

Video game news oriented community. No NanoUFO is not a bot :)

Posts.

  1. News oriented content (general reviews, previews or retrospectives allowed).
  2. Broad discussion posts (preferably not only about a specific game).
  3. No humor/memes etc…
  4. No affiliate links
  5. No advertising.
  6. No clickbait, editorialized, sensational titles. State the game in question in the title. No all caps.
  7. No self promotion.
  8. No duplicate posts, newer post will be deleted unless there is more discussion in one of the posts.
  9. No politics.

Comments.

  1. No personal attacks.
  2. Obey instance rules.
  3. No low effort comments(one or two words, emoji etc…)
  4. Please use spoiler tags for spoilers.

My goal is just to have a community where people can go and see what new game news is out for the day and comment on it.

Other communities:

Beehaw.org gaming

Lemmy.ml gaming

lemmy.ca pcgaming

  • 1 user online
  • 50 users / day
  • 269 users / week
  • 1.11K users / month
  • 3.92K users / 6 months
  • 1 subscriber
  • 12.6K Posts
  • 88.1K Comments
  • Modlog