Steam 2FA codes allegedly got leaked. If you use 2FA with your phone number, turn it off NOW and secure your account.

Confirmed false. See comment.

Baron Von J
link
fedilink
English
294d

Steam is warning users to enable Steam Guard Mobile Authenticator and keep an eye on account activity.

Fuck off and let me use my own TOTP app already.

MudMan
link
fedilink
264d

I cut Steam some slack because they were early to that particular party, so they got grandfathered in. Plus the QR signin is fairly useful (not that they couldn’t do it regardless, but still).

Their app is pretty ancient, can be kinda buggy and it’s not great overall, though.

Rose
link
fedilink
English
23d

I’m personally of the opinion that a separate app sign in is okay as an additional measure, if the app is actually useful. For example, GitHub does this well - they support TOTP, and the mobile app is okay. Steam mobile app is useful, but TOTP option as a fallback would be nice.

Maybe the most useless thing I have on this front is the Blizzard app, really. The app is not particularly useful for me, I’d rather just use TOTP, if they had the option.

MudMan
link
fedilink
13d

Like I said I’m torn on that front. I only ever use the Steam app for QR login and TFA. Their grand design was that you’d be monitoring it as a marketplace back when they had these protoNFT ideas of how big their hats and trading cards were going to get.

But I never cared about those and they never put enough effort on the game store side of the app for it to be a better alternative than making purchases on the PC app instead, so… Would it be worth it to use a general TOTP app instead of a QR code for first time login and transaction validation? I’d say very likely, considering I already have a couple of those for a bunch of other services.

@[email protected]
link
fedilink
English
54d

I remember reading something about Steam having some of the best login protection even before HTTPS was a thing. I gotta find that article again since it was pretty cool

Pika
link
fedilink
English
134d

Steam is one of the few apps that I’m fully okay with having on my phone and using for 2fa. I especially like that when I go to login it’s like Discord where I can scan a QR code to confirm from the App instead of having to type in a number that expires. Like it would be nice to have the other functionality as well but I’m content with their current system

Baron Von J
link
fedilink
English
34d

I don’t mind that they have 2FA features in their app. I mind that using SMS for this has been known to be bad practice for years and they’ve tried to leverage that insecurity to push users to the Steam app. It’s reckless and this current data breach is only possible because of it.

EarMaster
link
fedilink
English
34d

Although it is not officially supported you can do this: https://github.com/keepassxreboot/keepassxc/discussions/9591

I did it years ago (I would say 10+ years) and it works perfectly fine.

Saik0
link
fedilink
English
33d

You can also extract and give it to bitwarden as well for those folks using that.

Create a post

Welcome to the largest gaming community on Lemmy! Discussion for all kinds of games. Video games, tabletop games, card games etc.

Weekly Threads:

What Are You Playing?

The Weekly Discussion Topic

Rules:

  1. Submissions have to be related to games

  2. No bigotry or harassment, be civil

  3. No excessive self-promotion

  4. Stay on-topic; no memes, funny videos, giveaways, reposts, or low-effort posts

  5. Mark Spoilers and NSFW

  6. No linking to piracy

More information about the community rules can be found here and here.

  • 1 user online
  • 227 users / day
  • 926 users / week
  • 2.38K users / month
  • 6.63K users / 6 months
  • 1 subscriber
  • 6.03K Posts
  • 123K Comments
  • Modlog