Steam 2FA codes allegedly got leaked. If you use 2FA with your phone number, turn it off NOW and secure your account.

Confirmed false. See comment.

@[email protected]
link
fedilink
English
124d

So what are the details of the risk here? Can texted 2FA use old codes to math out new ones? Is it just that they know which phone number goes to an account they can do another kind of attack on to get new codes?

From what I read these are old texted one time codes. Good one time, generally only for a few minutes. Useless now.

Or is this bad only because there’s a breach somewhere, they don’t know where, and who knows what else they have?

MudMan
link
fedilink
64d

I guess if the affected users are keeping their phone and TFA method you could target their phone numbers to try to intercept new codes, although that’s not doable at scale.

Having phone numbers associated to accounts out in public is pretty bad in general, though.

Create a post

Welcome to the largest gaming community on Lemmy! Discussion for all kinds of games. Video games, tabletop games, card games etc.

Weekly Threads:

What Are You Playing?

The Weekly Discussion Topic

Rules:

  1. Submissions have to be related to games

  2. No bigotry or harassment, be civil

  3. No excessive self-promotion

  4. Stay on-topic; no memes, funny videos, giveaways, reposts, or low-effort posts

  5. Mark Spoilers and NSFW

  6. No linking to piracy

More information about the community rules can be found here and here.

  • 1 user online
  • 227 users / day
  • 926 users / week
  • 2.38K users / month
  • 6.63K users / 6 months
  • 1 subscriber
  • 6.03K Posts
  • 123K Comments
  • Modlog