Steam 2FA codes allegedly got leaked. If you use 2FA with your phone number, turn it off NOW and secure your account.

Confirmed false. See comment.

    • Asafum@feddit.nl
      link
      fedilink
      English
      arrow-up
      9
      ·
      edit-2
      2 hours ago

      Thank you for sharing this! Why should journalists verify anything, right? It’s not like it’s their job to report factual information they researched or anything…

  • slazer2au@lemmy.world
    link
    fedilink
    English
    arrow-up
    36
    ·
    2 hours ago

    “historic SMS text message with one-time passcodes for Steam, including the recipient’s phone number”.

    Oh, so they are selling phone numbers.

    The 2fa codes are useless after 1 min.

    • givesomefucks@lemmy.world
      link
      fedilink
      English
      arrow-up
      3
      ·
      2 hours ago

      Yeah. I think someone used the term “historic” appropriately, that it’s old

      And people are assuming it was used as an exaggeration like “this is a big deal”.

  • Baron Von J@lemmy.world
    link
    fedilink
    English
    arrow-up
    24
    arrow-down
    2
    ·
    2 hours ago

    Steam is warning users to enable Steam Guard Mobile Authenticator and keep an eye on account activity.

    Fuck off and let me use my own TOTP app already.

    • MudMan@fedia.io
      link
      fedilink
      arrow-up
      9
      ·
      2 hours ago

      I cut Steam some slack because they were early to that particular party, so they got grandfathered in. Plus the QR signin is fairly useful (not that they couldn’t do it regardless, but still).

      Their app is pretty ancient, can be kinda buggy and it’s not great overall, though.

    • Pika@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      7
      ·
      2 hours ago

      Steam is one of the few apps that I’m fully okay with having on my phone and using for 2fa. I especially like that when I go to login it’s like Discord where I can scan a QR code to confirm from the App instead of having to type in a number that expires. Like it would be nice to have the other functionality as well but I’m content with their current system

      • Baron Von J@lemmy.world
        link
        fedilink
        English
        arrow-up
        4
        arrow-down
        1
        ·
        1 hour ago

        I don’t mind that they have 2FA features in their app. I mind that using SMS for this has been known to be bad practice for years and they’ve tried to leverage that insecurity to push users to the Steam app. It’s reckless and this current data breach is only possible because of it.

  • PassingThrough@lemm.ee
    link
    fedilink
    English
    arrow-up
    11
    ·
    2 hours ago

    So what are the details of the risk here? Can texted 2FA use old codes to math out new ones? Is it just that they know which phone number goes to an account they can do another kind of attack on to get new codes?

    From what I read these are old texted one time codes. Good one time, generally only for a few minutes. Useless now.

    Or is this bad only because there’s a breach somewhere, they don’t know where, and who knows what else they have?

    • MudMan@fedia.io
      link
      fedilink
      arrow-up
      3
      ·
      2 hours ago

      I guess if the affected users are keeping their phone and TFA method you could target their phone numbers to try to intercept new codes, although that’s not doable at scale.

      Having phone numbers associated to accounts out in public is pretty bad in general, though.

  • Pika@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    6
    ·
    2 hours ago

    Okay so where’s the value here? Like I’m sure the phone numbers are worthwhile but including the 2fa codes with the phone number doesn’t seem like worthfull information, unless steam doesn’t properly have OTP setup and they don’t expire in a timely manner, but I’m willing to bet that a company like steam has a properly configured system