Steam 2FA codes allegedly got leaked. If you use 2FA with your phone number, turn it off NOW and secure your account.
5000$ for 89 million 2FA codes, obviously its false 😂
Submitted 10 months ago by simple@lemm.ee to games@lemmy.world
Steam 2FA codes allegedly got leaked. If you use 2FA with your phone number, turn it off NOW and secure your account.
5000$ for 89 million 2FA codes, obviously its false 😂
Aside from this being false, it’s kinda crazy that Steam has had no significant public leaks.
I once wrote the guy listed for their infrastructure that one of their mail servers is configured incorrectly.
He got back to me after 2 hours thanking me and telling me he fixed it.
Thought that was pretty impressive for a company of their size.
That’s what happens when you don’t have to think one quarter at a time. You actually realize that investing in your IT infrastructure is way cheaper than shit breaking or a breach happening.
So I know it's confirmed false, but I wanted to take the opportunity to ask how you good folks stay in the know about critical/time sensitive compromises like this was believed to be?
Dunno if other people have a faster way of finding out about potential data breaches, but for me, the original Bleeping Computer article about this showed up on my newsfeed and that’s how I found out about it, followed a few hours later by other sites parroting the same news while quoting the BC article. It wasn’t till I saw this post that I learned this breach is a fake though. So, I’d say just keep an eye on your newsfeed and if you see something there, check any tech news social media communities you’re a part of for the same news and for further details.
Already debunked
Well I already changed my password and my old password was shit so thank you late april fools prank.
Thanks for the update. False alarm.
Thank you for sharing this!
Looking at how this started, it’s even more depressing.
Okay so where’s the value here? Like I’m sure the phone numbers are worthwhile but including the 2fa codes with the phone number doesn’t seem like worthfull information, unless steam doesn’t properly have OTP setup and they don’t expire in a timely manner, but I’m willing to bet that a company like steam has a properly configured system
In case any time travelers want to make some slow cash?
“historic SMS text message with one-time passcodes for Steam, including the recipient’s phone number”.
Oh, so they are selling phone numbers.
The 2fa codes are useless after 1 min.
Yeah, that’s pretty dumb.
Were I a nefarious scheming hacker, I wouldn’t pay shit for that.
Yeah. I think someone used the term “historic” appropriately, that it’s old
And people are assuming it was used as an exaggeration like “this is a big deal”.
Steam is warning users to enable Steam Guard Mobile Authenticator and keep an eye on account activity.
Fuck off and let me use my own TOTP app already.
Although it is not officially supported you can do this: github.com/keepassxreboot/keepassxc/…/9591
I did it years ago (I would say 10+ years) and it works perfectly fine.
Steam is one of the few apps that I’m fully okay with having on my phone and using for 2fa. I especially like that when I go to login it’s like Discord where I can scan a QR code to confirm from the App instead of having to type in a number that expires. Like it would be nice to have the other functionality as well but I’m content with their current system
I don’t mind that they have 2FA features in their app. I mind that using SMS for this has been known to be bad practice for years and they’ve tried to leverage that insecurity to push users to the Steam app. It’s reckless and this current data breach is only possible because of it.
So what are the details of the risk here? Can texted 2FA use old codes to math out new ones? Is it just that they know which phone number goes to an account they can do another kind of attack on to get new codes?
From what I read these are old texted one time codes. Good one time, generally only for a few minutes. Useless now.
Or is this bad only because there’s a breach somewhere, they don’t know where, and who knows what else they have?
Really?
hal_5700X@sh.itjust.works 10 months ago
According to Steam, no leak occurred.