techradar.com

arakhis_, do games w Switch 2 mouse mode (such potential)
@arakhis_@feddit.org avatar

Am I the only one thinking that a huge chunk of the initial audience are Nintendo adults who already have a pc for main games and a switch on the side?

Feels like this gimmick (although every new Nintendo console gets one) was so forced just to upsell a switch 1 and justify splitting the community with exclusive releases. Really sad to see mk world not playable with a player base on switch 1. Most next gen were happily bought enough with a reasoning in increasing hardware (which the switch 2 really also does well).

Just the predatory move of splitting or even passively force the playerbase to leave behind the switch 1, makes the mouse sensor so MEH… I mean… lackluster in my eyes. Idk

SynopsisTantilize,

Sure but the switch is 10 year old hardware. You know what else was released at that time? The iPhone 6s…do you currently use an iPhone 6s?

arakhis_, (edited )
@arakhis_@feddit.org avatar

yes lol. I also have a 4070ti though

EDIT: I have no clue where this could be a relevant argument

SynopsisTantilize,

Yea I use a 2080ti and currently am playing FTL (2012) I have no room to talk lol

O_R_I_O_N, do games w Switch 2 mouse mode (such potential)

Lol

vane, do games w Switch 2 mouse mode (such potential)

RIP floors and tables.

Hazelnutcookiez, do games w Switch 2 mouse mode (such potential)

I’m pretty excited for this feature honestly, I know a lot of games won’t use it but still it’s gonna be fun.

kaeurennetwo, do games w (Edit: Confirmed false) Hacker advertises alleged database of 89 million Steam 2FA codes
@kaeurennetwo@lemmy.world avatar

Really?

PassingThrough, do games w (Edit: Confirmed false) Hacker advertises alleged database of 89 million Steam 2FA codes

So what are the details of the risk here? Can texted 2FA use old codes to math out new ones? Is it just that they know which phone number goes to an account they can do another kind of attack on to get new codes?

From what I read these are old texted one time codes. Good one time, generally only for a few minutes. Useless now.

Or is this bad only because there’s a breach somewhere, they don’t know where, and who knows what else they have?

MudMan,

I guess if the affected users are keeping their phone and TFA method you could target their phone numbers to try to intercept new codes, although that's not doable at scale.

Having phone numbers associated to accounts out in public is pretty bad in general, though.

baronvonj, do games w (Edit: Confirmed false) Hacker advertises alleged database of 89 million Steam 2FA codes
@baronvonj@lemmy.world avatar

Steam is warning users to enable Steam Guard Mobile Authenticator and keep an eye on account activity.

Fuck off and let me use my own TOTP app already.

Pika,
@Pika@sh.itjust.works avatar

Steam is one of the few apps that I’m fully okay with having on my phone and using for 2fa. I especially like that when I go to login it’s like Discord where I can scan a QR code to confirm from the App instead of having to type in a number that expires. Like it would be nice to have the other functionality as well but I’m content with their current system

baronvonj,
@baronvonj@lemmy.world avatar

I don’t mind that they have 2FA features in their app. I mind that using SMS for this has been known to be bad practice for years and they’ve tried to leverage that insecurity to push users to the Steam app. It’s reckless and this current data breach is only possible because of it.

MudMan,

I cut Steam some slack because they were early to that particular party, so they got grandfathered in. Plus the QR signin is fairly useful (not that they couldn't do it regardless, but still).

Their app is pretty ancient, can be kinda buggy and it's not great overall, though.

NotSteve_,

I remember reading something about Steam having some of the best login protection even before HTTPS was a thing. I gotta find that article again since it was pretty cool

umbraroze,
@umbraroze@slrpnk.net avatar

I’m personally of the opinion that a separate app sign in is okay as an additional measure, if the app is actually useful. For example, GitHub does this well - they support TOTP, and the mobile app is okay. Steam mobile app is useful, but TOTP option as a fallback would be nice.

Maybe the most useless thing I have on this front is the Blizzard app, really. The app is not particularly useful for me, I’d rather just use TOTP, if they had the option.

MudMan,

Like I said I'm torn on that front. I only ever use the Steam app for QR login and TFA. Their grand design was that you'd be monitoring it as a marketplace back when they had these protoNFT ideas of how big their hats and trading cards were going to get.

But I never cared about those and they never put enough effort on the game store side of the app for it to be a better alternative than making purchases on the PC app instead, so... Would it be worth it to use a general TOTP app instead of a QR code for first time login and transaction validation? I'd say very likely, considering I already have a couple of those for a bunch of other services.

EarMaster,
@EarMaster@lemmy.world avatar

Although it is not officially supported you can do this: github.com/keepassxreboot/keepassxc/…/9591

I did it years ago (I would say 10+ years) and it works perfectly fine.

slazer2au, do games w (Edit: Confirmed false) Hacker advertises alleged database of 89 million Steam 2FA codes

“historic SMS text message with one-time passcodes for Steam, including the recipient’s phone number”.

Oh, so they are selling phone numbers.

The 2fa codes are useless after 1 min.

givesomefucks,

Yeah. I think someone used the term “historic” appropriately, that it’s old

And people are assuming it was used as an exaggeration like “this is a big deal”.

Cocodapuf,

Yeah, that’s pretty dumb.

Were I a nefarious scheming hacker, I wouldn’t pay shit for that.

Lojcs, do games w (Edit: Confirmed false) Hacker advertises alleged database of 89 million Steam 2FA codes

In case any time travelers want to make some slow cash?

yesman, do games w (Edit: Confirmed false) Hacker advertises alleged database of 89 million Steam 2FA codes
Pika, do games w (Edit: Confirmed false) Hacker advertises alleged database of 89 million Steam 2FA codes
@Pika@sh.itjust.works avatar

Okay so where’s the value here? Like I’m sure the phone numbers are worthwhile but including the 2fa codes with the phone number doesn’t seem like worthfull information, unless steam doesn’t properly have OTP setup and they don’t expire in a timely manner, but I’m willing to bet that a company like steam has a properly configured system

sudneo, do games w (Edit: Confirmed false) Hacker advertises alleged database of 89 million Steam 2FA codes
Asafum,

Thank you for sharing this! Why should journalists verify anything, right? It’s not like it’s their job to report factual information they researched or anything…

sudneo,

Looking at how this started, it’s even more depressing.

simple,

Thanks for the update. False alarm.

rickyrigatoni,

Well I already changed my password and my old password was shit so thank you late april fools prank.

tisktisk, do games w (Edit: Confirmed false) Hacker advertises alleged database of 89 million Steam 2FA codes

So I know it's confirmed false, but I wanted to take the opportunity to ask how you good folks stay in the know about critical/time sensitive compromises like this was believed to be?

Nitrate55, (edited )
@Nitrate55@lemmy.dbzer0.com avatar

Dunno if other people have a faster way of finding out about potential data breaches, but for me, the original Bleeping Computer article about this showed up on my newsfeed and that’s how I found out about it, followed a few hours later by other sites parroting the same news while quoting the BC article. It wasn’t till I saw this post that I learned this breach is a fake, though. So, I’d say just keep an eye on your newsfeed and if you see something there, check any tech news communities and other relevant social media communities that you’re a part of for the same news and for further details.

Edit: There’s also sites like Have I Been Pwned where you can put in your email and get information on every known data breach involving your email address. The site can also notify you about any new data breaches where your email showed up in the affected data.

specialseaweed, do games w (Edit: Confirmed false) Hacker advertises alleged database of 89 million Steam 2FA codes

Aside from this being false, it’s kinda crazy that Steam has had no significant public leaks.

entwine413,

That’s what happens when you don’t have to think one quarter at a time. You actually realize that investing in your IT infrastructure is way cheaper than shit breaking or a breach happening.

domi,
@domi@lemmy.secnd.me avatar

I once wrote the guy listed for their infrastructure that one of their mail servers is configured incorrectly.

He got back to me after 2 hours thanking me and telling me he fixed it.

Thought that was pretty impressive for a company of their size.

Kualdir, do games w (Edit: Confirmed false) Hacker advertises alleged database of 89 million Steam 2FA codes
@Kualdir@feddit.nl avatar

5000$ for 89 million 2FA codes, obviously its false 😂

  • Wszystkie
  • Subskrybowane
  • Moderowane
  • Ulubione
  • esport
  • fediversum
  • test1
  • ERP
  • rowery
  • Technologia
  • krakow
  • muzyka
  • shophiajons
  • NomadOffgrid
  • informasi
  • FromSilesiaToPolesia
  • retro
  • Travel
  • Spoleczenstwo
  • gurgaonproperty
  • Psychologia
  • Gaming
  • slask
  • nauka
  • sport
  • niusy
  • antywykop
  • Blogi
  • lieratura
  • motoryzacja
  • giereczkowo
  • warnersteve
  • Wszystkie magazyny