Post B6OS74T2IlAjb8jTO4 by JosJuice@mastodon.social
(DIR) More posts by JosJuice@mastodon.social
(DIR) Post #B6OQ3hXEuHH7hKxp3o by demize@unstable.systems
0 likes, 0 repeats
occasionally the steam mobile app logs me out and I have to log back inevery time, this is terrifying, because steam’s 2FA is within the mobile app. so if it’s somehow lost my login entirely, I will be locked outanyway, this is why we have the popular standards of TOTP and (more lately) passkeys (née FIDO2 U2F) and you should use them instead of rolling your own
(DIR) Post #B6OQu1TA2LXaa60N5E by JosJuice@mastodon.social
0 likes, 0 repeats
@demize Doesn't Steam force you to enable SMS as an alternative 2FA method so you won't get locked out? (Which is terrible for different reasons)
(DIR) Post #B6ORyw0DtCel1pNLVI by JosJuice@mastodon.social
0 likes, 0 repeats
@demize Correction, they let you disable 2FA using SMS. And last time I checked, disabling 2FA in this way was the *only* way to transfer 2FA to a new phone
(DIR) Post #B6ORywBZD1jLb0gPBY by demize@unstable.systems
0 likes, 0 repeats
@JosJuice that you can disable 2FA if you get locked out doesn’t mean you didn’t get locked out :pand I’m not sure if I have SMS fallback for that, I don’t remember it being a thing when I set this up many years ago
(DIR) Post #B6OS74T2IlAjb8jTO4 by JosJuice@mastodon.social
0 likes, 0 repeats
@demize You never entered your phone number?
(DIR) Post #B6OSB1CWO6XKcrtFA0 by demize@unstable.systems
0 likes, 0 repeats
@JosJuice having just checked after that it seems I did, but from other replies it also seems you don’t have to
(DIR) Post #B6OSPTFKudAxf468wa by JosJuice@mastodon.social
0 likes, 0 repeats
@demize Hmm, interesting. I thought it forced me, but it was a really long time ago
(DIR) Post #B6OVJAdfTvQU4mAO80 by whitequark@social.treehouse.systems
0 likes, 0 repeats
@JosJuice @demize the solution to this is to extract the 2FA secret* and shove it into keepassxc (which has a special 2FA mechanism just for steam!)* presumably impossible on iOS but i don't care about iOS
(DIR) Post #B6OVJAp0nkV4dxTRoG by demize@unstable.systems
0 likes, 0 repeats
@whitequark @JosJuice a few years ago I even saw someone extract the secret and just use it as a normal TOTP secret and it worked finedunno if it still would, but it’s hilarious† how it really is just “TOTP but we only let you use our app for it”†in that “why are corporations like this” kind of way
(DIR) Post #B6OveGbn4y5hTq0aVE by qenya@unstable.systems
0 likes, 0 repeats
@demize oh gods yeah this happened to me literally yesterday. the terror