Steam Shows Major Flaw in Security
Steam shows major flaw in security
Personally i have never had a account hijacked or phished but shouldn't steam work on some type of better security for its customers? we are talking about spending customers who steam is basically allowing to have accounts stolen or illegally accessed.

im curious why this has been going on for years and steam has failed to address it and fix the exploits , i think a easy solution would be to lock down the accounts using financial information, set up secret passwords that can't be changed and never accessable , that a real account holder could use to lock down or regain access to an account in the event that its "hijacked" "Stolen" "phished".

This would also deter people selling steam accounts with games, because the account could be reclaimed by the orginal owner after payment with this security / code/ secret password.
< >
15 yorumdan 1 ile 15 arası gösteriliyor
There is no way to stop people from giving away their own account info.

Financial info changes (change banks because you move, or bank closes, or you get better deal at another bank, change credit cards and stuff like that). There is also the fact you can put wallet funds in without putting in a credit card or even paypal stuff.

Secret password that you can never change is ripe to get peoples accounts hijacked. "Greetings, I'm a Valve admin, we have had reports that your account has illegal on it, we need your login and secret password to make sure you are legit and check the items." And yes people fall for stuff like that.

You can already lock down your account if you think its been hijacked.

No it would not stop anything, if anything it would make things worse when people sell an account, then a few weeks later they "recover it" by saying it was hijacked.
they are secure\locked down its called MFA....
İlk olarak Gwarsbane tarafından gönderildi:
There is no way to stop people from giving away their own account info.
Yeah there is.
You use a multi-factor authentication scheme where at least one of the factors triggers at least one time on each newly encountered device and performs an exchange that involves an automated machine-to-machine communication, where the user is not made privy to any key to manually read back from device A and enter into device B.

As long as it's all automated and the user plays no part in the hand off, they don't have anything to give away.
That guy again?
That guy banned again?

Maybe one day he'll learn the concept of futility.
The weakest element in a chain of security measures is the human. That is a known fact for many years by now.
Wow that was a fast ban. Wonder what triggered it today.
İlk olarak Overseer tarafından gönderildi:
The weakest element in a chain of security measures is the human. That is a known fact for many years by now.

Absolutely, the security system can be air tight, but the biggest point of failure, is the human that controls it.

No one can stop you giving away your account, but hey, I don’t know about you, but i have never accepted random messages on discord or steam. Plus, if it is someone I know personally, I can recognize how they type and/or spell.

But ya, no one can stop you, the user, from logging into a shady website and giving away your account.
İlk olarak Overseer tarafından gönderildi:
The weakest element in a chain of security measures is the human. That is a known fact for many years by now.
yep unfortunately. my brother in law is working for it security companies and he always tells me that there is a factor that no one manages to fix in regards to security and it's the human factor.
Ahhh... the old Layer 8 problem...

That's between the chair and the keyboard
İlk olarak Qbert ⭐ tarafından gönderildi:
Ahhh... the old Layer 8 problem...

That's between the chair and the keyboard
unfortunately
the facts are

out of the millions of users on steam, only a tiny fraction of them compromise their accounts

if i were steam/valve, i wouldn't spend any more on this either

there is just so much you can do before it starts to cost more than it is worth
En son KalGimpa tarafından düzenlendi; 22 Mar 2023 @ 7:05
So... I've been on Steam for a while and I even consider myself a bit of a "fanboy" (nothing fanatic though). I basically only game on Steam and I love the interaction on the forums and the activity list.

Needless to say: over the years I've gained a nice amount of Steam friends. Some I chat with often, others through the forums, etc, etc. I take this part kinda serious.

Thing is... It has only happened once to me that I noticed one of my Steam friends accounts getting hijacked. He started sending out bizarre chats so I knew what I had to do. The now former Steam friend also never contacted me again.

I think those aren't bad numbers. I mean... if things were that bad, surely I should have noticed this happen a lot more? Also considering that some of my Steam friends are vivid FPS players. Yet nothing ;)
İlk olarak ShelLuser tarafından gönderildi:
Needless to say: over the years I've gained a nice amount of Steam friends. Some I chat with often, others through the forums, etc, etc. I take this part kinda serious.

Thing is... It has only happened once to me that I noticed one of my Steam friends accounts getting hijacked. He started sending out bizarre chats so I knew what I had to do. The now former Steam friend also never contacted me again.

Same stats here too. Only a single "friend" got phished and sent me phishing link. But I think the stats are kinda biased.

I have a mix of RL and internet people on my list. The biased part: I probably add people, who are more... cautious. Never accepted a friend request from a random I never heard of. If I am cautious and choose the people I add, the chance for them to fall for the simplest nigerian prince is pretty low.
İlk olarak Qbert ⭐ tarafından gönderildi:
Ahhh... the old Layer 8 problem...

That's between the chair and the keyboard
Back in the day when I did customer service on the phone, before we transferred the irate customer to tech support we'd instruct them to let tech support know that the code for their problem was "ID 10 T".
İlk olarak Cathulhu tarafından gönderildi:
That guy again?
That guy banned again?

Maybe one day he'll learn the concept of futility.
I take it he's pretty popular?
< >
15 yorumdan 1 ile 15 arası gösteriliyor
Sayfa başına: 1530 50

Gönderilme Tarihi: 20 Mar 2023 @ 21:22
İleti: 15