This topic has been locked
Sharp Muffin Oct 14, 2022 @ 3:30pm
New Steam Guard might be a security flaw!
Hello everyone.

In my opinion the new way of authenticating when you login might be more insecure. It makes you have to be logged in on mobile steam app 24/7 and this for me is a huge security flaw. Imagine that my phone for some reason ends up in the wrong hands? The old way was much better than this. No login required in the mobile app. I don't even have my account remembered on my Desktop!

I know I'm not the only one worried about this, I hope valve does something. At least let us choose if we want to stay like before, with the widget!
< >
Showing 1-15 of 101 comments
Sleepy Oct 14, 2022 @ 3:35pm 
are you concerned youll lose your phone, or that it will be stolen?

this seems like an overreaction to something insignificant.
Serendipity Oct 14, 2022 @ 3:43pm 
Originally posted by mikosovich:
are you concerned youll lose your phone, or that it will be stolen?

this seems like an overreaction to something insignificant.

Hardly insignificant if you trying to keep your account safe and there is something there that feels like a threat., like op I also do not like being connected to any web site all the time I always log out.
Sharp Muffin Oct 14, 2022 @ 4:04pm 
Originally posted by mikosovich:
are you concerned youll lose your phone, or that it will be stolen?

this seems like an overreaction to something insignificant.


It's all about having your account safe. There is money "invested" in my account that I don't want to lose because of something that used to be right and now to me looks like a security problem.
ShelLuser Oct 14, 2022 @ 5:33pm 
Originally posted by Sharp MuffinPT:
It makes you have to be logged in on mobile steam app 24/7 and this for me is a huge security flaw. Imagine that my phone for some reason ends up in the wrong hands?
Then it depends on your common sense in securing your phone.

Dunno about you but I do my banking business with my phone, I'm a day trader (stock excange) and a large portion of that is handled by me using my phone, I can order stuff on my phone, etc. etc.

There are much bigger concerns here.

Not to mention... if I try to buy something through the Steam app I still have to authenticate myself again with the payment provider. Why imagine people going after Steam when there are much bigger fish to go after, like identify theft?

If your phone gets stolen and you failed to properly protect it then you have way more bigger concerns on your hands in this day and age.
Chika Ogiue Oct 14, 2022 @ 5:52pm 
There is no excuse for forcing someone to be permanently logged in on the Steam app. The fact it won't even let you sign out without removing the authenticator is not justifiable by any sane person. It's a flaw that needs fixing.
AleRi0N_ Oct 14, 2022 @ 5:57pm 
When the mobile app first launched back in 2012 IIRC, it was always 24/7 online running in the background but you could sing out. Now, with this new change, things are gonna get worse for sure.
cSg|mc-Hotsauce Oct 14, 2022 @ 6:15pm 
Originally posted by AleRi0N_:
When the mobile app first launched back in 2012 IIRC, it was always 24/7 online running in the background but you could sing out. Now, with this new change, things are gonna get worse for sure.

Mobile Guard launched in 2015.

Steam Guard Email launched in 2011.

:qr:
ShelLuser Oct 14, 2022 @ 6:55pm 
Originally posted by Chika Ogiue:
There is no excuse for forcing someone to be permanently logged in on the Steam app.
No one does: nothing is stopping you from signing out once you used the app.

Of course after that you do need to authenticate yourself again if you want to support your authentication elsewhere.
Chika Ogiue Oct 14, 2022 @ 8:05pm 
Originally posted by ShelLuser:
nothing is stopping you from signing out once you used the app

Have you tried signing out of the app? You cannot. Try it. Open your app, tap on your avatar, and then select "Sign out". You get the following error:
The account you are attempting to sign out has an active Steam Guard authenticator on this device. Please migrate or remove your authenticator and try again.
PocketYoda Oct 14, 2022 @ 8:06pm 
Originally posted by miko:
are you concerned youll lose your phone, or that it will be stolen?

this seems like an overreaction to something insignificant.
Anyone can lose a phone its very easy thing to lose.. and the Phone security can be opened easily.
Originally posted by ShelLuser:
Originally posted by Chika Ogiue:
There is no excuse for forcing someone to be permanently logged in on the Steam app.
No one does: nothing is stopping you from signing out once you used the app.

Of course after that you do need to authenticate yourself again if you want to support your authentication elsewhere.
You can't log out..
Last edited by PocketYoda; Oct 14, 2022 @ 8:07pm
DeadBeat Oct 14, 2022 @ 8:11pm 
Originally posted by Chika Ogiue:

Have you tried signing out of the app? You cannot. Try it. Open your app, tap on your avatar, and then select "Sign out". You get the following error:
The account you are attempting to sign out has an active Steam Guard authenticator on this device. Please migrate or remove your authenticator and try again.

I think it's just Valve's way of nudging you into the direction of using the QR feature so they make it a pain in the ass to get out of it without disabling steam guard on the phone.
If you've got an android you can use this thread to get back to the old app.
https://steamcommunity.com/discussions/forum/8/5533260453821252322/

Last edited by DeadBeat; Oct 14, 2022 @ 8:14pm
Darth Schumy Oct 14, 2022 @ 8:34pm 
Phones are hackable, even if they're not stolen or lost. Storing login details for your account are even more vulnerable than phones. The old system was safer, faster and just less of a pain for the end user. I have to now log into email to log into Steam - I'm going to get tired of that shiot soon enough.
Last edited by Darth Schumy; Oct 14, 2022 @ 8:37pm
Lunatix Oct 14, 2022 @ 9:10pm 
Obviously using his phone and being logged to Steam is a big security risk, but it's Valve what do you expect. And this new app is so laggy, multi billionary company can't pay competent developers (no offense <3)
Last edited by Lunatix; Oct 14, 2022 @ 9:12pm
lOKI Oct 14, 2022 @ 9:38pm 
yeah phones are hackables
PocketYoda Oct 14, 2022 @ 9:41pm 
Originally posted by Lunatix:
Obviously using his phone and being logged to Steam is a big security risk, but it's Valve what do you expect. And this new app is so laggy, multi billionary company can't pay competent developers (no offense <3)
They don't want to not that they can't.. Large companies are cheap.
< >
Showing 1-15 of 101 comments
Per page: 1530 50

Date Posted: Oct 14, 2022 @ 3:30pm
Posts: 101