此主題已被鎖定
Clan Wolf 2016 年 11 月 4 日 下午 10:14
Steam Desktop Authentication
*update 16/05/18

with the growth of steam lately. increasing sophsiticated attacks. customers expensive items getting bigger. and this SDA getting fakes on the internet, to lure in hijacks. this nefty program is at HIGH RISK.

I'm making the switch. only use this temporarily for when you do not have a mobile and trading is needed.


update from github

WARNING: Recently there have been fake versions of SDA floating around that will steal your Steam account. Never download SDA from any place other than this github repo!

Don't use anymore, this thread will stay here as a relic of what once was. I have no connection to the github maker, i would of left a comment on github but it isn't allowed.

I dont encourage you use this, you are takings RISKS if use the open source program, you were warned. i have nothing to do with the makers. Read the comments, go to reddit for info




general rule about steam accounts, your more at risk the higher the value of your items are worth. attackers know this and are watching you. There is no metric for this, mid and high hundreds and thousands in worth. Is more eyes on you and its worth attackers time and resources to steal it from you.

*********************
https://github.com/Jessecar96/SteamDesktopAuthenticator

https://www.reddit.com/r/SteamDesktopAuth/

https://www.reddit.com/r/tf2/comments/3ug38r/introducing_the_steam_desktop_authenticator_beta/?st=iv4va1zs&sh=36100af3


*********************

everyone uses email authentication and everyone must have at the very least have a basic mobile that gets calls and sms, all services employ this now.

dont use a voip account that acts like a mobile which you control through your pc, its a measure for being anonymous. But types like this or types of email Valve detect and reject as acceptable, so don't bother. Valve are too smart for most.

steam requires you give them a mobile number, in case your account is hacked. you can have sms sent to you a reset code etc (so keeping mobile updated is important)

but if you fail to do this before losing your mobile, this here will sort you out

(don't rely on steam tickets to fix your problem, unless its not fixable with the below link!)

https://help.steampowered.com/en/wizard/HelpWithLogin/

use steam desktop authenticate (not by valve) its the external software program steam customers wanted so they dont have to use a mobile app, so someone in the community wrote it

steam is an open API, so uses their open api keys so you can login through it like bot sites.

it will just use your accounts mobile number and will activate steam into thinking your using the mobile app. gives you the tokens you need to verify trades with players.


take in consideration security, strong passwords/licensed anti-virus (if you use free stuff, your running risks) channel your trading goods to another account, on a another pc if you can.

So then through that 2nd desktop authenticate account setup which you use to trade with. This will limit harm to your main account as you dont use it to trade with others, only your alt.

but remember you are still NOT SAFE using this, read comments below. You are still taking huge risks. if your lazy about your online security, this isn't for you. However mobile users generally have lacked passwords, which is part of my quarrel.


HOW TO SETUP


INSTRUCTIONS: write everything down

run program> click setup new account (just login)

your steam account login

name
password

(should be long and complicated, no words. mix of letters, numbers, special characters and upper case letters you can even use _ - + = : ; even a space

so you login into like any other bot key, it sends you a email verification code, enter that on the 2nd prompt.

just as the 3rd prompt for passkey below appears, assuming your steam account mobile is up to date. you get a sms code, but dont use it just yet. its after passkey

4th prompt it will ask you to make a passkey, just a password not the same as your steam login, but just as complex.

5th prompt 'its own sauce' it will give out a revocation code ###### (its just 1 letter at the beginning and 5 numbers), use this when it asks for it. write it down. if you skipped revocation code later when it asks you will have to begin again.

6th prompt enter sms code, you were given ###### (its a code of 5 numbers)

7th prompt it asks for the revocation code ######, enter that.

you should get a email notification, steam guard mobile authentication is enabled successfully on your account. GOOD JOB

now go trade, use the automatically generated tokens you see changed every 10 seconds to verify trades with others

Update* Even if you lose your imported mafiles, its easy to redo. Just remove mobile authenicator from account on steam - follow prompts, sends a text code then a email code, enter both.
You cannot restart the process on the program without removing this first, it detects your account is linked etc. Then redo the steps. Take it slow, do it a few times, to restart remove from manifest. As long as you know your username and password and the wizard link above (as a 2nd to last move) It will be all right.

update 30/06/17
new update SDA1.0.8.1, old is 7.2.

you can still get tokens to login but trade confirmations require this update, you also need newer .net framework 4.6.2 for it to work. Old .net was 4.5.2.

Updating 8.1 has me currently confused, the page says the following about updating:

Extract all the files contained inside the ZIP file over your copies of the same files wherever you installed Steam Desktop Authenticator. The program will not run unless you extract all the files.

what you do with the extract files and import of mafiles doesnt work, as far as im concerned.

Honestly it is easier just to follow my steps for complete renewel, using the new version 8.1.
p.s this sort of guide is gotten lengthy, but im too lazy to make it into a guide. Those really dont help.

as always any problems, take it up with the person on github who made SDA, like you i just wanted it to make life easier so i can get on with stuff.



Be safe
最後修改者:Clan Wolf; 2018 年 5 月 15 日 下午 3:16
引用自 The Giving One:
引用自 Clan Wolf
yeah true that, you take this on you are taking a risk...disclaimer.

but the reasoning discussion has yet to begin. i think most agree highly complex passwords that are never the same, are beyond 16 characters (i use 30 or more) and a good anti-virus. format windows if needed and browsers that are not full of malware

how long until attackers find a way through, a first defense is important
Until a user changes such complex passwords on the same compromised device, as in a computer infected with malware, for example, which is the biggest and most well-known source of account compromises.

EDIT..Correction...a big source, if not THE biggest.

That just can give the newly changed password right over to the attacker, possibly.
< >
目前顯示第 16-27 則留言,共 27
Clan Wolf 2016 年 11 月 9 日 下午 1:06 
so many pitfalls with steam trading, cancel a trade 7 day ban. dont use trading in over like 7 days then reactivate - 7 day ban.

using the auth, cant now. alt is locked have to wait another 7 days. but main pops up saying trade hold 15 days, even though i just traded minutes before and earlier

make sure you have both accounts synced to the same setup, so there is no confusion otherwise........TRADE BAN!

other pitfalls i know are out there but havent discovered them yet.

its like saying Highground!

https://www.youtube.com/watch?v=B7FMh3YtK_w
最後修改者:Clan Wolf; 2016 年 11 月 9 日 下午 1:11
Clan Wolf 2016 年 11 月 9 日 下午 1:12 
also what if you were to run the software on something other than a pc. what about a raspberry pi or some OS on a usb stick? everyone should be using those anyway.

just no windows.

Creepy Eye 2017 年 6 月 15 日 上午 8:08 
hey, is sda no need to wait 15 days?
Clan Wolf 2017 年 6 月 15 日 上午 8:16 
its a desktop version of the mobile app (well part of the app) to get your login tokens and confirm trades, so if you dont like to use mobile apps in that way, this is the alternative that valve didnt want.
Stratiotis 2017 年 6 月 15 日 上午 8:20 
oh ok
The Giving One 2017 年 6 月 15 日 上午 9:47 
引用自 Clan Wolf
You can use Steam Desktop Authenticator on multiple computers at the same time, with the same Steam account(s).
Yep, but better hope those computers don't get compromised and the items/accounts hijacked. Having all security on one device is not two factor authentication. Just posting this here so others know the risks involved.
Clan Wolf 2017 年 6 月 15 日 下午 12:42 
its gone
Clan Wolf 2017 年 6 月 30 日 上午 6:31 
new update, read note.
Peek-a-Boo ™ ♣ 2018 年 3 月 7 日 上午 9:28 
new up but conformations & checking for updates arent workig
Clan Wolf 2018 年 5 月 2 日 上午 12:52 
you only need authenticator if you do trades, just to log on and play games. email verify is all you need. but authenticator will do both


just remember if you log on to your main accounts, on different computers. mobile is better for you. at LAN or school with desktop auth you wont get on as you dont have software control.

if you want to persist with desktop auth like i do, make account purely just for LAN cafe and share games and dont use authenticator, so no trading. trading should only go thru your main

its also tricky to setup multiple main accounts for trade with desktop auth on the one computer, i havent tried this yet. maybe with virtual machines
Clan Wolf 2018 年 5 月 2 日 上午 12:59 
new up but conformations & checking for updates arent workig


refresh confirmations always, works for me. and never mind about update, i see that too. new version will come from github, reinstall to use, be sure to follow deactivate account from authenticator first.

isnt much in the way of updates, 1.0.8.1 is the latest

update from github

WARNING: Recently there have been fake versions of SDA floating around that will steal your Steam account. Never download SDA from any place other than this github repo!

最後修改者:Clan Wolf; 2018 年 5 月 2 日 上午 1:02
Clan Wolf 2018 年 5 月 15 日 下午 3:03 
its more a temporary alternative. i didn't have a good enough mobile when i started. still don't like em. but things have changed. account lists (username + password) can be copy/paste with notepad app.

when everything can be safely done on a pc, i'll go back to it.
< >
目前顯示第 16-27 則留言,共 27
每頁顯示: 1530 50

張貼日期: 2016 年 11 月 4 日 下午 10:14
回覆: 27