B 2019 年 4 月 26 日 下午 2:08
Steam guard cooldown change
Hello everyone,
Whenever you disable mobile auth on your phone (and automatically go to e-mail confirmations), you get 15 day cooldown like that you have turned off your steam guard in total.
I believe it should be changed that if you go from Mobile Auth > E-mail conf , it recognizes that you had Steam Guard turned on the whole time.
What do you people think?
Cheers!
< >
目前顯示第 1-12 則留言,共 12
Crashed 2019 年 4 月 26 日 下午 2:18 
引用自 BUDI ******.***
Hello everyone,
Whenever you disable mobile auth on your phone (and automatically go to e-mail confirmations), you get 15 day cooldown like that you have turned off your steam guard in total.
I believe it should be changed that if you go from Mobile Auth > E-mail conf , it recognizes that you had Steam Guard turned on the whole time.
What do you people think?
Cheers!

Is this to help you interact with that gambling site you are advertising?
最後修改者:Crashed; 2019 年 4 月 26 日 下午 2:18
B 2019 年 4 月 26 日 下午 2:19 
Had it in my name for a while, changed now :UncommonSmile:
cSg|mc-Hotsauce 2019 年 4 月 26 日 下午 3:39 
It is there to protect your account.

The amount of time for disabling the app is not going to be shortened. Especially since you gave away your account info to various sites.

BUDI {連結已移除}

BUDI ♥♥♥♥♥♥♥♥♥♥.com

BUDI vgoreaper.gg

BUDI gamdom

27 BUDI {連結已移除}

28 BUDI {連結已移除}

BUDI {連結已移除} 28

BUDI spinpit.co

:qr:
最後修改者:cSg|mc-Hotsauce; 2019 年 4 月 26 日 下午 3:40
B 2019 年 4 月 26 日 下午 4:24 
It is a mistake from Valves point of view. No-one can access my steam account without having access to both my steam account and my e-mail.
Btw, you obviously do not know anything about API's.
All websites use Steam API to make an user log in, website never gets username and password of a user. That is why it goes through steamcommunity.com website.
cSg|mc-Hotsauce 2019 年 4 月 26 日 下午 4:27 
引用自 BUDI
It is a mistake from Valves point of view. No-one can access my steam account without having access to both my steam account and my e-mail.
Btw, you obviously do not know anything about API's.
All websites use Steam API to make an user log in, website never gets username and password of a user. That is why it goes through steamcommunity.com website.

If you ever have to enter in ALL your account info into a login page while already logged into Steam itself in a browser, you just gave away ALL your info INCLUDING your code to a phishing login page.

ALL the sites in your name history have been know to have redirected phishing login pages at some point in the last year.

I know how the API works. There is a reason why there is a 1-click verification in it.

:qr:
最後修改者:cSg|mc-Hotsauce; 2019 年 4 月 26 日 下午 4:28
The Giving One 2019 年 4 月 26 日 下午 4:33 
Oh boy. This OP really does not know about all the API scams and phishing victims we have seen a huge influx of in the recent months on the forums here.

There is a reason why in your name alias history, it shows as "LINK REMOVED", and the "hearts" also. Might want to think carefully about that.

Also, they already tried shorter cooldown times. That did not work. People kept giving away their account credentials (*cough cough*) and getting their accounts compromised.
B 2019 年 4 月 27 日 上午 1:26 
I love it how people do not know what they are talking about but still keep thinking all the websites (that were in my name at least) are stealing users info.

1) When it says "Link Removed", it is usually because a lot of people reported that link. Sometimes it is because it was a malicious website, but a lot of the times it is Valve trying to close down gambling.

2) When you want to login to a website using Steam API, if the website redirects you to steamcommunity.com/login....
That means that it is legit.
At the moment that you enter your information ON OFFICIAL STEAM WEBSITE, special code is generated both on your localStorage and on that websites database. Then Steam redirects you to that website and website has to check if your localStorage.steamloginkey == database_value_for_your_account
That way it is 100% safe for users to log into the websites using Steam API.

3)This wasn't the point of this discussion, the points is that there is unnecessary 15-day cooldown when you turn off your Mobile Auth and switch to e-mail conf, that needs to be removed.

:golden:
Crashed 2019 年 4 月 27 日 上午 5:00 
引用自 BUDI
1) When it says "Link Removed", it is usually because a lot of people reported that link. Sometimes it is because it was a malicious website, but a lot of the times it is Valve trying to close down gambling.
You know that "♥♥♥♥♥♥♥♥♥♥" ad that keeps popping up in the community? It's phishing, and I have been reporting it repeatedly as it changes domains to both Malwarebytes and PhishTank.
Valve now has a legitimate reason to shut down gambling, as they are facing a lawsuit now: https://www.pcgamer.com/the-native-american-quinault-nation-has-filed-a-lawsuit-against-valve-over-gambling/

It would be a good idea to change your password immediately, especially if the prompt made you log in again.

引用自 BUDI
2) When you want to login to a website using Steam API, if the website redirects you to steamcommunity.com/login....
That means that it is legit.
That isn't verification that Valve has reviewed the site to ensure it doesn't do anything fraudulent or illegal, or otherwise violates its TOS.
最後修改者:Crashed; 2019 年 4 月 27 日 上午 5:01
The Giving One 2019 年 4 月 28 日 下午 2:07 
引用自 BUDI
3)This wasn't the point of this discussion, the points is that there is unnecessary 15-day cooldown when you turn off your Mobile Auth and switch to e-mail conf, that needs to be removed.

:golden:
Except that was addressed above, and you not liking the duration that it is now (15 days) does not equal it being "unnecessary".

Lots of people don't like taxes, too, but they are necessary.
引用自 The Giving One
Also, they already tried shorter cooldown times. That did not work. People kept giving away their account credentials (*cough cough*) and getting their accounts compromised.
Do you seriously think you are the first user to come here with this suggestion ? Use the forum search. That is what it says to do in the pinned thread anyway.

"This topic has been pinned, so it's probably important"

http://steamcommunity.com/discussions/forum/10/135507548120407092/

Please consider searching before posting, as your suggestion may have already been brought up before.
76561198407601200 2019 年 4 月 28 日 下午 3:00 
引用自 BUDI
Hello everyone,
I believe it should be changed that if you go from Mobile Auth > E-mail conf , it recognizes that you had Steam Guard turned on the whole time.
What do you people think?

I'd rather have my account safe-guarded than being impatient. Do other tasks until you are able to trade.
The Giving One 2019 年 4 月 28 日 下午 3:05 
Also, as usually the case and interestingly relevant, why did you not make this suggestion a long time ago ?

After all, this has been the way it is for a long, long time. I know the answer. As with often the case with people that find out the same thing applies to them as everyone else :

You only came to make this suggestion because now, it is actually affecting you, and not just others. People often just want to change the way things work, only because it is now affecting them.
Quint the Alligator Snapper 2019 年 4 月 28 日 下午 6:51 
引用自 cSg|mc-Hotsauce
2) When you want to login to a website using Steam API, if the website redirects you to steamcommunity.com/login....
That means that it is legit.
At the moment that you enter your information ON OFFICIAL STEAM WEBSITE, special code is generated both on your localStorage and on that websites database. Then Steam redirects you to that website and website has to check if your localStorage.steamloginkey == database_value_for_your_account
That way it is 100% safe for users to log into the websites using Steam API.
FYI I've seen at least one site simulate an entire browser window popup pretending to be a Steam login page.



Also, e-mail confirmation does not fix the problem of the same malware-infected computer being used to access both Steam and e-mail account.
< >
目前顯示第 1-12 則留言,共 12
每頁顯示: 1530 50

張貼日期: 2019 年 4 月 26 日 下午 2:08
回覆: 12