安裝 Steam
登入
|
語言
簡體中文
日本語(日文)
한국어(韓文)
ไทย(泰文)
Български(保加利亞文)
Čeština(捷克文)
Dansk(丹麥文)
Deutsch(德文)
English(英文)
Español - España(西班牙文 - 西班牙)
Español - Latinoamérica(西班牙文 - 拉丁美洲)
Ελληνικά(希臘文)
Français(法文)
Italiano(義大利文)
Bahasa Indonesia(印尼語)
Magyar(匈牙利文)
Nederlands(荷蘭文)
Norsk(挪威文)
Polski(波蘭文)
Português(葡萄牙文 - 葡萄牙)
Português - Brasil(葡萄牙文 - 巴西)
Română(羅馬尼亞文)
Русский(俄文)
Suomi(芬蘭文)
Svenska(瑞典文)
Türkçe(土耳其文)
tiếng Việt(越南文)
Українська(烏克蘭文)
回報翻譯問題
Which is all kinds of hilarious and quintessential shortsightedness on Valve's part, once more.
All major players in big tech are converging on FIDO authentication standards. Microsoft; Apple; and Google all surface it in their OSes and want to use its open-ended nature of pluggable authenticators to push people away from weak passwords to whatever stronger alternative login mechanism is a good fit for them; whether that be a dedicated hardware key; a key stored in the device TPM; or some kind of biometrics like fingerprint or eyescan.
In addition to their own services they provide in their role as industry leading digital service providers, other service providers in the digital domain such as Meta as well as e.g. major financial service providers have also adopted FIDO or are in the process of doing so.
Give it a year.
Eventually Valve is going to find itself being dragged into implementing support for it anyway, because it's going to be the norm.
Like if its a beta test right now, why would they add more problems to their workload? There's literally no reason for them to add more to the existing project unless its involved with the beta item entirely
What is interesting to me at this moment is : "Why did valve go this way, which incentives drove them to this decision". From what i know it can not be to create "the securest way" / a very secure way. But as other people stated, i do not see it is the easiest or cheapest way either, so i am kind of confused.
To the other comments above i can say, that i agree with them, but just because many others do things, it is not the best way to go there. The main reason is, that all arguments that matter point in the direction of FIDO authentication. At least according to "my facts".
Maybe someone can share some insight on what is the thinking here on valves side ?
However, U2F should be optional (like it is for other online accounts, this weakens the standard against phishing however) since not everyone is going to buy a hardware key and hardware keys are incredibly easy to lose.
Having said all that, skip U2F altogether and go straight to FIDO2 which requires an additional pin entry (working example on Cloudflare), this effectively removes the need to use and store passwords, regardless of encryption level.
Don't see a problem with confirming trades optionally via FIDO2 either, a modal would just appear asking to insert the hardware key and enter in the pin code, there's already native support for this across many desktop and mobile operating systems.
but for steam login fido2 would be awesome.
The various FIDO standards do support transmitting additional data to be presented on a secure screen. But it's an optional feature that not all FIDO-compatible authenticators have to support.
That said; the FIDO standards also require as a mandatory feature that an authenticator can be queried for which features it supports. Meaning hypothetically Steam could allow the same instant completion of trades when confirming them via a FIDO authenticator that supports a secure screen to show the trade contents; and fall back on the 15 day escrow that currently also accompanies e-mail confirmation, when a user employs a FIDO authenticator that doesn't support a secure screen.
so yeah while I love the idea currently that's not practical. you'd need to at least convince Microsoft (as they run the WebAuthn Client on Windows 10/11) to actually pass it, as well as get makers of Devices which could theoretically run FIDO2 to ACTUALLY incorporate it, that would lower the ceiling at least far enough that a Ledger Nano S (for those that have one, as it's no longer being made) or a Trezor One would be enough as those are the Cheapest devices I am aware that play U2F while having a screen, and they still are 60€-ish.
It would also be great if they allowed getting backup codes without a phone number(SMS), they're the only company that i know of that has backup codes behind one, really annoying.