QR Code Login
Discord has this awesome feature where you can login on the desktop version just by scanning a on screen qr code through the Discord app on your phone.

This removes the need to manually enter your email and password etc. You literally open Discord on your phone, scan the qr code shown on your desktop Discord and voila you are logged in.

If Steam could do something like this too that would be great!
< >
1-7 van 7 reacties weergegeven
discord qr logins where literally immediately exploited to hijack accounts
Ummm talk about a massive security breach. Anyone can read your login info off it. I mean you might as well save your login credentials in an unsecured text file.
In case you're wondering how that works

1) you go to a 'fake' discord login site
2) you log in. I know have your credentials and log into Discord
3) I receive the 'login' QR code
4) my website shows this QR code to you
5) you scan the QR code and 'authorize' my login
6) I'm now logged into your account
7) I immediately kick you out, change the password, add a 2fa
Origineel geplaatst door Satoru:
In case you're wondering how that works

1) you go to a 'fake' discord login site
2) you log in. I know have your credentials and log into Discord
3) I receive the 'login' QR code
4) my website shows this QR code to you
5) you scan the QR code and 'authorize' my login
6) I'm now logged into your account
7) I immediately kick you out, change the password, add a 2fa

Which isn't much different than the phishing that already happens. Not only with Steam, but for 2FA in general.
Not through another service, no. They're working on a QR scanner of their own though...

What's next?

We’re already working on improvements to the Steam Chat app, including voice chat. With Steam Chat moving to its own dedicated app, the original Steam Mobile app will see significant upgrades focused on account security. Our plans include better Steam Guard options to help securely log into your Steam account, such as QR codes and one-touch login, and improved app navigation.

https://steamcommunity.com/games/593110/announcements/detail/1621770561065348220

In ValveTime.

:qr:
Laatst bewerkt door cSg|mc-Hotsauce; 12 feb 2021 om 9:18
I didn't even think of a security risk being involved, maybe it can tie in with 2FA for added security.
< >
1-7 van 7 reacties weergegeven
Per pagina: 1530 50

Geplaatst op: 12 feb 2021 om 3:17
Aantal berichten: 7