Generate a Keyfile for account recovery when email is unreachable
After reading about the shutdown of lavabit's email service, where I am sure that many people have their accounts, I realized that it might be a good idea to have a keyfile for account recovery. If implemented, I would like it to be something like this:
The user goes to their account settings, and enables recovery of account via keyfile by checking a checkbox. This would prevent people from trying to gain access to your account. Once activated, a button would appear saying "generate key" would appear. This would generate a 4096 bit RSA private key, which then would prompt for a location to download the file to, also telling the user to keep the contents of the key safe.

In the future at some point, your email goes down and you have steam guard enabled, as well as the option for recovery via keyfile, you could upload the file, and change your password and email if needed WITHOUT having to input the steam guard code. Once used, the previous key would become invalid, and there would be a prompt to generate a new key. The system would also limit recovery tries to 5 times every 24 hours, to prevent people from abusing the system.

I think that this would help because currently, if you have Steam Guard enabled, if you try to access Steam from a new device and your email provider goes down, or quits, the only available option is to try to contact steam support to regain access to your account.

This way of recovery validation would be secure(as a 4096 bit key is impractical to try to break), but also would solve the issue of being locked out of accounts.
< >
11/1 megjegyzés mutatása
You can already change your contact email, from an already validated computer, without accessing to the old email account.
< >
11/1 megjegyzés mutatása
Laponként: 1530 50

Közzétéve: 2013. aug. 13., 23:03
Hozzászólások: 1