TorMazila Jul 4, 2016 @ 10:34am
Steam account+web-sms services=danger
I see lots of folks using "google sms receive online", click, choose one of many phone numbers and use it for something.

If you have done that - you're in trouble - anyone can find out your steam login name (and corresponding display name), e-mail and change e-mail to anything they want. And I guess do a lot of harm as well. One of my steam friends was "clever" to do exactly that and we barely managed to put things back as they were. It was funny to find out that there were several other accounts using the same phone number. The guy has hit 200 items limit in no time as well (he doesn't do much trading). If he din't got hit by weird "you can't trade due to recent e-mail change" - I bet he'd didn't notice anything at all.
< >
Showing 1-4 of 4 comments
wuddih Jul 4, 2016 @ 11:00am 
sidefact:
if one account of the phonenumber gets vacbanned, all other acccounts with the same number also get vacbanned.

it is a dumb idea to use phonenumbers you dont have any contract over to begin with.
TorMazila Jul 6, 2016 @ 3:33am 
I didn't think of VAC bans option at all :) . Phone number isn't your taxpayer id or anything as permanent as that - in Ukraine you can buy a sim use it, after it gets invalidated due to non-payment a cell op keeps the phone number for some half a year and assigns it to a new sim card. And then you go buy the "fresh new card" which turns out to get SMS's from gazillion of unknown services and calls from people you don't know who start calling you by the names you never heard of (that actually happened to me 2 years ago, was somewhat funny, unless the things happened at midnight).

Steam has no control over cell operator to know that 'my new SIM' is really new for me and when I attach it to my account and it has all sorts of "bad things happened in the past" that (as you say) get instantly transfered over to my account - so how Steam is going to rule out that situation? Things get even trickier considering that I and the past owner definitely live in the same country and can even happen to use the same ISP, so the only difference will be our login names and e-mail addresses - and it's impossible to prove that I own only one of them or both.

It is a dumb idea to use SMS at all - it has been proven that it's not that secure as we're used to think - GSM signalling can make your phone traffic get routed via and to some unexpected third party. And it doesn't take an arm and a leg to get access to GSM signalling - that's how twitter&co accounts get "hacked".
If you loose your 2FA device - supposedly you'll be able to set up a new one using the recovery code, and you don't get the code via sms.

And one more scenario - you come to a job inteview. Out of sheer fun the HR goes to a steam site and inputs your cell number. A buzzling sound comes out of your pocket (you're stupid enough not to turn off your phone before the interview), or even if it doesn't - they still see you have a steam account linked. "So how much time you're into gaming?" they ask. Your answer ?
Tito Shivan Jul 6, 2016 @ 4:46am 
Securing your account through a public phone number is like securing your home with a TSA-Approved luggage lock.
TorMazila Jul 6, 2016 @ 6:35am 
Originally posted by Tito Shivan:
Securing your account through a public phone number is like securing your home with a TSA-Approved luggage lock.
GSM signalling is hackable - it doesn't require even 10K$ nowdays. So "securing through your personal GSM phone SMS" is as secure as you stated above :).

It was supposed to be secured with 2FA, which essentially is a number generator function of (current time, init number that you should backup) - you get (or post to steam - not sure) the init number via the authenticator software and the software is authorized once using the code from SMS. Never again you need that phone/SMS. Unexpectedly it turns out you can't disable the phone and leave only 2FA.

And as I said before - using a cell phone in steam negates your privacy. You can have 1000 e-mails for each and every occasion, but you can't easily have multiple phones - they require regular payments (even ukrainian prepaids require topping up like once a year), they require phones and sometimes even some activity.If someone here has 2-3 sims - it is for others to be able to call for free or for being able to save on calls (we have 3 GSM operators and there are several CDMA - but SMS can't reach them). Having a sim for steam?!

Once you get the facts that
a) anyone can validate that you have steam account (and e.g. you are not supposed to be a gamer at all)
b) should some secret scervice wish to find out "who is who" - they will be able to do that without asking steam and without you even noticing the activity unless they decide to hack into your account (which doesn't make sense for them).
c) there are other options like rogue GSM ase stations :)
you'll definitely not like the idea of relying on GSM SMS.

BTW, our Privabank has stopped using SMS for logging into its internet-banking and are either calling you or you can call them - and that happens after you've entered a correct password.
Last edited by TorMazila; Jul 6, 2016 @ 6:50am
< >
Showing 1-4 of 4 comments
Per page: 1530 50

Date Posted: Jul 4, 2016 @ 10:34am
Posts: 4