STEAM GROUP
Steamworks Development SteamworksDev
STEAM GROUP
Steamworks Development SteamworksDev
524
IN-GAME
8,112
ONLINE
Founded
October 11, 2012
Oct 10, 2023 @ 10:57am
Coming Soon: Security improvements for managing builds and Steamworks users
< >
Showing 151-165 of 180 comments
luckz Nov 29, 2023 @ 7:40am 
If you are happy with the security risks (account theft), you can use third party desktop software for 2FA instead of their mobile app.
Of course won't get you past the text message requirements either way.
Multiverse Dec 17, 2023 @ 4:25am 
Unfortunately we are unable to accept VOIP phone numbers. Please enter a mobile number associated with a phone that you physically have in your possession.

Ugh. Standards based TOTP please. SMS, even from major carriers, is NOT designed for security -- simjacking is a thing.
Ben Lubar Dec 17, 2023 @ 9:21am 
Originally posted by luckz:
If you are happy with the security risks (account theft), you can use third party desktop software for 2FA instead of their mobile app.
Of course won't get you past the text message requirements either way.
If you have the authenticator app (official or otherwise) it sends the confirmation via that rather than a text message.
Duck Whitman Dec 21, 2023 @ 10:46pm 
Originally posted by WON:
This is terrible. Our whole pipeline is automated and can be triggered by an international team anywhere on the globe where one team might be sleeping... At least allow for MULTIPLE phone numbers...
I second this.
Eric.B Dec 21, 2023 @ 11:36pm 
Originally posted by Duck Whitman:
Originally posted by WON:
This is terrible. Our whole pipeline is automated and can be triggered by an international team anywhere on the globe where one team might be sleeping... At least allow for MULTIPLE phone numbers...
I second this.

The solution for single-phone, multicomputer SMS is to use KDE Connect. Pair the updating computers to the phone via KDE Connect. Set the permissions on the phone to allow SMS for each paired machine. This whitelist will allow anyone paired with the phone to see and send SMS on their computer through the phone. This setup only works on the phone's Intranet. You'll need to use a VPN on the remote computers to make it work over the Internet.

I do not know how well KDE Connect works on Windows. But it is working great on my Linux/FreeBSD/NetBSD shop. Of course, this means you'll need to buy a phone/line specifically for Steam, as anyone paired on your team will have access to the phone's SMS system. Don't use the same phone for banking (although it's unsafe to have a bank that uses SMS 2FA.)

It's still no solution compared to TOTP Steam! In fact, you're making it MUCH more insecure for me.
Last edited by Eric.B; Dec 21, 2023 @ 11:57pm
Lost in Days Studio Jan 22, 2024 @ 2:47am 
you know it is especially great when you get locked out of publishing an important patch for your game when the sms system gets broken at random. Currently stuck in an infinite "failed to send sms" loop since yesterday. :steamthumbsup:
Last edited by Lost in Days Studio; Jan 22, 2024 @ 2:48am
Atorcoppe Jan 27, 2024 @ 5:19pm 
Originally posted by Lost in Days Studio:
you know it is especially great when you get locked out of publishing an important patch for your game when the sms system gets broken at random. Currently stuck in an infinite "failed to send sms" loop since yesterday. :steamthumbsup:

Oh so it's not just me then. Great. :/
Les Jan 28, 2024 @ 10:43am 
Originally posted by Atorcoppe:
Originally posted by Lost in Days Studio:

Oh so it's not just me then. Great. :/

I think everyone is somewhat affected. We have substantially reduced the frequency of updates compared to before.

I find it inconvenient to stay up for two hours, typing seven Steam Guard codes during the upload and then entering seven mobile codes on the website to release builds.

This process needs to go back to drawing board.
Last edited by Les; Jan 29, 2024 @ 3:15am
GE-0 Feb 20, 2024 @ 4:57pm 
Originally posted by luckz:
If you are happy with the security risks (account theft), you can use third party desktop software for 2FA instead of their mobile app.
Of course won't get you past the text message requirements either way.
Yeah, great idea, now i’m able to automate everything again. Btw even official Steam mobile app allows linking Steam Guard without a phone number, and custom 3rd-party solutions can do that to, so just be sure to write down the recovery code.
In the end no phone number needed, no smartphone needed, i’ve encrypted that Steam Guard "seed" value using Windows Data Protection API (DPAPI), so it can’t be read under different PC and user, and i’m getting codes out third party console/software library implementation of Steam Guard.

Originally posted by Ben Lubar:
If you have the authenticator app (official or otherwise) it sends the confirmation via that rather than a text message.
Yeap, which can be confirmed using desktop/console/software lib.
luckz Feb 21, 2024 @ 10:15am 
Originally posted by GE-0:
Btw even official Steam mobile app allows linking Steam Guard without a phone number, and custom 3rd-party solutions can do that to, so just be sure to write down the recovery code.
Mh, how did you sign up for Steam Guard without a phone number though? In the past I always had to provide one and go through the SMS code motions once.
GE-0 Feb 21, 2024 @ 10:37am 
Originally posted by luckz:
Mh, how did you sign up for Steam Guard without a phone number though? In the past I always had to provide one and go through the SMS code motions once.
True, looks like it was changed unknown time ago.

So, i'm on Android, official Steam app, now on the step where it asks «Enter your phone number below, with an international prefix» below the blue "Next" button there’s a small gray underlined text «I don’t have access to a phone number» which is actually clickable, and after clicking a dialog appears:
Skip Phone Number Add (sic!)
(Not Recommended) This reduces your security and increases the time it takes to recover an account.
[Skip] [Don’t skip]
After skipping it asks for a code from the email instead to finish linking Steam Guard, happy end.

One more note: also you won’t be able to generate Backup Steam Guard codes since the code never arrives to the mailbox, it claims to have sent it in an SMS, but that’s a mistake since there’s no number. Other than that i haven’t noticed any other differences.
Last edited by GE-0; Feb 21, 2024 @ 10:38am
P1 Mar 16, 2024 @ 5:22am 
All fun and games until I can't release one of my builds because steam doesn't send me a damn SMS code. No SMS received in the past hour on multiple attempts. Worked before, so this is clearly something that is going to be happening in the future. All future builds are now at the mercy of valves SMS service, and considering half the time steamworks has issues anyway, this is going to be a ♥♥♥♥♥♥♥ pain in the ass.
Lukifah Mar 17, 2024 @ 4:05pm 
i changed my number and now i can't update the game i recently released.
IBOL17 Jul 26, 2024 @ 9:49pm 
I found out about this today, after spending 9 months on a single update that was a complete user interface overhaul. No problems in beta. I said "main branch release today!".
Nope. Old phone number. No SMS. No response from customer service on changing my number.
GE-0 Jul 28, 2024 @ 6:59am 
Originally posted by GE-0:
Originally posted by luckz:
Mh, how did you sign up for Steam Guard without a phone number though? In the past I always had to provide one and go through the SMS code motions once.
True, looks like it was changed unknown time ago.

So, i'm on Android, official Steam app, now on the step where it asks «Enter your phone number below, with an international prefix» below the blue "Next" button there’s a small gray underlined text «I don’t have access to a phone number» which is actually clickable, and after clicking a dialog appears:
Skip Phone Number Add (sic!)
(Not Recommended) This reduces your security and increases the time it takes to recover an account.
[Skip] [Don’t skip]
After skipping it asks for a code from the email instead to finish linking Steam Guard, happy end.

One more note: also you won’t be able to generate Backup Steam Guard codes since the code never arrives to the mailbox, it claims to have sent it in an SMS, but that’s a mistake since there’s no number. Other than that i haven’t noticed any other differences.
↑ Reminder: Steam Mobile Guard can be activated and used without having a phone number linked.
< >
Showing 151-165 of 180 comments
Per page: 1530 50