• Some users have recently had their accounts hijacked. It seems that the now defunct EVGA forums might have compromised your password there and seems many are using the same PW here. We would suggest you UPDATE YOUR PASSWORD and TURN ON 2FA for your account here to further secure it. None of the compromised accounts had 2FA turned on.
    Once you have enabled 2FA, your account will be updated soon to show a badge, letting other members know that you use 2FA to protect your account. This should be beneficial for everyone that uses FSFT.

Steam hacking went beyond the forums

steam forums are back up now btw.

why no authentication usb key service yet?

People can have thousands of dollars of games on their steam accs but they are only protected by a simple password. Great.

Steam guard?

people just want a neato toy that spits out random tokens, because they think requiring a seperate device somehow makes it more secure. whoever here has heard about the recent RSA secureID government breach deploying a similar scheme would know that it's just as vulnerable. if/when someone manages to figure out the seed algo used to generate these numbers, blizzard is fucked just the same.

interesting reading on such number generating trinkets we put our faith in:
http://arstechnica.com/security/new...nt-allow-direct-attack-on-secureid-tokens.ars

steamguard acts on the same principle, instead of relying on a common seed to generate this number through a device, they will ask you to confirm client logins from new locations by generating a token link to reply through email. that way you get the exact same security without requiring an extra device, why doesn't blizzard deploy such a simple yet effective means of keeping our accounts safe? because they want to sell you some toys.

someone correct me if I'm wrong but I don't believe blizzard does anything like this without signing up for either the mobile or call-in authenticator, the latter is free but still a hassle since you have to assign a voice line to it. then people are less likely to use this because you have to jump through a bunch of hoops, instead of a simple opt-in service like steam. it's like squishing an ant with a sledgehammer.
 
steam forums are back up now btw.





people just want a neato toy that spits out random tokens, because they think requiring a seperate device somehow makes it more secure. whoever here has heard about the recent RSA secureID government breach deploying a similar scheme would know that it's just as vulnerable. if/when someone manages to figure out the seed algo used to generate these numbers, blizzard is fucked just the same.

interesting reading on such number generating trinkets we put our faith in:
http://arstechnica.com/security/new...nt-allow-direct-attack-on-secureid-tokens.ars

steamguard acts on the same principle, instead of relying on a common seed to generate this number through a device, they will ask you to confirm client logins from new locations by generating a token link to reply through email. that way you get the exact same security without requiring an extra device, why doesn't blizzard deploy such a simple yet effective means of keeping our accounts safe? because they want to sell you some toys.

someone correct me if I'm wrong but I don't believe blizzard does anything like this without signing up for either the mobile or call-in authenticator, the latter is free but still a hassle since you have to assign a voice line to it. then people are less likely to use this because you have to jump through a bunch of hoops, instead of a simple opt-in service like steam. it's like squishing an ant with a sledgehammer.

I was saying steam guard is the solution to your password being the only thing protecting your account.
 
^^right and I totally agree, point being steamguard is more effective because people are more likely to use it, and it's less susceptible to single point vulnerabilities that even professional security firms are falling victim to. that's why Gabe felt confident enough to make his steam login public, because he knows that anyone trying to take his account will get nowhere, when they have to confirm ownership through an address that only he has access to.
 
Last edited:
Back
Top