170
submitted 7 months ago by neme@lemm.ee to c/games@sh.itjust.works
all 30 comments
sorted by: hot top controversial new old
[-] subtext@lemmy.world 78 points 7 months ago

TL;DR

We have examined the leak sample and have determined this was NOT a breach of Steam systems.

You do not need to change your passwords or phone numbers as a result of this event. It is a good reminder to treat any account security messages that you have not explicitly requested as suspicious. We recommend regularly checking your Steam account security at any time at https://store.steampowered.com/account/authorizeddevices

[-] bappity@lemmy.world 9 points 7 months ago
[-] Shortstack@reddthat.com 7 points 7 months ago

This is why on steam I don’t store my credit card information, nor on basically any other site that I can get away with it.

Yeah it is a pain in the ass for the times I want to buy something, having to put it the card details every single time, but it’s worth my peace of mind if a breach happens. By this point I have memorized my card numbers so it’s not too awful of a pendantic habit now.

[-] eager_eagle@lemmy.world 6 points 7 months ago

It's a credit card, you can dispute charges and will likely get a refund.

I've done it a few times for different reasons.

[-] Shortstack@reddthat.com 1 points 7 months ago

So have I, but weigh that against the hassle of needing to call and be on hold and so on. Let alone the additional burden of knowing I have to stay on top of checking my statements for fraudulent charges

I’d rather avoid all that by never letting it grow to be a problem

[-] eager_eagle@lemmy.world 1 points 7 months ago* (last edited 7 months ago)

I've always done it on the app, no phone call or chat. But regardless, it's not like it's going to happen. I have my cc info (and throwaway cards like privacy.com) in several websites and nothing like this ever happened. All times I've requested a refund was due to the service/product not being what was promised, not due to a data leak. The convenience definitely beats the risk.

[-] stringere@sh.itjust.works 3 points 7 months ago

Just accidentally memorize it from having to manually pay a bunch of bills online in a short span!

[-] flandish@lemmy.world 2 points 7 months ago

i use privacy.com with a virtual card with a vendor lock and max limit. it also helps remind me when I’m spending too much there … 😂

That's nice, but their refusal to support linking to credit cards made me abandon using their cards.

[-] Shortstack@reddthat.com 1 points 7 months ago

That’s for a very good reason that they don’t allow that.

If it was allowed it would be a wet dream for credit card churning

[-] Shortstack@reddthat.com 1 points 7 months ago

Yeah, but you lose out on credit card rewards, aka free money, going that route.

I’ve used them a couple times where my privacy was worth more, and once where I didn’t want a company having a card to put recurring charges on

Technically it costs money even if their fees are forgettable.

[-] chemical_cutthroat@lemmy.world 1 points 7 months ago

Most banks will offer virtual cards. You can use those instead of your actual card number, and if they get stolen you just cancel that virtual card, but your account is untouched.

[-] Jimmycakes@lemmy.world 1 points 7 months ago

I only use those for short term and set them to expire after a month or however long I need them for on that site. Great way to make sure I don't auto renew anything and if it gets stolen it's already expired. As long as it's a credit card even if there is fraud they pay you back instantly. Never ever store a debit card anywhere.

[-] bitwolf@sh.itjust.works 4 points 7 months ago

I would really like to auth my steam account with a normal TOTP app.

I know you can extract the TOTP from Steam authenticator but there's risk involved with it.

[-] Fitzsimmons@lemmy.blahaj.zone 1 points 7 months ago
[-] bitwolf@sh.itjust.works 2 points 7 months ago

Doing it wrong and losing access.

Can you fallback to email pin if you lose your steam authenticator?

[-] xuv@lemmy.blahaj.zone 2 points 7 months ago

Yes, you can reset to email in case you break your phone or something. It's one of the account recovery options.

Some logins now require an interactive prompt in the app instead of a TOTP code though. I see them when my IP address changes due to VPN endpoints lately.

[-] Diurnambule@jlai.lu 4 points 7 months ago

Two factor auth clan

[-] purplemonkeymad@programming.dev 1 points 7 months ago

So far it either sounds like they are replaying the message, or it's just a (partial) list of numbers that used steam. Might be good for targeting, but that is about it. They would have to know the associated account to do any intercept attacks.

this post was submitted on 14 May 2025
170 points (98.3% liked)

Games

22361 readers
31 users here now

Video game news oriented community. No NanoUFO is not a bot :)

Posts.

  1. News oriented content (general reviews, previews or retrospectives allowed).
  2. Broad discussion posts (preferably not only about a specific game).
  3. No humor/memes etc..
  4. No affiliate links
  5. No advertising.
  6. No clickbait, editorialized, sensational titles. State the game in question in the title. No all caps.
  7. No self promotion.
  8. No duplicate posts, newer post will be deleted unless there is more discussion in one of the posts.
  9. No politics.

Comments.

  1. No personal attacks.
  2. Obey instance rules.
  3. No low effort comments(one or two words, emoji etc..)
  4. Please use spoiler tags for spoilers.

My goal is just to have a community where people can go and see what new game news is out for the day and comment on it.

Other communities:

Beehaw.org gaming

Lemmy.ml gaming

lemmy.ca pcgaming

founded 2 years ago
MODERATORS