

deleted by creator
deleted by creator
Valve literally told the guy who spread the news on Twitter that they do not use Twillo as a SMS 2FA provider at all: https://twitter.com/MellowOnline1/status/1922458687316074640
Good on TechRadar for actually bothering to mention BleepingComputer’s article about it, but they still didn’t mention where the news originated from.
It all began in this LinkedIn post, which wrongfully claimed that the “leak” was coming from Twillo (Also funny is that this is an AI company): https://www.linkedin.com/posts/underdark-ai_cybersecurity-databreach-steam-activity-7327022917370703872-JqN3/
Then the Twitter guy got involved in it, then the “news” sites ran off with what the guy on Twitter said.
Lemme just quote this insightful comment in Steam subreddit as well: https://www.reddit.com/r/Steam/comments/1kmeoqo/steam_doesnt_use_twillo_no_need_to_change/ms9n1xx/
To clarify why changing your passwords is basically pointless
- Steam does not use Twillo for its MFA implementation. Twillo doesnt store the keys for the MFA implementation.
- Twillo doesn’t store passwords, meaning even if you assume Twillo was breached, it has no passwords to leak.
- Twillo only has a centralized MFA app similar to Google Authenticator. Again this does NOT STORE PASSWORDS
- If Twillo was compromised, the only possible vector would be an SMS hijacking attack, and that’s IF Steam uses Twillo as its SMS intermediary
- If we assume #4 then, which is a stretch, CHANGING YOUR PASSWORD IS POINTLESS. Its attacking the SMS network. You can change your password every other minute. The attacker can simply generate and SMS code and take over your account that way. Your password is pointless in this scenario
- If you are ‘paranoid’ and want to do something ‘actually useful’ remove your phone number from your account, which still again makes a LOT of assumptions above everything tl;dr changing your password is pointless, remove your phone number if you are ‘paranoid’
Change your passwords if you want to, but there is no need to panic.
Btw, selling 89 MILLION Steam accounts’ data for just 5000$? Really???
Like legit, the guy hates Ataturk’s guts, yet these idiots claim that he is a Kemalist.
I want what they are smoking. Must be some pretty good shit.
Ah yes, the guy who had no ill will towards anybody, tried to unify people to the best of his ability, and provided cheaper food for the poor… is a Nazi!
Holy shit, the sheer stupidity needed to come up with such a take!
It comes from Terry A. Davis’s description of CIA, FBI and the like: “They glow in the dark”
I love how people immediately downvoted you to hell for this lmfao.
Like yeah, the guys on the comments: only people use rm -rf, absolutely no scripts use it at all. Something like motherfucking STEAM absolutely didn’t remove people’s data that one time. And hey, their so beloved
--no-preserve-root
didn’t prevent that from happening. :DI love and currently use Linux, but my GOD some Linux people are annoying.
If something like
del C:\*.*
somehow ended up deleting your D: drive too, we wouldn’t stop hearing the end of it, but here on Linux systems, it is a perfectly normal thing, and people somehow DEFEND this atrocity lmfao.rm shouldn’t exist at its current form. Full stop.