Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse

NodeBB

  1. Home
  2. Games
  3. You can now use authenticator apps to keep your GOG account secure!

You can now use authenticator apps to keep your GOG account secure!

Scheduled Pinned Locked Moved Games
games
38 Posts 20 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • sonotsugipaa@lemmy.dbzer0.comS [email protected]

    What does GOG's 2FA do that Steam's 2FA doesn't?

    N This user is from outside of this forum
    N This user is from outside of this forum
    [email protected]
    wrote last edited by [email protected]
    #8

    At a glance (haven't enabled yet, will later today), GoG uses the RFC standard TOTP model. This means you can use whatever app you want whether that is the google authenticator that ties it to your cloud account, something related to your password manager (e.g. keepass or bitwarden), or even just a python script you have in a random directory. It gives you control of your 2FA and protects you in the event you lose a device without properly de-authenticating it.

    Valve use their own model that, to my knowledge, is only accessible through the Steam mobile app. Which is a huge nightmare if you ever have a device stolen/damaged (and is why you back up the recovery code)


    Just enabled. Yup, bog standard TOTP and they even provide the plaintext key so that I don't have to extract it from a QR code.

    1 Reply Last reply
    24
    • sonotsugipaa@lemmy.dbzer0.comS [email protected]

      What does GOG's 2FA do that Steam's 2FA doesn't?

      R This user is from outside of this forum
      R This user is from outside of this forum
      [email protected]
      wrote last edited by
      #9

      Unless I’m missing something, Steam only does code to email 2FA, not an actual TOTP app

      ulrich@feddit.orgU sonotsugipaa@lemmy.dbzer0.comS 2 Replies Last reply
      5
      • sonotsugipaa@lemmy.dbzer0.comS [email protected]

        What does GOG's 2FA do that Steam's 2FA doesn't?

        ulrich@feddit.orgU This user is from outside of this forum
        ulrich@feddit.orgU This user is from outside of this forum
        [email protected]
        wrote last edited by [email protected]
        #10

        It presumably works with a normal TOTP app.

        E: confirmed it works

        sonotsugipaa@lemmy.dbzer0.comS 1 Reply Last reply
        6
        • R [email protected]

          Unless I’m missing something, Steam only does code to email 2FA, not an actual TOTP app

          ulrich@feddit.orgU This user is from outside of this forum
          ulrich@feddit.orgU This user is from outside of this forum
          [email protected]
          wrote last edited by
          #11

          They have TOTP but only in their app.

          R 1 Reply Last reply
          9
          • ulrich@feddit.orgU [email protected]

            They have TOTP but only in their app.

            R This user is from outside of this forum
            R This user is from outside of this forum
            [email protected]
            wrote last edited by
            #12

            So effectively, they don’t do what GOG is doing.

            ulrich@feddit.orgU 1 Reply Last reply
            4
            • R [email protected]

              So effectively, they don’t do what GOG is doing.

              ulrich@feddit.orgU This user is from outside of this forum
              ulrich@feddit.orgU This user is from outside of this forum
              [email protected]
              wrote last edited by
              #13

              Not exactly, no

              1 Reply Last reply
              2
              • moe90@feddit.nlM [email protected]
                This post did not contain any content.
                antibullyranger@ani.socialA This user is from outside of this forum
                antibullyranger@ani.socialA This user is from outside of this forum
                [email protected]
                wrote last edited by [email protected]
                #14

                2FA (Time-based One-Time Password) login

                Gog, how are you even securing accounts?
                You mean securing access to accounts through 3rd party TOTP, which again, isn't sessioning access authenticatively. We already invented that.

                1 Reply Last reply
                2
                • ulrich@feddit.orgU [email protected]

                  It presumably works with a normal TOTP app.

                  E: confirmed it works

                  sonotsugipaa@lemmy.dbzer0.comS This user is from outside of this forum
                  sonotsugipaa@lemmy.dbzer0.comS This user is from outside of this forum
                  [email protected]
                  wrote last edited by
                  #15

                  Steam works with a normal TOTP app for me, hell, it works with two normal TOTP apps for me

                  ulrich@feddit.orgU 1 Reply Last reply
                  4
                  • R [email protected]

                    Unless I’m missing something, Steam only does code to email 2FA, not an actual TOTP app

                    sonotsugipaa@lemmy.dbzer0.comS This user is from outside of this forum
                    sonotsugipaa@lemmy.dbzer0.comS This user is from outside of this forum
                    [email protected]
                    wrote last edited by
                    #16

                    Steam works with a normal TOTP app for me, hell, it works with two normal TOTP apps for me

                    R 1 Reply Last reply
                    1
                    • sonotsugipaa@lemmy.dbzer0.comS [email protected]

                      Steam works with a normal TOTP app for me, hell, it works with two normal TOTP apps for me

                      R This user is from outside of this forum
                      R This user is from outside of this forum
                      [email protected]
                      wrote last edited by
                      #17

                      Teach a brother how? I swear I couldn’t find it anywhere in the account settings.

                      sonotsugipaa@lemmy.dbzer0.comS 1 Reply Last reply
                      1
                      • R [email protected]

                        Now when will Steam do this?

                        G This user is from outside of this forum
                        G This user is from outside of this forum
                        [email protected]
                        wrote last edited by
                        #18

                        Idk why people think they cant add steam, i have it in my Aegis app.

                        sunny@slrpnk.netS mangopenguin@lemmy.blahaj.zoneM 2 Replies Last reply
                        12
                        • sonotsugipaa@lemmy.dbzer0.comS [email protected]

                          Steam works with a normal TOTP app for me, hell, it works with two normal TOTP apps for me

                          ulrich@feddit.orgU This user is from outside of this forum
                          ulrich@feddit.orgU This user is from outside of this forum
                          [email protected]
                          wrote last edited by
                          #19

                          I'm pretty sure it doesn't but I'll bite: How did you set that up?

                          sonotsugipaa@lemmy.dbzer0.comS 1 Reply Last reply
                          4
                          • R [email protected]

                            Teach a brother how? I swear I couldn’t find it anywhere in the account settings.

                            sonotsugipaa@lemmy.dbzer0.comS This user is from outside of this forum
                            sonotsugipaa@lemmy.dbzer0.comS This user is from outside of this forum
                            [email protected]
                            wrote last edited by [email protected]
                            #20

                            I don't quite remember how to get the TOTP secret from the Steam app (they could in fact take notes from GOG here), iirc you have to extract it from the Android app via adb;
                            but once you have it, if this GitHub comment is correct you simply have to set the code size to 5 digits.

                            If your phone has a rooted Android install, I found this guide.

                            ... I swear when I did it, it wasn't this hard ._.

                            1 Reply Last reply
                            4
                            • ulrich@feddit.orgU [email protected]

                              I'm pretty sure it doesn't but I'll bite: How did you set that up?

                              sonotsugipaa@lemmy.dbzer0.comS This user is from outside of this forum
                              sonotsugipaa@lemmy.dbzer0.comS This user is from outside of this forum
                              [email protected]
                              wrote last edited by
                              #21

                              I don't recall, I've set it up a few years ago - I've been trying to look for instructions for another comment, but it seems that they made it VERY difficult for people without rooted Android to obtain the TOTP secret.

                              Though it is RFC 6238 compliant, using 5 digits instead of 6.

                              ulrich@feddit.orgU 1 Reply Last reply
                              2
                              • b0nk3rs@lemmy.worldB [email protected]

                                Thanks for this. Long overdue from GOG.

                                M This user is from outside of this forum
                                M This user is from outside of this forum
                                [email protected]
                                wrote last edited by
                                #22

                                Their platform is really outdated. Can’t even edit or remove a game review without contacting support. It’s dumb. They’re losing precious time because of this

                                S mitm0@lemmy.worldM lootboblin@lemmy.worldL M 4 Replies Last reply
                                8
                                • sonotsugipaa@lemmy.dbzer0.comS [email protected]

                                  I don't recall, I've set it up a few years ago - I've been trying to look for instructions for another comment, but it seems that they made it VERY difficult for people without rooted Android to obtain the TOTP secret.

                                  Though it is RFC 6238 compliant, using 5 digits instead of 6.

                                  ulrich@feddit.orgU This user is from outside of this forum
                                  ulrich@feddit.orgU This user is from outside of this forum
                                  [email protected]
                                  wrote last edited by [email protected]
                                  #23

                                  Okay, let's say there's currently no native support for normal TOTP, mostly because Steam doesn't give you access to your TOTP key.

                                  sonotsugipaa@lemmy.dbzer0.comS 1 Reply Last reply
                                  4
                                  • ulrich@feddit.orgU [email protected]

                                    Okay, let's say there's currently no native support for normal TOTP, mostly because Steam doesn't give you access to your TOTP key.

                                    sonotsugipaa@lemmy.dbzer0.comS This user is from outside of this forum
                                    sonotsugipaa@lemmy.dbzer0.comS This user is from outside of this forum
                                    [email protected]
                                    wrote last edited by
                                    #24

                                    That much I can agree with at this point.

                                    Actually, it's arguably even worse - it's not that Steam doesn't support normal TOTP, it's that Steam goes out of their way to prevent TOTP from being used without switching to an entirely new algorithm.

                                    ulrich@feddit.orgU 1 Reply Last reply
                                    1
                                    • sonotsugipaa@lemmy.dbzer0.comS [email protected]

                                      That much I can agree with at this point.

                                      Actually, it's arguably even worse - it's not that Steam doesn't support normal TOTP, it's that Steam goes out of their way to prevent TOTP from being used without switching to an entirely new algorithm.

                                      ulrich@feddit.orgU This user is from outside of this forum
                                      ulrich@feddit.orgU This user is from outside of this forum
                                      [email protected]
                                      wrote last edited by [email protected]
                                      #25

                                      Could be worse. GOG's approach is super annoying, and a lot of platforms (like fucking Apple) actually require the use of insecure and invasive SMS verification. And as far as I know Steam hasn't been hit with any data breaches since 2011.

                                      sonotsugipaa@lemmy.dbzer0.comS 1 Reply Last reply
                                      1
                                      • moe90@feddit.nlM [email protected]
                                        This post did not contain any content.
                                        B This user is from outside of this forum
                                        B This user is from outside of this forum
                                        [email protected]
                                        wrote last edited by
                                        #26

                                        About time

                                        1 Reply Last reply
                                        4
                                        • moe90@feddit.nlM [email protected]
                                          This post did not contain any content.
                                          P This user is from outside of this forum
                                          P This user is from outside of this forum
                                          [email protected]
                                          wrote last edited by
                                          #27

                                          Thanks, and added.

                                          Although it would have been nice if I could "upgrade" from email based 2step instead of having to disable it.

                                          1 Reply Last reply
                                          2
                                          Reply
                                          • Reply as topic
                                          Log in to reply
                                          • Oldest to Newest
                                          • Newest to Oldest
                                          • Most Votes


                                          • Login

                                          • Login or register to search.
                                          Powered by NodeBB Contributors
                                          • First post
                                            Last post
                                          0
                                          • Categories
                                          • Recent
                                          • Tags
                                          • Popular
                                          • World
                                          • Users
                                          • Groups