Install Steam
login
|
language
简体中文 (Simplified Chinese)
繁體中文 (Traditional Chinese)
日本語 (Japanese)
한국어 (Korean)
ไทย (Thai)
Български (Bulgarian)
Čeština (Czech)
Dansk (Danish)
Deutsch (German)
Español - España (Spanish - Spain)
Español - Latinoamérica (Spanish - Latin America)
Ελληνικά (Greek)
Français (French)
Italiano (Italian)
Bahasa Indonesia (Indonesian)
Magyar (Hungarian)
Nederlands (Dutch)
Norsk (Norwegian)
Polski (Polish)
Português (Portuguese - Portugal)
Português - Brasil (Portuguese - Brazil)
Română (Romanian)
Русский (Russian)
Suomi (Finnish)
Svenska (Swedish)
Türkçe (Turkish)
Tiếng Việt (Vietnamese)
Українська (Ukrainian)
Report a translation problem



The phone number is primarily used as an account recovery mechanism. It is not a primary MFA mechanism Steam uses.
You are no more or less secure using the Steam Mobile Authenticator than you are any other authenticator
Note that the authenticator follows the RFC to the letter. There’s no actual requirement to allow the seed to be used by other authenticator
Plus you then can’t get push notification nor can you use QR code logins either
Which again does not make the Steam Authenticator less secure in any way.
Again the phone SMS is only used for account recovery and is not a primary MFA mechanism.
As I alluded to above, you *are* less secure using the Steam Mobile Authenticator than any other TOTP app because it is built into the Steam app, where most users will already be logged into a Steam account.
If you are that paranoid about the app, the app allows yoh to have biometrics (faceid or fingerprint) to access the entire app or parts of the app. Not to mention this requires physical access to your phone, at which point you’ve already lost
QR code logins and push notifications are not essential features. I have no interest in either. I just want to have a more secure Steam account and participate in the market without 15-day holds without having the Steam app installed.
There would be absolutely nothing wrong with Steam using TOTP via any authenticator app as their primary 2FA method. Most (all?) of Valve's competitors do this, and you could let users set up other 2FA methods for account recovery if they so choose.
Add: Biometrics should never be used as a password: only as a username. If I had my Steam account secured with a separate TOTP app and someone had physical access to my phone, it would do them no good, because they would need a password to access the TOTP code and they would need a different password to access my Steam account information. That is a much more secure setup than keeping an account with access to your credit card information always logged in, which is how the Steam app works.
The Steam Mobile Authenticator is less secure than using a separate TOTP/HTOP app, while simultaneously being inconvenient, as you are required to install an app specifically for Steam if you want to participate in the marketplace without restrictions. My primary concern *is not* security, but Steam's primary justification for the Steam Mobile Authenticator is security, and it is worse at that than just using the same thing everyone else uses, namely TOTP/HOTP. This is why I am calling the SMA a joke, and why I am asking for them to support TOTP/HOTP through any authenticator app that supports those standards.
Just one person?
There are a multitude of people who have never lost access to their Steam account. The very ones who do not give away their account details.
Less secure?
If it is less secure lets test that theory?
What is my account name?
What is my password?
If you get both right i will authorise the login.
As a sidenote: People lose access to Ubisoft, Blizzard, EA accounts etc and what do they all have in common? They do not use the Steam Mobile app you claim is less secure.
It is a discussion forum for suggestions and ideas and there have being numerous threads about the same topic. Valve wants their own app, and they can because like any online business they can choose what is. My bank for example has their own app.