• 3 Posts
  • 23 Comments
Joined 2 years ago
cake
Cake day: June 28th, 2023

help-circle

  • Valve literally told the guy who spread the news on Twitter that they do not use Twillo as a SMS 2FA provider at all: https://twitter.com/MellowOnline1/status/1922458687316074640

    Good on TechRadar for actually bothering to mention BleepingComputer’s article about it, but they still didn’t mention where the news originated from.

    It all began in this LinkedIn post, which wrongfully claimed that the “leak” was coming from Twillo (Also funny is that this is an AI company): https://www.linkedin.com/posts/underdark-ai_cybersecurity-databreach-steam-activity-7327022917370703872-JqN3/

    Then the Twitter guy got involved in it, then the “news” sites ran off with what the guy on Twitter said.

    Lemme just quote this insightful comment in Steam subreddit as well: https://www.reddit.com/r/Steam/comments/1kmeoqo/steam_doesnt_use_twillo_no_need_to_change/ms9n1xx/

    To clarify why changing your passwords is basically pointless

    1. Steam does not use Twillo for its MFA implementation. Twillo doesnt store the keys for the MFA implementation.
    2. Twillo doesn’t store passwords, meaning even if you assume Twillo was breached, it has no passwords to leak.
    3. Twillo only has a centralized MFA app similar to Google Authenticator. Again this does NOT STORE PASSWORDS
    4. If Twillo was compromised, the only possible vector would be an SMS hijacking attack, and that’s IF Steam uses Twillo as its SMS intermediary
    5. If we assume #4 then, which is a stretch, CHANGING YOUR PASSWORD IS POINTLESS. Its attacking the SMS network. You can change your password every other minute. The attacker can simply generate and SMS code and take over your account that way. Your password is pointless in this scenario
    6. If you are ‘paranoid’ and want to do something ‘actually useful’ remove your phone number from your account, which still again makes a LOT of assumptions above everything tl;dr changing your password is pointless, remove your phone number if you are ‘paranoid’

    Change your passwords if you want to, but there is no need to panic.

    Btw, selling 89 MILLION Steam accounts’ data for just 5000$? Really???





  • I feel like as long as there is money to be gained from it (be it via clicks or whatever), these people will stay.

    So you gotta, in video game terms, “hit the boss on its weakpoint”.

    What also grinds my gears is that one guy in there who ban evaded twice, everyone else knows who they are, yet they still remain on the forums to this day. If that doesn’t tell anybody that that site has a serious moderation problem, I don’t know what will.


  • This is all entirely Michael’s fault because he refuses to have anything resembling of a moderation.

    Use adblockers. Never give him any of your precious money. He doesn’t deserve a single penny of it.

    Edit: Fun fact: Karol also stopped visiting Phoronix forums a fair bit of time ago. GEE, I wonder what caused it to happen?

    Edit 2: That particular forum post is now loginwalled LMFAO





  • This looks promising. I always yearned for Foobar2000 to be on Linux natively.

    However layout editor part is quite confusing (adding widgets seem to add them not where I want them at), and I couldn’t get it to play any music, as both drag and drop to a playlist and open file option in the menu causes the program to crash. Plugins didn’t load at all until I manually copied them to the places fooyin was looking for, though I wonder if this is an AUR package issue or not.

    I’ll keep using DeaDBeeF despite some complaints I have with it for the time being, and will keep a close eye on this one.



  • The reason it is so shit is that because there is NO moderation whatsoever (nor there is any care for having it, as there wouldn’t be cases like someone that had done ban evasion twice still being active on the forums otherwise). And I think I can safely say that it is just like the same as other social media:

    More heated and stupid arguments = more page clicks and views = more ad revenue (Michael definitely inserts some ads into the forums, like come on now)

    I have absolutely no regrets using adblockers on there (or internet-wide), and Michael has the GALL to call his subscription service “Premium”… unbeknownst to him that a golden coated excrement is in the end… still a piece of excrement. :V



  • So people are catching up to the fact that the thing everyone loves to call “AI” is nothing more than just a phone autocorrect on steroids, as the pieces of electronics that can only execute a set of commands in order isn’t going to develop a consciousness like the term implies; and the very same Crypto/NFTbros have been moved onto it so that they can have some new thing to hype as well as in the case of the latter group, can continue stealing from artists?

    Good.