Hacker News new | ask | show | jobs
by simongr3dal 1985 days ago
I’m just annoyed that Steam still doesn’t support standard TOTP two factor but uses either an email code or their app.
2 comments

If you root your phone you can get the secret out and use it with regular TOTP software that implements that variant (I forgot the name - I just know Bitwarden supports it).
There are some desktop implementations of Steam TOTP client, so you don't even need a rooted phone, as long as you trust some random open source code. https://github.com/KeeTrayTOTP/KeeTrayTOTP#documentation
> In the case of Steam Mobile Authenticator the new output format was reverse engineered by various developers

Oh, so it was a custom one! Was convinced that it was a less used standard algo.

Not just that, I just noticed that the Steam app does not support iPhone backups. Blizzard app does, as does the Verisign VIP Access app. Pretty lame. The restore SMS didn’t arrive on time either that evening, fun!