• Hey, guest user. Hope you're enjoying NeoGAF! Have you considered registering for an account? Come join us and add your take to the daily discourse.

STEAM | December 2015 - _ Diretide Greetings and Happy Holidailies

Status
Not open for further replies.

Nzyme32

Member
Steam / Valve have release a rather long explanation for their Security and Trading initiatives:

Recently we've seen the community have a good discussion about the pros and cons of trade holds. We thought we'd walk through how we decided to implement them, in the hopes that it helps you understand why they're absolutely necessary.



Compromised accounts and item theft

Account theft has been around since Steam began, but with the introduction of Steam Trading, the problem has increased twenty-fold as the number one complaint from our users. Having your account stolen, and your items traded away, is a terrible experience, and we hated that it was becoming more common for our customers.

Once an account was compromised, the items would be quickly cleaned out. They'd then be traded again and again, eventually being sold to an innocent user. Looking at their account activity, it wasn't too hard to figure out what happened, but undoing it was harder because we don't want to take things away from innocent users. We decided to err on the side of protecting them: we left the stolen goods, and we created duplicates on the original compromised account to replace them. We were fully aware of the tradeoff here. Duplicating the stolen items devalues all the other equivalent items in the economy. This might be fairly minor for common items, but for rare items this had the potential to significantly increase the number in existence.



The number of hijacked accounts continues to grow

This was an unacceptable status quo and we needed to address it. In revisiting our strategy to stop it, we found two things of note.

First, enough money now moves around the system that stealing virtual Steam goods has become a real business for skilled hackers. Second, practically every active Steam account is now involved in the economy, via items or trading cards, with enough value to be worth a hacker's time. Essentially all Steam accounts are now targets.

The "I got hacked" story is told so frequently it's become commonplace. And that makes it easy to forget its significance; compromised security of email accounts and PCs, Steam account violation, and theft. We used to hold the opinion that if you were smart about account security, you'd be protected--it's easy to assume that users whose accounts were stolen were new or technically naïve users who must be sharing their passwords or clicking on suspicious links. That's simply not the case.

What used to be a handful of hackers is now a highly effective, organized network, in the business of stealing and selling items. It would be easier for them to go after the users who don't understand how to stay secure online, but the prevalence of items make it worthwhile to target everyone. We see around 77,000 accounts hijacked and pillaged each month. These are not new or naïve users; these are professional CS:GO players, reddit contributors, item traders, etc. Users can be targeted randomly as part of a larger group or even individually. Hackers can wait months for a payoff, all the while relentlessly attempting to gain access. It's a losing battle to protect your items against someone who steals them for a living.

We can help users who've been hacked by restoring their accounts and items, but that doesn't deter the business of hacking accounts. It's only getting worse.



How we can stop it

We've worked to improve account security features, closed loopholes, improved how and when we message users that their account is at risk, added self-locking, and created the Steam Guard Mobile Authenticator (two-factor authentication).

Two-factor authorization is the use of a separate device to confirm your identity. The security of this system is based on moving that step from your PC to a device a hacker can't access, such as your smartphone. PCs can be easily compromised, therefore a PC-based authenticator would not provide better security than a password or email authentication.

We needed to create our own two-factor authenticator because we need to show users the contents of the trade on a separate device and have them confirm it there. Requiring users to take a code from a generic authenticator and enter it into a hijacked PC to confirm a trade meant that hackers could trick them into trading away items they didn't intend to. This basically made it impossible to use a generic third party authenticator, such as Google Authenticator, to confirm trades.



Here's the tradeoff

At this time, most people have not protected their account with this increased level of security. Many don't believe that they are actually a worthwhile target for a hacker who's out to make money. Some felt they were smart enough about security to not need two-factor authorization. And other users knew they needed it, but couldn't use it due to reasons beyond their control, like not having access to a mobile phone.

So what if instead of trying to prevent hackers from being able to steal a Steam account that hasn't enabled two-factor authentication, we tried removing their ability to profit from the theft. If hackers couldn't move the stolen goods off the hacked account, then they couldn't sell them for real money, and that would remove the primary incentive to steal the account. Hackers fundamentally rely on trading to offload stolen goods. The Steam Community Market doesn't work well for that purpose, because purchases can't be moved around as quickly (purchased items can't be traded for 7 days), and they can't ensure the items move to an account they control.

One option proposed was to simply remove trading. The Steam Market already accounted for the vast majority of virtual goods exchanged by Steam users. We even generate revenue off those transactions, which helps cover the cost of fraud, unlike person-to-person trades. And removing trading was by far the easiest solution to implement. But we felt that was a bad choice for users. Another easy choice would have been to require two-factor authentication for trading, but that's bad for the same reasons as removing it entirely. It's important that you can give a friend a TF2 weapon when he comes to try out the game, or give a friend the last trading card she needs to craft a game badge.

We felt that two-factor authentication was secure enough that it would protect anyone who enabled it, so the problem was the accounts that couldn't enable it (e.g. no mobile phone access). In the end, we arrived at the changes we're deploying today:

Anyone losing items in a trade will need to have a Steam Guard Mobile Authenticator enabled on their account for at least 7 days and have trade confirmations turned on. Otherwise, items will be held by Steam for up to 3 days before delivery.

If you've been friends for at least 1 year, items will be held by Steam for up to 1 day before delivery.

Accounts with a Mobile Authenticator enabled for at least 7 days are no longer restricted from trading or using the Market when using a new device since trades on the new device will be protected by the Mobile Authenticator.


This means that anyone using the Steam Guard Mobile Authenticator to confirm trades is able to continue trading as always. Users who haven't enabled it, or can't, can still trade, but they'll have to wait up to 3 days for the trade to go through. This gives both Steam and users the time to discover their accounts have been hacked and recover it before the hackers can steal their items.



A difficult balance

Once again, we're fully aware that this is a tradeoff with the potential for a large impact on trading. Any time we put security steps in between user actions and their desired results, we're making it more difficult to use our products. Unfortunately, this is one of those times where we feel like we're forced to insert a step or shut it all down. Asking users to enter a password to log into their account isn't something we spend much time thinking about today, but it's much the same principle - a security cost we pay to ensure the system is able to function. We've done our best to make the cost as small as possible, for as few people as possible, while still retaining its effectiveness.

Hopefully this post has given you some insight into the problem, and why we've taken this approach. As always, we'll continue to read the community's discussions throughout the Steam forums and the web at large, and we look forward to hearing your thoughts.
 
is hothothot even a proper designation
Lets consult this chart.

CS9IzPmU8AACUg_.jpg
 

Kacho

Member
When is SquareEnix going to port over the Dragon Quest games on Steam? They've brought over most of the Final Fantasy games, now it's time to show Dragon Quest some love. Please. :(
 

CheesecakeRecipe

Stormy Grey

Once an account was compromised, the items would be quickly cleaned out. They'd then be traded again and again, eventually being sold to an innocent user. Looking at their account activity, it wasn't too hard to figure out what happened, but undoing it was harder because we don't want to take things away from innocent users. We decided to err on the side of protecting them: we left the stolen goods, and we created duplicates on the original compromised account to replace them. We were fully aware of the tradeoff here. Duplicating the stolen items devalues all the other equivalent items in the economy. This might be fairly minor for common items, but for rare items this had the potential to significantly increase the number in existence.

That's an impressive amount of transparency on Valve's part. It makes sense that they wouldn't want to anger users, but I can't think of an instance where users would have noticed that in practice. Really bold of them to admit, but it seems they want to go all-in to explain themselves on why heightened security measures are becoming a focus for them.
 

Ambitious

Member
Hello there, Steam-GAF. One question: Is the Xbox 360 controller still considered the best controller for PC gaming, or do people prefer the XBO controller or the DS4 now? I'm thinking about buying a controller for my younger brother for Christmas.
I found a thread asking this very question, and it seems to be close to a tie between XB360 and DS4.
 

Dr.Acula

Banned
Who knew that idling for cards and selling out my entire inventory was actually protecting me from becoming targeted? Neat.
 

chronomac

Member
Hello there, Steam-GAF. One question: Is the Xbox 360 controller still considered the best controller for PC gaming, or do people prefer the XBO controller or the DS4 now? I'm thinking about buying a controller for my younger brother for Christmas.
I found a thread asking this very question, and it seems to be close to a tie between XB360 and DS4.

I've had a few issues with the Xbox One controller, specifically with drivers, but it when it works it's the best. If nothing else, it has a much better d-pad than the 360 controller, so if you play side-scrollers or anything like that it's probably worth it.
 

jshackles

Gentlemen, we can rebuild it. We have the capability to make the world's first enhanced store. Steam will be that store. Better than it was before.
That's an impressive amount of transparency on Valve's part. It makes sense that they wouldn't want to anger users, but I can't think of an instance where users would have noticed that in practice. Really bold of them to admit, but it seems they want to go all-in to explain themselves on why heightened security measures are becoming a focus for them.

That's what I thought too. It's strange reading the news section of Steam and actually hearing news about Steam.

Hello there, Steam-GAF. One question: Is the Xbox 360 controller still considered the best controller for PC gaming, or do people prefer the XBO controller or the DS4 now? I'm thinking about buying a controller for my younger brother for Christmas.
I found a thread asking this very question, and it seems to be close to a tie between XB360 and DS4.

Most people (myself included) upgraded from the Xbox 360 controller to the XBO controller. Lots of people use DS4 and the WiiU Pro, but they still require third party drivers.

Lots of people like the Steam Controller.
 
Hello there, Steam-GAF. One question: Is the Xbox 360 controller still considered the best controller for PC gaming, or do people prefer the XBO controller or the DS4 now? I'm thinking about buying a controller for my younger brother for Christmas.
I found a thread asking this very question, and it seems to be close to a tie between XB360 and DS4.

I have a xbone and wireless adapter never had any problems, plug and play no driver install or anything (Windows 10). The headphone jack on the controller is awesome. As for the controller itself it is very much the same as the 360, I have yet to do too much dpadding though.
 

jshackles

Gentlemen, we can rebuild it. We have the capability to make the world's first enhanced store. Steam will be that store. Better than it was before.
so does blood and bullets or whatsitelliotpess name but i don't play it either

You should fix that. Blues and Bullets was pretty rad, and apparently episode 2 is coming out sometime soon.
 

Locust

Member
Hello there, Steam-GAF. One question: Is the Xbox 360 controller still considered the best controller for PC gaming, or do people prefer the XBO controller or the DS4 now? I'm thinking about buying a controller for my younger brother for Christmas.
I found a thread asking this very question, and it seems to be close to a tie between XB360 and DS4.
Xbone controller is pretty good yeah, just make sure its the one with the headphone jack. The bumpers on the old version are shite.
 

FLD

Member
When is SquareEnix going to port over the Dragon Quest games on Steam? They've brought over most of the Final Fantasy games, now it's time to show Dragon Quest some love. Please. :(

I know, right? Now that FFX is all but confirmed, they're pretty much done with the FF back catalogue. If they don't start porting the DQ mobile ports next, I'm going to be so sad. I really hope Dragon Quest Heroes was just the beginning.

I only played DQVIII and I want to play the other ones, damnit! If they don't announce something soon, I'm likely going to cave a get a 3DS next year...
 
I think I've scored more goals and had more points in the few PC matches of Rocket League I've done than I did in every match on PS4 combined
 

jshackles

Gentlemen, we can rebuild it. We have the capability to make the world's first enhanced store. Steam will be that store. Better than it was before.
I know, right? Now that FFX is all but confirmed, they're pretty much done with the FF back catalogue. If they don't start porting the DQ mobile ports next, I'm going to be so sad. I really hope Dragon Quest Heroes was just the beginning.

I only played DQVIII and I want to play the other ones, damnit! If they don't announce something soon, I'm likely going to cave a get a 3DS next year...

The Dragon Quest games might be a little tougher to transition to PC, since the mobile versions are stuck in a fixed portrait mode and the UI is tied to that.

Regarding the ugly as hell FFVI, I really don't understand why SE can't do something like this:

https://www.youtube.com/watch?v=fQrBSO74DzA

Since they are still capable on doing it

Those sprites don't even look as good as the sprites in Final Fantasy Record Keeper. But yeah, I kinda agree even though I don't mind the new graphics.
 

TheSeks

Blinded by the luminous glory that is David Bowie's physical manifestation.
E-mail Subject said:
Resident Evil 0 / biohazard 0 HD REMASTER Is Now Available On Steam!

OH MY GOD IN HEAVEN! CAPCOM STEALTH RELEASED BIOHAZARD ZERO WITHOUT TELLING ANYONE ABOU--

E-mail Body said:
Hello <<Username Here>>
The following item on your wishlist is now available for prepurchase:

--Oh.

Damn it, Valve. Next time at least have an accurate e-mail message title, please? I just about had a heart attack and throwing money at my screen.

Need to pre-order for Cheerleader and RPD Basketball Team Rebecca.
 

accel

Member
Regarding region-locking on Humble - that's pretty evil. If I understand it correctly, right now that's only for South America, but...
 

zkylon

zkylewd
You should fix that. Blues and Bullets was pretty rad, and apparently episode 2 is coming out sometime soon.

ehh, i watched the giantbomb quicklook, was unimpressed

It will add mod support.
The BoI community is huge so someone will probably make som great mods.


Also


You win A FUCKING SWORD.
lol that picture's hilarious

hope modding tools come quick so someone can get rid of those spiders for me
 

Pachimari

Member
I know, right? Now that FFX is all but confirmed, they're pretty much done with the FF back catalogue. If they don't start porting the DQ mobile ports next, I'm going to be so sad. I really hope Dragon Quest Heroes was just the beginning.

I only played DQVIII and I want to play the other ones, damnit! If they don't announce something soon, I'm likely going to cave a get a 3DS next year...

They gotta port Final Fantasy I and II first at least. But the Dragon Quest games are in portrait, and I really don't want them like that on PC.
 

FLD

Member
The Dragon Quest games might be a little tougher to transition to PC, since the mobile versions are stuck in a fixed portrait mode and the UI is tied to that.

Oh right, I forgot about that. And with how Dragon Quest sells in the west, now I'm wondering if they'd even be willing to put the effort into fixing those issues...

Yeah okay, all my optimism is gone now. I need a 3DS for Persona Q and SMTIV, anyway... :(
 

Ludens

Banned
Next year is DQ anniversary, I'm sure SE will do something if DQH will sell enough.

The true shame here is Chrono Trigger still has no PC version, that game is simply a masterpiece.
 

Nzyme32

Member
Hello there, Steam-GAF. One question: Is the Xbox 360 controller still considered the best controller for PC gaming, or do people prefer the XBO controller or the DS4 now? I'm thinking about buying a controller for my younger brother for Christmas.
I found a thread asking this very question, and it seems to be close to a tie between XB360 and DS4.

I enjoyed using the Xbox 360 controller, except the dpad, up till two years ago when it broke. Xbox One is a great improvement but it was my bros so I moved to the DS3 as a temporary solution. However, now I've settled on the Steam Controller. After about 50hrs of use, I'm extremely happy with it for both the normal controller based games and everything else that the Steam Controller can enable thanks to it's features. It's all a matter of taste though, so try what you like and explore options as you go. All of them need drivers but Sony's don't really exist outside of community made ones. Both the Xbox and Steam Controllers are easy to set up
 

madjoki

Member
I have thousands of titles in the queue. Never bothered with it. Wonder if cards drop every x amount of games.

I assume it's something like one per queue (12 items) and 1-3 per day, so it's similar amount than last years. and one complete set for everyone after trading.
 

Ludens

Banned
I'm the only one with messed up time played on Steam during last two weeks?
I lost something like 90 hours on the global time, while it's reported correctly on single games.
 
Status
Not open for further replies.
Top Bottom