Installed Steam on a new computer. Signed in. It sent a passcode to my GMail. I signed into GMail. It wanted me to 2FA because I hadn’t signed into Google on that device. It sent a notification to my phone, which I never received. I had it resend the notification twice, still nothing. Tried again with my phone’s offline passcodes. Neither worked. Tried the QR code/Bluetooth connection, and that finally did it.

At least I got through in the end, but fuck, it’s annoying.

  • chickentendrils@lemmy.ml
    link
    fedilink
    English
    arrow-up
    5
    ·
    edit-2
    1 day ago

    Yeah for Steam you have to use 3rd party tools or pull a file off your mobile device/emulator and extract the TOTP secret (and use plugins for password managers to render the alphanumeric code with the characters they want, it’s just a non-standard TOTP representation and sucks so much).

    The maker of that “Authy” shit that’s just TOTP generator/backup once again locked behind your fuckin phone number deserves a special place in hell. It’s Twilio, a virtual phone/SMS API provider… and owner of Sendgrid. Same deal as with Steam where they’ll add the TOTP secret to the Authy app and you have to extract it manually to use in a different app/password manager. At least the codes are part of the IETF standard. Just generated with an uncommon <30s step interval for rolling over and I believe are 7 digits instead of 6. KeepassXC natively had configuration for it at least.