The cryptography behind passkeys (blog.trailofbits.com)
235 points by tatersolid 1d ago 213 comments
Updated rate limits for unauthenticated requests (github.blog)
92 points by xena 5d ago 125 comments
A note about the security of your Steam account
14 taubek 8 5/15/2025, 6:29:09 AM store.steampowered.com ↗
Statement from Valve
So not really an issue.
One of my friends was known to quip that Steam had better security than most banks, even in the early days. And it's true that Steam accounts host data and purchases that are quite valuable to the customers, as well as highly attractive to thieves, so customers do well to protect their accounts to the fullest extent.
A long time ago I was the holder of a Steam account, and I was once notified in email that someone had successfully entered both my username and password, since the password was trivial and/or reused from some other account I had. Since the account was still protected by MFA, I chose to take no action at all. But I believe that the perpetrator had some sort of Russian connection, IPv4 geolocation or something. But it was clearly an instance of: https://m.xkcd.com/2176/
Switching from sms mfa to their in app mfa will protect you against this type of leak in the future.