{"id":17913,"date":"2020-03-17T20:33:23","date_gmt":"2020-03-18T04:33:23","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2020\/03\/17\/news-11646\/"},"modified":"2020-03-17T20:33:23","modified_gmt":"2020-03-18T04:33:23","slug":"news-11646","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2020\/03\/17\/news-11646\/","title":{"rendered":"Protecting your Steam account against scammers and trolls"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2020\/03\/11033925\/steam-privacy-security-featured.jpg\"\/><\/p>\n<p><strong>Credit to Author: Leonid Grustniy| Date: Wed, 11 Mar 2020 07:42:18 +0000<\/strong><\/p>\n<p>If you are reading this post, it&#8217;s safe to assume that you have a Steam account. Unfortunately, in addition to Steam&#8217;s millions of bona fide gamers, the platform includes <a href=\"https:\/\/securelist.com\/steam-powered-scammers\/94553\/\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">scammers looking to profit at others&#8217; expense<\/a>. We tell you the security and privacy settings you can use to guard against them.<\/p>\n<ul>\n<li><a href=\"#security\">How to protect your Steam account<\/a>\n<ul>\n<li><a href=\"#security-password\">How to change your Steam password<\/a><\/li>\n<li><a href=\"#security-steam-guard\">How to configure Steam Guard\u00a0\u2014 two-factor authentication on Steam<\/a><\/li>\n<li><a href=\"#security-steam-guard-mobile\">How to set up Steam Guard Mobile Authenticator<\/a><\/li>\n<li><a href=\"#security-devices\">How to ensure that only you are logged in to your account<\/a><\/li>\n<li><a href=\"#security-links\">How to guard against phishing links on Steam<\/a><\/li>\n<\/ul>\n<\/li>\n<li><a href=\"#privacy\">How to configure privacy on Steam<\/a>\n<ul>\n<li><a href=\"#privacy-private-account\">How to make your Steam account private<\/a><\/li>\n<li><a href=\"#privacy-gaming-info\">How to hide game information and your Steam inventory<\/a><\/li>\n<li><a href=\"#privacy-comments\">How to avoid spam on Steam<\/a><\/li>\n<li><a href=\"#privacy-workshop-screenshots\">How to hide screenshots and Steam Workshop items<\/a><\/li>\n<\/ul>\n<\/li>\n<li><a href=\"#phishing\">How to avoid leaking data, money, and items on Steam<\/a><\/li>\n<\/ul>\n<h2 id=\"security\">How to protect your Steam account<\/h2>\n<p>To keep your account from being hijacked, you need to protect it. This is where the security settings come in. To open them, in the app on your computer:<\/p>\n<ul>\n<li>Click your name in the upper right corner.<\/li>\n<li>Select <em>Account Details<\/em>.<\/li>\n<\/ul>\n<p>Another way to reach the very same settings in the desktop Steam app:<\/p>\n<ul>\n<li>Click <em>Steam<\/em> in the upper left corner.<\/li>\n<li>Select <em>Settings<\/em>.<\/li>\n<\/ul>\n<h3 id=\"security-password\">Your Steam password must be strong<\/h3>\n<p>Is your Steam password short and guessable like 123456 or the name of a pet? Or do you use the same one as for your Facebook and\/or Gmail accounts? Then we recommend changing it right away.<\/p>\n<p>We have a separate post about <a href=\"https:\/\/www.kaspersky.com\/blog\/strong-password-day\/25519\/\" target=\"_blank\" rel=\"noopener noreferrer\">how to come up with (and not forget) a virtually unbreakable password<\/a>. And here&#8217;s why <a href=\"https:\/\/www.kaspersky.com\/blog\/never-reuse-passwords-story\/24808\/\" target=\"_blank\" rel=\"noopener noreferrer\">you should never reuse passwords<\/a>.<\/p>\n<p>To change your Steam password:<\/p>\n<ul>\n<li>Open the Steam settings.<\/li>\n<li>Select <em>Change Password&#8230;<\/em>.<\/li>\n<\/ul>\n<h3 id=\"security-steam-guard\">How to configure Steam Guard\u00a0\u2014 two-factor authentication on Steam<\/h3>\n<p>Even the most reliable password will not help if it gets stolen \u2014 no one is insured against that, unfortunately. So be sure to enable two-factor authentication (2FA), which Valve calls Steam Guard. With 2FA, when you or anyone else tries to log into your account from an unknown device, Steam asks not only for your password, but for an additional code that is sent to your e-mail or generated in the mobile app.<\/p>\n<p>These codes are updated automatically every 30 seconds, so it is almost impossible to guess them. What&#8217;s more, they work only once, so if you log in with it, no one else can.<\/p>\n<p>By default, Steam sends those codes by e-mail. Here&#8217;s what to do if for some reason you disabled it or want to receive codes in the Steam mobile app (which we&#8217;ll cover in the next section):<\/p>\n<ul>\n<li>Open the settings.<\/li>\n<li>Click <em>Manage Steam Guard Account Security&#8230;<\/em> or <em>Manage Steam Guard<\/em>.<\/li>\n<li>Choose how you want to receive access codes: by e-mail or in the mobile app.<\/li>\n<\/ul>\n<p> <input type=\"hidden\" class=\"category_for_banner\" value=\"kisa-generic-2\" \/> <\/p>\n<h3 id=\"security-steam-guard-mobile\">How to set up Steam Guard Mobile Authenticator<\/h3>\n<p>Receiving one-time codes by e-mail is rather slow and not very reliable because e-mail accounts often get hijacked. There is a better way: Steam lets you generate one-time codes in the mobile app. First, it&#8217;s safer. Second, the code is always generated instantly. Here&#8217;s how to set up Steam Guard on your phone:<\/p>\n<ul>\n<li>Install the Steam app on your smartphone (<a href=\"https:\/\/apps.apple.com\/gb\/app\/steam-mobile\/id495369748\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">iOS<\/a> or <a href=\"https:\/\/play.google.com\/store\/apps\/details?id=com.valvesoftware.android.steam.community&amp;hl=en\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">Android<\/a>), and log in to your account.<\/li>\n<li>Tap the three bars in the upper left corner.<\/li>\n<li>Select <em>Steam Guard<\/em>.<\/li>\n<li>Tap <em>Add Authenticator<\/em>.<\/li>\n<li>Enter your phone number, if it&#8217;s requested.<\/li>\n<li>Open the e-mail from Steam and confirm that you want to link the number to your account.<\/li>\n<li>In the app on your phone, tap <em>Next<\/em> and enter the code from the text message.<\/li>\n<li>Make a note of the recovery code the app displays and keep it in a safe place\u00a0\u2014 you will need it if you ever lose your phone.<\/li>\n<li>Tap <em>Done<\/em> and you&#8217;re all set. From now on, the app will display your 2FA codes in the <em>Steam Guard<\/em> section.<\/li>\n<\/ul>\n<h3 id=\"security-devices\">How to ensure that only you are logged in to your account<\/h3>\n<p>If you forget to log out on someone else&#8217;s computer, or suspect that you&#8217;ve been hacked, you can force a logout on all devices save for the one that you are using. To do so, in the app on your computer:<\/p>\n<ul>\n<li>Open the settings.<\/li>\n<li>Select <em>Manage Steam Guard Account Security&#8230;<\/em> or <em>Manage Steam Guard<\/em>.<\/li>\n<li>Click <em>Deauthorize all other devices<\/em>.<\/li>\n<\/ul>\n<p>Now the only person logged in to your account is you. Now is also the ideal time to <a href=\"#security-password\">change your password<\/a> and <a href=\"#security-steam-guard\">enable Steam Guard<\/a> to keep outsiders out of your account.<\/p>\n<h3 id=\"security-links\">How to guard against phishing links on Steam<\/h3>\n<p>Cyberpoachers in search of accounts full of games and items are constantly creating fake sites to steal Steam logins and passwords. To lure users in, they post links in the comments section or elsewhere, promising things like game keys, free items, or huge discounts. If you swallow the bait, your credentials go straight to the scammers.<\/p>\n<p>To protect you against this fatal mistake, Steam warns about links that lead to third-party sites. This option is available and active by default in the mobile app, but if for some reason you disabled it:<\/p>\n<ul>\n<li>Open the mobile app.<\/li>\n<li>Tap the three bars in the upper left corner of the screen.<\/li>\n<li>Select <em>Settings<\/em>.<\/li>\n<li>Open <em>Application Preferences<\/em>.<\/li>\n<li>Select <em>Alert for non-Steam Links<\/em>.<\/li>\n<\/ul>\n<p> <input type=\"hidden\" class=\"category_for_banner\" value=\"kis-trial-cyberattacks\" \/> <\/p>\n<h2 id=\"privacy\">Configuring Steam privacy<\/h2>\n<p>Having an excessively public profile can cause problems. For example, if scammers see that you have expensive games or items in your collection, they are more likely to take an unwanted interest in your Steam account. And if you allow just anyone to leave comments on your page, don&#8217;t be surprised if you get flooded with spam and insults. Therefore, we recommend spending some time configuring restrictions on third-party access to the information in your profile.<\/p>\n<p>Here&#8217;s where the settings are in the desktop version of Steam:<\/p>\n<ul>\n<li>Click your name in the upper right corner of the screen.<\/li>\n<li>Select <em>View my profile<\/em>.<\/li>\n<li>Click <em>Edit Profile<\/em>.<\/li>\n<li>Select <em>My Privacy Settings<\/em>.<\/li>\n<\/ul>\n<p>In the Steam mobile app, you can find them here:<\/p>\n<ul>\n<li>Tap the three bars in the upper left corner of the screen.<\/li>\n<li>Select <em>Settings<\/em>.<\/li>\n<li>Open <em>Application Preferences<\/em>.<\/li>\n<li>Click <em>Steam Preferences<\/em>.<\/li>\n<li>Open the <em>Privacy Settings<\/em> tab.<\/li>\n<\/ul>\n<h3 id=\"privacy-private-account\">How to hide your Steam profile from outsiders<\/h3>\n<p>If you don&#8217;t want strangers to see your profile at all, make it fully private. To do so:<\/p>\n<ul>\n<li>Open the privacy settings.<\/li>\n<li>Tap the link next to <em>My profile<\/em>.<\/li>\n<li>Select <em>Friends Only<\/em> or <em>Private<\/em>.<\/li>\n<\/ul>\n<p>Now only your name and avatar are visible to outsiders. These elements cannot be hidden, but on Steam there is nothing to stop you from using a fictitious name and a favorite anime character as your profile picture.<\/p>\n<h3 id=\"privacy-gaming-info\">How to hide information about your games, items, and friends<\/h3>\n<p>If you want to hide only some information (such as lists of games, or collections of skins) from outside eyes, use Steam&#8217;s privacy settings to tailor its visibility.<\/p>\n<ul>\n<li>Open the privacy settings.<\/li>\n<li>Click the link next to <em>Game details<\/em>, <em>Friends List<\/em>, or <em>Inventory<\/em>.<\/li>\n<li>Select <em>Friends Only<\/em> or <em>Private<\/em>.<\/li>\n<\/ul>\n<h3 id=\"privacy-workshop-screenshots\">How to hide screenshots and illustrations on Steam<\/h3>\n<p>Screenshots and illustrations also do not have to be shown to everyone. You can limit their visibility at any time. The settings for each picture are individual; that is, you can choose for each image whether you want it to be visible to everyone, or shown only to friends, or maybe just for you.<\/p>\n<p>To hide a new screenshot or illustration, select <em>Private<\/em> or <em>Friends only<\/em> under <em>Visibility<\/em> in the upload window.<\/p>\n<p>To hide an already uploaded screenshot or illustration:<\/p>\n<ul>\n<li>Open your screenshots or illustrations.<\/li>\n<li>Click <em>Manage Screenshots<\/em> or <em>Manage<\/em>.<\/li>\n<li>Select the images that you want to hide.<\/li>\n<li>Click <em>Make Friends Only<\/em> or <em>Make Private<\/em>.<\/li>\n<\/ul>\n<p>Sometimes it is more convenient not to hide a picture, but to make it viewable by link only. That way, it will not appear in search results or the Steam community feed, allowing you to choose who to share it with. If the picture is new, select <em>Private<\/em> under <em>Visibility<\/em> in the upload window. If you want to restrict access to an already uploaded screenshot or illustration:<\/p>\n<ul>\n<li>Open your screenshots or illustrations.<\/li>\n<li>Click <em>Manage Screenshots<\/em> or <em>Manage<\/em>.<\/li>\n<li>Select the images that you want to hide.<\/li>\n<li>Click <em>Make Unlisted<\/em>.<\/li>\n<\/ul>\n<p>On the relevant pages of your profile, you can limit the visibility of videos, mods, and items created in the Steam Workshop as well.<\/p>\n<h3 id=\"privacy-comments\">How to avoid spammers and trolls on Steam<\/h3>\n<p>Already hidden your most personal stuff? Now let&#8217;s deal with spam and trolling. To prevent strangers from posting comments or dropping questionable links in your profile, you can restrict access to comments. To do so:<\/p>\n<ul>\n<li>Open the privacy settings.<\/li>\n<li>Click the link under <em>Can post comments on my profile<\/em>.<\/li>\n<li>Select <em>Friends Only<\/em> or <em>Private<\/em>.<\/li>\n<\/ul>\n<h2 id=\"phishing\">How to avoid leaking data, money, and items on Steam<\/h2>\n<p>Your profile is now configured, thank Gaben. Now your gaming life is much better protected than before. However, cybercriminals can still try to scam you \u2014 for example, <a href=\"https:\/\/www.kaspersky.com\/blog\/more-steam-threats\/22171\/\" target=\"_blank\" rel=\"noopener noreferrer\">by selling an already used game key<\/a> or <a href=\"https:\/\/www.kaspersky.com\/blog\/steam-scam\/11317\/\" target=\"_blank\" rel=\"noopener noreferrer\">asking to borrow an expensive item<\/a>. Be careful and don&#8217;t trust just anyone.<\/p>\n<ul>\n<li>Don&#8217;t follow links in messages from &#8220;support service&#8221; or other users. Scams can be based on carrots (such as fake lotteries with juicy prizes) or sticks (threats to block user accounts and the like). Check all information in official sources.<\/li>\n<li>Don&#8217;t rely on good faith and scout&#8217;s honor. And be wary of any freebie. Remember that if something is too cheap, it&#8217;s probably a trap.<\/li>\n<li>Don&#8217;t install game-enhancing extensions or third-party programs. Using cheat software could result in a VAC ban, and in most cases it will simply infect your computer instead of giving you a leg up on the competition.<\/li>\n<li>Use a <a href=\"https:\/\/www.kaspersky.com\/advert\/security-cloud?redef=1&#038;THRU&#038;reseller=gl_kdailyplacehold_acq_ona_smm__onl_b2c_kasperskydaily_wpplaceholder____ksc___\" target=\"_blank\">reliable security solution<\/a> that identifies malware and phishing links. If you have our antivirus installed, find out <a href=\"https:\/\/www.kaspersky.com\/blog\/kis-settings-for-steam\/13970\/\" target=\"_blank\" rel=\"noopener noreferrer\">how to hook it up with Steam<\/a> (spoiler: It&#8217;s easy).<\/li>\n<\/ul>\n<p> <input type=\"hidden\" class=\"category_for_banner\" value=\"kis-gaming\" \/> <br \/><a href=\"https:\/\/www.kaspersky.com\/blog\/steam-privacy-security\/33981\/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=steam-privacy-security\" target=\"bwo\" >https:\/\/blog.kaspersky.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2020\/03\/11033925\/steam-privacy-security-featured.jpg\"\/><\/p>\n<p><strong>Credit to Author: Leonid Grustniy| Date: Wed, 11 Mar 2020 07:42:18 +0000<\/strong><\/p>\n<p>A brief but comprehensive guide to security and privacy on the world\u2019s most popular gaming platform.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10425,10378],"tags":[10598,8816,11224,11059,714,11226,11227,10428],"class_list":["post-17913","post","type-post","status-publish","format-standard","hentry","category-kaspersky","category-security","tag-2fa","tag-apps","tag-gamers","tag-games","tag-security","tag-settings","tag-steam","tag-tips"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/17913","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=17913"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/17913\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=17913"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=17913"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=17913"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}