• MajesticElevator@lemmy.zip
      link
      fedilink
      English
      arrow-up
      6
      ·
      2 days ago

      Their platform is really outdated. Can’t even edit or remove a game review without contacting support. It’s dumb. They’re losing precious time because of this

        • MajesticElevator@lemmy.zip
          link
          fedilink
          English
          arrow-up
          1
          ·
          edit-2
          3 hours ago

          I don’t think it has cloud saving, easy wine/proton, API for achievements and shit… just overall unfit for “bigger games”. It has similar functionality to GOG’s offline downloads. I haven’t really used it so can’t say.

          I probably won’t try it if they also take a huge cut from sales like 30% or something EDIT: They seem to let you choose whatever you want, and charge 10% by default (https://itch.io/docs/creators/payments#open-revenue-sharing). That’s neat! However, payment method fees always apply. You can opt into them collecting the money through their account at seemingly no fee, and won’t be exposed to chargebacks. That’s incredible!

      • Seefoo@lemmy.world
        link
        fedilink
        English
        arrow-up
        4
        ·
        13 hours ago

        the store is a losing proposition right now from CDPR perspective. I am just happy to have a different place I can buy games that’s not steam

      • NuXCOM_90Percent@lemmy.zip
        link
        fedilink
        English
        arrow-up
        28
        arrow-down
        1
        ·
        edit-2
        2 days ago

        At a glance (haven’t enabled yet, will later today), GoG uses the RFC standard TOTP model. This means you can use whatever app you want whether that is the google authenticator that ties it to your cloud account, something related to your password manager (e.g. keepass or bitwarden), or even just a python script you have in a random directory. It gives you control of your 2FA and protects you in the event you lose a device without properly de-authenticating it.

        Valve use their own model that, to my knowledge, is only accessible through the Steam mobile app. Which is a huge nightmare if you ever have a device stolen/damaged (and is why you back up the recovery code)


        Just enabled. Yup, bog standard TOTP and they even provide the plaintext key so that I don’t have to extract it from a QR code.

            • Sonotsugipaa@lemmy.dbzer0.com
              link
              fedilink
              English
              arrow-up
              3
              ·
              2 days ago

              I don’t recall, I’ve set it up a few years ago - I’ve been trying to look for instructions for another comment, but it seems that they made it VERY difficult for people without rooted Android to obtain the TOTP secret.

              Though it is RFC 6238 compliant, using 5 digits instead of 6.

              • Ulrich@feddit.org
                link
                fedilink
                English
                arrow-up
                5
                ·
                edit-2
                2 days ago

                Okay, let’s say there’s currently no native support for normal TOTP, mostly because Steam doesn’t give you access to your TOTP key.

                • Sonotsugipaa@lemmy.dbzer0.com
                  link
                  fedilink
                  English
                  arrow-up
                  2
                  ·
                  2 days ago

                  That much I can agree with at this point.

                  Actually, it’s arguably even worse - it’s not that Steam doesn’t support normal TOTP, it’s that Steam goes out of their way to prevent TOTP from being used without switching to an entirely new algorithm.

      • ramble81@lemm.ee
        link
        fedilink
        English
        arrow-up
        5
        arrow-down
        3
        ·
        2 days ago

        Unless I’m missing something, Steam only does code to email 2FA, not an actual TOTP app

          • ramble81@lemm.ee
            link
            fedilink
            English
            arrow-up
            2
            ·
            2 days ago

            Teach a brother how? I swear I couldn’t find it anywhere in the account settings.

            • Sonotsugipaa@lemmy.dbzer0.com
              link
              fedilink
              English
              arrow-up
              5
              arrow-down
              2
              ·
              edit-2
              2 days ago

              I don’t quite remember how to get the TOTP secret from the Steam app (they could in fact take notes from GOG here), iirc you have to extract it from the Android app via adb;
              but once you have it, if this GitHub comment is correct you simply have to set the code size to 5 digits.

              If your phone has a rooted Android install, I found this guide.

              … I swear when I did it, it wasn’t this hard ._.

  • purplemonkeymad@programming.dev
    link
    fedilink
    English
    arrow-up
    2
    ·
    2 days ago

    Thanks, and added.

    Although it would have been nice if I could “upgrade” from email based 2step instead of having to disable it.

  • 反いじめ戦隊@ani.social
    link
    fedilink
    English
    arrow-up
    1
    arrow-down
    10
    ·
    edit-2
    1 day ago

    2FA (Time-based One-Time Password) login

    Gog, how are you even securing accounts? You mean securing access to accounts through 3rd party TOTP, which again, isn’t sessioning access authenticatively. We already invented that.