Skip to content

Add Steam Guard TOTP variant (#44) - #97

Merged
sidick merged 2 commits into
mainfrom
issue-44-steam-guard
Jul 22, 2026
Merged

sidick merged 2 commits into
mainfrom
issue-44-steam-guard

Conversation

@sidick

@sidick sidick commented Jul 22, 2026

Copy link
Copy Markdown
Owner

Summary

Stacked on #96 (issue-43-sha2-totp) — targets that branch, not main, since both touch otp.c's dispatch.

  • Steam's mobile authenticator uses the same HMAC-SHA1/30s TOTP construction as everyone else, but renders the truncated value as 5 characters from Steam's own 26-symbol alphabet instead of decimal digits.
  • Adds a new account type ("steam", vault type id 2) with its own renderer (src/core/steamguard.c), sharing otp.c's RFC 4226 dynamic-truncation step via a new otp_truncate().
  • Reachable via otpauth://steam/... URIs, a STEAM switch on the CLI's bare-secret ADD, and the GUI's existing typed-URI/secret entry point (extended IPC forwarding: new AAP_ADD_SECRET_STEAM command).
  • The GUI's account-edit form no longer forces digits-6-to-8/period validation on Steam accounts (those fields aren't consulted for this type).

Test plan

  • make test — 292 host unit tests pass, including Steam Guard vectors
  • Vectors in tests/test_steamguard.c were derived independently via Python's stdlib hmac/hashlib, not this codebase's own HMAC-SHA1 — so the test isn't just checking the implementation against itself
  • make m68k-docker / make gui-docker — plain 68000 baseline cross-builds succeed
  • make gui-smoke — headless Copperline GUI smoke test passes
  • make smoke — CLI smoke test passes
  • Manual CLI run: added a Steam account via both the STEAM bare-secret flag and an otpauth://steam/... URI, confirmed identical correct codes, and confirmed a plain bare-secret add is unaffected
  • userdocs/ updated in this PR (new "Steam Guard" section in Managing-Accounts.md, CLI-Reference.md, Troubleshooting-and-FAQ.md); docs/VAULT_FORMAT.md updated for the new type id

🤖 Generated with Claude Code

Base automatically changed from issue-43-sha2-totp to main July 22, 2026 06:02
@sidick
sidick enabled auto-merge (squash) July 22, 2026 07:10
sidick and others added 2 commits July 22, 2026 09:54
Steam's mobile authenticator uses the same HMAC-SHA1/30s TOTP construction
as everyone else, but renders the truncated value as 5 characters from
Steam's own 26-symbol alphabet instead of decimal digits. Adds a new
account type ("steam", vault type id 2) with its own renderer
(src/core/steamguard.c, sharing otp.c's RFC 4226 dynamic-truncation step
via the new otp_truncate()), reachable via otpauth://steam/... URIs, a
STEAM switch on the CLI's bare-secret ADD, and the GUI's existing typed-
URI/secret entry point and IPC forwarding. Vectors in
tests/test_steamguard.c were derived independently via Python's stdlib
hmac/hashlib, not this codebase's own HMAC, so the test doesn't just
check the implementation against itself.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Mirrors the ChaCha20 dead-end already documented here: unlike SHA-1
(which backs PBKDF2's iteration-heavy vault KDF), the new primitives
each do at most one HMAC per code render, so there's no hot loop for
hand-written asm to pay off in.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@sidick
sidick force-pushed the issue-44-steam-guard branch from 2556b97 to 1f3335d Compare July 22, 2026 08:55
@sidick
sidick merged commit e9e1e78 into main Jul 22, 2026
7 checks passed
@sidick
sidick deleted the issue-44-steam-guard branch July 22, 2026 08:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant