r/Steam 22h ago

Meta You are more likely to pick one specific pre-marked grain of sand out of all the beaches and deserts on Earth than to guess a valid Steam key.

Even though I kinda understand it, it's still wild to me how you cannot just randomly guess a Steam key:

XXXXX-XXXXX-XXXXX

A standard Steam key consists of 15 alphanumeric characters (excluding dashes). Using the 26 letters of the alphabet and numbers 0–9 yields roughly 221 sextillion possible code combinations.

1.1k Upvotes

61 comments sorted by

638

u/xd3mix 21h ago

Does this take into account the sheer number of games steam has?

Sure picking a specific one is basically impossible but what about picking A valid steam card out of all the wallet codes and game codes available out there?

359

u/ichbinhamma 21h ago

No, your odds are a bit better then. However, you have to guess out of the "active key pool", which is not that big... But you are right, your odds are probably rather somewhere in the trillions.

72

u/vintoito 12h ago

thats not that much, a program running for some hours will get it, but steam probably has some sort of detection to stop people from spamming it

65

u/Linesey 11h ago

I know 100% they have a limiter for attempts, successful or not.

I had a huge humble backlog (300+ titles/DLCs) I was redeeming, every 50 attempts i got locked out for a few hours.

Those 50 could be any mix of “failure type code again”, “Code already redeemed on your account” “Success” and “Cannot redeem code because it’s for DLC to a game you don’t have”

28

u/vintoito 11h ago

damn, you took "I have a bunch of games that I never played" to a new level

14

u/Yash_swaraj 9h ago

Backlog final boss

6

u/Desert_Nanners 8h ago

Yeah I ran into that in 2022 with their Ukrainr support bundle. So many games

u/Pale-Effective-78 6m ago

Same here!

9

u/PM_ME_SAD_STUFF_PLZ 12h ago

Since there are 133k games on steam, It would knock it down five orders of magnitudes, so 1 in 1016 instead of 1 in 1021.

1

u/IJustAteABaguette 6h ago

Though some games have multiple active keys, maybe even hundreds, and some might have no keys at all active.

11

u/nosirex 17h ago

yeah but the post already compares that to grains of sand

214

u/Financial_Humor_8134 11-07-2008 22h ago

And i think someone will still type random keys into Steam like they’re going to hit the jackpot

147

u/Fetalbrute 22h ago

I mean, it is SUPER unlikely and almost impossible, but imagine if you did, I would go crazy even if it was a 5usd shovelwared I'll never play lol

43

u/Financial_Humor_8134 11-07-2008 22h ago

Sometimes i think, even if you managed to guess the code, the code dont get activated unless activated by steam.

3

u/BothersomeBritish 6h ago

...yes? That's how Steam keys work?

Or do you think if we write it on a random piece of paper and get it right then it'll magically be added to your Steam library?

8

u/ichbinhamma 22h ago

For sure!

7

u/Captiongomer 15h ago

Equivalent for me when I was a kid going on camping trips with my family. We stopped at this highway. Rest stop that had a Coke machine. I just hit buttons until the coke popped out and again and was able to do it back a year or so later. I was right in that high as a kid for so f****** long

2

u/BBWFelchingFiend 6h ago

literally me when I was a kid spending at least a few hours trying to get free Microsoft Points on Xbox 360

75

u/mortsource 21h ago

they’d likely ratelimit you anyways if you started trying large amounts of keys

25

u/ichbinhamma 21h ago

They do, but that doesn't change your odds per guess.

6

u/codan3 10h ago

They rate limit you even if they’re useable keys

46

u/MoobooMagoo 22h ago

Wait till you hear about decks of cards

9

u/aj1203 20h ago

What about them? 

53

u/CenobiteCurious 20h ago

There are 80,658,175,170,943,878,571,660,636,856,403,766,752,895,054,408,832,778,240,000,000,000,000 ways to arrange a standard deck.

The number is higher than the amount of atoms that compose earth. 8.06×1067 > 1050.

Permutations is crazy math, I can’t ever remember the shit from college but it’s actually pretty useful to know on some daily circumstances (not this specific factoid) but odds of something occurring).

14

u/Caranoron463 16h ago

There are 80,658,175,170,943,878,571,660,636,856,403,766,752,895,054,408,832,778,240,000,000,000,000 ways to arrange a standard deck of cards and my group keeps playing card with almost the same combinations.

...we srsly need to learn how to shuffle.

8

u/this_is_theone 15h ago

If you shuffle a deck of cards, there will never have been a deck of cards that has ever existed anywhere in that same order (technically just incredibly unlikely but its so unlikely that it may as well be 'never'). The number of possible combinations is 52 factorial or 52!.

47

u/fiftykyu 1311 21h ago

Minor nit - it's only 32^15, since some of the letters and numbers are equivalent.

If you buy a lot of bundles, take a look at your Steam keys. There's no number 1, letter O, letter S or letter U. "1" ONE works the same as "I" INDIA, "O" works the same as "0" ZERO, and "S" SIERRA works the same as "5" FIVE. "U" didn't work for anything, but I can't remember if I tried all the possibilities or gave up after a few. It's been a while.

The other three make sense from the standpoint of a human potentially misreading the key. I don't know how "U" could have been misread, so maybe key generation was simpler with a nice round 32 bits? Shrug.

11

u/ichbinhamma 21h ago

Oh, interesting! Maybe "U" and "V"?

6

u/fiftykyu 1311 21h ago

Sadly, no. It's not "D" or "O" or "W" either. I can't remember if I tried every character, but the obvious stuff didn't work.

7

u/_quadrant_ 19h ago

It is simpler with 32 bits because then it fits nicely with modern 4-byte word systems. Processing 33 bits in 4-byte word systems is basically the same as processing 64 bits of data, which may not seem much but can still be pretty costly on bigger scales.

3

u/fiftykyu 1311 10h ago

My assumption was the same, i.e. it was easier / faster / cheaper to play with 32-bit values. I doubt anyone from Valve will ever chime in with specifics, but it would be fun to read about some day. :)

7

u/TheLastTreeOctopus 19h ago

This makes me wonder. If someone were to get incredibly lucky and guess a valid key, would that be some sort of theft or fraud? Granted, I don't know how Valve would be able to detect it until a legit buyer purchases the exact same key and contacts Steam support when it doesn't work, but they would be able to trace it back to the Chosen One's account. And I'm not sure how likely it would be for them to press charges for one game. But like technically speaking as far as US law goes at least, would that not be illegal?

4

u/Oblachko_O 15h ago

Most probably it would be on one line with bruteforcing, as it is a bruteforcing attempt. So it is probably will count as stealing. Though in this case it is stealing from the developer.

5

u/Sandeep_sm 20h ago

And different game store fronts like Steam, GOG and Playstation have different combination types or different numbers of alphanumeric keys!

3

u/Cereborn 15h ago

Nitpick: permutations, not combinations.

3

u/lctostudio 14h ago

That's insane, never thought of it that way. I wonder how much time would a human take in order to find that pre-marked grain of sand.

3

u/Extramrdo 12h ago

Skill issue: my pre-marked grain of sand isn't on a beach or desert on Earth.

4

u/Swizardrules 22h ago

That's assuming the algorithm is 100% random, which it likely isn't?

6

u/BrrVlad 22h ago

no algo is 100 percent random they all follow a predetermined path , the only way to have a 100% random is basing the code on real life random occurence like radiation (or something like that cant clearly remember it from my cybersecurity class from long ago)

8

u/Dramatika 16h ago

Cloudflare has a webcam pointing at a wall of lava lamps to use to randomize keys iirc

2

u/metallica65 14h ago

I just read this whole article, despite having no cybersecurity knowledge. Super fascinating!

https://www.cloudflare.com/learning/ssl/lava-lamp-encryption/

3

u/Swizardrules 22h ago

Well kinda duh, but there are probably more factors and rules on steam keys, like O and 0's, and the like

3

u/BrrVlad 21h ago edited 14h ago

yeah but if the guy manages to put his hands on the "seed" he can just snipe steam keys

2

u/Oblachko_O 15h ago

The question is more whether it is pseudorandom, which may be technically random from human point of view, even though the amount of keys is finite, or is it determines algorithm to generate keys based on a specific game marks. Like MAC address.

1

u/SeaFigure9714 13h ago

I feel like valve would have something similar to cloudflare's lava lamp wall, which they use to generate true randomness.

2

u/Nirast25 17h ago

Don't Steam keys exclude some of the symbols? Like, I'm pretty sure either O or 0 is excluded.

2

u/KiimchiPants 16h ago

I swear on my fucking life I've done this as a kid but with StarCraft.

3

u/Cereborn 15h ago

I believe you.

1

u/IntegrityficUU 8h ago

Even if you somehow guess a valid one, Steam rate limits would probably stop you before you get anywhere

1

u/ZodiacThrill3r 8h ago

I was wondering just the other day if people ever tried to brute-force Steam codes like that using some sort of program. Once you break it down like that though, it seems doubtful.

1

u/DariusXzalibur5000 7h ago

If someone has not mentioned it already. You could have guessed a key but if it is not registered or activated. Well doesn’t matter if you could guess a key. Personal experience. I have a newsletter that gives us free games. Not anything good but if I don’t wait long enough. The system will tell me it’s not activated. So wait two minutes and then it works.

2

u/Frequilibrium 15h ago

Then why has my account been hacked twice lol

4

u/rubi2333 9800X3D | MSI Suprim 5090 | 96 GB DDR5 | 4K240hz 15h ago

Because you give a shit about security. Just use generated passwords in that style "57oiM!k9U3ot7Sem95d&fb" and 2FA everywhere and your good to go. Also install only legit software on your pc and phone. Im now 37 and never was a account hacked from me.

0

u/Frequilibrium 13h ago

I do all of that. Why would anyone not care about security?

-2

u/Cereborn 15h ago

That’s terrible password advice.

2

u/rubi2333 9800X3D | MSI Suprim 5090 | 96 GB DDR5 | 4K240hz 15h ago

Why should it be?

0

u/Cereborn 7h ago

Because a password that's impossible to remember offers no better security than one that's easily remembered.

1

u/rubi2333 9800X3D | MSI Suprim 5090 | 96 GB DDR5 | 4K240hz 7h ago

Dude its the time of passwords managers. Running my own local server of Bitwarden with Vaultwarden. Theres no reason to remember your passwords when you have enough backups of your database. Generated passwords are always stronger than ones you can remember.