• Hey, guest user. Hope you're enjoying NeoGAF! Have you considered registering for an account? Come join us and add your take to the daily discourse.

Steam security issue revealed personal info to other users on XMas Day (fixed)

rje

Member
Meanwhile at valve...

Ok3AGrI.gif
 

Grief.exe

Member
If you dont save purchasing details, what would they be able to see?

Account name, email, phone number, purchases.

Yup! Same thing happened to me! I haven't bought anything today.

This is in Swedish Krona and this sum is about 5 euros. So I haven't been as screwed as this poor fellow.
WMfgR5Q.png

Financial institutions are sometimes delayed with posting transactions, especially with the holidays.

Did you buy anything previously?
 
I can't wait to see how big the fine is from the EU for the breach in Data Protection.

Turn on mobile authentication for Steam and/or email so that any prospective hacker has to physically track you down to get into your account

AHA! This makes sense.

October - Steam Client keeps asking you to add your mobile. No one does.
November - Steam Client makes adding your mobile part of a Community Badge. No one does.
December - Steam Client HACKS ITSELF SO YOU'LL FINALLY ADD YOUR MOBILE NUMBER!
 

Striek

Member
...and people were posting account names in this thread.
Pretty rational to go "hey I'm in XYZs account not mine WTF" its not the users responsibility in this scenario.

Makes more sense to me than posting bullet points you don't even know are true over and over.
 

fhqwhgads

Member
Valve really needs to say something about this, anything really. Just something that stops the scaremongering and people trusting literally any source that crops up.
 
As one of the accounts affected by this (shout-outs to the nice random people on Steam contacting me to chat because they were in my account and looking at my stuff--all seemed like standup, trustworthy guys), the basic information I want to know:

1) Was this a breach, a staff error, or a configuration error that happened due to some unusual hardware cascade situation?
2) How many users were affected?
3) How many people accessed my information?
4) What information did they access?
5) If my address or cc info was even partially exposed, I expect a year or two of credit monitoring
6) If a breach, was my tax information accessed
7) Will I be permitted to change my login username in light of this?

It goes without saying that if purchasing was exposed they should do a full rollback, but I'm not worried about that because that's obvious. More worried about the personal info.

I just want an honest post-mortem, but the sad thing is, given Valve's previous history of dealing with those issues (remember the part where devs could or still can inject JS into Steam Store pages?) I highly doubt it.
 

Rebel Leader

THE POWER OF BUTTERSCOTCH BOTTOMS
So if I understand this right I'm not supposed to change to change the info from my steam account? Why?

if you logged in, it would put your account in the rotation. More likely for it to be shown to someone else


Wait untill steam comes back online
 

benny_a

extra source of jiggaflops
So if I understand this right I'm not supposed to change to change the info from my steam account? Why?
The current understanding is that this is/was a caching problem, so all account related activities make you more vulnerable than not doing anything, so you never create any cache entries that can be exposed.

If you have the ability to block Steam from Paypal for example then do it that way.
 

Syder

Member
Changed my PayPal password. Pretty sure that's the only method of payment I've ever used.

I mean, surely Valve has to fix this and not leave any customers out of pocket or games. People have been moving away from Steam a little bit lately and this could really hurt them long term if they don't fix this rapidly.
 

Cleve

Member
So if I understand this right I'm not supposed to change to change the info from my steam account? Why?

Simply attempting to load up your page would put it in the cache that others were viewing. It was poorly phrased. The intent was "don't load any steam pages at all, even if it is to remove details" but it all looks like it's shut down now anyway.
 

MrDaravon

Member
So if I understand this right I'm not supposed to change to change the info from my steam account? Why?

If I'm understanding what people are saying correctly, making changes on steam could potentially float your account to the top of the cached list which is what people are/were able to see. Seems to be why people are recommending to disconnect Steam through the Paypal side of things.
 

AxeMan

Member
Jus woke up to this news. Couldn't get the store to show on Steam and saw this thread.

IS the problem fixed yet? I was able to get into my account, I couldn't see anyone else, just the store wouldn't load.

Also, this is more vindication of my belief to never let 3rd parties store your CC details if you can avoid it. It's a two second job to pump the details in as needed
 
Top Bottom