• Hey, guest user. Hope you're enjoying NeoGAF! Have you considered registering for an account? Come join us and add your take to the daily discourse.

Steam security issue revealed personal info to other users on XMas Day (fixed)

jacobeid

Banned
Wow this is about 100x worse than anything that ever happened to PSN.

Yup. This is next level stuff. Had a guy with almost $19 in his account. Deleted his CC for him. Can't believe I could even do that. Jesus.

I use PayPal and deleted it from there and changed my password to be safe, but, fuck.
 

MrV4ltor

Member
I can literally switch through accounts by clicking on different games and access people's wishlists, shopping carts and information. This is a mess. Hope nobody is doing anything on my account.
 

Zomba13

Member
So snooping in my guys recent purchases it shows they added two Steam money cards today but no bought anything after it and it's still showing £0.00 in the wallet so HOPEFULLY this means whoever has your account can't buy anything with your money (though they might be able to see stuff like the last digits of your credit card and/or youur mobile number if linked).
 
My friend informed me. When you go into 'Account Information' via Steam Client, it leads you to other peoples pages.

I looked at it and there is another guys page named 'minkey314' and it has saved credit card information, which is not mine. I can see his mail address clearly. Also if that random guy has money in Steam Wallet, I think you can spend it too. Mine has $0 at all.

I think big security issue is happening right now. You can check it with Steam Client. I am not gonna upload a screenshot because I dont want to spoil that guys e-mail address or other info.

Same here. See another guys account info. "orenasaf's account" apparently. from the US
 
This is beyond fucked

I have access to some poor dudes account, can change his steam guard, add a phone number...

How this service is still up is frankly embarrassing.
 

Bebpo

Banned
For everyone worrying about your CC getting stolen, I thought it only shows the last 4 digits of the card if you have it saved?
 

-Opaque-

Member
Just noticed so I came here how can i make sure all credit card info is not in my account?

I don't think you can, as the page where you would remove it is the page spitting out random others peoples accounts :|
If you are lucky enough to see your own then tear it all out.
Depending on how they set it up 2 factor auth *may* protect you (for login attempts, not for seeing the info) *if* they require the phone number to turn it off. But I've never turned it off so can't confirm :(
 

Tenebrous

Member
Emailed a friend on Skype. She lives 100 miles away in the UK, and we both have the same Steam user. Username begins with Salv, and the email has PMC in it.
 

Morrigan Stark

Arrogant Smirk
I don't have thousands of dollars tied to my GAF account
Sure, but you'd give your Steam name for, say, a gaffer to add you on their friendlist right?

That is unequivocally false.

A GAF user name is publicly available, while a Steam user name is completely private for security reasons.
So when you give your Steam name to someone to add you, you're compromising your account security? Come on. Besides, people are probably saying "hey I got joedude123 too" repeatedly all over the Internet, damage's done really.
 
I know for my CC they will still need that three digit code AFAIK. Hopefully that keeps me safe while they sort this out. I imagine that any stuff they try to buy will be tied to my account and refundable when this is all said and done but there is a lot of other personal info on my account.

Damn.
 
Well disabled my PayPal. Still, have like $100 in my Steam wallet but not too worried as I'm sure I'll be sending cuss words to Valve support to refund any purchases I personally didn't make.
 

Steel

Banned
For everyone worrying about your CC getting stolen, I thought it only shows the last 4 digits of the card if you have it saved?

Yeah, but last 4 digits can get you into a lot of personal stuff combined with email and phone.
 

Tendo

Member
Just checked on mobile and yup. I'm some other dude. How do I delete my cards from steam if I can't see myself?
 

Dunkley

Member
"On that day, the digital future received a grim reminder."

Honestly that's fucked up, can't even log onto my Steam account now.
 

Clawww

Member
oh my fucking god this is crazy, I'm in another person's account, was just trying to check my own balance/payment info and I have access to this user's steam balance WTF WTF WTF
 
I'm getting an error code when I try to access my account security page in the windows app. Maybe they've caught onto it? Or something else is going on...
 

Madchad

Member
got some other guys account up when i went to my funds in steam

Deleted his CC details for him. Hope some one else is as kind to me :x
 
Lol Merry X-Mas Steam GAF.

WTF

Side Note: Something similar happened last night on PSN for about 30-60 seconds. It appeared I was signed into someone else's account on my PS4. I exited the store then re-entered and the problem was gone.

I'm thinking this is too similar to be a coincidence. Perhaps this is Lizard Squad or some other hacktivist group making a statement about the lack of security on various online services....
 
Sure, but you'd give your Steam name for, say, a gaffer to add you on their friendlist right?


So when you give your Steam name to someone to add you, you're compromising your account security? Come on. Besides, people are probably saying "hey I got joedude123 too" repeatedly all over the Internet, damage's done really.

You don't have to give your account name to someone. account/login name and profile name are independent. No one ever needs to know your login except for you, and it shouldn't be the same as your profile name.
 

kami_sama

Member
Sure, but you'd give your Steam name for, say, a gaffer to add you on their friendlist right?


So when you give your Steam name to someone to add you, you're compromising your account security? Come on. Besides, people are probably saying "hey I got joedude123 too" repeatedly all over the Internet, damage's done really.

You don't give your account nae, you give them your username. It's not the same, and I think valve doesn't let them be the same.
 
Top Bottom