• Hey, guest user. Hope you're enjoying NeoGAF! Have you considered registering for an account? Come join us and add your take to the daily discourse.

Steam security issue revealed personal info to other users on XMas Day (fixed)

wrowa

Member
I know it's difficult for people to think big picture on certain things, but can you think what day it is?

"It's holidays" isn't an excuse when you are operating one of the biggest online stores worldwide storing huge amounts of sensible user data. Especially so since it's known that hackers love to use Christmas for their attacks (if this is a hack). They absolutely should have security measures in place to take care of these issues quickly, even if this "just" means taking everything offline (which might not be as easy as it sounds, but that's something you figure out -before- shit hits the fan).
 

Alucrid

Banned
Once again.

NO ACCOUNT INFORMATION CAN BE CHANGED.

NO PURCHASES CAN BE MADE.

THE MOST PEOPLE CAN SEE IS YOUR E-MAIL, AND PURCHASE HISTORY.



Is it a clusterfuck? Absolutely. But aside from some random person knowing your e-mail and seeing that you've bought Hunniepop, YOU HAVE NOTHING TO WORRY ABOUT.
some guy on the other page said he was deleting people's credit cards...so account information can be changed?
 
Lmfao I've gotten into like 8 different peoples accounts


Gg Valve this is the biggest fuck up I've seen from a video game service. At least the PSN hacks didn't leak shit out in the open
 

Bunta

Fujiwara Tofu Shop
Maybe we should consider deleting the credit card info of any account we get logged into and then log out?

A good deed on Christmas day, we could save people a bit of money... assuming someone else doesn't get logged in to their account immediately after.

I've tried deleting paypal emails and CC numbers for people, but it gives me a login screen.
 
Once again.

NO ACCOUNT INFORMATION CAN BE CHANGED.

NO PURCHASES CAN BE MADE.

THE MOST PEOPLE CAN SEE IS YOUR E-MAIL, AND PURCHASE HISTORY.



Is it a clusterfuck? Absolutely. But aside from some random person knowing your e-mail and seeing that you've bought Hunniepop, YOU HAVE NOTHING TO WORRY ABOUT.
Judging from the fact that I have seen someone's billing address and phone number, along with the last four digits of their card and their paypal e-mail, I don't think that's true.
 
Once again.

NO ACCOUNT INFORMATION CAN BE CHANGED.

NO PURCHASES CAN BE MADE.

THE MOST PEOPLE CAN SEE IS YOUR E-MAIL, AND PURCHASE HISTORY.



Is it a clusterfuck? Absolutely. But aside from some random person knowing your e-mail and seeing that you've bought Hunniepop, YOU HAVE NOTHING TO WORRY ABOUT.

But I dont want spam in my email or people to know I purchased a Kawaii Black Ops DLC.
 

ItIsOkBro

Member
So the things that CAN happen are:

People buying things with your Steam credit
Changing your emails to something else
Looking at whatever information is saved to your card, including your phone number and address

What else?

Caching issue my ass tbh. What cached page can actually lead to functionality like it.
 

Rebel Leader

THE POWER OF BUTTERSCOTCH BOTTOMS
Once again.

NO ACCOUNT INFORMATION CAN BE CHANGED.

NO PURCHASES CAN BE MADE.

THE MOST PEOPLE CAN SEE IS YOUR E-MAIL, AND PURCHASE HISTORY.



Is it a clusterfuck? Absolutely. But aside from some random person knowing your e-mail and seeing that you've bought Hunniepop, YOU HAVE NOTHING TO WORRY ABOUT.

Except I just deleted some ones CC one someones account
 

yatesl

Member
some guy on the other page said he was deleting people's credit cards...so account information can be changed?

The other guy was wrong. If you click delete either nothing happens, or you get an error.

Judging from the fact that I have seen someone's billing address and phone number, along with the last four digits of their card and their paypal e-mail, I don't think that's true.

OK, I'll give you PayPal e-mail - but really, that's usually just the same as someone's e-mail.

Nothing can be done with the last 4 digits of someone's card.
 

Kayant

Member
Wow just noticed this. This is awful sightly happy I use paypal for steam stuff but this is one hell of a mistake.
 
Once again.

NO ACCOUNT INFORMATION CAN BE CHANGED.

NO PURCHASES CAN BE MADE.

THE MOST PEOPLE CAN SEE IS YOUR E-MAIL, AND PURCHASE HISTORY.



Is it a clusterfuck? Absolutely. But aside from some random person knowing your e-mail and seeing that you've bought Hunniepop, YOU HAVE NOTHING TO WORRY ABOUT.

You'd be wrong. Someone definitely removed my phone number from my account.
 
I get that this is sort of embarrassing but whats the problem? No one can actually see your important info. All the profiles just show "card ending in xxxx-1234" or "phone number ending 1234". The security measures are actually working here.
 

dickroach

Member
so I'm looking at my bank account and apparently someone charged $100 at the liquor store last night! this is unacceptable. I dunno who did it and I'm too hungover to figure it out
 

Hylian7

Member
Once again.

NO ACCOUNT INFORMATION CAN BE CHANGED.

NO PURCHASES CAN BE MADE.

THE MOST PEOPLE CAN SEE IS YOUR E-MAIL, AND PURCHASE HISTORY.



Is it a clusterfuck? Absolutely. But aside from some random person knowing your e-mail and seeing that you've bought Hunniepop, YOU HAVE NOTHING TO WORRY ABOUT.
Exposing emails still isn't a good thing.

Really with I could delete my CC info.
 

MoonGred

Member
Can't access my account info either.

If someone makes a purchase with your account would you still receive the confirmation email?
 

Rellik

Member
It's not.


I went to delete CC

CC deleted

not on my account

Yep. I've just clicked the delete button on someone's email address and it's removed it from their account under 'Store & Purchase History' but it still remains under 'Contact Info' with no way to remove it.
 

styl3s

Member
Once again.

NO ACCOUNT INFORMATION CAN BE CHANGED.

NO PURCHASES CAN BE MADE.

THE MOST PEOPLE CAN SEE IS YOUR E-MAIL, AND PURCHASE HISTORY.



Is it a clusterfuck? Absolutely. But aside from some random person knowing your e-mail and seeing that you've bought Hunniepop, YOU HAVE NOTHING TO WORRY ABOUT.
So steam isn't allowing any purchases?
 

iNvid02

Member
people need to stop with the damage control kool aid, its a security breach because of the information that can be viewed
 
So glad I don't trust anyone to have my credit card info saved. It really is not a bother to have to enter credit card info every time you buy a game.

I clicked the link above and also not logged in on mobile chrome and saw someone else's account. Full email last digits of credit card etc. $13 in account. Great fuck up.

Hopefully valve does not get a free pass on this and get all the criticism and more that Sony did. But let's wait and see what the cause of this was.
 

Yosei

Member
On mobile everytime I go to account details I get into an account from someone else. This is really bad, steam must be shut down right now.
 
Once again.

NO ACCOUNT INFORMATION CAN BE CHANGED.

NO PURCHASES CAN BE MADE.

THE MOST PEOPLE CAN SEE IS YOUR E-MAIL, AND PURCHASE HISTORY.



Is it a clusterfuck? Absolutely. But aside from some random person knowing your e-mail and seeing that you've bought Hunniepop, YOU HAVE NOTHING TO WORRY ABOUT.

Well this calmed me down a bit. Will definitely change my email and never save my card info again though.
 

ClearData

Member
Guys I tried to purchase something to see if my card information was stored and everything was grayed out. Did Valve turn off the store? If so, good.
 
Top Bottom