• Hey, guest user. Hope you're enjoying NeoGAF! Have you considered registering for an account? Come join us and add your take to the daily discourse.

Steam security issue revealed personal info to other users on XMas Day (fixed)

tim.mbp

Member
Guess I'm thankful I don't save payment info (thanks LastPass) and have 2FA turned on. Hopefully Valve will get their shit together.
 

iNvid02

Member
Q4YyNu4.png


Not me, someone posted.

is this your first steam sale? congrats on the big haul
 

cyba89

Member
People should really stop making assumptions (like people were not able to make purchases) when we don't know any facts about this yet.

And I'm baffled at the amount of people here trying to downplay this fuck-up somehow.
 

butzopower

proud of his butz
Not trying to excuse Valve here as this totally sounds like something they did to themselves, but shutting down a massive system like Steam would take quite a bit of time. You have caching servers that will keep a lot of the site up even if they pull the plug. You want to make sure you don't cause any more damage than you already have (ie. lock yourself out of your own servers that you can't even shut down then, etc).

The worst thing to do in panic mode is to panic and pull all the wires. When shit hits the fan, you want to be less reactionary and be making informed decisions.
 

Steel

Banned
Gabe will give a long written reply.

People will say that he was humble and took his lumps and they still trust Valve.

That's about it.

Eh, I'd go so far as to say we'll get a bunch of free cards and badges.

Yippee.

In all seriousness though, this is class action lawsuit worthy. I think Valve will bleed some money to those effected. At absolute least to their steam wallet.
 

szaromir

Banned
hahahahaha

People have "invested" lots of lots of money into a small group of corporations. When they get completely burned after spending years defending their use of money they will either

1) be really, really fucking pissed
2) go into complete denial and make sure everyone knows they are right

Yup, extremely sad.
 

jacobeid

Banned
Please both learn to read, as that is not what youjacobeid originally wrote. Thank you.

I quite literally posted a list of the details that have been exposed through this link, that were not exposed through PSN, and said as such. Not quite sure what you're getting at here, but whatever.
 
I guess Steam Guard is working correctly. Was unaware of this Steam fuck up and when I tried logging into my account, I got email from Valve saying there was a login attempt from me (IP address on email is identical to my pc's IP address).

So, I should be ok?
 

benny_a

extra source of jiggaflops
This is not the time to post random shit you find somewhere without proper attribution from trustworthy sources.
 
Those database dumps aren't public to normal people. You could literally go into anything Steam related and get a new person's account. So you are under the whims of literally anyone who could touch the steam stuff.

I'm not sure what's worse, but it's clearly on the same level.

what if you do it really really fast on several computers/virtual computers/slices and record all this information?....
 

Grief.exe

Member
Will update if we can substantiate Smash's post. I don't know if we will be able to.

What we know so far

  • Most likely an error in the way Steam caches pages.
  • People are able to access random Steam profiles and see compromising information, account names, emails, last 2 digits of credit card, paypal email address, purchases, etc.
  • No changes can be made to the effected account, no purchases can be made. Any evidence to the contrary is, as of yet, unsubstantiated.
  • It's been advised to not access Steam URLs, including the client, until we have more information.
  • Do not post account names you see, huge security risk.
  • Do not log into Steam to unlink your Paypal. If you feel the need, can be done from the actual Paypal website.
  • Reminder: Steamdb is not affiliated with Valve in any way.

bJK2asd.png


owZ6BYU.png


3lbQyvr.png


I'll update this post with more information going forward.
 

Hektor

Member
I quite literally posted a list of the details that have been exposed through this link, that were not exposed through PSN, and said as such. Not quite sure what you're getting at here, but whatever.

You posted a list of data that was compromised. Exactly the same kind of data that was compromised in the PSN breach. That it was exposed to the public rather than a group of hackers was not part of your post.
 

Stumpokapow

listen to the mad man
So much for people saying you couldn't buy or do anything on other peoples accounts right? Nothing to worry about right?

Do you think that screenshot is real? If it is real, do you think it is confirmed to be connected to this issue, or is it possible that it was someone's actual purchases?
 
Top Bottom