• Hey, guest user. Hope you're enjoying NeoGAF! Have you considered registering for an account? Come join us and add your take to the daily discourse.
  • The Politics forum has been nuked. Please do not bring political discussion to the rest of the site, or you will be removed. Thanks.

Steam security issue revealed personal info to other users on XMas Day (fixed)

May 6, 2014
5,438
0
375
It is absolutely inexcusable that they haven't pulled the plug yet. This is completely incomparable to any of the high profile hacks we've seen in recent years. Fuck you, Valve. This is beyond uncool.
 

yatesl

Member
Jun 3, 2012
2,799
0
0
FUNDS CAN ABSOLUTELY BE ADDED TO ACCOUNTS

It literally just happened to my friend so stop spreading bullshit and damage controlling for valve.

Screenshot please, and blank out personal details. You can see "Add funds", but clicking the buttons don't do anything.

For what it's worth, I'm not damage controlling anything - I'm trying to put people at ease, as this is (understandably) snowballing like crazy.
 

Vamphuntr

Member
Dec 5, 2008
13,792
0
0
QC
Being on Christmas is not en excuse for them being slow to pull the plug. They have millions of users and they are a huge IT/software/store service company. Pull the plug already.
 

BHK3

Banned
Dec 18, 2011
5,890
0
0
28
A paper street house
This seems really bad like the hacking of PSN bad.

From what I recall no ones information was actually taken, I don't remember a single thread saying they had money stolen. PSN was simply taken down and everyone was told to change their info, standard procedure for when security systems are compromised.
 

Tain

Member
Jun 13, 2004
24,278
4
1,555
horizonvanguard.com
i love how corporate apologists are still peddling their shit even in this situation

it's blowing my mind

idgaf if people can't change my shit, seeing my email and last 4 digits and partial phone numbers and addresses etc etc? this is a big fucking deal

I don't think it's at all unreasonable to ask that Valve take down the Steam servers as quickly as they can.
 

JP

Member
Mar 7, 2010
6,734
169
0
Just to be secure, would it not be better if people didn't log into their account when it's like this? Although there's been no confirmation as to what is happening, if the site has been compromised at some level, then it may be best not to be entering log in information while it's compromised.
 

jacobeid

Banned
Oct 3, 2012
6,804
0
0
It is absolutely inexcusable that they haven't pulled the plug yet. This is completely incomparable to any of the high profile hacks we've seen in recent years. Fuck you, Valve. This is beyond uncool.

Yeah. What the fuck.

This might be enough for me to dump them.
 

Jinfash

needs 2 extra inches
Oct 16, 2007
13,883
3
1,335
Jinfash
Once again.

NO ACCOUNT INFORMATION CAN BE CHANGED.

NO PURCHASES CAN BE MADE.

THE MOST PEOPLE CAN SEE IS YOUR E-MAIL, AND PURCHASE HISTORY.



Is it a clusterfuck? Absolutely. But aside from some random person knowing your e-mail and seeing that you've bought Hunniepop, YOU HAVE NOTHING TO WORRY ABOUT.
This a major fuck up as far as privacy breaches go, regardless of whether funds and CC's can be used or not.

An all caps NOTHING TO WORRY ABOUT coming from someone with zero knowledge and access to the service's back-end is worthless.
 

Zomba13

Member
Sep 27, 2009
19,651
7
705
Oh hey, Is the store/account pages down for anyone else? Looks like Valve might've finally shut it down.
 

perorist

Unconfirmed Member
May 15, 2012
5,403
0
0
 

shadowkat

Unconfirmed Member
Mar 28, 2013
11,060
0
0
Stupid thing is that I just saved my cc info to the store and I've never done that before.

Valve needs to fix this shit ASAP.
 

Alethebeer

Member
Aug 8, 2011
526
0
0
Italy
What we know so far

  • Most likely an error in the way Steam caches pages.
  • People are able to access random Steam profiles and see compromising information, account names, emails, last 2 digits of credit card, paypal email address, purchases, etc.
  • No changes can be made to the effected account, no purchases can be made. Any evidence to the country is, as of yet, unsubstantiated.
  • It's been advised to not access Steam URLs, including the client, until we have more information.
  • Do not post account names you see, huge security risk.





I'll update this post with more information going forward.

Quote for science
 

Joqu

Member
Feb 16, 2013
5,512
0
0
The Waffle Kingdom
From what I recall no ones information was actually taken, I don't remember a single thread saying they had money stolen. PSN was simply taken down and everyone was told to change their info, standard procedure for when security systems are compromised.

Yup. This is way worse than PSN as far as I'm concerned.
 

Card Boy

Banned
Aug 11, 2010
17,104
1
0
VIC, Australia
I always thought Valve was a garbage company and this just proves it. This is so much worse than the PSN debacle. This is what you get when you put all your eggs in one basket.
 

Hopeford

Member
Jan 19, 2015
1,766
1
290
I think I only had paypal on my account, not my credit card. What's killing me is that I'm not 200% sure of that.
 

BlueLiquid

Member
Apr 4, 2015
622
0
0
I'm on mobile and can't log in through the iOS app. Did they finally pull the plug? I couldn't get to my account page at all. It was always a random stranger's.

I'm livid. No excuse for this.