• Hey, guest user. Hope you're enjoying NeoGAF! Have you considered registering for an account? Come join us and add your take to the daily discourse.

Steam security issue revealed personal info to other users on XMas Day (fixed)

Q4YyNu4.png


Not me, someone posted.

I mean this could easily be shopped...
 

Big-ass Ramp

hella bullets that's true
how does a company like steam have ZERO social media presence for stuff like this? This is extremely laziness or hubris.
 
Like the other's said it was in a trailer, but I removed it anyway and sorry If I ruined the moment for you.

nah, it's cool. it's just a brief moment anyways and i guess it's not a huge spoiler if they're putting it in trailers. thanks though!


it did look cool though, but i did at first think that was fan-made lol
 

Rhaknar

The Steam equivalent of the drunk friend who keeps offering to pay your tab all night.
most of my friend's list is still playing games as usual

nothing-stops-this-train.gif
 

Haunted

Member
Are people from valve astroturfing this thread or are people really this servile to corporations?
Can't imagine the former, that would mean Valve employees are actually doing something.


Jokes aside, this is pretty much a nightmare scenario for Valve and the customers invested in the ecosystem. If there's any one person able to be blamed, their head is going to roll over this.
 
What I gather from this (just read through the thread and Twitter):

It looks like local CDN servers were just throwing account management pages at the user that were hot in its local cache (which is why some people got the same user's account page). This is why SteamDB recommended users not unlink their account information- successfully accessing your account management page means it'll go to the top of a server's cache, meaning it might end up being viewed by someone else.

I'm having trouble reasoning about the possible root cause here: on any other day, I'd guess that Valve toggled some feature relating to mobile authentication (since they just started pushing that so heavily), which caused some unexpected bug to arise in the cache retrieval code. But it's Christmas, and messing with feature toggles on a holiday is a big no-no for any high traffic web-based service.
 

Tubie

Member
I'm way more scared about personal info like my name, address and phone potentially shown to millions (?) of random people all over the world.

Fraud CC purchases can be fixed rather easily, the other stuff not so much.
 

Joni

Member
Not trying to excuse Valve here as this totally sounds like something they did to themselves, but shutting down a massive system like Steam would take quite a bit of time. You have caching servers that will keep a lot of the site up even if they pull the plug. You want to make sure you don't cause any more damage than you already have (ie. lock yourself out of your own servers that you can't even shut down then, etc).

The worst thing to do in panic mode is to panic and pull all the wires. When shit hits the fan, you want to be less reactionary and be making informed decisions.

In cases like this, I expect there to be a system in place to deconnect the system from the network. Something tested.
 

inky

Member
Well, I changed my email password just in case. Exposing my billing address, email and phone number (and last credit card numbers) and login name is still pretty damn worrysome tho.

Fuck this shit.
 

Pie and Beans

Look for me on the local news, I'll be the guy arrested for trying to burn down a Nintendo exec's house.
The exciting stopclock continues on until Vave bother to send out an e-mail about this.
 

benny_a

extra source of jiggaflops
actually chaos is the only way I find enjoyment in life

so keep posting this random shit so people can panic!
I think we have currently enough FUD that people don't need to intentionally need to post information that isn't verified.

That goes either the way of causing panic or downplaying it.

We're in information gathering mode to ascertain the significance of this.
 

jmga

Member
So much for people saying you couldn't buy or do anything on other peoples accounts right? Nothing to worry about right?

And you believe a random screenshot posted on the internet when no one has been able to confirm you can make purchases from another's account because...
 

Smash88

Banned
Listen I saw it posted on Reddit and just wanted people to STAY SAFE AND change everything and be careful.

I'm also checking 4chan /v/ and /b/ and they are showing peoples CC info, paypal, everything, they are doxxing people they got cached.

It's not spreading panic, it's a realistic scenario. The image could be fake for all we know, but I'm looking at people's CC info on 4chan right now.
 

Mxrz

Member
So. That's pretty much one of the worst things that could happen to Steam. Remarkable to see the "But Sony" come crashing in this early, too. Going to be a crazy January.

Goes without saying, but changing/securing emails/cc probably a good idea right now.
 
Top Bottom