Something seriously wrong with the service. Will update in a bit.
Don't do anything with your Steam account right now, since there's a very good chance you're actually doing so with someone else's account and financial details.
It looks at first glance like a major vulnerability. I've put my Steam client into offline mode for now. Still reading up on this.
If you were an idiot (like me) and had Steam save your Paypal info for quick buys, you can totally detach that from within the Paypal site.
Always fun to load up Steam's website and find out it's in Polish and logged in as someone else :P
Quote from: Arctic Blast on December 25, 2015, 04:20:19 PM
If you were an idiot (like me) and had Steam save your Paypal info for quick buys, you can totally detach that from within the Paypal site.
Good advice. Also, if you're currently logged in and have credit card info saved, go to your account details page and delete it. And never have it saved again! :P
My advice is to put your client into offline mode and if you're logged in on the website,
log out.
https://www.hackread.com/hackers-shutdown-ea-sports-steam-servers-for-christmas/
Just to lighten the mood a bit...man, some of these people have terrible taste in games. People actually purchase some of this crap?!
Quote from: Huw the PooGood advice. Also, if you're currently logged in and have credit card info saved, go to your account details page and delete it.
Keep in mind that doing so requires going to your account details, and you're probably going to find yourself looking at the account details of a completely different person.
For those who want to detach a Paypal account, log in to the Paypal and click on any Steam purchase in your transactions list. There will be a link in the entry that opens up saying 'Manage WWW.Steampowered.com payments'. Clicking on that brings up another Window. One of the lines at the top of that window mentions status. You can click to cancel the payment agreement between Paypal and Steam.
You can also go into paypal and there is a screen called Payment Preferences...it lists all the places you have linked your account, including Valve....I was actually stunned to see how many places I had somehow linked.....immediately canceled them all (not just because of this event, but no reason to have them linked like that).
Looks like Valve have shut down the store.
The popular theory right now is that admin mode has somehow been unlocked for everyone. I personally disagree, but there clearly is some kind of permissions issue and is potentially extremely serious. Someone at Valve needs to purge their entire payment details database right now.
My money's on a hack. Christmas Day has, sadly, become a popular time to hack stuff, and changes to permissions is an obvious resulting action.
This is going to be a shitty Christmas for some people at Valve. :(
Could also be a page caching issue....where online sessions are being mixed up.....I have seen some applications do that before and can be messy....I guess we'll see:)
To reiterate: log out of Steam completely. Preferably don't even go to the website any more. If this is a hack, they could potentially be serving nasty shit to any visitors.
There are reports of fraudulent transactions appearing on credit cards (can you really see them that quickly?). I'm taking it with a grain of salt, but if you do have card information saved on Steam, it's worth keeping a close eye on transactions. And don't keep your card info saved on Steam.
Just got on to delete my saved info and it wouldn't let me do anything, black screen was pretty much all I got regardless of what I clicked on.
Yes, my bank will show purchases immediately in pending state when they happen, so you can see them quickly....I have alerting attached to my accounts so I would be notified if anyone transacted against my account within seconds....nothing so far.
I don't have any card info saved, thankfully - when did this first start? Earlier today?
1-2 hours ago I think.
Crap so it's literally just cropped up...
http://www.rockpapershotgun.com/2015/12/25/steam-is-going-haywire-people-can-access-others-accounts/
Merry Christmas, Valve.
Ugh! Helmet on. Hiding behind couch. :o
From Steam Database Twitter........
"By the way, this is not a security breach. This is page caching gone rogue. Most likely not respecting Cache-Control headers"
https://twitter.com/SteamDB/status/680492664610000896
Guess someone doesn't know the definition of "security breach".
Quote from: IronX on December 25, 2015, 05:18:28 PM
Ugh! Helmet on. Hiding behind couch. :o
Good plan. Move over a bit.
Valve are denying it's a hack. I'll paste the community moderator's post here:
QuoteWe've gotten reports that people sometimes see other people's account information on the account page. Valve has been made aware of this and are working on a fix.
Some frequently asked questions:
- No, Steam is not hacked
- Creditcard info and phone numbers are, as required by law, censored and not visible to users
Quote from: AchillesLastStand on December 25, 2015, 05:19:58 PM
Guess someone doesn't know the definition of "security breach".
Agreed. That you can view, at least, someone's name and full address details absolutely makes it a security breach.
Typical Valve arrogance. Sorry, the Twitter account is not related to Valve.
Quote from: Huw the Poo on December 25, 2015, 05:22:39 PM
Valve are denying it's a hack. I'll paste the community moderator's post here:
QuoteWe've gotten reports that people sometimes see other people's account information on the account page. Valve has been made aware of this and are working on a fix.
Some frequently asked questions:
- No, Steam is not hacked
- Creditcard info and phone numbers are, as required by law, censored and not visible to users
What about Steam Wallet info, is that accessible?
Quote from: AchillesLastStand on December 25, 2015, 05:26:21 PM
What about Steam Wallet info, is that accessible?
Apparently so, loads of people have reported being able to see wallet balances etc.
Well shit. I'm stuck at work for another 5 hours and can't access anything from here to check balances or reset passwords.
Quote from: Huw the Poo on December 25, 2015, 04:50:24 PM
There are reports of fraudulent transactions appearing on credit cards (can you really see them that quickly?). I'm taking it with a grain of salt, but if you do have card information saved on Steam, it's worth keeping a close eye on transactions. And don't keep your card info saved on Steam.
doesnt it still ask for your last 3 digits
and wouldnt you just get the game on your library?
Quote from: AchillesLastStand on December 25, 2015, 05:26:21 PM
Quote from: Huw the Poo on December 25, 2015, 05:22:39 PM
Valve are denying it's a hack. I'll paste the community moderator's post here:
QuoteWe've gotten reports that people sometimes see other people's account information on the account page. Valve has been made aware of this and are working on a fix.
Some frequently asked questions:
- No, Steam is not hacked
- Creditcard info and phone numbers are, as required by law, censored and not visible to users
What about Steam Wallet info, is that accessible?
Yep. I was seeing wallet balances, addresses, email addresses, Paypal email addresses...all sorts of things you want some random person viewing.
Now I'm reminded that I thought I saw some Admin options available for me earlier on :))
Quote from: Huw the Poo on December 25, 2015, 04:34:52 PM
To reiterate: log out of Steam completely. Preferably don't even go to the website any more. If this is a hack, they could potentially be serving nasty shit to any visitors.
What about accessing through Linux or iPhone, just to make sure no card info is stored? as far as I know, I've only used Paypal (which I've just disengaged from Steam) but I've been a member a long time and guessing expiration dates on Credit Cards is not that hard to do.
So, since I never did log out, I figured I'd check things out now that Steam is reporting things are fixed. Looks like they are.
Can I take my helmet off?
Quote from: Gusington on December 25, 2015, 06:42:22 PM
Can I take my helmet off?
Leave it on. It makes you look dashing.
Just got back from my mom's where we were for Christmas to see all of this. Looks like I missed the worst of it. Things seem to be working fine for me, now.
From a technical perspective, the symptoms sound like a cache/load balancing issue rather than a deliberate hack. I've seen similar things on ecommerce web servers at clients of mine. That they were able to restore service this quickly supports that idea.
Not that this means that this wasn't a serious security breach, which it most definitely was. Any release of Personally Identifiable Information to unauthorized third-parties is by definition a security breach. Valve has a mess on their hands now.
As a general practice, I recommend turning on Steam Guard and using the Steam Remote Authenticator (not email verification) for two-factor account authentication. That might or might not have helped in this case, but it certainly is a vast improvement over single-factor password authentication in day-to-day use. Valve clearly has a huge problem with accounts getting attacked, credentials stolen, and inventories raided outside of this issue. Two-factor is as much a must with Steam these days as it is with Blizzard.
I've had that SMS verification thing for a while so I'm hoping I'm ok but that probably wouldn't have helped if other folks were logging in under their own user name and password just to see my stuff instead of theirs.
I signed in and was logged in as someone else! I immediately logged out. So far no strange charges on my credit card or Paypal. :o
I seem to be good...and everything back to normal....no weird charges or anything. It will be interesting to see how Steam handles this issue, it absolutely was a huge deal, can't sweep this one under the rug:)
It won't make me stop using them, but certainly will be more careful and have removed all payment links (only had Paypal).
The CC purchases on Steam still require the manual input of the three digit security code on the back of the card, and without that they would not be able to complete a purchase. I guess even with a lucky guess (technically not that hard) all they could really do is buy something and gift it to someone, which I would dispute the purchase anyway. So far so good though as there are no pending transactions on that card.
Edit 1: The interesting thing is that if the people could ever be identified I supposed Valve could sue them for lost revenue, which could be substantial (not to mention administrative and court costs).
Maybe it is just me, but I would think hackers would be gamers (I am profiling a stereotype I am sure) and they should be the least likely to cause gamers problems.
Scum of the earth.
Quote from: undercovergeek on December 25, 2015, 05:31:59 PM
doesnt it still ask for your last 3 digits
and wouldnt you just get the game on your library?
For some reason, Steam stopped asking for my 3-digit card verification # months ago. I thought it rather odd.
Should've taken my saved info off at that point or switched it over to PayPal verification which should require the extra password.
Despite leaving Steam logged in, and being away during this whole drama, nothing has happened to mine.
Quote from: RangerX3X on December 25, 2015, 07:41:57 PM
Maybe it is just me, but I would think hackers would be gamers (I am profiling a stereotype I am sure) and they should be the least likely to cause gamers problems.
...you haven't played public multiplayer a lot, I'm guessing. ;)
Quote from: JasonPratt on December 25, 2015, 08:29:07 PM
Quote from: RangerX3X on December 25, 2015, 07:41:57 PM
Maybe it is just me, but I would think hackers would be gamers (I am profiling a stereotype I am sure) and they should be the least likely to cause gamers problems.
...you haven't played public multiplayer a lot, I'm guessing. ;)
Not much, no.
Saw this steam response...seem pretty casual about it.
Steam is back up and running without any known issues. As a result of a configuration change earlier today, a caching issue allowed some users to randomly see pages generated for other users for a period of less than an hour. This issue has since been resolved. We believe no unauthorized actions were allowed on accounts beyond the viewing of cached page information and no additional action is required by users.
We will see
Quote from: Grim.Reaper on December 25, 2015, 10:03:16 PM
Saw this steam response...seem pretty casual about it.
Steam is back up and running without any known issues. As a result of a configuration change earlier today, a caching issue allowed some users to randomly see pages generated for other users for a period of less than an hour. This issue has since been resolved. We believe no unauthorized actions were allowed on accounts beyond the viewing of cached page information and no additional action is required by users.
Just woke up to read this thread. Seems the caching issues been resolved and having checked my PayPal nothing suspicious there either. But yeah, you would expect a more serious statement on their behalf. As it is this seems to be just a separate statement, and at Steampowered there's no mention of this at all on their News page.
Not a very reassuring approach...
OK, now I can say it: Typical Valve arrogance!
HA!
Even if customers couldn't initiate a transaction on some one's account, they still had access to see other peoples information....that is still pretty serious and they have seemed to ignore that.
Will be interesting to see where it goes......maybe 10 free games to all customers:)
Any security breach is a big one and needs to be taken seriously, especially given that security is an even bigger issue for Valve (a purely digital distribution channel) than for a firm like Target. My bet is that their A Team for Corporate Communications and crisis control isn't all at the helm just yet, although a lot more of them are working today than planned to be. The tech/security folks all got nasty pages/phone calls on Christmas Day, but the Communications types probably won't be back until Monday.
If the issue was limited to seeing the last few digits of a random users' CC, that's not as worrisome to me. Info like that is valuable on the black market, but typically when it's downloaded from a hacked payments file, rather than manually transcribed by entry-level Nigerian hacker-sweatshop employees looking at clients' individual log-on pages.
Of course, my gift functionality isn't working this morning so I have no idea what presents I might have received from friends yesterday while I was busy with family... :knuppel2:
The 10 cheapest games you don't already own on Steam for free! >:D
Guess I missed all the excited as well.
Semantics around the whole thing are interesting. BusinessDictionary defines "security breach" as
Quote"An act from outside an organization that bypasses or contravenes security policies, practices, or procedures."
It then notes that
Quote"A similar internal act is called security violation."
I suppose one could still argue over whether a "security violation" has to be intentional. If we assume that it does not, then this would be a "security violation." If we assume that it does require intentionality it would be neither a "security breach" nor a "security violation" - which leaves one digging for another term, which escapes me at the moment.
All that said, I think that fuller disclosure is almost always better in these situations. When you don't take time to break down what actually happened it leaves folks wondering...Panzerde offered a much better response. :)
Steams side of the story....
http://www.pcgamer.com/valve-apologizes-for-steams-troubled-christmas