URGENT: Don't buy anything on Steam right now

Started by Huw the Poo, December 25, 2015, 04:16:26 PM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

Arctic Blast

Quote from: AchillesLastStand on December 25, 2015, 05:26:21 PM
Quote from: Huw the Poo on December 25, 2015, 05:22:39 PM
Valve are denying it's a hack.  I'll paste the community moderator's post here:

QuoteWe've gotten reports that people sometimes see other people's account information on the account page. Valve has been made aware of this and are working on a fix.

Some frequently asked questions:
- No, Steam is not hacked

- Creditcard info and phone numbers are, as required by law, censored and not visible to users

What about Steam Wallet info, is that accessible?

Yep. I was seeing wallet balances, addresses, email addresses, Paypal email addresses...all sorts of things you want some random person viewing.

Tpek

Now I'm reminded that I thought I saw some Admin options available for me earlier on  :))

Staggerwing

Quote from: Huw the Poo on December 25, 2015, 04:34:52 PM
To reiterate: log out of Steam completely.  Preferably don't even go to the website any more.  If this is a hack, they could potentially be serving nasty shit to any visitors.

What about accessing through Linux or iPhone, just to make sure no card info is stored? as far as I know, I've only used Paypal (which I've just disengaged from Steam) but I've been a member a long time and guessing expiration dates on Credit Cards is not that hard to do.
Vituð ér enn - eða hvat?  -Voluspa

Nothing really rocks and nothing really rolls and nothing's ever worth the cost...

"Don't you look at me that way..." -the Abyss
 
'When searching for a meaningful embrace, sometimes my self respect took second place' -Iggy Pop, Cry for Love

... this will go down on your permanent record... -the Violent Femmes, 'Kiss Off'-

"I'm not just anyone, I'm not just anyone-
I got my time machine, got my 'electronic dream!"
-Sonic Reducer, -Dead Boys

Arctic Blast

So, since I never did log out, I figured I'd check things out now that Steam is reporting things are fixed. Looks like they are.

Gusington

✡

слава Україна!

We can't live under the threat of a c*nt because he's threatening nuclear Armageddon.

-JudgeDredd

Arctic Blast


panzerde

Just got back from my mom's where we were for Christmas to see all of this. Looks like I missed the worst of it. Things seem to be working fine for me, now.

From a technical perspective, the symptoms sound like a cache/load balancing issue rather than a deliberate hack. I've seen similar things on ecommerce web servers at clients of mine. That they were able to restore service this quickly supports that idea.

Not that this means that this wasn't a serious security breach, which it most definitely was. Any release of Personally Identifiable Information to unauthorized third-parties is by definition a security breach. Valve has a mess on their hands now.

As a general practice, I recommend turning on Steam Guard and using the Steam Remote Authenticator (not email verification) for two-factor account authentication. That might or might not have helped in this case, but it certainly is a vast improvement over single-factor password authentication in day-to-day use. Valve clearly has a huge problem with accounts getting attacked, credentials stolen, and inventories raided outside of this issue. Two-factor is as much a must with Steam these days as it is with Blizzard.
"This damned Bonaparte is going to get us all killed" - Jean Lannes, 1809

Castellan -  La Fraternite des Boutons Carres

Staggerwing

I've had that SMS verification thing for a while so I'm hoping I'm ok but that probably wouldn't have helped if other folks were logging in under their own user name and password just to see my stuff instead of theirs.
Vituð ér enn - eða hvat?  -Voluspa

Nothing really rocks and nothing really rolls and nothing's ever worth the cost...

"Don't you look at me that way..." -the Abyss
 
'When searching for a meaningful embrace, sometimes my self respect took second place' -Iggy Pop, Cry for Love

... this will go down on your permanent record... -the Violent Femmes, 'Kiss Off'-

"I'm not just anyone, I'm not just anyone-
I got my time machine, got my 'electronic dream!"
-Sonic Reducer, -Dead Boys

bbmike

I signed in and was logged in as someone else! I immediately logged out. So far no strange charges on my credit card or Paypal.  :o
"My life is spent in one long effort to escape from the commonplace of existence."
-Sherlock Holmes

"You know, just once I'd like to meet an alien menace that wasn't immune to bullets."
-Brigadier Lethbridge-Stewart

"There's a horror movie called Alien? That's really offensive. No wonder everyone keeps invading you!"
-The Doctor

"Before Man goes to the stars he should learn how to live on Earth."
-Clifford D. Simak

Grim.Reaper

I seem to be good...and everything back to normal....no weird charges or anything.  It will be interesting to see how Steam handles this issue, it absolutely was a huge deal, can't sweep this one under the rug:)

It won't make me stop using them, but certainly will be more careful and have removed all payment links (only had Paypal).

RangerX3X

#40
The CC purchases on Steam still require the manual input of the three digit security code on the back of the card, and without that they would not be able to complete a purchase. I guess even with a lucky guess (technically not that hard) all they could really do is buy something and gift it to someone, which I would dispute the purchase anyway. So far so good though as there are no pending transactions on that card.

Edit 1: The interesting thing is that if the people could ever be identified I supposed Valve could sue them for lost revenue, which could be substantial (not to mention administrative and court costs).

Maybe it is just me, but I would think hackers would be gamers (I am profiling a stereotype I am sure) and they should be the least likely to cause gamers problems.

Scum of the earth.

Nefaro

Quote from: undercovergeek on December 25, 2015, 05:31:59 PM

doesnt it still ask for your last 3 digits

and wouldnt you just get the game on your library?


For some reason, Steam stopped asking for my 3-digit card verification # months ago.  I thought it rather odd. 

Should've taken my saved info off at that point or switched it over to PayPal verification which should require the extra password.



Despite leaving Steam logged in, and being away during this whole drama, nothing has happened to mine.


JasonPratt

Quote from: RangerX3X on December 25, 2015, 07:41:57 PM
Maybe it is just me, but I would think hackers would be gamers (I am profiling a stereotype I am sure) and they should be the least likely to cause gamers problems.

...you haven't played public multiplayer a lot, I'm guessing. ;)
ICEBREAKER THESIS CHRONOLOGY! -- Victor Suvorov's Stalin Grand Strategy theory, in lots and lots of chronological order...
Dawn of Armageddon -- narrative AAR for Dawn of War: Soulstorm: Ultimate Apocalypse
Survive Harder! -- Two season narrative AAR, an Amazon Blood Bowl career.
PanzOrc Corpz Generals -- Fantasy Wars narrative AAR, half a combined campaign.
Khazâd du-bekâr! -- narrative dwarf AAR for LotR BfME2 RotWK campaign.
RobO Q Campaign Generator -- archived classic CMBB/CMAK tool!

RangerX3X

Quote from: JasonPratt on December 25, 2015, 08:29:07 PM
Quote from: RangerX3X on December 25, 2015, 07:41:57 PM
Maybe it is just me, but I would think hackers would be gamers (I am profiling a stereotype I am sure) and they should be the least likely to cause gamers problems.

...you haven't played public multiplayer a lot, I'm guessing. ;)

Not much, no.

Grim.Reaper

Saw this steam response...seem pretty casual about it.

Steam is back up and running without any known issues. As a result of a configuration change earlier today, a caching issue allowed some users to randomly see pages generated for other users for a period of less than an hour. This issue has since been resolved. We believe no unauthorized actions were allowed on accounts beyond the viewing of cached page information and no additional action is required by users.