URGENT: Don't buy anything on Steam right now

Started by Huw the Poo, December 25, 2015, 04:16:26 PM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

Swatter


Crossroads

Quote from: Grim.Reaper on December 25, 2015, 10:03:16 PM
Saw this steam response...seem pretty casual about it.

Steam is back up and running without any known issues. As a result of a configuration change earlier today, a caching issue allowed some users to randomly see pages generated for other users for a period of less than an hour. This issue has since been resolved. We believe no unauthorized actions were allowed on accounts beyond the viewing of cached page information and no additional action is required by users.

Just woke up to read this thread. Seems the caching issues been resolved and having checked my PayPal nothing suspicious there either. But yeah, you would expect a more serious statement on their behalf. As it is this seems to be just a separate statement, and at Steampowered there's no mention of this at all on their News page.

Not a very reassuring approach...
Campaign Series Legion | CS: Vietnam | CS: Middle East

CS: Vietnam DAR: LZ Albany as NVA (South Vietnam 11/17/65)  
CS: Middle East DARs: High Water Mark (Syria 10/12/73) Me vs Berto | Riptide (Libya 8/6/85) Me vs Berto | The Crossroads (West Bank 6/5/67)  Me vs Berto

Boardgame AARs: AH D-Day | MMP PanzerBlitz2 Carentan | OSS Putin's Northern War | GMT Next War: Poland | LnL Against the Odds DIY

Huw the Poo

OK, now I can say it: Typical Valve arrogance!

HA!

Grim.Reaper

Even if customers couldn't initiate a transaction on some one's account, they still had access to see other peoples information....that is still pretty serious and they have seemed to ignore that.

Will be interesting to see where it goes......maybe 10 free games to all customers:)

FarAway Sooner

Any security breach is a big one and needs to be taken seriously, especially given that security is an even bigger issue for Valve (a purely digital distribution channel) than for a firm like Target.  My bet is that their A Team for Corporate Communications and crisis control isn't all at the helm just yet, although a lot more of them are working today than planned to be.  The tech/security folks all got nasty pages/phone calls on Christmas Day, but the Communications types probably won't be back until Monday.

If the issue was limited to seeing the last few digits of a random users' CC, that's not as worrisome to me.  Info like that is valuable on the black market, but typically when it's downloaded from a hacked payments file, rather than manually transcribed by entry-level Nigerian hacker-sweatshop employees looking at clients' individual log-on pages.

Of course, my gift functionality isn't working this morning so I have no idea what presents I might have received from friends yesterday while I was busy with family...   :knuppel2:


JasonPratt

The 10 cheapest games you don't already own on Steam for free!  >:D
ICEBREAKER THESIS CHRONOLOGY! -- Victor Suvorov's Stalin Grand Strategy theory, in lots and lots of chronological order...
Dawn of Armageddon -- narrative AAR for Dawn of War: Soulstorm: Ultimate Apocalypse
Survive Harder! -- Two season narrative AAR, an Amazon Blood Bowl career.
PanzOrc Corpz Generals -- Fantasy Wars narrative AAR, half a combined campaign.
Khazâd du-bekâr! -- narrative dwarf AAR for LotR BfME2 RotWK campaign.
RobO Q Campaign Generator -- archived classic CMBB/CMAK tool!

davidshq

Guess I missed all the excited as well.

Semantics around the whole thing are interesting. BusinessDictionary defines "security breach" as
Quote"An act from outside an organization that bypasses or contravenes security policies, practices, or procedures."

It then notes that

Quote"A similar internal act is called security violation."

I suppose one could still argue over whether a "security violation" has to be intentional. If we assume that it does not, then this would be a "security violation." If we assume that it does require intentionality it would be neither a "security breach" nor a "security violation" - which leaves one digging for another term, which escapes me at the moment.

All that said, I think that fuller disclosure is almost always better in these situations. When you don't take time to break down what actually happened it leaves folks wondering...Panzerde offered a much better response. :)