Pages: [1] 2
|
 |
|
Author
|
Topic: Steam Hacked. (Read 11077 times)
|
Surlyboi
Terracotta Army
Posts: 10966
eat a bag of dicks
|
Sketchy on details at the moment, but Kotaku sez Steam was hacked. This would explain why the forums have been suckful of late. Also, watch your credit cards for weird activity.
|
Tuned in, immediately get to watch cringey Ubisoft talking head offering her deepest sympathies to the families impacted by the Orlando shooting while flanked by a man in a giraffe suit and some sort of "horrifically garish neon costumes through the ages" exhibit or something. We need to stop this fucking planet right now and sort some shit out. -Kail
|
|
|
WayAbvPar
|
Ugh. Not what I wanted to see, especially while EA is trying to shove Origin down everyone's throats.
|
When speaking of the MMOG industry, the glass may be half full, but it's full of urine. HaemishM
Always wear clean underwear because you never know when a Tory Government is going to fuck you.- Ironwood
Libertarians make fun of everyone because they can't see beyond the event horizons of their own assholes Surlyboi
|
|
|
Rasix
Moderator
Posts: 15024
I am the harbinger of your doom!
|
Then I guess it's a good thing that I stopped having Steam save the CC details after I got my new card.
This will make the holiday sale a bit more annoying, but I think I'll manage.
|
-Rasix
|
|
|
Ingmar
Terracotta Army
Posts: 19280
Auto Assault Affectionado
|
The silver lining is that apparently Valve's security isn't as brain dead as say Sony's, and all the passwords were hashed and the credit card numbers were encrypted.
|
The Transcendent One: AH... THE ROGUE CONSTRUCT. Nordom: Sense of closure: imminent.
|
|
|
murdoc
Terracotta Army
Posts: 3037
|
Dear Steam Users and Steam Forum Users,
Our Steam forums were defaced on the evening of Sunday, November 6. We began investigating and found that the intrusion goes beyond the Steam forums.
We learned that intruders obtained access to a Steam database in addition to the forums. This database contained information including user names, hashed and salted passwords, game purchases, email addresses, billing addresses and encrypted credit card information. We do not have evidence that encrypted credit card numbers or personally identifying information were taken by the intruders, or that the protection on credit card numbers or passwords was cracked. We are still investigating.
We don’t have evidence of credit card misuse at this time. Nonetheless you should watch your credit card activity and statements closely.
While we only know of a few forum accounts that have been compromised, all forum users will be required to change their passwords the next time they login. If you have used your Steam forum password on other accounts you should change those passwords as well.
We do not know of any compromised Steam accounts, so we are not planning to force a change of Steam account passwords (which are separate from forum passwords). However, it wouldn’t be a bad idea to change that as well, especially if it is the same as your Steam forum account password.
We will reopen the forums as soon as we can.
I am truly sorry this happened, and I apologize for the inconvenience.
Gabe.
|
Have you tried the internet? It's made out of millions of people missing the point of everything and then getting angry about it
|
|
|
Paelos
Contributor
Posts: 27075
Error 404: Title not found.
|
Well fuck.
|
CPA, CFO, Sports Fan, Game when I have the time
|
|
|
MisterNoisy
Terracotta Army
Posts: 1892
|
Crap. This is the second time this year I've had to get a new AmEx number because of my gaming habit.
|
XBL GT: Mister Noisy PSN: MisterNoisy Steam UID: MisterNoisy
|
|
|
Kail
Terracotta Army
Posts: 2858
|
Do we need to do that? I was under the impression that we should be okay unless they somehow break the encryption, which is unlikely.
|
|
|
|
Ingmar
Terracotta Army
Posts: 19280
Auto Assault Affectionado
|
I'm not changing my card unless I actually see a funky transaction, it is entirely too much of a pain in the ass and I've already changed numbers twice this year.
|
The Transcendent One: AH... THE ROGUE CONSTRUCT. Nordom: Sense of closure: imminent.
|
|
|
MisterNoisy
Terracotta Army
Posts: 1892
|
Do we need to do that? I was under the impression that we should be okay unless they somehow break the encryption, which is unlikely.
Call it a habit. It's AmEx, so they next-day FedEx a new card to you. Gotta love their customer service.
|
XBL GT: Mister Noisy PSN: MisterNoisy Steam UID: MisterNoisy
|
|
|
UnSub
Contributor
Posts: 8064
|
This kind of thing is one of the reasons I don't trust the cloud.
|
|
|
|
Hawkbit
Terracotta Army
Posts: 5531
Like a Klansman in the ghetto.
|
The way of the future is not being hack-proof, it's having damage mitigation/recovery procedures in place. It's not a question of IF your shit will get hacked, rather WHEN it will.
Just don't ever, ever use debit cards online.
|
|
|
|
Tale
Terracotta Army
Posts: 8567
sıɥʇ ǝʞıן sʞןɐʇ
|
"Steam only has, what, 35 million users? Somebody scored big." - F-Secure CRO @Mikko Hypponen "Steam user? Worried about your account? Tip: Steam => Settings => Manage Steam Guard Account Security => Deauthorize all other computers now"
|
|
|
|
Samwise
Moderator
Posts: 19324
sentient yeast infection
|
Just don't ever, ever use debit cards online.
Don't most debit cards have the same fraud protection that credit cards do? I know mine does (although it's moot because the one I use on Steam goes with an account that I'm about to close).
|
|
|
|
Chimpy
Terracotta Army
Posts: 10633
|
I never saved a CC with steam (I actually haven't done saved CC#s for non-subscription things for a long time now) so I am not overly concerned.
I did do the de-auth thing for the hell of it though.
|
'Reality' is the only word in the language that should always be used in quotes.
|
|
|
Hawkbit
Terracotta Army
Posts: 5531
Like a Klansman in the ghetto.
|
Just don't ever, ever use debit cards online.
Don't most debit cards have the same fraud protection that credit cards do? I know mine does (although it's moot because the one I use on Steam goes with an account that I'm about to close). They don't. With a credit card, by law you are only responsible for $50 of fraudulent activity. With a debit card, you may or may not only be responsible for $50 of fraudulent activity, but the whole time the investigation is transpiring you are out your cold, hard cash. Oh, and those checks you had written? They're all going to bounce and guess who gets to eat the fees? Last Christmas day we got a call from the bank that three minutes prior someone used our debit card in the UK to buy some electronics. We lived in Ohio. Why it registered on their 'odd transactions' list, yet still processed, I have no idea. Luckily our bank was really good about getting the cash back to us in four days and they accepted all the bounced checks without fees. But other banks may not. I've never used the new cards online yet.
|
|
|
|
Thrawn
Terracotta Army
Posts: 3089
|
It amazes me that people exist that need to be told to watch their CC statements for suspicious charges. Why would you not take 30 seconds to look over your bill every month by default.  Steam seems to be handling this really well though (so far), no Steam outage even compared to PSN being down for weeks.
|
"Sometimes I think the surest sign that intelligent life exists elsewhere in the Universe is that none of it has tried to contact us."
|
|
|
Soukyan
Terracotta Army
Posts: 1995
|
"Steam user? Worried about your account? Tip: Steam => Settings => Manage Steam Guard Account Security => Deauthorize all other computers now"
Bingo. The first thing I did followed by a new password and updated security question. Never did store CC info on Steam. Entirely too dangerous to store that anywhere online.
|
"Life is no cabaret... we're inviting you anyway." ~ Amanda Palmer"Tree, awesome, numa numa, love triangle, internal combustion engine, mountain, walk, whiskey, peace, pascagoula" ~ Lantyssa"Les vrais paradis sont les paradis qu'on a perdus." ~Marcel Proust
|
|
|
Amaron
Terracotta Army
Posts: 2020
|
|
|
|
|
Kageru
Terracotta Army
Posts: 4549
|
Although storing CC details can help avoid it getting stolen by key-loggers. Remember reading one account that came out with that outcome.
Not sure how removing authorization from machines on steam helps that much. If they steal my credit card details they're probably not going to buy me games with it.
And thankfully no "plain-text data file" debacle so far.
|
Is a man not entitled to the hurf of his durf? - Simond
|
|
|
Engels
Terracotta Army
Posts: 9029
inflicts shingles.
|
You guys do realize that only the most amateur businesses would store your CC info in an unencrypted format, right? And that hacking that encrypted number would take for freakin' ever, yes? In fact, and I can't speak for Steam here, but when I worked at Amazon, the CC info wasn't even available to Amazon; the encryption was part of the CC transaction process that would be forwarded to the CC agency/bank itself; Amazon had no way of getting the raw CC number either.
|
I should get back to nature, too. You know, like going to a shop for groceries instead of the computer. Maybe a condo in the woods that doesn't even have a health club or restaurant attached. Buy a car with only two cup holders or something. -Signe
I LIKE being bounced around by Tonkors. - Lantyssa
Babies shooting themselves in the head is the state bird of West Virginia. - schild
|
|
|
Soukyan
Terracotta Army
Posts: 1995
|
You guys do realize that only the most amateur businesses would store your CC info in an unencrypted format, right? And that hacking that encrypted number would take for freakin' ever, yes? In fact, and I can't speak for Steam here, but when I worked at Amazon, the CC info wasn't even available to Amazon; the encryption was part of the CC transaction process that would be forwarded to the CC agency/bank itself; Amazon had no way of getting the raw CC number either.
This is why Amazon's system is more secure than others.
|
"Life is no cabaret... we're inviting you anyway." ~ Amanda Palmer"Tree, awesome, numa numa, love triangle, internal combustion engine, mountain, walk, whiskey, peace, pascagoula" ~ Lantyssa"Les vrais paradis sont les paradis qu'on a perdus." ~Marcel Proust
|
|
|
Amaron
Terracotta Army
Posts: 2020
|
And that hacking that encrypted number would take for freakin' ever, yes?
The problem is the decryption info for the CC database might of also been compromised for all we know. If they are halfway competent it should be safe of course.
|
|
|
|
apocrypha
Terracotta Army
Posts: 6711
Planes? Shit, I'm terrified to get in my car now!
|
OK, I'm fed up with this shit. Time to make the switch to some kind of password management system so that I can use a different password for every single site and app and thus when something gets hacked I only have to worry about that one site.
Is KeePass good? Anyone here use it? Do I need the "Professional" version (2.x) or is the "Classic" version (1.x) sufficient?
|
"Bourgeois society stands at the crossroads, either transition to socialism or regression into barbarism" - Rosa Luxemburg, 1915.
|
|
|
Tebonas
Terracotta Army
Posts: 6365
|
I use 1Password since shortly after the Sony Case (I have to thank my ages old Everquest account for that).
I had to buy it, but it has clients for Windows, Linux and iOS which synch with each other.
I tried Keepass (1.x) and it worked well enough so that I wouldn't have replaced it if I had a single OS and wasn't a lazy fuck.
|
|
|
|
Baldrake
Terracotta Army
Posts: 636
|
LastPass works well and is free.
|
|
|
|
Ironwood
Terracotta Army
Posts: 28240
|
This kind of thing is one of the reasons I don't trust the cloud.

|
"Mr Soft Owl has Seen Some Shit." - Sun Tzu
|
|
|
DraconianOne
Terracotta Army
Posts: 2905
|
I can't see a way to find out what CC info Steam may have stored? Anyone know how to find this out and clear it? (Not that I think any CCs of mine that might be stored are currently valid but I want to check anyway)
|
A point can be MOOT. MUTE is more along the lines of what you should be. - WayAbvPar
|
|
|
Ironwood
Terracotta Army
Posts: 28240
|
Wait, you can't change your password from the Web Login ?
That's annoying.
|
"Mr Soft Owl has Seen Some Shit." - Sun Tzu
|
|
|
Thrawn
Terracotta Army
Posts: 3089
|
Is KeePass good? Anyone here use it? Do I need the "Professional" version (2.x) or is the "Classic" version (1.x) sufficient?
I've used Keepass + Dropbox for a while now and really like it, couldn't speak to 2.x vs 1.x though. Used Lastpass for a while but quit trusting them after they had their own security problems.
|
"Sometimes I think the surest sign that intelligent life exists elsewhere in the Universe is that none of it has tried to contact us."
|
|
|
01101010
Terracotta Army
Posts: 12007
You call it an accident. I call it justice.
|
Wait, you can't change your password from the Web Login ?
That's annoying.
It gets worse if you have been auto-logging into Steam and now can't recall which of the 700 passwords you used. There is no easy reset password link. I am going to have to wrestle with customer service again. 
|
Does any one know where the love of God goes...When the waves turn the minutes to hours? -G. Lightfoot
|
|
|
Fordel
Terracotta Army
Posts: 8306
|
Wait, you can't change your password from the Web Login ?
That's annoying.
It gets worse if you have been auto-logging into Steam and now can't recall which of the 700 passwords you used. There is no easy reset password link. I am going to have to wrestle with customer service again.  For what it's worth, I had forgotten my steam password awhile ago and had them reset it by the next day. Of course I didn't do this during a big security breach problem... so good luck?
|
and the gate is like I TOO AM CAPABLE OF SPEECH
|
|
|
Xuri
Terracotta Army
Posts: 1199
몇살이세욬ㅋ 몇살이 몇살 몇살이세욬ㅋ!!!!!1!
|
Anyone have any experience with http://passwordmaker.org ? I guess it's time to upgrade from my "1 password for important stuff, 1 password for less important stuff, 1 password for regular stuff and 1 throwaway password" to something more secure, and I'm not sure how to go about doing just that.
|
-= Ho Eyo He Hum =-
|
|
|
Kageru
Terracotta Army
Posts: 4549
|
Passwords in a text file protected with bcrypt or PGP works for me. I can't see a way to find out what CC info Steam may have stored? Anyone know how to find this out and clear it? (Not that I think any CCs of mine that might be stored are currently valid but I want to check anyway)
You could always just do an order upto the payment page and see what info it presents.
|
Is a man not entitled to the hurf of his durf? - Simond
|
|
|
Zetor
Terracotta Army
Posts: 3269
|
At my workplace (IT security evaluation lab, so paranoia level is over 9000) we use KeePass with randomly-generated 16+char passwords; the KeePass databases themselves are stored on encrypted USB sticks. Personally I think using KeePass by itself with unique ~16-char mixed-case alphanum/special character passwords is good enough. As an aside, this comic is cute, but it's not actually true in practice -- such passphrases are only strong if they're 20+ characters and 4+ words long, and most places on teh intarweb silently truncate your passwords at 12~14 characters, which can lead to a nasty surprise if you're using lowercase dictionary words for your passphrase. Using a long passphrase for KeePass or your encrypted USB stick is a good idea, though.
|
|
|
|
|
Pages: [1] 2
|
|
|
 |