Announcement

Collapse
No announcement yet.

Steam compromised

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • Steam compromised

    On exiting a game just now, Steam popped up this update:
    November 10th, 2011
    Dear Steam Users and Steam Forum Users:

    Our Steam forums were defaced on the evening of Sunday, November 6. We began investigating and found that the intrusion goes beyond the Steam forums.

    We learned that intruders obtained access to a Steam database in addition to the forums. This database contained information including user names, hashed and salted passwords, game purchases, email addresses, billing addresses and encrypted credit card information. We do not have evidence that encrypted credit card numbers or personally identifying information were taken by the intruders, or that the protection on credit card numbers or passwords was cracked. We are still investigating.

    We don’t have evidence of credit card misuse at this time. Nonetheless you should watch your credit card activity and statements closely.

    While we only know of a few forum accounts that have been compromised, all forum users will be required to change their passwords the next time they login. If you have used your Steam forum password on other accounts you should change those passwords as well.

    We do not know of any compromised Steam accounts, so we are not planning to force a change of Steam account passwords (which are separate from forum passwords). However, it wouldn’t be a bad idea to change that as well, especially if it is the same as your Steam forum account password.

    We will reopen the forums as soon as we can.

    I am truly sorry this happened, and I apologize for the inconvenience.

    Gabe.


    ---------- Post added at 05:45 PM ---------- Previous post was at 05:38 PM ----------

    Unfortunately, the forums are still down in a state that you're unable to change your forum password as of yet. The password to your Steam account can and should be changed as normal through the client if it was the same as your forum password.
    lagolakshmi on Guildwork :: Lago Aletheia on Lodestone

  • #2
    Re: Steam compromised

    hashed and salted passwords
    Sounds delicious.

    Comment


    • #3
      Re: Steam compromised

      ....... -,- I wonder if it is the same group that is hacking all the companies....

      Anonymous said they did the PSN.... but then after that SE again, PSN 2 more times, and then XBLIVE and now Steam -.- this is getting ridiculous
      -------------------------------------------------------------------------
      Kain (FFIV): I am aware of my actions, but can do nothing about them.

      Comment


      • #4
        Re: Steam compromised

        True story: Had a guy who claims to be a hacker try to recruit me last week. Pretty surreal.

        I can remember a time many years ago when the hacker community was more like the International Brotherhood of Magicians. Secrets were just that - secrets - passed or traded carefully from one member to another, and there wasn't this sort of widespread desire for infamy and/or monetary gain.

        Nowadays, hackers come more often in one of two flavors: internet trolls on steroids, or more nefarious scum motivated by greed (read: usually organized crime).

        This doesn't mean that there isn't an elite cadre of hackers out there who still operate more like a secret society than Amway, but they're definitely in the minority these days.


        Icemage

        Comment


        • #5
          Re: Steam compromised

          Well at least they had encryption and didn't wait like two weeks to tell everyone about it. You know, unlike a certain network. Gabe even broke the news himself. Just further proof Valve is a class act.

          Comment


          • #6
            Re: Steam compromised

            Originally posted by Omgwtfbbqkitten View Post
            Well at least they had encryption and didn't wait like two weeks to tell everyone about it. You know, unlike a certain network.
            Actually the time frame was pretty similar. Sony discovered PSN was hacked on April 20, announced it on April 26.

            Valve's forums were hacked on November 5, and they announced this today on November 10.

            The primary difference is that (for now at least) Steam remains online and operational.
            Gabe even broke the news himself. Just further proof Valve is a class act.
            There we agree.


            Icemage

            Comment


            • #7
              Re: Steam compromised

              And to be fair, it wasn't Steam itself that was hacked. The only way you're likely to be in any danger is if you used the same username and pass for both Steam and its forum, which is bad security practice in the first place but probably extremely common.

              ---------- Post added at 08:39 PM ---------- Previous post was at 08:37 PM ----------

              Actually, reading it again I may have misinterpreted that.
              lagolakshmi on Guildwork :: Lago Aletheia on Lodestone

              Comment


              • #8
                Re: Steam compromised

                So, what did Tasky do this time?
                sigpic
                "In this world, the one who has the most fun is the winner!" C.B.
                Prishe's Knight 2004-Forever.

                その目だれの目。

                Comment


                • #9
                  Re: Steam compromised

                  Originally posted by Raydeus View Post
                  So, what did Tasky do this time?
                  This is why we need an UN-Thank button. It should give negative forum experience points.


                  Bastok & Windurst Rank 10. ZM, CoP, ToAU, WoTG, ACP, MKD, ASA & SOA Complete.
                  99 Kannagi / 99 Armageddon / 119 Nirvana Adventuring Fellow: Level 99
                  99 SMN / 99 NIN / 99 COR / 99 WHM / 99 PUP / 99 BLM / 99 THF / 99 SCH / 99 GEO

                  Yyg's Blog: Tree of Awesome!

                  Comment


                  • #10
                    Re: Steam compromised

                    MPK button?



                    PS > And it seems still nothing so far about problems outside the forums, encrypted passwords are encrypted.
                    sigpic
                    "In this world, the one who has the most fun is the winner!" C.B.
                    Prishe's Knight 2004-Forever.

                    その目だれの目。

                    Comment


                    • #11
                      Re: Steam compromised

                      Customer Complaints Department
                      lagolakshmi on Guildwork :: Lago Aletheia on Lodestone

                      Comment


                      • #12
                        Re: Steam compromised

                        Jormy looks constipated... did you feed him Time Mage hats (again)?
                        sigpic
                        "In this world, the one who has the most fun is the winner!" C.B.
                        Prishe's Knight 2004-Forever.

                        その目だれの目。

                        Comment


                        • #13
                          Re: Steam compromised

                          Originally posted by Taskmage View Post
                          And to be fair, it wasn't Steam itself that was hacked. The only way you're likely to be in any danger is if you used the same username and pass for both Steam and its forum, which is bad security practice in the first place but probably extremely common.

                          ---------- Post added at 08:39 PM ---------- Previous post was at 08:37 PM ----------

                          Actually, reading it again I may have misinterpreted that.
                          It wouldn't even matter. Some of the moderators were probably employees of Valve's network operations (e.g. Steam) and had likely registered with their work email, namely that of Valve's domain signature. Thus, it stands to reason, that you can take that and attempt to log-in through the more sensitive areas of the site with these credentials. And we all know that, despite all warnings and education, people will end up being lazy and use 1 password for pretty much a lot of what they do. That's the lucky break that would be the compromise (or at least one scenario)

                          We still don't know if they also were able to drop a back door with root access into the servers. I think part of the reason why the forums are still down is that they are trying to track back where information are being transmitted to and I wouldn't be surprised if they got the Feds involved as well. Also of importance for them is to nail down any zero-day exploits and malware/trojans.

                          Comment


                          • #14
                            Re: Steam compromised

                            A minor update on this was posted today: News - Message from Gabe to Steam Community
                            Dear Steam Users and Steam Forum Users:

                            We continue our investigation of last year's intrusion with the help of outside security experts. In my last note about this, I described how intruders had accessed our Steam database but we found no evidence that the intruders took information from that database. That is still the case.

                            Recently we learned that it is probable that the intruders obtained a copy of a backup file with information about Steam transactions between 2004 and 2008. This backup file contained user names, email addresses, encrypted billing addresses and encrypted credit card information. It did not include Steam passwords.

                            We do not have any evidence that the encrypted credit card numbers or billing addresses have been compromised. However as I said in November it's a good idea to watch your credit card activity and statements. And of course keeping Steam Guard on is a good idea as well.

                            We are still investigating and working with law enforcement authorities. Some state laws require a more formal notice of this incident so some of you will get that notice, but we wanted to update everyone with this new information now.

                            Gabe
                            lagolakshmi on Guildwork :: Lago Aletheia on Lodestone

                            Comment


                            • #15
                              Re: Steam compromised

                              Originally posted by Kailea View Post
                              ....... -,- I wonder if it is the same group that is hacking all the companies....

                              Anonymous said they did the PSN.... but then after that SE again, PSN 2 more times, and then XBLIVE and now Steam -.- this is getting ridiculous
                              you forgot SEGA & Microsoft, they got nailed too and I think even Nintendo a little while back.
                              sigpic


                              "BLAH BLAH BLAH TIDAL WAVE!!!"

                              Comment

                              Working...
                              X