Login
Sign Up


You are using the mobile version of the forum, some features have been disabled to have it responsive.
Limelight CityRP - v4b1Limelight CityRP - EU Build
Ares Defence Services DiscordAres Defence Services
Limelight Discord
Limelight CityRP - v4b1Limelight CityRP - EU BuildAres Defence Services DiscordAres Defence ServicesLimelight Discord

receiptDevelopment Blog:

Development Contributor Workflow

receiptHR Blog:

What *are* they doing over there?

receiptTeacher Blog:

Insight into the Teacher Team

receiptDevelopment Blog:

Infrastructure Upgrade 11/2019

receiptDevelopment Blog:

how suggestions???

receiptDevelopment Blog:

Planning for the future.


This forum uses cookies
This forum makes use of cookies to store your login information if you are registered, and your last visit if you are not. Cookies are small text documents stored on your computer; the cookies set by this forum can only be used on this website and pose no security risk. Cookies on this forum also track the specific topics you have read and when you last read them. Please confirm whether you accept or reject these cookies being set.

A cookie will be stored in your browser regardless of choice to prevent you being asked this question again. You will be able to change your cookie settings at any time using the link in the footer.

Closed 
Steam has a massive security hole
Judge Rage radio_button_checked
Deny, Defend, Depose
Membership
Posts: 1,057
Threads: 79
Likes Given: 762
Likes Recieved: 1369 in 539 posts
Joined: Aug 2015
Reputation: 12
#1
Dec 26, 2015, 12:04 AM
Okay so, if you go into the store on Steam it will put you into someone's else's account - Valve haven't yet said anything, but it looks like they've shut the Steam store down. Make sure your account is safe.

Sorry this isn't very long, just wrote the basics. If you want to know more, read one of the sources.

Source: https://www.theverge.com/2015/12/25/1066...y-problems
https://kotaku.com/steam-goes-nuts-offer...1749718979
(This post was last modified: Dec 26, 2015, 12:05 AM by Judge Rage. Edited 1 time in total.)
Posts: 3,867
Threads: 393
Likes Given: 1690
Likes Recieved: 3666 in 1253 posts
Joined: Aug 2015
Reputation: 62
#2
Dec 26, 2015, 12:17 AM
Thanks for sharing, at one point I had 20£ on my account it was exciting!

Also bad because adresses and credit card information could be slightly seen
(This post was last modified: Dec 26, 2015, 12:18 AM by Bambo.)
jarz radio_button_checked
Member
Membership
Posts: 330
Threads: 17
Likes Given: 137
Likes Recieved: 434 in 197 posts
Joined: Aug 2015
Reputation: 6
#3
Dec 26, 2015, 12:42 AM
Reddit has gone off the hook.
/r/steam

Also, make sure your phone number is not changed, and that you have mobile authenticator on.

IF YOU HAVE A CREDIT/DEBIT HOOKED TO YOUR STEAM ACCOUNT, TRANSFER THE FUNDS FROM SAID CARD TO A SAFE ACCOUNT. IF YOU DON'T, YOU RISK HAVING SAID FUNDS PROCESSED INTO STEAM CASH, THUS MAKING IT IMPOSSIBLE TO GET IT BACK ON YOUR CARD.
(This post was last modified: Dec 26, 2015, 12:43 AM by jarz.)
evilmat360 radio_button_checked
That inactive fuck
Membership
Posts: 540
Threads: 27
Likes Given: 252
Likes Recieved: 164 in 110 posts
Joined: Aug 2015
Reputation: 3
#4
Dec 26, 2015, 12:45 AM
gg Valve. Best advice atm is just stay off steam. Client isnt able to connect anyway it seems atm.
[Image: bkZ74Ui.png]
(This post was last modified: Dec 26, 2015, 12:48 AM by evilmat360.)
Voluptious radio_button_checked
Veteran
Veteran Member
Posts: 1,122
Threads: 50
Likes Given: 301
Likes Recieved: 462 in 215 posts
Joined: Aug 2015
Reputation: 10
#5
Dec 26, 2015, 03:28 AM
Steam is beeing hit with a MASSIVE DDos atm, would probably knock us off for months if WE got the full force of it. Due to this heavy load this glitch happens. Valve themselves have suggested to stay off the store for now. Its only transactions that are affected, not stored credit cards.

My source here
[Image: nrNF2MT.png]

[Image: khZmsDz.png]
(This post was last modified: Dec 26, 2015, 03:30 AM by Voluptious. Edited 1 time in total.)
Judge Rage radio_button_checked
Deny, Defend, Depose
Membership
Posts: 1,057
Threads: 79
Likes Given: 762
Likes Recieved: 1369 in 539 posts
Joined: Aug 2015
Reputation: 12
#6
Dec 26, 2015, 04:48 AM
(Dec 26, 2015, 12:42 AM)jarz Wrote: Reddit has gone off the hook.
/r/steam

Also, make sure your phone number is not changed, and that you have mobile authenticator on.

IF YOU HAVE A CREDIT/DEBIT HOOKED TO YOUR STEAM ACCOUNT, TRANSFER THE FUNDS FROM SAID CARD TO A SAFE ACCOUNT. IF YOU DON'T, YOU RISK HAVING SAID FUNDS PROCESSED INTO STEAM CASH, THUS MAKING IT IMPOSSIBLE TO GET IT BACK ON YOUR CARD.

I read advice on Reddit to phone up your credit card company and ask to block all transactions with Valve Corporation. 

Course, I don't use credit or debit cards so I'm fine. Thank god it's all over now.
(This post was last modified: Dec 26, 2015, 04:49 AM by Judge Rage.)
Decay radio_button_checked
Too weird to live, too rare to die.
Administrator (CityRP)
Posts: 863
Threads: 53
Likes Given: 766
Likes Recieved: 784 in 352 posts
Joined: Aug 2015
Reputation: 26
#7
Dec 26, 2015, 10:45 AM
This is why I don't save my info online. Yet again I thank my excessive paranoia
The following 3 users Like Decay's post:
  • Cunix, Doodleh, Faustie
Barkles radio_button_checked
The Joker in the pack
Core Staff
Posts: 2,069
Threads: 63
Likes Given: 701
Likes Recieved: 1614 in 745 posts
Joined: Aug 2015
Reputation: 22
#8
Dec 26, 2015, 11:07 AM
I was lucky whilst it was going on I got into my account via steam mobile and took my card off it Tongue

Hackers are welcome to the £0.05 in my account anyway lol
[Image: Z8vTR8U.png]
Judge Rage radio_button_checked
Deny, Defend, Depose
Membership
Posts: 1,057
Threads: 79
Likes Given: 762
Likes Recieved: 1369 in 539 posts
Joined: Aug 2015
Reputation: 12
#9
Dec 26, 2015, 01:52 PM
(Dec 26, 2015, 11:07 AM)Barkles Wrote: I was lucky whilst it was going on I got into my account via steam mobile and took my card off it Tongue

Hackers are welcome to the £0.05 in my account anyway lol

Soviethooves messaged me to tell me and by the time I was actually on my computer Valve had shut down the store. 

All that's on my account is 4 quid and my e-mail address so have fun.
George radio_button_checked
Actively inactive
Veteran Member
Posts: 1,261
Threads: 28
Likes Given: 716
Likes Recieved: 1433 in 530 posts
Joined: Aug 2015
Reputation: 20
#10
Dec 26, 2015, 03:49 PM
Use PayPal as you have to log in to it before you can buy anything, which is effectively two-stage security.
[Image: olA44b8.png]
bimkx radio_button_checked
Developer
Developer
Posts: 820
Threads: 52
Likes Given: 913
Likes Recieved: 774 in 303 posts
Joined: Aug 2015
Reputation: 12
#11
Dec 26, 2015, 04:18 PM
The facts:
There was no DDOS for starters, valve took the servers down upon learning of the breach.

It was purely a failure with the web caching server showing sensitive information.

Attempting to remove your info caused more security issues as the pages showing your information were then cached for everyone to see.

Next time there's a situation like this you should really get proper sources for your info and not get into this scaremongering circlejerk.
SteamDB's twitter next time there's an issue like this.
The following 1 user Likes bimkx's post:
  • Innovative
Voluptious radio_button_checked
Veteran
Veteran Member
Posts: 1,122
Threads: 50
Likes Given: 301
Likes Recieved: 462 in 215 posts
Joined: Aug 2015
Reputation: 10
#12
Dec 26, 2015, 10:14 PM
https://youtu.be/x80VOkFwsL0 << Totalbiscuit PSA

https://youtu.be/dkSslseq9Y8 << Tom scott explanation (WATCH THIS!!!)

Only the last few digits of your credit card and number were exposed. Steam would never in hell show you a full credit card detail as that would never be cached, that would be sendt directly to the main server.

People are overreacting here.
[Image: nrNF2MT.png]

[Image: khZmsDz.png]
(This post was last modified: Dec 26, 2015, 10:15 PM by Voluptious. Edited 1 time in total.)
Judge Rage radio_button_checked
Deny, Defend, Depose
Membership
Posts: 1,057
Threads: 79
Likes Given: 762
Likes Recieved: 1369 in 539 posts
Joined: Aug 2015
Reputation: 12
#13
Dec 26, 2015, 11:58 PM
(Dec 26, 2015, 04:18 PM)LivKX Wrote: The facts:
There was no DDOS for starters, valve took the servers down upon learning of the breach.

It was purely a failure with the web caching server showing sensitive information.

Attempting to remove your info caused more security issues as the pages showing your information were then cached for everyone to see.

Next time there's a situation like this you should really get proper sources for your info and not get into this scaremongering circlejerk.
SteamDB's twitter next time there's an issue like this.

I know Valve took down their servers. However, I think the source Vol quotes is saying that a DDOS caused the failure.
bimkx radio_button_checked
Developer
Developer
Posts: 820
Threads: 52
Likes Given: 913
Likes Recieved: 774 in 303 posts
Joined: Aug 2015
Reputation: 12
#14
Dec 27, 2015, 05:28 AM
There was no DDoS, only an accidental bug/human error with the caching server.
That's it, one server misconfigured.
No hacks, no DDoS, no major security issue.
Most you could probably do was prank call somebody using their number you found on steam .
Y'all need to chill, we don't need to go all PSN/XBL kids, crying when it's down on Christmas day.
Project radio_button_checked
Assisting and Mapping
RP Assistant (CityRP)
Posts: 2,979
Threads: 177
Likes Given: 2858
Likes Recieved: 1519 in 920 posts
Joined: Aug 2015
Reputation: 46
#15
Dec 27, 2015, 11:39 AM
tbh It was fixed fast and we still could play our games.
[Image: sO5GyCt.png]
Closed 




Users browsing this thread: 1 Guest(s)