Steam security issue revealed personal info to other users on XMas Day (fixed)

Okay, so it's not a hack, but it's on the busiest day (for most people) of the year and they don't even drop us a fucking email saying 'Hey someone might have your phone number, real name and shit, so....sorry?"

WTF. I didn't even know about this.

Well, the servers were only shut off about a half hour ago - they probably are still trying to assess the damage before making an official statement.

Terrible response time, I agree.
 
no, they have a plan in place for that.

if i remember correct, something about you being able to download them for like a few months, and them then working without steam being operational.
They claim they have a plan but I don't believe it. Valve doesn't have the legal ability to remove DRM from all the third party games on their service.
 
SteamDB has no affiliation with Valve, they're just guessing at what happened. I don't understand why people keep linking to them...
Probably because Valve continues to be completely silent about all of this and DB is one of the only things to go on.
 
Maybe this will mean Valve will get some proper support now.

*Hears Gabe laugh*
But their precious flat management structure and automation..

All these obvious issues people have been bringing up for years, from communication to support, coming home to roost. I've been a fan and pretty loyal for ages but after this, fuck that slow ass company. Gonna take significant action (and time) to make things right again.
 
Okay, so it's not a hack, but it's on the busiest day (for most people) of the year and they don't even drop us a fucking email saying 'Hey someone might have your phone number, real name and shit, so....sorry?"

WTF. I didn't even know about this.

What's even worse is that they don't even seem to have a "KILL IT ALL SHUT IT DOWN" button for situations like these. Downtime on Christmas is much less bad in terms of PR than potential mass-information leaks on Christmas.
 
Steam stores the three digit code as well as the full credit card number. I've never had to add the CVV number when using a stored card on Steam.

Doesn't store the 3 digit code. When a card gets authenticated, Valve gets a token. If you choose to store the card, Valve stores the last four digits of the card, the card type, and the token. Next time around the credit card processor is handed the token, checks to see if the token is valid, and charges the card.
 
Okay, so it's not a hack, but it's on the busiest day (for most people) of the year and they don't even drop us a fucking email saying 'Hey someone might have your phone number, real name and shit, so....sorry?"

WTF. I didn't even know about this.

Yea it's a pretty F'd up situation.

I was thinking about this, and I think the problem stems from a lack of accountability in Valve's 'no management' structure. When shit goes wrong no one is going to want to take blame.
 
SteamDB has no affiliation with Valve, they're just guessing at what happened. I don't understand why people keep linking to them...
Because their guesses are probably close to the truth?
Because we all saw the results of whatever happened and it being a caching issue explains that?
Because they look into how Steam operates literally every day and know it super well?

I don't understand why people keep trying to discredit posts from them because they aren't valve. Spend literally 5 minutes looking up who they are instead of aren't.
 
Okay, so it's not a hack, but it's on the busiest day (for most people) of the year and they don't even drop us a fucking email saying 'Hey someone might have your phone number, real name and shit, so....sorry?"

WTF. I didn't even know about this.

Yea I feel the exact same way. This was beyond fucked up, and their continued silence on the issue is worrisome. Steam needs to get its shit together in regards to customer service. They have some of the shittiest customer service around, and have gotten away with it for the most part.

Edit: Had no idea about this issue until I logged on gaf. Had I not checked gaf I would have never known about this until they decided to come out publicly.
 
Okay, so it's not a hack, but it's on the busiest day (for most people) of the year and they don't even drop us a fucking email saying 'Hey someone might have your phone number, real name and shit, so....sorry?"

WTF. I didn't even know about this.

It's fucking ridiculous that we have to find out about our details potentially being compromised from Gaf or wherever instead of from the piece of shit company in question.
 
Oh FFS.

I don't have any, you know, money, so my risk here is pretty small, but Jesus Christ this is some weak shit.

And it seems to be on their end too?

Definitely taking my info off Steam ASAP.
 
Christmat gift for all, people's account information. -_-

Is my account safe if I haven't logged in and checked the store since like 16 hours ago?
 
So how do we reconcile the different information from those speculating about the nature of the breach/caching problem maintaining that no action should have been possible on the read-only account info with the reports of people having their accounts cleared out/posting financial statements showing they've been charged?
The people saying no action should be possible are in no position to say such a thing and some of the people saying certain actions are possible aren't stupid/assholes.
 
Valve's silence is inexcusable.

Christmas Day breh.

Should I be panicking right now and trying to edit my account info via the mobile site should I just wait till the dust settles?

It's difficult to understand what's really going on here.
 
Hi guys, I am on paypal, but I can't remove steam from my payments? Does anyone have an idiots guide?

Guide to unlink Valve from Paypal.

  1. Log in
  2. Access your settings through the cog in the upper right hand corner
  3. Click Preapproved payments
  4. Click Valve, corp
  5. Select cancel option



Simply posting as much information as I can find from viable sources that have complete knowledge of Valve's backend, api, and crack it open on a daily basis.
.
 
So according to the Steam DB blog this wasn't a hack or DDOS? Weird coincidence that if it IS an internal error it's happening on the one day that hacks and DDOS attacks happen historically
 
Well, the servers were only shut off about a half hour ago - they probably are still trying to assess the damage before making an official statement.

Terrible response time, I agree.
Even a quick tweet to the effect of "We're aware of the problem, are investigating, and have shut down the service in the interem" would be better than nothing.
 
Okay, so it's not a hack, but it's on the busiest day (for most people) of the year and they don't even drop us a fucking email saying 'Hey someone might have your phone number, real name and shit, so....sorry?"

WTF. I didn't even know about this.

You're only 2 hours late for the party. Thank god for Twitter and places like GAF spreading the news.

At the end of the day, Valve is a company, and they've just made a huuuuuuuge fuck up. They aren't going to be distributing any statement until a legal team checks and double checks it. Probably not until after it's fixed as well.

Not saying I agree with this, just saying this is how it is. As always with these issues and more recently hacks, we will get a 'it's fixed' message with probably 0% technical information on what actually went on. I work in IT, and when we fuck up we have to issue our customers a detailed RFO report (Reason for outage). I'd like these companies to have to provide the same for consumers.

Currently, we know nothing for sure. Every statement is from someone issuing statements on Valves behalf with no right to and no insight into what's actually going on. The billing/payment stuff appears to be true from our own members talking about it and people from journo establishments such as IGN stating they have had purchases on their account. We'll see what happens as this unfolds.
 
Okay, so it's not a hack, but it's on the busiest day (for most people) of the year and they don't even drop us a fucking email saying 'Hey someone might have your phone number, real name and shit, so....sorry?"

WTF. I didn't even know about this.

It happened two hours ago. The sheer fact that the Steam Store is down is a record for a network this size.
 
So according to the Steam DB blog this wasn't a hack or DDOS? Weird coincidence that if it IS an internal error it's happening on the one day that hacks and DDOS attacks happen historically
It's always possible that a hack or DDOS caused it but it's highly unlikely that it was intended to cause it.
 
Christmas Day breh.

Still inexcusable. If you don't have contingency for worst-case scenario for one of the busiest days of the year, maybe don't open that day? Of course they will open, so they should have had something.
 
Christmas Day breh.

Should I be panicking right now and trying to edit my account info via the mobile site should I just wait till the dust settles?

It's difficult to understand what's really going on here.

BREH
BRO RUSSBRO

SteamDB is saying it's a caching issue, so you shouldn't do anything.
 
Christmas Day breh.

Nah that isn't an excuse. Valve is a multi-million dollar company whos entire business model is based around its reputation. Not having at least one or two people who don't care or don't celebrate Christmas to sort shit out in case something happens is terrible.
 
Top Bottom