Steam security issue revealed personal info to other users on XMas Day (fixed)

In this thread: people freaking out about their personal information being leaked, despite the high likelihood that said personal info had already been leaked elsewhere.

Ah well, that makes it OK then.

Please post your name, personal address, login email and user name and phone here, someone already has it anyway.

I'm waiting... aww, you got banned? LOL Fuck off.
 
This really seems like cache poisoning to me. But maybe there's new information I missed.

Basically for whatever reason their profile page cache keys did not have a unique identifier like a user ID added. Obviously speculation but seen it before at my job.

In this thread: people freaking out about their personal information being leaked, despite the high likelihood that said personal info had already been leaked elsewhere.

Your post is reductionist and a generalization.
 
In this thread: people freaking out about their personal information being leaked, despite the high likelihood that said personal info had already been leaked elsewhere.

Information was displayed through Steam. Something Valve controls and maintains.

No one knows who saw the information, no one knows who may do with that information.

The amount of defense Valve can get is amazing.
 
There is and it had nothing to do with passwords.
It had a lot to do with account pages. To change you password you would go through the account page which would have made it available to others. Doing nothing at all would have actually been safer at the time.
 
In this thread: people freaking out about their personal information being leaked, despite the high likelihood that said personal info had already been leaked elsewhere.
ll wanted to inform you that I haven't received your credit card number, your email or your address yet. I feel like I shouldn't be the only 1 who doesn't have that information yet.
 
They deserved to be sued for this shit if all their reaction is going to be a 2 line description of what we knew already.
 
They seriously can't just leave it at that. Leaking PII comes with huge repercussions.

fuck off valve


That is a message to Kotaku, not Steam users.

It would be idiotic to assume that Valve would not comment directly to Steam users when the issue is this large, arguably larger than the issues they have had in the past and have commented on to Steam users.

If they don't - then they can go fuck themselves
 
on the one hand you have to take into account that it's Christmas day, but on the other, regardless of their relative size or how they choose to operate, this is a multi billion dollar corporation we're talking about

Yep, this is beyond bush league. The most basic responsibility of a service-based company is to announce that something has happened, share any confirmed info, and shut down service until it can be verified to be safe. Valve has done none of that.

I hope people who praise valve's management structure take a good look at this situation. Every part of this fiasco -- the half-assed ddos mitigation, the apparent untested launch of code with a massive security hole, and the complete silence to their customer base -- is a direct result of an organizational culture with no leadership, no responsibility, and no employees who are expected to do difficult or unpleasant work.

It's a good post, it's not going to be easy to accept for them (clearly) or for fans, because that's the foundation and culture that seemingly helped them get to where they are today, but they haven't been that same company for a while now, they're a giant multi billion dollar corporation providing a service with over a hundred million users, they need to face that reality.

I'd rather have a valve with a more typical and rigid structure that's able to get the basics right like other companies over this clown outfit they have going on, they don't seem to be doing anything out of the ordinary at this point which would be impossible or severely hampered by a regular hierarchy.
 
That is a message to Kotaku, not Steam users.

It would be idiotic to assume that Valve would not comment directly to Steam users when the issue is this large, arguably larger than the issues they have had in the past and have commented on to Steam users.

If they don't - then they can go fuck themselves

The problem here is that they answered Kotaku before releasing an actual statement to their customers...
 
Is it over???

ots-terenas.png
 
This is an answer to Kotaku's mail to Valve.

Should they apologize to fucking Kotaku?

Why not wait for an official statement like a rational person and fucking rage like a spoiled 12yo child IF it doesn't come?

Why do you think Kotaku ask them about this? It's to inform their readers which are most likely steam users. It's just basic courtesy.

Not to mention they didn't even bother to write anything directly to their customers.
 
Probably the greatest security failure of all time in gaming, and Valve is acting far worse than Sony ever did... Whelp...

Definitely going to use the service more sparingly from here on out...

*grumble grumble 600 games*
 
I still cant log in. Im annoyed. Justkeeps saying my password is incorrect. This is from ipad iphone. Im away from my pc for a week
 
You know, if my company accidentally revealed customer address/emails/phone numbers, the OCC would be on our ass in 3 hours flat.

The fact they can't be arsed to make an official statement speaks volumes.
 
This is an answer to Kotaku's mail to Valve.

Should they apologize to fucking Kotaku?

Why not wait for an official statement like a rational person and fucking rage like a spoiled 12yo child IF it doesn't come?

It's pretty ridiculous that we're getting even an acknowledgement of anything via Kotaku instead of directly from Valve.
 
Top Bottom