Bay 12 Games Forum

Please login or register.

Login with username, password and session length
Advanced search  

Author Topic: Steam Situation Resolved  (Read 4980 times)

miauw62

  • Bay Watcher
  • Every time you get ahead / it's just another hit
    • View Profile
Steam Situation Resolved
« on: December 25, 2015, 04:12:56 pm »

I do not know what the fuck is going on, but serious shit is going down.


r/steam thread.
You can log into random strangers' accounts. Keep a VERY close eye on your credit/debit cards, don't visit the store pages NO MATTER WHAT, don't log in anywhere, etc.


As I said, I don't know shit, just throwing this out there as a warning to people who might not know.
« Last Edit: December 25, 2015, 07:25:05 pm by miauw62 »
Logged

Quote from: NW_Kohaku
they wouldn't be able to tell the difference between the raving confessions of a mass murdering cannibal from a recipe to bake a pie.
Knowing Belgium, everyone will vote for themselves out of mistrust for anyone else, and some kind of weird direct democracy coalition will need to be formed from 11 million or so individuals.

Metalax

  • Bay Watcher
    • View Profile
    • Steam Profile
Re: STEAM SECURITY BREACH
« Reply #1 on: December 25, 2015, 04:24:07 pm »

General consensus is that it isn't a deliberate attack, but rather a problem with the cacheing server after the downtime an hour or so ago. The server is being too aggressive in caching pages so it's serving those it shouldn't.


Actual card details should not be accessible other than the last 4 digits, however billing addresses may well be visible.

The steam Community servers got taken down 20 mins ago, but the main store pages are still live appear to have just gone down.
Logged
In the beginning was the word, and the word was "Oops!"

raptorfangamer

  • Bay Watcher
  • Svenleton King
    • View Profile
Re: STEAM SECURITY BREACH
« Reply #2 on: December 25, 2015, 04:28:55 pm »

paranoia made me lock my acc, definitive ptw.
Logged
"Tobar, whats that on the wall?"

"That, Urist, is a reminder not to piss me off..."

Knave

  • Bay Watcher
    • View Profile
Re: STEAM SECURITY BREACH
« Reply #3 on: December 25, 2015, 04:31:49 pm »

Aye, thanks for the info. Hopefully no one loses anything of value!
Logged

Shadowlord

  • Bay Watcher
    • View Profile
Re: STEAM SECURITY BREACH
« Reply #4 on: December 25, 2015, 04:32:21 pm »

I wonder if Valve has the ability to effectively do a rollback of their database to before this started.
Logged
<Dakkan> There are human laws, and then there are laws of physics. I don't bike in the city because of the second.
Dwarf Fortress Map Archive

BigD145

  • Bay Watcher
    • View Profile
Re: STEAM SECURITY BREACH
« Reply #5 on: December 25, 2015, 04:46:34 pm »

A good reason to not store payment info.
Logged

Cthulhu

  • Bay Watcher
  • A squid
    • View Profile
Re: STEAM SECURITY BREACH
« Reply #6 on: December 25, 2015, 05:14:54 pm »

Payment info isn't accessible.  You're randomly seeing cached page info for other players' accounts.  Trying to buy something or change credit card info or anything like that will just 404 you.

The store's down now but the only thing you really need to do is not visit store or community on your account.  If you're not in the cache nobody can see your shit.

Change your password on your email if it's listed there.
Logged
Shoes...

Uristides

  • Bay Watcher
    • View Profile
Re: STEAM SECURITY BREACH
« Reply #7 on: December 25, 2015, 05:18:53 pm »

Payment info isn't accessible.  You're randomly seeing cached page info for other players' accounts.  Trying to buy something or change credit card info or anything like that will just 404 you.

The store's down now but the only thing you really need to do is not visit store or community on your account.  If you're not in the cache nobody can see your shit.

Change your password on your email if it's listed there.
So you can see other people's wishlists but not add nekopara and hunybop to them? That's both relieving, and slightly disappointing.
Logged

Catastrophic lolcats

  • Bay Watcher
  • [FORTRESSDESTROYER:2]
    • View Profile
Re: STEAM SECURITY BREACH
« Reply #8 on: December 25, 2015, 05:45:25 pm »

I just woke up my the annual christmas bender and been trying to paste together what happened. It seems like it was not a deliberate attack, more like a dodgy update that was probably automated. Looks like it's caching information that it shouldn't be.

Steam has pulled the plug now on the store and community so there shouldn't be any further problems until they fix it. Playing your games should be completely fine.
EDIT: seems like the site is back up.
« Last Edit: December 25, 2015, 06:27:07 pm by Catastrophic lolcats »
Logged

Nighthawk

  • Bay Watcher
  • INT Score: Yes
    • View Profile
Re: STEAM SECURITY BREACH
« Reply #9 on: December 25, 2015, 06:36:41 pm »

Still can't seem to log in, though. It appears to redirect to the home page without actually logging in.
Logged

Yourmaster

  • Bay Watcher
  • Not the weirdest on Bay12!
    • View Profile
Re: STEAM SECURITY BREACH
« Reply #10 on: December 25, 2015, 06:44:02 pm »

And this is why I don't put my credit card online. Ever.
Logged
10/10.
Wants to rape and enslave my innocent night faeries ;-;

Metalax

  • Bay Watcher
    • View Profile
    • Steam Profile
Re: STEAM SECURITY BREACH
« Reply #11 on: December 25, 2015, 07:20:43 pm »

The situation now appears to have been resolved, and Steam should be fully back up.

Steam community mod post on the issue.

Confirmation that it wasn't a hack and card numbers and phone numbers were not exposed.

edit: Just as a follow up, this is a list of all the information potentially compromised.

Account page:

    Your log-in ID
    Your log-in email address
    Your country
    The last 4 digits of your phone number if you linked one
    The type of authentication you were using for Steam Guard
    Your wallet balance

Account page payment info:

    The type and last 2 digits of your credit card info, if you saved it
    Your full billing address and phone number, if you clicked on edit
    Your PayPal email address, if you saved it

Purchase history page:

    Your transaction history, including gifts you sent to other people
    The last two digits of any credit card that you have paid with, even if you did not save it

License page:

    The games you activated and the type and date of activation
« Last Edit: December 26, 2015, 11:52:10 am by Metalax »
Logged
In the beginning was the word, and the word was "Oops!"

etgfrog

  • Bay Watcher
  • delete & NULL;
    • View Profile
Re: Steam Situation Resolved
« Reply #12 on: December 26, 2015, 01:09:47 pm »

Hm...steam is pretty much cant be accessed, now considering the swarm of unique ids that were going to the steam page, I can only guess it was a bunch of bots trying to gather as much data as possible. So now it is either a ddos attack in retaliation for the security breach or a mass hijack of account attempt. Then again...the stupid factor is still a possibility, valve removing all chaching from their websites.
Logged
"How dare you get angry after being scammed."

Ukrainian Ranger

  • Bay Watcher
    • View Profile
Re: Steam Situation Resolved
« Reply #13 on: December 26, 2015, 01:18:39 pm »

Quote
Your full billing address and phone number, if you clicked on edit
Your PayPal email address, if you saved it

*Facepalms*
Logged
War must be, while we defend our lives against a destroyer who would devour all; but I do not love the bright sword for its sharpness, nor the arrow for its swiftness, nor the warrior for his glory. I love only that which they defend.

gimli

  • Bay Watcher
    • View Profile
Re: STEAM SECURITY BREACH
« Reply #14 on: December 26, 2015, 02:24:02 pm »

And this is why I don't put my credit card online. Ever.

This is why you use a virtual CC [attached to your bank account]. My virtual CC is always on 0, I only transfer money to it when I buy stuff.
Logged