Steam Hacked

Moss

CFC Scribe
Retired Moderator
Joined
May 1, 2002
Messages
6,584
Location
Minnesota
The_J posted this on the main page and in the Civ V section, but for those of you that don't visit those areas and still use Steam, a little heads up:

http://forums.steampowered.com/forums/
Dear Steam Users and Steam Forum Users:

Our Steam forums were defaced on the evening of Sunday, November 6. We began investigating and found that the intrusion goes beyond the Steam forums.

We learned that intruders obtained access to a Steam database in addition to the forums. This database contained information including user names, hashed and salted passwords, game purchases, email addresses, billing addresses and encrypted credit card information. We do not have evidence that encrypted credit card numbers or personally identifying information were taken by the intruders, or that the protection on credit card numbers or passwords was cracked. We are still investigating.

We don’t have evidence of credit card misuse at this time. Nonetheless you should watch your credit card activity and statements closely.

While we only know of a few forum accounts that have been compromised, all forum users will be required to change their passwords the next time they login. If you have used your Steam forum password on other accounts you should change those passwords as well.

We do not know of any compromised Steam accounts, so we are not planning to force a change of Steam account passwords (which are separate from forum passwords). However, it wouldn’t be a bad idea to change that as well, especially if it is the same as your Steam forum account password.

We will reopen the forums as soon as we can.

I am truly sorry this happened, and I apologize for the inconvenience.

Gabe.
 
*is not gloating over Steamers*
 
Anyone else think this could be the start of a huge marketing thing for Half Life 3?

If not, I'll bet it was a fan who is fed up with Valve's secrecy on HL3. Or he lost his hats.
 
Every system is vulnerable to being hacked, no matter how secure you make it. A part of my job includes database & web security, so.. it's basically a matter of putting up walls to slow hackers down. If you put up a couple, it will stop the not-so-brilliant and lazy. Put up a couple more, and you make it harder and harder, but it's impossible to secure yourself completely, unless you sever your internet connection. In which case you're still not fully secure, but in most cases you probably would be. (We had a guy walk into our building once, steal a computer, hack it at home, then use the passwords to hack into our network. Fortunately this was a security company we hired to determine how secure our systems were)

So yeah, this can happen to any company. It doesn't mean that Steam sucks or that they didn't secure their servers enough.

edit: It's also very good to see them being so honest about this to the community.
 
Every system is vulnerable to being hacked, no matter how secure you make it. A part of my job includes database & web security, so.. it's basically a matter of putting up walls to slow hackers down. If you put up a couple, it will stop the not-so-brilliant and lazy. Put up a couple more, and you make it harder and harder, but it's impossible to secure yourself completely, unless you sever your internet connection. In which case you're still not fully secure, but in most cases you probably would be. (We had a guy walk into our building once, steal a computer, hack it at home, then use the passwords to hack into our network. Fortunately this was a security company we hired to determine how secure our systems were)

So yeah, this can happen to any company. It doesn't mean that Steam sucks or that they didn't secure their servers enough.

edit: It's also very good to see them being so honest about this to the community.

I'm guessing they learned from the Sony fiasco it is better PR for them to be honest upfront.
 
In the aftermath, Valve offers free hats for TF2 users.

This is gonna hurt Obama, politically.
 
Spoiler :

If somebody hacks into your web server that could mean that they have access to a lot of important information, including any server-side codethat accesses databases with secure data, ftp account information, .. basically a really good starting point to hack other parts of the system. If it's a big enough company then they should everything fully secure.. but you'd be surprised. There are always vulnerabilities, and if a hacker was determined or lucky enough to get into one of your systems, then he is probably already working on getting into the others... So get the hell up from that couch and patch the holes

I'm guessing they learned from the Sony fiasco it is better PR for them to be honest upfront.

Yeah, pretty much.. Valve's userbase is a lot more important to them than Sony's is to Sony... It's one of their selling points: "We treat our customers well!". So they kinda had to do it. I bet it was decided in less than 5 minutes at the meeting and most of the time was spent drafting the letter
 
Yet another reason why steam sucks.


Did I ever mention that I'm glad that I didn't register to Steam? I feel sorry for the people who are affected by it, though. :(
 
What's with all the Steam hate?

Steam is what turned me from a game pirate to a guy who buys ALL his games. I have 114 games in my library and I spent at most $300 over 11 months buying them all. That's under $3 a game! I have the full Civ 4 series, Civ V, a crapload of Valve stuff, a ton of Paradox games, a couple Football Manager titles, racing games, cities xl.. and lots and lots of games.

It's made all my games easily accessible, so now instead of having to screw around with dvds, cds, cd-keys, cracks, loaders, all I do is click "install" and "play" and i'm ready to kick arse

Anyway, I guess I just don't understand the hate, Valve is a very community oriented company
 
What's with all the Steam hate?

Steam is what turned me from a game pirate to a guy who buys ALL his games. I have 114 games in my library and I spent at most $300 over 11 months buying them all. That's under $3 a game! I have the full Civ 4 series, Civ V, a crapload of Valve stuff, a ton of Paradox games, a couple Football Manager titles, racing games, cities xl.. and lots and lots of games.

It's made all my games easily accessible, so now instead of having to screw around with dvds, cds, cd-keys, cracks, loaders, all I do is click "install" and "play" and i'm ready to kick arse

Anyway, I guess I just don't understand the hate, Valve is a very community oriented company

I agree, Steam is the best thing to happen to gaming in a while.
 
What's with all the Steam hate?

Steam is what turned me from a game pirate to a guy who buys ALL his games. I have 114 games in my library and I spent at most $300 over 11 months buying them all. That's under $3 a game! I have the full Civ 4 series, Civ V, a crapload of Valve stuff, a ton of Paradox games, a couple Football Manager titles, racing games, cities xl.. and lots and lots of games.

It's made all my games easily accessible, so now instead of having to screw around with dvds, cds, cd-keys, cracks, loaders, all I do is click "install" and "play" and i'm ready to kick arse

Anyway, I guess I just don't understand the hate, Valve is a very community oriented company

I agree, Steam is the best thing to happen to gaming in a while.

Full agreement here.

As for the hacking thing, I changed my password, hopefully this can all be sorted out soon.
 
...and it's things like this that make me glad I keep my gaming PC and my internet life disconnected.
 
Stupid hackerz-d00dz
 
Hackers are just criminals that hide behind a computer screen these days.
Look, hackers aren't standing up for anything like rightousness or any of that stuff, their just jerks and criminals. Criminals that needed to be treated just like a guy who robs grocery stores.
 
Top Bottom