Putting the 'role' back in role-playing games since 2002.
Donate to Codex
Good Old Games
  • Welcome to rpgcodex.net, a site dedicated to discussing computer based role-playing games in a free and open fashion. We're less strict than other forums, but please refer to the rules.

    "This message is awaiting moderator approval": All new users must pass through our moderation queue before they will be able to post normally. Until your account has "passed" your posts will only be visible to yourself (and moderators) until they are approved. Give us a week to get around to approving / deleting / ignoring your mundane opinion on crap before hassling us about it. Once you have passed the moderation period (think of it as a test), you will be able to post normally, just like all the other retards.

The Great Christmas 2015 Steam Security Breach

Metro

Arcane
Beg Auditor
Joined
Aug 27, 2009
Messages
27,792
You could get a U-play only copy from Amazon/other places for $6 months ago.
 

Abu Antar

Turn-based Poster
Patron
Joined
Jan 19, 2014
Messages
13,584
Enjoy the Revolution! Another revolution around the sun that is. Shadorwun: Hong Kong Divinity: Original Sin 2 Pillars of Eternity 2: Deadfire Pathfinder: Wrath I'm very into cock and ball torture I helped put crap in Monomyth
Valve will get away with this. There are already people defending them. They are even worse than SJWs.

I can't be arsed to give a fuck. I'm removing all info that I can and then just move along to playing my games.

Fuck Gaben, etc, etc.
 

pippin

Guest
Them shrugging it off will be the "official statement", so to speak. People commenting about Valve's shortcomings/failures are going to be seen as whispers from people who just want to destroy gaming.
 

Turjan

Arcane
Joined
Mar 31, 2008
Messages
5,047
Them shrugging it off will be the "official statement", so to speak.
People tend to forget that you don't admit to any wrongdoing if the threat of a lawsuit hangs above your head. This changes when it becomes likely that you will get convicted, but before that, you better only admit to things that are already proven.

Let's see whether anyone can prove that Valve showed complete phone numbers. That would be a game changer.
 

Infinitron

I post news
Staff Member
Joined
Jan 28, 2011
Messages
97,507
Codex Year of the Donut Serpent in the Staglands Dead State Divinity: Original Sin Project: Eternity Torment: Tides of Numenera Wasteland 2 Shadorwun: Hong Kong Divinity: Original Sin 2 A Beautifully Desolate Campaign Pillars of Eternity 2: Deadfire Pathfinder: Kingmaker Pathfinder: Wrath I'm very into cock and ball torture I helped put crap in Monomyth
It helps Valve that this is the middle of a holiday, so the game journos (and anybody else) who might bang out an angry editorial about this event are on vacation.
 

Jarpie

Arcane
Patron
Joined
Oct 30, 2009
Messages
6,611
Codex 2012 MCA
Anyone know if there's way to find out if my info was accessed?
 

Vikter

Learned
Patron
Joined
Jan 17, 2015
Messages
148
Location
Brazil
PC RPG Website of the Year, 2015
You should tweet to Valve the following:
##@Valve
youraccountname
yourpassword

Exactly like that. The ## means it will be a secret tweet (a DM won't work because their inbox is full). Gaben already said they are using this system to whitelist users and see if they have been hacked or not.

Before you complain about sending your password out, note that this is a two-step authentication. They will reset it and send it to your email anyway.
 

Gerrard

Arcane
Joined
Nov 5, 2007
Messages
12,061
They don't have to say anything because no actually sensitive info has been leaked.
 

Jigawatt

Arcane
Joined
Aug 13, 2009
Messages
3,409
Location
in a desert, walking along in the sand
It only shows you a few digits anyway. There's no way to use it

Yeah, because having last 4 digits of your credit card means you can use it.

No full credit card info so they cant do jack shit

Incorrect. Last 4 cc + billing address + email address makes for a pretty strong social engineering play. Here's an example of just email address and last 4. Whilst this obviously isn't 'the full Ashley Madison', it's still quite a serious breach of user data.
 

Gerrard

Arcane
Joined
Nov 5, 2007
Messages
12,061
It only shows you a few digits anyway. There's no way to use it

Yeah, because having last 4 digits of your credit card means you can use it.

No full credit card info so they cant do jack shit

Incorrect. Last 4 cc + billing address + email address makes for a pretty strong social engineering play. Here's an example of just email address and last 4. Whilst this obviously isn't 'the full Ashley Madison', it's still quite a serious breach of user data.

Did you even bother reading that post or just pull it out of google results? Do you also happen to use one email address and password for everything by any chance?
 

Mustawd

Guest
It only shows you a few digits anyway. There's no way to use it

Yeah, because having last 4 digits of your credit card means you can use it.

No full credit card info so they cant do jack shit

Incorrect. Last 4 cc + billing address + email address makes for a pretty strong social engineering play. Here's an example of just email address and last 4. Whilst this obviously isn't 'the full Ashley Madison', it's still quite a serious breach of user data.

Did you even bother reading that post or just pull it out of google results? Do you also happen to use one email address and password for everything by any chance?


Seriously. I have like 3 different emails with different passwords. Yeah, what happened is alarming, but let's not freak out just yet.
 

Jigawatt

Arcane
Joined
Aug 13, 2009
Messages
3,409
Location
in a desert, walking along in the sand
Did you even bother reading that post or just pull it out of google results?
Did you? It specifically states that the last 4 digits of a cc were used as alternate verification in a call to GoDaddy, which in turn allowed for an MX record change to route password reset emails to an attacker controlled server.

Do you also happen to use one email address and password for everything by any chance?
This isn't about whether it affects me personally
 

Metro

Arcane
Beg Auditor
Joined
Aug 27, 2009
Messages
27,792
Anyone know if there's way to find out if my info was accessed?
Your info is perfectly safe... in my hands.

Ne-wayz, servers were fine for me yesterday but now it's acting like I'm not fully logged into Steam. It shows my username and wallet balance in the upper right but not my wishlist or other community features. Asks me to log in to view my queue and shit but I'm hesitant to do that.
 
Last edited:

Vikter

Learned
Patron
Joined
Jan 17, 2015
Messages
148
Location
Brazil
PC RPG Website of the Year, 2015
Just because some people have several email accounts and are prepared doesn't mean the breach didn'r involve sensitive personal information. I want my free game.
 

Gerrard

Arcane
Joined
Nov 5, 2007
Messages
12,061
Did you? It specifically states that the last 4 digits of a cc were used as alternate verification in a call to GoDaddy, which in turn allowed for an MX record change to route password reset emails to an attacker controlled server.
No, it clearly says the last 6 digits were required, and that the idiot operator let him guess the first 2. So the moral of the story is: don't use shitty service providers, and most definitely don't be a special snowflake with a custom email hosted by such providers for important shit. This would've never happened if the guy was using a gmail account.

I'm surprised the guy didn't sue the living fuck out of them.
 
Unwanted

jcd

Punished JCD
Patron
Joined
Jan 4, 2012
Messages
10,681
Location
UNATCO HQ
Codex 2014 PC RPG Website of the Year, 2015 Codex 2016 - The Age of Grimoire Bubbles In Memoria
11293d46475dbfe8a39f7579e9c951071351c1a5ad6dc372ebe20a37f094ad7aee0a4f6f3d70ac8bfcd5ba00ff6576d07f47035f17e1e6286fa17378c0a17923305aff7d4dea4e2a45ddcc6d2d02b3d631ad99cbec1f284cbfbd3cf4dd74966b5c29faef4e2b81210a7281bfa6279674371d669c963ff53f167d7b29fa7e0c6355de93764429e888da589a26eeaf3593182005d7681d97071905a8301967535356854a7bc9bc6b4040ea80b6a3e6f4aaf3a93782b3db9c0ca7d61a34d346cc1414eb7978698ae6bd34868263faff259149c51113ad52f0ba0c72fe09805eaf725fe1c578441cba74ef3e6a18dfed126541eec453b52193c4b34b36d79a7a285d26b2de860a4dd8ac289b7a9e5812171b607e41b823487badc2129b33e68145578c3a8e838ac23072b1d3b46911844c5d3f1394668d16114d60cef8ce8de14d7644bc9b729a052f3ec4e7670708640dfc4f42dd8d3e124029759067dee66d1cf31e022ff11d69980337d6ab0d4131ac0eeac8c4488d999088a77e44f5dd001fa13ab9efba56f0e3bfbd9ddadccb850a5a5d9614fac71da8204e7f24ad32c345e28c77127c4804f6fd94b26baef364e9b93986c21409b316cabf4d921fdfb838846a1a5f0f99d0c5e4d3539df851ac3e8a57862bc9bf14fea55f98abc35fa8b9f351a04cfd6c89d929dc24fa974807e7d2711dab6ed46de4af061413954e14f91c2aee5cdb5b2c36c5d3ef086997d018c891d3c2c18c090ffb8b7dec7bf848c6e27be02096ece419c1dabc6a649455e1f5ba0f0c96f2bedc01ea68ec49d7fd70d44f8d3248b4e4bcbdd0dec50c7ac6a7099684c65c392e70aa21481c8992bf66f894039acb575e75b0fb4ee2bd3d874ac13333b0f0c90b53a5dd32f18b85998c4f87f39b3df33817be64fc50648b62ef79dfb2cc4afbfd4d387477be4f19d132c7cc7cb6d9fdf61ab77507dd2fc564ef246a1afc06135407858d3de7674016fdcf1783cb48b6c2fec31aee1ec10a978d8c7ddb26d6072584f464c8ad0c1789178434305665568ef862692979dd77c9fdd7b9fd02fb12a2aff588b132023e5a5b0f35ced42d0f676c9ac02ef04ca5d4f7f9574478a4b10bc56424a7823e353999802c9df2b3e26a9775c7f025f2a351c6d86766623f5783214f5f57eb1194e5bbde666ed9f16d8f839f62d06cadb0bd725d7c9a18d494d22dac04ff63d593db2ebe0344b2fd2d0f3271d04723f82f47f1c33135aaa1618b4ace7a681d93d7d99067fe90c3e2e32f797bcd14e0c025db23a0077f051b8e58ca1865fbaf107f45b3337aaf9d11b2c58e0bffe7cd45a4b083e9095befe95aa1b0df5fb9846663a2fbb8ea255cead93d058ced90d2a00214836e607a8f23de0d8d3410739d310050f09b894c184e8e943f7b9f4e3cc062ab1d4ec229cc7351b634d9f4a587bbc3be82fab1e10984fde241075f70fe0742ec7bc430966977c10e4b245d2c0376821524ff13eec3a9120b133bc531ef350fd425c47cb5dd1c91ce22c263c9dabbe27fdcfe22742cfd0dae3a1041115f63d5d03c582defe4057f7b135f2869d7e51296106cee301df24dd371c87a8b42a2d4626357c489c99b9332cc7c5c1f1735c6d627892dbf7527180a6be743c36a2c7758a7da49d30c568921c854a9304aad02272a05e5e134813d9c26a3d311215bec3ab6e39512123dfcb9a9ddc75de38bf0018d526d7293775671e7b827d8f479b5ff9ab5f5d5a5af7f2157fa255f4c516ee099f6f874ad580dd01f69abba58c59f4c7c434f3d420ed1a834281271a28feb43cb4597b8c709a3068af6a72fb7ad089cc9c75f4942a9be9ea1a3ab953bc247d5d7acf38be742792bc76930c62a125f6a84932c1a5ee86f8274fd363106928e34c31d4aa165b026ce421f39de4f874191c35c2e6d7b422527e13356e7cb2aa033461c84844171c2f8ddf78998172d3c0056631da33dafcb95cc3d010124c2aa754bd2f1137f2bf11ec19dfcc0a1d08243593a9817aa506e7f62a9667d5845821e0b5bdcfa7b7a74cc5427ec63ff4f338cd6b5ec5a6fc72da5251401aac8df9c9753b3d24cd7f8e42129221a66ec96d9ef5fa660775298476565f5be1d1fc9fc3db3fb4bad389cc9668ea6e0d473000cae7e871313a139627b57387ba8e10f650692fe877516259b6db35eeaebca99a399f9901914160f11e32aff7e76a08344d513042a4c55da47d05b07378ae39eb11a166c5dd0492387bbdbcc24d1459d90453e08ef0fb2f83cba69ffbcdd5ee68bed3b392250083b4251a9d3dbf4933de8ecea62b90f145d11346cf5f0823159233610e07dfd595b75739267a31be87538453db42faee571a9b5e44681bdd1c4eea3437ed2ab8d8dc092248ac36c5807eb686ca57030ea7070fe0252a7a908b702cc61552fb43b5aa057ebc682b3fccbc01af28779313d09bc629ad23ebad3fb11aefd611582810055b1f452e03a2efbcf88fc2bd360572bdfe9753334e370f7bc32a2d232f8f249e5af45857e30305bdaac28d351df16bbbc3d90bfe7f0103f3eb015c69f115e99e61594654a3eabdf0538fc46a6eb958570910643c3fbc64a25ca24b2cdb5bc2966a4bec84a7a71ab070050858078fff7b19ac51a61ba34a07ea232540378371c064ef551e0e255fd1c7ca11726935743d29f947cfdc8eec62875bac4dff2b43f21cc0c80e1967606ed410c39f502aa7b6e17b3a37b7aa2b98409539045c6287011d662144f86e7c30a5a7f820691d4398031d2420bd5a808d8b603eb87f41f1445e0486936b5a04210f005fd2b44be4790099238d73f9f8f7ba7eb7cba1fe7e7406471fcd928b9b4847d0004d4a60e9620cf62752e34c771b1ee313cf7c4073cd09c62e5aa213a4fe2f8bb2e2f753d962d021c626e770248fca75e550d63096e532ae38348672ccebd9dcdb05e4d1f5fbd44914a7142525cc8af177a69ff2448161716524fc926cb06c9f99d63fbcc8b60a248b3d8130440fd78bc825829cae8f7827884f22aff3227b61ef068206ea8d074020526dfd8afbab9e6a6304a572de2d274ee6f13fc2c2ac9079529a25dccab20010a46e8f21a3dd9a212d6bc9c588d0bfc6055013e23c38d0a97d8fb74f1a503d40a7c888ec865c444769db543fb07d5a03ad2c3c195a84bd9e24c5ce2a22b159fde2bb00732d5183585d5675a41cf17fc0993a4350bda02293ce5924a7927f4ddd86c69cb07f5b80c11d2cf667222e53ecf368b3da17abab02485a37ae5d4f168385c0bb60871342e65dbd7c26082b4f8d8e8342719541b23b3d79bf3d351a45ac5c948b405d074de1cd0cf0f386af65ad6293cdede912d36158ea2011465c71ca08c126507ce8b109e07e081d937f43acadda04904e7592a8351c87d58da785715841687c013a56ff481d943d7c28ece0477df4838edb1b3b7d6c1db641d58e7e9f29625feaf71f8ae0fac6512a6737cf37f782da49af1d0044dfc8458d0fb1ab31fcf121ce747db44008288b54884685ee69298f783866ebca18ed461a9a334b3d23e6b25ffc498c86efb4a56f2d85a2f82e60c7339c29e443f2c7cfa5afda40597bdb33c82497a23ee9cfee42fc6dafcc5b3e4551dd68204a089dabc175f7433b7b09f3fea0f4429078aa2185db10bd03be8b0a8bd2a7fc4e8f896e2d9fe7fc77468ef7015cc731ed88a5b398133b4ef546eead89c1e62c6f8deced2c60b8f92e7b753433d3476b434e3f1dfefd1953c9654e376de2a8b72007f181d605750bf5a55a148c551f507349de40af6073476965b1ac1124097b138e13884f84228716040645672c3dc403f1884e08f9cdfd033f388b151a367a9c6976db42772169da3d619997566626c7c2971f2d273e82f7d2759adc6f26242535e6362ee63b58a5076073dce5aae4d0669d338e4228d32841c0a22698fbbdc9934c2794ba73cd3857bf745c56d92a6d4b522487d20ce17cb228ed115aefc610593d0e56ef18ce4a05b65cdc464e1df1f82a414136e191f665b674690a9c7efa66cb90b1337118244bd46a7848b2ee83156b70fde8c6fd32bbf43e4389e1cf83656839b68a7b56d31e2014ec52d35c7e9e5554f1b1ea890d44ed664f7863e11259e02c3d5ad7aa8b90e5e57b7b7f930def4432b4a68f60795730e93f7e46c5f7dc92d06b399a643b7b4ae7dfcca48ebb03e8995d4d4ca6e86930b3c2872981d4acc69906bfab6a667821a62860947ef5d71c1dbcbcbb3567834d69bfffaeb31d136d4e3e30fdb03609e72d7e3b0048faf418f99d558423514c72ef4d1c06f1672db85b61b06353eaea2607acbae7af0a2f6b12743c1c3d15a24bd2ff0868ea9dcabf87a3aa202e8e0fe37d14934cf8bb4a1afa26a79a045049cb146d36b967483d140666676ef1ee457b946ef1f7676817e5ded4d0d16866c669f3d63215b5f45c01ee6ecfab56f92348331f12b9086a1df3eefa82e7baf4bfe316030184b0988dc9bf4aa4a4e8526294f9db67895e416e8afba9aa29fd32b1af40cce0bfbddbfb13a07a6505aabfc180006b3d90019408a3252956915d3b7e635898468a863b9bccf9800d98c2c5506adc8e9d4044a58b9c232917c80d1905327bf3b8fa4bf2297107b5886d48545bc19911175190c9878760399d290c37903a574f7aedceb1240171e0cee29380e1ca3f6a98352f1a8911b4cb3bdca2fa202e1d3a9ead00caaa4033c062c3e6211cf1a3db1287ecf0d5241a89f2629e31e3ea57d957ccc1ebd565bc117d3fedc4697ba9e3ec630e674a295fbfd4c2eb3947d9022fd46669c09bd07c85c796d4de4d052a75629b16a32426c4a4cd875d49d6efe7f789c5928342b8a88b64ddb1d89e11434bfc6f679c373e0f79a932014f307ea08ac51c8978747bfc4e9ecdcf1afe28f5f6af74730f5ae240bcc92cc0ba4035c642aab2451461b944ddeea83843c02c165cd754315b5e17b6ae8d3dc55a7d3dbbdc7470168e83a7a1d643c9fa481a8876dcbe9d9599ac7ee5d856e82f8c1388e3ee5f343c00eb7dc6536f802303758fed8236d0984bbe419b3b7eccdaabe3e86c6f44bac1dc0c9bc70aeeea5b9369feec0d33bb202fade93235032d103fe679f5e8f83e41b39d40a4e7dec8003072aedfd0bf7bb51f14b4036bb6a7863d704ef9893480aea021d82e8f76208fc48499af3b493996a2c52390250f64ac725fbaf33fce776004406d3f97637baed71460ef949957c818ea4e1f9e257a594e1d5f04ee7bc88e0be9ea3ad79c739f70dad8f0638424933820701da1f45775fb079ff169c3a17135aeb7106772d2b7718e88d4e5c8309464497485cd370e2fc7fdb2383765a736c2d7b2c44f2dc619f1781532c965815d5392fd6a54af3261bbe9eba8fc76566b30c5c7744253f19d4af4d1d432de20f7420226803cb8a6d8a4e4a34efa98a764b7d47d21fb464cada576289fac05aa3e38449302963a4ad84884c5a599637a9e73bd47b48a2a2f01e5d4be69284825489f33227b2b07edad300dccdb6c1dce77213cfcafa03886b6604d57302bfc3ff5ca4497b2b93ee05eab2e8a4d64691c15c31e8abc3bc9110aea4135510d038a3a81b64600fb83f4b33c5a71867a1ffb9818b1d03d29fe6d2b3c631481987042069d33884f4e8c7551c3f4fa06e03503177cb569c63c032795d9ed04cb006f3b3ada50d63cfb94c53bcefdb29a23752ebbdde1fde5d788734d18009618dd5623122bc3cdcf5af5ca8e2f003741f141c571dd929c0e34597c19ce268d5849cc40a0225315f8896a9889aaa0c668e6e8d396a
 
Last edited:

jagged-jimmy

Prophet
Joined
Jan 25, 2008
Messages
1,552
Location
Freeside
Codex 2012
Anyone know if there's way to find out if my info was accessed?
If it was really a caching issue, i guess everyone NOT browsing his account details around the critical time is safe.
So if you were busy playing Underrail as the rest of us, cool members, you should be safe.
 

As an Amazon Associate, rpgcodex.net earns from qualifying purchases.
Back
Top Bottom