Putting the 'role' back in role-playing games since 2002.
Donate to Codex
Good Old Games
  • Welcome to rpgcodex.net, a site dedicated to discussing computer based role-playing games in a free and open fashion. We're less strict than other forums, but please refer to the rules.

    "This message is awaiting moderator approval": All new users must pass through our moderation queue before they will be able to post normally. Until your account has "passed" your posts will only be visible to yourself (and moderators) until they are approved. Give us a week to get around to approving / deleting / ignoring your mundane opinion on crap before hassling us about it. Once you have passed the moderation period (think of it as a test), you will be able to post normally, just like all the other retards.

The Great Christmas 2015 Steam Security Breach

Zarniwoop

TESTOSTERONIC As Fuck™
Patron
Joined
Nov 29, 2010
Messages
18,727
Shadorwun: Hong Kong
If it was really a caching issue, i guess everyone NOT browsing his account details around the critical time is safe.
So if you were busy playing Underrail as the rest of us, cool members, you should be safe.
Underrail my ass. You were playing Fallout 4. Just admit it, there's no shame in it.

Ok there's lots of shame in it but still admit it.
 

Turjan

Arcane
Joined
Mar 31, 2008
Messages
5,047
Update on Christmas Issues
Steam Blog - Valve
8:01pm
We'd like to follow up with more information regarding Steam's troubled Christmas.

What happened

On December 25th, a configuration error resulted in some users seeing Steam Store pages generated for other users. Between 11:50 PST and 13:20 PST store page requests for about 34k users, which contained sensitive personal information, may have been returned and seen by other users.

The content of these requests varied by page, but some pages included a Steam user’s billing address, the last four digits of their Steam Guard phone number, their purchase history, the last two digits of their credit card number, and/or their email address. These cached requests did not include full credit card numbers, user passwords, or enough data to allow logging in as or completing a transaction as another user.

If you did not browse a Steam Store page with your personal information (such as your account page or a checkout page) in this time frame, that information could not have been shown to another user.

Valve is currently working with our web caching partner to identify users whose information was served to other users, and will be contacting those affected once they have been identified. As no unauthorized actions were allowed on accounts beyond the viewing of cached page information, no additional action is required by users.

How it happened

Early Christmas morning (Pacific Standard Time), the Steam Store was the target of a DoS attack which prevented the serving of store pages to users. Attacks against the Steam Store, and Steam in general, are a regular occurrence that Valve handles both directly and with the help of partner companies, and typically do not impact Steam users. During the Christmas attack, traffic to the Steam store increased 2000% over the average traffic during the Steam Sale.

In response to this specific attack, caching rules managed by a Steam web caching partner were deployed in order to both minimize the impact on Steam Store servers and continue to route legitimate user traffic. During the second wave of this attack, a second caching configuration was deployed that incorrectly cached web traffic for authenticated users. This configuration error resulted in some users seeing Steam Store responses which were generated for other users. Incorrect Store responses varied from users seeing the front page of the Store displayed in the wrong language, to seeing the account page of another user.

Once this error was identified, the Steam Store was shut down and a new caching configuration was deployed. The Steam Store remained down until we had reviewed all caching configurations, and we received confirmation that the latest configurations had been deployed to all partner servers and that all cached data on edge servers had been purged.

We will continue to work with our web caching partner to identify affected users and to improve the process used to set caching rules going forward. We apologize to everyone whose personal information was exposed by this error, and for interruption of Steam Store service.
 
Last edited:

Infinitron

I post news
Staff Member
Joined
Jan 28, 2011
Messages
97,504
Codex Year of the Donut Serpent in the Staglands Dead State Divinity: Original Sin Project: Eternity Torment: Tides of Numenera Wasteland 2 Shadorwun: Hong Kong Divinity: Original Sin 2 A Beautifully Desolate Campaign Pillars of Eternity 2: Deadfire Pathfinder: Kingmaker Pathfinder: Wrath I'm very into cock and ball torture I helped put crap in Monomyth
That's better. I was beginning to think the bizarre apologism seen in this thread and elsewhere was going to win
 

Zarniwoop

TESTOSTERONIC As Fuck™
Patron
Joined
Nov 29, 2010
Messages
18,727
Shadorwun: Hong Kong
Mandatory Fapanese transurashun:

Update on Christmas Issues


GabeN: What happen?


Between 11:50 PST and 13:20 PST


Mechanic: We get signal.

GabeN: What!

Codexer: Steam client turn on

Steam: It's you, пара счетом случайного чувак, welcome to your Steam account.

Steam client: How are you gentlemen !!
Steam client: All your doxx are belong to us.
Steam client: You are on the way to seeing some random Steam account for no reason.

Codexer: Nigga you gay!!

Steam client: You habu no chanceru to surbaibu make youru taimu.
Steam client: Ha ha ha ha …

9GAG: Captain!!

GabeN: Take off every ‘DDoS’!!
GabeN: You know what you doing.
GabeN: Move ‘DDoS’.
GabeN: For great denial.
 

jagged-jimmy

Prophet
Joined
Jan 25, 2008
Messages
1,552
Location
Freeside
Codex 2012
If it was really a caching issue, i guess everyone NOT browsing his account details around the critical time is safe.
So if you were busy playing Underrail as the rest of us, cool members, you should be safe.
Underrail my ass. You were playing Fallout 4. Just admit it, there's no shame in it.

Ok there's lots of shame in it but still admit it.
Not owning Oblivion, Fallout 3 or Skyrim. Why start with shit games now? :obviously:

VdKlsQL.png
 

Gambler

Augur
Joined
Apr 3, 2006
Messages
767
By now everyone should be used to the idea that every large service you're using will eventually leak all the information you've entered there. I'm seriously tired of people who feign surprised indignation every time this happens.

The reality is that no matter how much lip service companies will pay to "security" this will keep happening. Even if those companies legitimately increase investment in their own security (which they should) this will keep happening, although slightly less often.

The right thing to do is to accept that hacks and screw-ups will happen and design systems accordingly. Minimize the amount of information collected and stored. Purge old data. Make it easy to be pseudonymous. Decentralize services.

I remember that for years Steam was demanding your physical address whenever you wanted to buy anything, even if it was via PayPal. That kind of stuff is what people should really be outraged about, but most of the time the reaction ranges from dumb indifference to idiotic fanboy apologism.
 

Lyric Suite

Converting to Islam
Joined
Mar 23, 2006
Messages
56,643
If it was really a caching issue, i guess everyone NOT browsing his account details around the critical time is safe.
So if you were busy playing Underrail as the rest of us, cool members, you should be safe.
Underrail my ass. You were playing Fallout 4. Just admit it, there's no shame in it.

Ok there's lots of shame in it but still admit it.
Not owning Oblivion, Fallout 3 or Skyrim. Why start with shit games now? :obviously:

VdKlsQL.png

How do we know that's you?
 

jagged-jimmy

Prophet
Joined
Jan 25, 2008
Messages
1,552
Location
Freeside
Codex 2012
If it was really a caching issue, i guess everyone NOT browsing his account details around the critical time is safe.
So if you were busy playing Underrail as the rest of us, cool members, you should be safe.
Underrail my ass. You were playing Fallout 4. Just admit it, there's no shame in it.

Ok there's lots of shame in it but still admit it.
Not owning Oblivion, Fallout 3 or Skyrim. Why start with shit games now? :obviously:

VdKlsQL.png

How do we know that's you?
6TSNVSB.png
 

Infinitron

I post news
Staff Member
Joined
Jan 28, 2011
Messages
97,504
Codex Year of the Donut Serpent in the Staglands Dead State Divinity: Original Sin Project: Eternity Torment: Tides of Numenera Wasteland 2 Shadorwun: Hong Kong Divinity: Original Sin 2 A Beautifully Desolate Campaign Pillars of Eternity 2: Deadfire Pathfinder: Kingmaker Pathfinder: Wrath I'm very into cock and ball torture I helped put crap in Monomyth
There's a reason why I have never bought a game on GOG or STEAM.

Because you don't know how to login?

I have yet to spend money on a PC game and I might not for a while.

I know the codex is torrent friendly, mind helping a brother out with some links?

gonna get underrail and AOD

Joined:
Dec 22, 2015
 

sullynathan

Arcane
Joined
Dec 22, 2015
Messages
6,473
Location
Not Europe
There's a reason why I have never bought a game on GOG or STEAM.

Because you don't know how to login?

I have yet to spend money on a PC game and I might not for a while.

I know the codex is torrent friendly, mind helping a brother out with some links?

gonna get underrail and AOD

Joined:
Dec 22, 2015
I didn't buy them though
 

Turjan

Arcane
Joined
Mar 31, 2008
Messages
5,047
lI'm not worried, I'm such a poorfag they could't do anything with my stuff. Maybe send me "lol u gay" e-mails on Jew-Mail.
It can be annoying. Someone from the Ukraine just tried to steal my Humble Bundle account. Which is also weird, given that there's basically just some DRM-free games on there, so I'm not sure why anyone would even try.
 

As an Amazon Associate, rpgcodex.net earns from qualifying purchases.
Back
Top Bottom