Steam user database compromised, Newell addresses Steam users

  • Thread starter Deleted_171835
  • Start date
  • Views 5,826
  • Replies 52

RupeeClock

Colors 3D Snivy!
Member
Joined
May 15, 2008
Messages
6,497
Trophies
1
Age
34
Website
Visit site
XP
2,984
Country
Dammit, have to change all my passwords again.

Can't even use punctuation, one site wouldn't accept £ in the password, another wouldn't accept !, annoying shit.
 

alphamule

Well-Known Member
Member
Joined
Oct 24, 2011
Messages
429
Trophies
0
XP
184
Country
United States
Mentioning encryption, how does that work for credit cards? A previous poster said they use AES256 but I'm wondering how secure a 2048-bit public key given to them from the payment processor(card handler/bank) for their specific use is? They'd have to revoke the key with their payment processor but that shouldn't be too painful. It would require everyone to reenter their info, though. The advantage is that they encrypted card info is useless to any other vendor and definitely to any hackers.

It's also possible that every user has a unique 256-bit key sent by the payment processor using a public key to establish the 256-bit session key. This is otherwise known as SSL or variants. ;) You setup a secure channel (key exchange using public-key) and then send any keys of specific card holders over this. I highly doubt they have this level of security, but you never know. This is of course a trade secret/patented I bet. It would be funny to see payment processors still using the rather broken SSL 3.0, though!
 

RupeeClock

Colors 3D Snivy!
Member
Joined
May 15, 2008
Messages
6,497
Trophies
1
Age
34
Website
Visit site
XP
2,984
Country
http://kotaku.com/58...-the-steam-hack

Nice read actually. What similarities do we see?
I thought it took Sony MUCH longer to actually alert their users about the compromise? As in, Sony tried to save face by covering it up for some time... Valve were much swifter when they had realised it was not just a forum defacement.
On top of that, Sony had allegedly stored sensitive user credentials, including CC information in plain text, where as Valve hashed and salted CC numbers and passwords.

I'd still much rather trust Valve than Sony, and I still do trust Valve.
 

ShadowSoldier

Well-Known Member
Member
Joined
Oct 8, 2009
Messages
9,382
Trophies
0
XP
3,878
Country
Canada
I changed my password. I told my friend about it considering I'm using HIS credit card. I hope they get it solved soon, preferably before the launch of Arkham City. Or I'll even accept if they don't solve things in time, but we're still able to download the game.
 

alphamule

Well-Known Member
Member
Joined
Oct 24, 2011
Messages
429
Trophies
0
XP
184
Country
United States
I'm glad to hear that everything worked out! It seems that no one lost any steam purchases or their credit card info. Still, anyone with a lick of sense is going to go order a new card and change their forum+steam passwords.

What do you think was the motive for this? Profit? Bragging rights? And BTW lulzsec aren't the only people that can do this.
 

Seyiji

Rawr :3
Member
Joined
Nov 6, 2002
Messages
494
Trophies
2
Age
43
Location
PA
Website
www.rage3d.com
XP
860
Country
United States
As a gesture of goodwill gabe should give out a free game or credit
steam needs better security.
Steam giving out a free game = Steam giving out free Skyrim almost on release.

In other words, it won't happen.
Portal 1 has been free twice now. Team Fortress 2 went free to play. Owners of the original Half-Life who register the key on Steam receive Blue Shift, Opposing Force, Team Fortress Classic, Counter-Strike, Deathmatch Classic, Ricochet and Day of Defeat. Not to mention the constant content updates and engine upgrades for a bunch of Valve's games. Oh yeah Valve don't give us shit! :blink:

Anyhoo I heard through the grapevine that if shit got real they are going to start giving out copies of Portal 2 and beta access to DOTA 2.
 

Tom Bombadildo

Dick, With Balls
Member
Joined
Jul 11, 2009
Messages
14,580
Trophies
2
Age
29
Location
I forgot
Website
POCKET.LIKEITS
XP
19,272
Country
United States
As a gesture of goodwill gabe should give out a free game or credit
steam needs better security.
Steam giving out a free game = Steam giving out free Skyrim almost on release.

In other words, it won't happen.
Portal 1 has been free twice now. Team Fortress 2 went free to play. Owners of the original Half-Life who register the key on Steam receive Blue Shift, Opposing Force, Team Fortress Classic, Counter-Strike, Deathmatch Classic, Ricochet and Day of Defeat. Not to mention the constant content updates and engine upgrades for a bunch of Valve's games. Oh yeah Valve don't give us shit! :blink:

Anyhoo I heard through the grapevine that if shit got real they are going to start giving out copies of Portal 2 and beta access to DOTA 2.

Proven fake. Sorry. See here: http://gbatemp.net/topic/313334-valve-offering-free-portal-2-and-dota-2/page__view__findpost__p__3970380

Anyways, that sucks but luckily I never really used Steam to much. So...yay for me?
 

amptor

Banned!
Banned
Joined
May 2, 2003
Messages
2,552
Trophies
0
Age
33
Website
Visit site
XP
173
Country
United States
I'm not too worried about it. I don't store my CC info in there and even if I did, it would be useless for anyone to have since the card I used on there is hardcore against people that try to steal.

I guess the only thing that would be of concern is the password to the account just so that nobody can change it.

I don't believe that any information is safe on the internet.
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • No one is chatting at the moment.
    OctoAori20 @ OctoAori20: Welp