Bethesda's epic sci-fi RPG is here, and it's a big one. From shipbuilding to exploring the surface of Mars, our thoughts so far.
Starfield Review... In Progress
The first trailer for Grand Theft Auto 6 is finally here.
Grand Theft Auto 6 Trailer
We take an in-depth look at Avatar: Frontiers of Pandora and tell you why it should be heavily on your radar!
Avatar: Frontiers of Pandora - a Deep-Dive into its Potential
Range-wise, the ROG Rapture GT6 is phenomenal, and it's ideal for all gaming and non-gaming-related tasks.
ASUS ROG Rapture GT6 WiFi 6 Mesh System Review
Post by Dan @ 09:49am 11/11/11 | 20 Comments
Many of you have probably noticed the recent Steam forums downtime, but Valve have today confirmed that it's more than just technical issues. In an message sent to the Steam user base, Valve chief Gabe Newell revealed that not only were the Steam forums defaced by hackers, but customer database records of forum users were accessed.
We learned that intruders obtained access to a Steam database in addition to the forums. This database contained information including user names, hashed and salted passwords, game purchases, email addresses, billing addresses and encrypted credit card information. We do not have evidence that encrypted credit card numbers or personally identifying information were taken by the intruders, or that the protection on credit card numbers or passwords was cracked. We are still investigating.

We don't have evidence of credit card misuse at this time. Nonetheless you should watch your credit card activity and statements closely.

While we only know of a few forum accounts that have been compromised, all forum users will be required to change their passwords the next time they login. If you have used your Steam forum password on other accounts you should change those passwords as well.

We do not know of any compromised Steam accounts, so we are not planning to force a change of Steam account passwords (which are separate from forum passwords). However, it wouldn't be a bad idea to change that as well, especially if it is the same as your Steam forum account password.

We will reopen the forums as soon as we can.

I am truly sorry this happened, and I apologize for the inconvenience.
With so many big titles depending on Steamworks support this holiday season, we're certainly glad this has only affected the functionality of the Steam forums and not Steam proper thus far. Let's hope it stays that way.



valvesteamhack





Latest Comments
ravn0s
Posted 09:56am 11/11/11
awesome. good thing my steam forum password is different to the main one i use.
deadlyf
Posted 09:57am 11/11/11
I don't even know if I have a steam forum password so I guess I had better change my account one.
Plasma
Posted 10:18am 11/11/11
I don't remember what my forum password was, but it is different.

A good time to remind people to maybe turn on Google 2 factor authentication. If you get hacked there (like I did once) its really a pain in the ass. I think people got in because of the PS3 password leak.

Why also were credit cards stored along side forum information?

This also explains the e-mails I got from 'Steam Forums' that looked hacker-ish.
Eorl
Posted 10:21am 11/11/11
Whoa...
carson
Posted 10:22am 11/11/11
A good time to remind people to maybe turn on Google 2 factor authentication. .

This.

I don't remember what my steam forum pwd was, but I've never had anything of mine hacked/stolen before and I've been using a similar password for years.
Outlaw
Posted 10:22am 11/11/11
owned, sony stylez
blaze0041
Posted 10:38am 11/11/11
They say that this is the information age, where knowledge is power... they were right. This might be the reason we have been seeing so many server hackings as of late.
Speaking of 2-factor authentication, Paypal also has 2-factor authentication (either through a security card/key that costs AU$32.95 to order or SMS). Are there any banks aside from HSBC that have 2-factor authentication?
Nukleuz
Posted 10:45am 11/11/11
Suncorp has 2-factor authentication. RSA Secure ID. $20. A no brainer really.
HeardY
Posted 12:40pm 11/11/11
CBA send text msg's with a pin to be input prior to transactions beibg processed.

HSBC rsa token annoys me, means I cant login to internet banking at work :/
Twisted
Posted 01:39pm 11/11/11
Wow, Google 2 factor was a f*****g pain to get setup, wasn't always obvious what to do :p
Eorl
Posted 01:55pm 11/11/11
ANZ has a system where you need to enter a secondary password when shopping online.
kettels
Posted 03:00pm 11/11/11
from couchrenegade on reddit

Everybody that has this (Steam Guard) enabled should do this right now:
Click Steam
Go to Settings
Manage Steam Guard Account Security...
Deauthorize all other computers now
Better to play it safe.
deadlyf
Posted 03:30pm 11/11/11
Suncorp has 2-factor authentication. RSA Secure ID. $20. A no brainer really.
They need to have some kind of universal version of this where you can get one ID key and apply it to banking/paypal/email/Steam/itunes and whatever else you feel a need to protect.
Deemsee
Posted 03:50pm 11/11/11
Sick of f*****g hackers.
Khel
Posted 04:11pm 11/11/11
What sort of programs do people use to manage their passwords? I use pretty much the same 2 or 3 passwords everywhere, and thats becoming less and less of a good idea as time goes on. I've seen people post here before about programs they use that generate and store all their passwords, and then all you need to remember is the password for that program and it manages all your other passwords and makes them all unique. Anyone got any recommendations?
thirdparty
Posted 04:29pm 11/11/11
Password Safe is good enough for Bruce Schneier - http://www.schneier.com/passsafe.html but if you need something on iDevices then maybe Keepass
Twisted
Posted 05:16pm 11/11/11
Suncorp has 2-factor authentication. RSA Secure ID. $20. A no brainer really.
Yep, and a separate password from your login password to do an external transfer (outside of Suncorp). Not to mention the fraud guys are bad ass. Do a purchase overseas that is outside your normal spending regions and they're on the phone to you pretty quick.

Edit: Is it just me or is there no way to do anything to your account if you don't have the Steam client installed...I can't find any way to change passwords or do anything to my account from the Steam site...
Whoop
Posted 06:33pm 11/11/11
^^ You do it all from within steam so probably not. There's a bunch of buttons to change your details & stuff in the main window. PM me your account details and I'll change them for you :p (p.s. don't do this)


What sort of programs do people use to manage their passwords? I use pretty much the same 2 or 3 passwords everywhere, and thats becoming less and less of a good idea as time goes on. I've seen people post here before about programs they use that generate and store all their passwords, and then all you need to remember is the password for that program and it manages all your other passwords and makes them all unique. Anyone got any recommendations?

keepass & use a key instead of a password, store the key on a USB drive and hide it?

e: ignore the key on a usb thing, I thought you were worried about having to remember the master password, I must learn to read some day.

last edited by Whoop at 18:33:28 11/Nov/11
Superform
Posted 06:56pm 11/11/11
http://news.punchjump.com/2011/11/10/valve-confirms-steam-hacked-credit-card-data-may-be-compromised/

The company said hackers obtained access to a database that included user names, hashed and salted passwords, game purchases, email addresses, billing addresses and encrypted credit card information.
Whoop
Posted 07:13pm 11/11/11
You mean the same info that's in the OP?

Does this affect people who don't save their CC details when purchasing through steam I wonder.
Commenting has been locked for this item.
20 Comments
Show