Home General Discussion

Steam Forums Apparently Hacked

polycounter lvl 7
Offline / Send Message
Karmageddon polycounter lvl 7
http://kotaku.com/5856975/steam-forums-apparently-hacked


"The Steam User's Forums and the Steam service account passwords are separate, but some users might use the same handles and passwords across both. If that pertains to you, it might be a good idea to change your Steam account password. And pronto."

Replies

  • Andreas
    Options
    Offline / Send Message
    Andreas polycounter lvl 11
    If they go after my steam account there'll be blood! That's one thing I've always been afraid off, my list of games getting hacked and deleted.
  • leilei
    Options
    Offline / Send Message
    leilei polycounter lvl 14
    Are they really hacked? Any non-Gawker source to confirm this?
  • Ace-Angel
    Options
    Offline / Send Message
    Ace-Angel polycounter lvl 12
    Maybe it's Gawker's way to hint at the fact they got hacked again, without loss in shares?
  • e-freak
    Options
    Offline / Send Message
    Current facts:
    • vBulletin Software was hacked to display an additional link to a Cheating Site which is NOT safe to browse.
    • vBulletin and Steam Accounts are NOT linked.
    • If the "Hackers" got the user-account database from the Steam Forums there's little use of it as the Passwords are encrypted (if they are even stored in the same Database).
    • If you're using the same Password on Steam and in the Forums, Steam Guard (hope you have that activated) would still protect your Account.
    • If you're using the same Password on the Forums and on other sites on the internet, it might be a good idea to change them. No panic, nothing is lost, procedure as usual.

    Speculation:
    There will be cake :)
  • DrunkShaman
    Options
    Offline / Send Message
    DrunkShaman polycounter lvl 14
    Andreas wrote: »
    If they go after my steam account there'll be blood!

    ...Wow, really? O.O
  • eld
    Options
    Offline / Send Message
    eld polycounter lvl 18
    Andreas wrote: »
    If they go after my steam account there'll be blood! That's one thing I've always been afraid off, my list of games getting hacked and deleted.

    I'm pretty sure valve values security on their steam service a thousand times higher than their forum.
  • Andreas
    Options
    Offline / Send Message
    Andreas polycounter lvl 11
    eld wrote: »
    I'm pretty sure valve values making lots of hats for TF2 a thousand times higher than their forum.

    :P

    I'm sure you're right though. Gonna change my password just to be safe though.
  • leilei
    Options
    Offline / Send Message
    leilei polycounter lvl 14
    I hope they pull an epic and generate everyone a new password
  • eld
    Options
    Offline / Send Message
    eld polycounter lvl 18
    Andreas wrote: »
    :P

    I'm sure you're right though. Gonna change my password just to be safe though.

    If you use the same password on steam as you use on other places or the steam forums then do, or if you believe your password might have been compromised in some way on your own computer.

    It's highly likely that lots of people use the same password on the steam forums as they do on steam or even their own mail, which is the bad thing, but then again, it's a good thing you can't delete your own game, so the worst they'll be able to do with a compromised account is buy you games.

    And if you have secure login activated on your steam they wouldn't even be able to login from anywhere but authorized computers.

    Otherwise I would rate steam login information being compromised as being as plausible and horrifying as being the pc worlds own apocalypse:P
  • passerby
    Options
    Offline / Send Message
    passerby polycounter lvl 12
    ya shouldn't matter on steam accounts unelss you use the same pw on the forums.

    besides using the same PW on forums as you use for email, steam, or anything else that could give up personal info or cost you money is pretty stupid.

    if you use the same PW for everything even if it is a hard PW to crack, it means everything you registered to is only as safe as a weakest link among all the services you use.

    though wondering how, it was done, since if it was some exploit in vbulletin it could soon hit other sites, since a hell of a lot of professional or corporate sites run either vbulletin of ip board for there forums.
  • Noodle!
    Options
    Offline / Send Message
    Noodle! polycounter lvl 8
    Do you guys use different passwords for everything, then? There's no way I could do that, my memory just is not good enough.

    It sucks that what I used at steams forums is by far my most used one, out of only a few passes.
  • GarageBay9
    Options
    Offline / Send Message
    GarageBay9 polycounter lvl 13
    eld wrote: »
    If you use the same password on steam as you use on other places or the steam forums then do, or if you believe your password might have been compromised in some way on your own computer.

    It's highly likely that lots of people use the same password on the steam forums as they do on steam or even their own mail, which is the bad thing, but then again, it's a good thing you can't delete your own game, so the worst they'll be able to do with a compromised account is buy you games.

    And if you have secure login activated on your steam they wouldn't even be able to login from anywhere but authorized computers.

    Otherwise I would rate steam login information being compromised as being as plausible and horrifying as being the pc worlds own apocalypse:P


    ...or, y'know, they could log into your account and access VAC secured servers while using obvious cheats, getting you irreversibly banned. And then you're out several hundred dollars worth of software without ever having done anything wrong. A single-player only license of TF2, Borderlands, etc... pretty useless. And without any way to get it back, pretty damn maddening.
  • Michael Knubben
    Options
    Offline / Send Message
    Noodle: It's a good idea to have one password for websites you don't care about, and a complicated one for main email, bank etc.
    Make sure the two are not related at all, as the odds of the former being discovered are much, much higher (often no https, plus they're often idiotic with their security. When lifehacker got hacked, it turned out they only encrypted --poorly-- the first 8 characters of any password, making the more secure passwords... less secure. Wtf).
  • Ben Apuna
    Options
    Offline / Send Message
    Passwords don't necessarily have to be very complex just long.

    In this case size does matter :)
  • eld
    Options
    Offline / Send Message
    eld polycounter lvl 18
    GarageBay9 wrote: »
    ...or, y'know, they could log into your account and access VAC secured servers while using obvious cheats, getting you irreversibly banned. And then you're out several hundred dollars worth of software without ever having done anything wrong. A single-player only license of TF2, Borderlands, etc... pretty useless. And without any way to get it back, pretty damn maddening.

    True, but that often happens without steam or steam forums getting hacked in any way, people need to be more careful with their computer and where they use their password.

    If account information on steam was compromised, I don't think the first thing they would do would be to be extra vigilant to ban cheaters, they'd most likely lock down and change passwords for everyone the moment they knew.
  • Michael Knubben
    Options
    Offline / Send Message
    Ben: adding caps, numbers and symbols will make it more difficult, as will having something that's not in a dictionary.

    edit: as per your link, the difference between asdf and A5_f is 22.8 HOURS. And that's for an extremely short one.
  • DrunkShaman
    Options
    Offline / Send Message
    DrunkShaman polycounter lvl 14
    Mine wasnt hacked, but thanks for making me login to my steam account and realize that DC universe has gone free to play. o.O
  • Ben Apuna
    Options
    Offline / Send Message
    @MightyPea:

    No worries, my passwords are pretty insane and for the most part unique per site.

    Just pointing to that article which says in addition to at least one letter, number, and symbol (which forces a brute force password cracker to use the full character set) the length of the password will then determine it's actual strength, as in average time/effort before being cracked.

    So for those that have a hard time remembering a random mishmash of characters, numbers, and symbols, just make something unique and easy to remember then make up a easy to remember padding of some sort to fill it out up to the max allowed by the system.
  • Karmageddon
    Options
    Offline / Send Message
    Karmageddon polycounter lvl 7
    http://games.slashdot.org/story/11/11/10/2316220/valve-announces-massive-steam-server-intrusion

    "Valve has revealed that hackers have gained access to the Steam database and have pulled a variety of information. A statement from Gabe Newell reads in part: 'Dear Steam Users and Steam Forum Users, Our Steam forums were defaced on the evening of Sunday, November 6. We began investigating and found that the intrusion goes beyond the Steam forums. We learned that intruders obtained access to a Steam database in addition to the forums. This database contained information including user names, hashed and salted passwords, game purchases, email addresses, billing addresses and encrypted credit card information. We do not have evidence that encrypted credit card numbers or personally identifying information were taken by the intruders, or that the protection on credit card numbers or passwords was cracked. We are still investigating. We don’t have evidence of credit card misuse at this time. Nonetheless you should watch your credit card activity and statements closely."
  • aajohnny
    Options
    Offline / Send Message
    aajohnny polycounter lvl 13
    I changed my password even though it was different then the forums... I hope i'm safe now :/
Sign In or Register to comment.