Bay 12 Games Forum

Please login or register.

Login with username, password and session length
Advanced search  
Pages: 1 [2] 3

Author Topic: Steam forums hacked?  (Read 3481 times)

justinlee999

  • Bay Watcher
  • Unflappably FABULOUS
    • View Profile
Re: Steam forums hacked?
« Reply #15 on: November 09, 2011, 03:47:38 am »

I was in the middle of a Steam forum discussion with someone until this happened...

Also my Steam forum and game accounts are the same...
Logged

Knight of Fools

  • Bay Watcher
  • From Start to Beginning
    • View Profile
    • Knight of Fools
Re: Steam forums hacked?
« Reply #16 on: November 09, 2011, 10:26:50 am »

I wouldn't worry about it. I'm unclear on the specifics, but it's all but impossible for (Most) good services to have the users' passwords stolen, even if the server is hacked and all of the information is found, because, like someone mentioned, everything's encrypted. The reason that hackers can't get your password is the same reason that a forum doesn't tell you what your password is - Because it can't.

When you put a password in, the server jumbles it up into an unrecognizable mass of nonsense. It's clever to the point where it can't be reversed without a lot of effort, and that's only if you found the program used to make the jumble in the first place. If it's done poorly, like with the gaff Sony pulled a while back, then you have something to worry about, but most of the time breaches like this are usually exceptions rather than the rule. I honestly wouldn't be surprised if it were the moderator's own fault, but it's just as likely that it wasn't.

So, long story short: Don't worry about it too much, for now. If the Steam forums had a major breach like the one Sony had, then we'd have a lot more to talk about than one moderator getting hacked.
Logged
Proud Member of the Zombie Horse Executioner Squad. "This Horse ain't quite dead yet."

I don't have a British accent, but I still did a YouTube.

justinlee999

  • Bay Watcher
  • Unflappably FABULOUS
    • View Profile
Re: Steam forums hacked?
« Reply #17 on: November 09, 2011, 10:58:21 am »

So unless I have a big reason to be hacked, the hackers just wouldn't bother unencrypting mine?
Logged

Metalax

  • Bay Watcher
    • View Profile
    • Steam Profile
Re: Steam forums hacked?
« Reply #18 on: November 09, 2011, 11:11:14 am »

So unless I have a big reason to be hacked, the hackers just wouldn't bother unencrypting mine?
Essentially, yes. In general you have a far higher chance of your password being stolen by a keylogger that has gotten onto your system than by a hacker managing to unscramble properly stored passwords from a site.
Logged
In the beginning was the word, and the word was "Oops!"

cerapa

  • Bay Watcher
  • It wont bite....unless you are the sun.
    • View Profile
Re: Steam forums hacked?
« Reply #19 on: November 09, 2011, 11:21:32 am »

This sounds less like "the servers got haxxored" and more like an admin just got keylogged.

Which means the admin picked up a keylogger from somewhere. And the keylogger in question apparently gives information to the site that was given by the "hackers". I wonder what site the keylogger might have come from?
Logged

Tick, tick, tick the time goes by,
tick, tick, tick the clock blows up.

Metalax

  • Bay Watcher
    • View Profile
    • Steam Profile
Re: Steam forums hacked?
« Reply #20 on: November 09, 2011, 11:41:01 am »

yeah, apparently they have been going around in the comments replies on many of the gaming news sites claiming that "it wasn't us, honest. It was our unnamed rivals in providing malware."
Logged
In the beginning was the word, and the word was "Oops!"

Sergius

  • Bay Watcher
    • View Profile
Re: Steam forums hacked?
« Reply #21 on: November 09, 2011, 05:28:27 pm »

You can't just "unencrypt" a password, because they're usually encoded one-way as hashes, with a certain random key (called the salt) that is also stored. So while the password "GOOMBA" might get hashed into "YAS%%1y66hY2hXDs2366", you can't get the word GOOMBA out of it (data has gotten lost/ignored in the process). You just encode GOOMBA again with the same algorithm and then match the result again.

You could in theory end up with a possible different word that gives the same result, but the odds of it being alphanumeric (and able to be typed) are really small. Even programs that guessed your password in ZIP files merely gave you a random string that "worked", not your original password.

It's different from when you want encrypted data to actually be readable later. You just need your data to give out the same output each time.

At least that is how it happens in well designed security libraries. Some don't bother and store your password in plaintext and hope nobody has root access to the file. I'm pretty sure most open-source forum software use the first method though.
Logged

Metalax

  • Bay Watcher
    • View Profile
    • Steam Profile
Re: Steam forums hacked?
« Reply #22 on: November 10, 2011, 06:08:00 pm »

Update on it. Looks like they did actually manage to partially break into steam itself.

Quote
10 November 2011
Dear Steam Users and Steam Forum Users:

Our Steam forums were defaced on the evening of Sunday, November 6. We began investigating and found that the intrusion goes beyond the Steam forums.

We learned that intruders obtained access to a Steam database in addition to the forums. This database contained information including user names, hashed and salted passwords, game purchases, email addresses, billing addresses and encrypted credit card information. We do not have evidence that encrypted credit card numbers or personally identifying information were taken by the intruders, or that the protection on credit card numbers or passwords was cracked. We are still investigating.

We don’t have evidence of credit card misuse at this time. Nonetheless you should watch your credit card activity and statements closely.

While we only know of a few forum accounts that have been compromised, all forum users will be required to change their passwords the next time they login. If you have used your Steam forum password on other accounts you should change those passwords as well.

We do not know of any compromised Steam accounts, so we are not planning to force a change of Steam account passwords (which are separate from forum passwords). However, it wouldn’t be a bad idea to change that as well, especially if it is the same as your Steam forum account password.

We will reopen the forums as soon as we can.

I am truly sorry this happened, and I apologize for the inconvenience.

Gabe.
Logged
In the beginning was the word, and the word was "Oops!"

PsyberianHusky

  • Bay Watcher
  • The best at being the worst at video games.
    • View Profile
Re: Steam forums hacked?
« Reply #23 on: November 10, 2011, 07:21:26 pm »

I am glad Gabe manned up to ASAP.
I respect that man.
Logged
Thank you based dwarf.

EuchreJack

  • Bay Watcher
  • Lord of Norderland - Lv 20 SKOOKUM ROC
    • View Profile
Re: Steam forums hacked?
« Reply #24 on: November 11, 2011, 09:05:44 pm »

Can somebody tell me how to go about changing my password?

While I might like the Steam service, their interface is terrible.

Edit: Nevermind, I found it.

You have to select "settings" from Steam on the start menu.  Or something like that.

SHAD0Wdump

  • Bay Watcher
  • Hiding in SPAAACE!!!
    • View Profile
Re: Steam forums hacked?
« Reply #25 on: November 11, 2011, 11:50:10 pm »

The steam forums have returned.
Logged

klingon13524

  • Bay Watcher
  • The Mongols are cool!
    • View Profile
Re: Steam forums hacked?
« Reply #26 on: November 12, 2011, 03:03:56 am »

I am glad Gabe manned up to ASAP.
I respect that man.
Valve is awesome, what else is there to say?
Logged
By creating a gobstopper that never loses its flavor he broke thermodynamics
Maybe it's parasitic. It never loses its flavor because you eventually die from having your nutrients stolen by it.

Felius

  • Bay Watcher
    • View Profile
Re: Steam forums hacked?
« Reply #27 on: November 12, 2011, 09:10:59 pm »

It's quite the contrast when you compare with how Sony dealt with it.
Logged
"Why? We're the Good Guys, aren't we?"
"Yes, but that rather hinges on doing certain things and not doing others." - Paraphrased from Discworld.

nenjin

  • Bay Watcher
  • Inscrubtable Exhortations of the Soul
    • View Profile
Re: Steam forums hacked?
« Reply #28 on: November 12, 2011, 09:15:26 pm »

When you compare to how most major companies deal with it.
Logged
Cautivo del Milagro seamos, Penitente.
Quote from: Viktor Frankl
When we are no longer able to change a situation, we are challenged to change ourselves.
Quote from: Sindain
Its kinda silly to complain that a friendly NPC isn't a well designed boss fight.
Quote from: Eric Blank
How will I cheese now assholes?
Quote from: MrRoboto75
Always spaghetti, never forghetti

Felius

  • Bay Watcher
    • View Profile
Re: Steam forums hacked?
« Reply #29 on: November 12, 2011, 09:17:34 pm »

Indeed.

I'm also a bit impressed that it was big enough news to hit BBC: http://www.bbc.co.uk/news/technology-15690187
Logged
"Why? We're the Good Guys, aren't we?"
"Yes, but that rather hinges on doing certain things and not doing others." - Paraphrased from Discworld.
Pages: 1 [2] 3