The Glade 4.0
https://gladerebooted.net/

For Xmas, Steam Gave Users Access to Others' Accounts
https://gladerebooted.net/viewtopic.php?f=4&t=11539
Page 1 of 1

Author:  FarSky [ Fri Dec 25, 2015 4:36 pm ]
Post subject:  For Xmas, Steam Gave Users Access to Others' Accounts

Wow. That's a ****.

http://kotaku.com/steam-goes-nuts-offer ... 1749718979

Author:  Darkroland [ Sat Dec 26, 2015 12:48 pm ]
Post subject:  Re: For Xmas, Steam Gave Users Access to Others' Accounts

Yeah, it's kind of a click-baity title though, Kotaku style. From what I've read, no one had access to anyone else's account. Here's the official valve statement:

"Steam is back up and running without any known issues," a Valve spokesperson told GameSpot. "As a result of a configuration change earlier today, a caching issue allowed some users to randomly see pages generated for other users for a period of less than an hour. This issue has since been resolved. We believe no unauthorized actions were allowed on accounts beyond the viewing of cached page information and no additional action is required by users."

So effectively, the server would cache a visited account page, and then serve that to another user. No changes could be made, and purchases could not be completed with other's accounts. At most, the wallet value and e-mail addresses associated with accounts was exposed.

Definitely a huge failure security-wise, but not the apocalypse that all the blogs are making it out to be (assuming the reported data is accurate, I have yet to see a report from a user actually having anything lost/stolen).

Personally, I felt like something was up when I logged into go through my steam queue for my cards and the page was in Chinese.

Page 1 of 1 All times are UTC - 6 hours [ DST ]
Powered by phpBB® Forum Software © phpBB Group
https://www.phpbb.com/