back to article Gaming souk Steam spews credit card, personal info in Xmas Day security meltdown

Video game marketplace Steam is leaking people's personal information – including their payment details and billing addresses – to strangers. Gamers browsing the online store have found themselves logged into other people's accounts, revealing strangers' profile settings and other sensitive details, such as addresses, PayPal …

Page:

  1. Anonymous Coward
    Anonymous Coward

    It seems to be caching snafu

    Going to https://store.steampowered.com/checkout/?purchasetype=updatebillinginfo will give you the address and details of a random steam user.

    1. Destroy All Monsters Silver badge
      Flame

      I hope they have cached up on legal insurance, because lawyers need to hit this one hard.

      1. Martin Summers Silver badge

        “I hope they have cached up on legal insurance, because lawyers need to hit this one hard."

        Yes of course, the answer to all of life's problems is a lawyer isn't it. Please get some perspective, it's a minor privacy breach not someone taking nude pictures of you unawares in your bathroom and posting them online.

        1. Destroy All Monsters Silver badge

          > it's a minor privacy breach

          Jesus Christ, the things one hears in 2015.

          1. Martin Summers Silver badge

            "Jesus Christ, the things one hears in 2015."

            Hey I didn't say it was right did I, it still sucks and shouldn't happen. Like I said though, perspective...

            1. Anonymous Coward
              Anonymous Coward

              "Hey I didn't say it was right did I, it still sucks and shouldn't happen. Like I said though, perspective..."

              No, I just think your perspective and those of many others, is distorted. This isn't minor, the details which were leaked are very sensitive in the wrong hands. Details such as name, address, email, last four credit card numbers and recent purchase history are more than enough to commit fraud or phishing attacks.

              It was also hugely inconvenient, like many people who logged on during that period and discovered they were looking at another persons account I immediately called my bank and cancelled my card. There was no information from Steam about what was happening and I wasn't going to risk some stranger racking up purchases on my account* - even if they might have been refunded later. So now I'm without access to my current account for the next few days until a replacement card arrives, during the holiday season ...

              * Yes, it would seem that this wasn't likely to occur now that the cause of the problem has been revealed (albeit not directly by Steam in a message to their customers), however it was impossible to know that at the time.

              1. Boris the Cockroach Silver badge
                FAIL

                But you read

                the payment screen when you buy a game through steam the same as I do

                Fill in name, yupp, address,. yupp... phone number? nope dont get that one, CC number... then notice the box underneath that says "Save CC info? " with its little tick box.

                And you untick that box, and you untick that box because Valve is a big company and fekking useless at security just like everyone else on the internet.

                And even if you save CC info, whats wrong with having a debit card from the bank as well and only ever use the CC for on-line purchases... that way, if the company disappears between you buying and the stuff not arriving, at least you can call the CC company and cancel the payment.

                Gawd help us if you ever have to deal with a real crisis.... it'll be 'pull all the breakers and cut the cables because the amber light on the power supply board has gone out" only to find out the bulb has blown...

                1. Anonymous Coward
                  Anonymous Coward

                  Re: But you read

                  FWIW The same protections which apply to credit cards also happen to apply to my visa debit card - I've never once had any problems getting my bank to refund a charge on my debit card. My CC is kept for emergencies and foreign travel expenses only.

                  1. Danny 14

                    Re: But you read

                    Refunding a cc charge isnt an issue generally UNLESS you go over the CC limit. Then it become fun filing a note on your experian file and getting various flags removed. It is a fecking trawl.

    2. Turtle

      Or Log On To Other People's Steam Account Via Bing...

      I used Bing to find the store pages for two games, and logging on to the them, I found myself logged on, simultaneously, to the Steam accounts of two different people. I accessed their "Account Details" pages and could have gone further than that but I did not actually do so. I would imagine any other search engine would have gotten me the same results.

      It made me wonder if someone was logged on to my account but I wasn't able to access it. Although, as I write this, Steam is off-line entirely, I will have to check on that when they're up again, to see if anything has been changed. Steam only has my Paypal account; pretty sure that that doesn't get them any credit card info...

      Whatever shitty webpages Steam creates and sets to "public" when a new account is created were set to "private" by me a long time ago. Although I once had to (temporarily) set a few to "public" to do some trading, those too were reset to "private".

      Did that provide me with any protection, I wonder?...

      1. Turtle

        Re: Or Log On To Other People's Steam Account Via Bing...

        PS: Steam seems to be back online now, immediately after I submitted my previous post.

      2. Anonymous Coward
        Anonymous Coward

        Re: Or Log On To Other People's Steam Account Via Bing...

        If it was a caching issue, then most likely you would have been safe - you should worry if you saw your page ( as that would be cached and displayed to everybody for the next few minutes* until the cache expired )

        * depending on the cache ttl, or what triggers flushing the cache

  2. Benny

    If it is a caching issue/cookie thing, probably wise to not log in to your account at all..

  3. Anonymous Coward
    Anonymous Coward

    Tricky to remove payment details from your account when it won't actually show you your account...

    1. Adam 1

      Maybe you can just remove someone else's payment details and they can remove yours?

    2. joed

      I never really understood "save payment details" options (and why it's checked by default). It's like the merchants want the trouble of maintaining a database every hacker was after (Amazon, you better don't snooze). Same with regard to other personal info that's not required to complete one time payment.

      Bunch of hoarders.

      1. 404

        hehe Amazon.... They fuck up and I'm flying in with a Lvl90 mace - spend a lot of money there.

      2. Mark 85

        I wouldn't worry about Amazon at this moment. The US Gov got hit for 191 Million people's records.... The crackers/hackers/miscreant, etc. are gonna' busy for awhile.

      3. Tom 13
        Devil

        Re: I never really understood "save payment details" options

        Well, if they don't include that check box by default, they can get in serious trouble with their credit card processing company.

        Last time I was involved with it (which was over 10 years ago) you had to destroy the information no more than 60 days after the transaction was completed (including you receiving the money). I don't imagine that number has gone up. If you have a cockup like this, it's only bad PR and sodding users you piss off. If you don't have that check box you'll get your credit processing dropped immediately. That's some serious bad karma.

  4. Anonymous Coward
    Anonymous Coward

    Even on the Steam app I am logged in as me but when I view my account details I see someone else's. I don't think this is a caching issue, more of a database snafu with ID's screwed up.

    Someone from Steam needs to roll a DB backup restore and fix this asap.

  5. Anonymous Coward
    Anonymous Coward

    Its been up and down all day as as of 21:45 its down for me.

  6. DropBear
    Facepalm

    Actually, having to talk to your family is what I imagine hell must look like. Based on personal experience. And yeah, I wish I was kidding...

    1. Destroy All Monsters Silver badge

      You are not alone, DropBear.

      Working from the office now...

    2. Turtle

      @DropBear

      "And how many people commit suicide each year because they're forced to spend time with their families?!" - J. Belushi, c.1977, SNL.

  7. Chris Miller

    I'm not seeing anything unusual on my account. Is it perhaps a regional issue? (I'm in the UK.)

    1. Dazzz

      I see UK users reporting the same issue on irc

      If you can change your account pull the card details now!

  8. IanTP
    Pint

    Steam has never had or will ever have my payment details saved, uncheck the box, its the only way, other than nuking from space!

    Christmas beer in hand :)

    1. Destroy All Monsters Silver badge

      It's no use, you will now have to get a new credit card anyway because, how can you be sure?

      It's an epic fuckup make no mistake and "1 year of free credit monitoring" won't cut it.

      1. David Webb

        Steam never shows full CC details, just last 4 digits, the rest as **** **** ****.

  9. Mr Flibble
    FAIL

    SteamDB's view of what happened – they think that it was a cache problem. I've seen and heard enough to agree with that.

    1. Destroy All Monsters Silver badge

      "PROBABLY NOT A PROBLEM"

      Where is Gordon Freeman when you need to break something?

      1. This post has been deleted by its author

      2. Turtle

        In Beta, Possibly: "Where is Gordon Freeman...?"

        "Where is Gordon Freeman when you need to break something?"

        In beta, possibly. In the link given by Mr Flibble, https://steamdb.info/blog/recent-caching-issues-on-steam/ , we read the following entry in the comments:

        "A month ago or so HL3's existence on steam in beta was leaked https://steamdb.info/sub/66300/ " (but there is a following comment disputing its authenticity.)

  10. Anonymous Coward
    Anonymous Coward

    That's why

    I only pay for steam with one-time anonymous limited debit cards. And for other online purchases also.

    Anonymous, obviously, because anonymous.

    1. Anonymous Coward
      Anonymous Coward

      Re: That's why

      Steam gift cards purchased at the grocery store work well too. Especially when said grocery store has a gas reward points system and a 4x points sale on gift cards.

      1. Anonymous Coward
        Anonymous Coward

        Re: That's why

        Yes, but that doesn't feel nearly as James Bond-ish as using one-time cards...

  11. a_yank_lurker

    Seemed OK

    Logged in and everything seems ok, do not store CC with them or other details.

  12. This post has been deleted by its author

  13. Danhalen

    Yup, kinda regret logging into my account page now...

  14. Andy Brock
    Holmes

    Whatever the root cause, Steam should suspend services while figuring it out.

  15. Anonymous Coward
    Anonymous Coward

    I can only imagine

    I can only imagine some gentile wort in marketing absolutely had to have some new ridiculous doohickey on the site and it absolutely had to be done on Christmas Day because it was super serial. So some poor sap somewhere rolls it in because "it's not impacting" so demands the marketing director who is well known for his knowledge in such thing and he's very busy stomping his big clown feet. Probably some intern getting chewed out right now.

    Only saying because it's the kind of dumb shit my company does. Mmmmyuugg "it's just a minor CMS change"

    1. Fibbles

      Re: I can only imagine

      According to the denizens of this site, IT problems are never the fault of the IT department.

      Funny that.

      1. 404

        Re: I can only imagine

        Untrue statement.

        We all know IT 'Professionals' with MCSE's,Netware (remember how important that one was back then?), Cisco etc etc certs that are completely useless because reality isn't always covered in Microsoft's KB's. Business owner's sons who didn't know dick about IT yet got paid for it and my all time favorite: The Office IT Guru Who_Installed_Office_That_One_Time...

        IT has been and will increasingly become a commodity with increasing Great Ideas That Are Horribly Bad decisions as a result.

        1. Roland6 Silver badge

          Re: I can only imagine

          The Office IT Guru Who_Installed_Office_That_One_Time...

          A fascinating interview question is to ask an AD 'guru' is how many production environment forests have they set up from scratch...

  16. Anonymous Coward
    Anonymous Coward

    Oh good

    I never got around to updating my payment details on Steam.

    1. thomas k

      Re: Oh good

      Yes, I've only ever purchased one game through Steam and I'm hoping it was far enough back that it was on my previous bank card.

  17. Anonymous Coward
    Anonymous Coward

    Steam's update

    Here - may not be that bad.

    1. Destroy All Monsters Silver badge

      Re: Steam's update

      Good!

  18. Sureo

    Configuration change on Dec. 25

    Someone must be due for a promotion.

    1. Anonymous Coward
      Anonymous Coward

      Re: Configuration change on Dec. 25

      No longer!

Page:

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon