Steam Bug Allowed Password Resets Without Confirmation
An anonymous reader writes: Valve has fixed a bug in their account authentication system that allowed attackers to easily reset the password to a Steam account. When a Steam user forgets a password, he goes to an account recovery page and asks for a reset. The page then sends a short code to the email address registered with the account. The problem was that Steam wasn't actually checking the codes sent via email. Attackers could simply request a reset and then submit a blank field when prompted for the code. Valve says the bug was active from July 21-25. A number of accounts were compromised, including some prominent streamers and Dota 2 pros. Valve issued password resets to those accounts with "suspicious" changes over the past several days.
That's pretty funny considering the NIGHTMARE I went through getting my steam account reset as the email account I used to register (DOH!) was a previous work email that is no longer active, so sending me an email asking if I want to change my email is pointless. And now I find out that if I had have waited, it wasn't even verifying the code?
FFS
Glad I still have my account...
Damn straight.
-CM
Where is my HL3?
Then testing either sucks completely or ignores security functionality. This really is an absolute basic thing to test, just as testing that giving a wrong password does not give you access. The state of practical software engineering seems to still be abysmal, even after this problem has been known for a few decades. It is high time to legally bar amateurs from doing software that has any security functionality that protects customer assets and data.
Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
OP is a fuckwit.
So, got any good abo jokes?
ahhhhwwwww its all over now...free WAS good
lol virgins
Continuous Deployment is so awesome.
I got one of the password reset emails during this "attack". The email you receive specifically states:
If you are not trying to reset your Steam login credentials, please ignore this email. It is possible that another user entered their login information incorrectly.
Yep, if you didn't try to reset your password, ignore the fact that you got the password reset email.
Lucky me, apparently I enabled Steam Guard back in 2013.
How come I always find out about these bugs AFTER they'd have been useful?
....stop complaining about these hidden features and start thanking the developers for making it so easy for $random_hacker to ruin years of work.
It's funny, though, because resetting the password on a STEAM account the way you're supposed to can be a total clusterfuck that will leave you cursing for days, if not weeks. Ask me how I know.
Just cruising through this digital world at 33 1/3 rpm...
> The problem was that Steam wasn't actually checking the codes sent via email.
Really, Steam? Really? You really, truly didn't even bother to check the code you sent as "confirmation"? The code that is the raison d'être for sending the code in the first place?
This is the kind of mistake I'd expect from a newbie who's still getting the hang of "Hello, World!", not from a multi-million dollar team of professional developers.
Just cruising through this digital world at 33 1/3 rpm...
That explains why i receive tons of steam password reset code spam recently... SO has steam devs learned their lesson? Always check input values ;)
would be a bad Of Jordan Hubbard product, BSD'S may also wan+t THINKING ABOUT IT.
Microsoft's Xbox Live system had something similar a few years ago. In that case, the "bug" was actually a flaw in their online and phone support protocols and is pretty well documented here.
This was used to compromise a large number of accounts in 2011 and 2012, with the compromised accounts generally being used to make tradeable FIFA DLC purchases, allowing Xbox Live purchases to be laundered back into real cash.
I got stung by it myself, which utterly shocked me as my XBL password was a strong password that had only ever been entered into my 360 console - so even if my PC were compromised (and I was pretty sure it wasn't), the password certainly hadn't been extracted via a keylogger. MS were very prompt in responding and gave the impression that they were dealing with a lot of these cases. They refunded the £50 that the scumbag had spent and gave me 3 months free XBL Gold subscription as well, which seemed odd given I was still convinced the slip-up must have been on my end.
Wasn't until I saw that Kotaku article a few months later that I realised what had happened. The irony is that this was going on at the same time as the Sony PSN breach and, unlike the PSN breach, it resulted in accounts actually being compromised and fraudulent purchases being made. But as it was a steady drip-drip-drip of compromised accounts rather than an eye-catching big-bang "hack", the mainstream media never picked up on it.
"Dear Valve: Please go to http://ka.je/ to see a solution to your authentication problem. The Kaje Picture Password SAAS removes all passwords from your website, eliminates transmission of passwords across the net - they are converted to an encrypted hash in the browser - and prevents phishing attacks. The Kaje SAAS never knows anything about the user, so there is no way (short of hacking two different operating systems run by two different companies on completely separate networks, at least one of which is designed to prevent even a hack from being useful) for a black hat to get the user's info and password or other Proof of Knowledge. Kaje has built-in features to prevent keyboard and mouse snooping as well, and the vendor works diligently to know nothing about the user. There is no more private and secure method for user authentication or step-up authorization. And since the user uploads his/her own test challenge (picture or other), it acts automatically as two-factor authentication - much better than that "site key" that some banks are using, while being easier to remember."
Proofs of Knowledge include picture passwords, text passwords, cognitive self-tests, Captcha's and a bunch of others. NB - I work for the company. The founder is also the inventor of Self Encrypting Drives and has several patents related to online security.
It's easier to be a result of the past, but more fun to be a cause of the future! http://www.spacefinancegroup.com/
"Run, Forrest: RUN!!!" vs. a fair challenge http://news.slashdot.org/comme...
* I find it UTTERLY HILARIOUS seeing a bullshit artist mere talk TROLLING done zero loser like you has the NERVE to state what you did - especially after you RAN in that link above, gweihir... lol!
You don't HAVE the ability to code & the link above evidences it - you're a bullshit blowhard, nothing more - a MERE TECHIE MENIAL @ best/most!
(FACT: Minus coders like myself, you TECHIE or NETWORK ADMIN MENIALS ARE HELPLESS - just as you've SHOWN yourself to be in that link above!).
AS FAR AS SECURITY WARES?
Well, the day YOU can get the likes of malwarebytes' folks to recommend & HOST your wares as mine is??
THAT'S THE DAY AN INCOMPETENT MENIAL STOOGE LIKE YOURSELF CAN EVEN BEGIN TO SPEAK TO ME, you utter LIMITED little techie moron!
You can't even CODE, you fucking blowhard wannabe loser... & YET you're "telling us how it is"?? Please, make us laugh some more!
APK
P.S.=> Keep on shooting your blowhard done nothing in computing mouth off gweihir - I'll be RIGHT THERE AGAIN to expose your crap yet again (have fun with the shame you'll have to publicly endure here & YOU STARTED IT WITH ME YOU USELESS TROLLING LOSER WITH NO SKILLS BUT LOTS OF MERE "TALK", lmao)... apk
"Run, Forrest: RUN!!!" vs. a fair challenge http://news.slashdot.org/comme...
* I find it UTTERLY HILARIOUS seeing a bullshit artist mere talk TROLLING done zero loser like you has the NERVE to state what you did - especially after you RAN in that link above, gweihir... lol!
You don't HAVE the ability to code & the link above evidences it - you're a bullshit blowhard, nothing more - a MERE TECHIE MENIAL @ best/most!
(FACT: Minus coders like myself, you TECHIE or NETWORK ADMIN MENIALS ARE HELPLESS - just as you've SHOWN yourself to be in that link above!)
UNBELIEVABLE!
This DOLT wannabe that couldn't write any code to save his LIFE is "telling us how it is" - what an incredible douchebag, talking out his ass!
E.G.=> Per the link above, He put down an app I wrote that the likes of MALWAREBYTES own people RECOMMEND & HOST FOR ME NO LESS - what's his ass done?
ZERO!
APK
P.S.=> Keep on shooting your blowhard done nothing in computing mouth off gweihir - I'll be RIGHT THERE AGAIN to expose your crap yet again (have fun with the shame you'll have to publicly endure here & YOU STARTED IT WITH ME YOU USELESS TROLLING LOSER WITH NO SKILLS BUT LOTS OF MERE "TALK", lmao)... apk
"Run, Forrest: RUN!!!" vs. a fair challenge http://news.slashdot.org/comme...
* I find it UTTERLY HILARIOUS seeing a bullshit artist mere talk TROLLING done zero loser like you has the NERVE to state what you did - especially after you RAN in that link above, gweihir... lol!
You don't HAVE the ability to code & the link above evidences it - you're a bullshit blowhard, nothing more - a MERE TECHIE MENIAL @ best/most!
(FACT: Minus coders like myself, you TECHIE or NETWORK ADMIN MENIALS ARE HELPLESS - just as you've SHOWN yourself to be in that link above!)
APK
P.S.=> Keep on shooting your blowhard done nothing in computing mouth off gweihir - I'll be RIGHT THERE AGAIN to expose your crap yet again (have fun with the shame you'll have to publicly endure here & YOU STARTED IT WITH ME YOU USELESS TROLLING LOSER WITH NO SKILLS BUT LOTS OF MERE "TALK", lmao)... apk
"Run, Forrest: RUN!!!" vs. a fair challenge http://news.slashdot.org/comme...
* I find it UTTERLY HILARIOUS seeing a bullshit artist mere talk TROLLING done zero loser like you has the NERVE to state what you did - especially after you RAN in that link above, gweihir... lol!
You don't HAVE the ability to code & the link above evidences it - you're a bullshit blowhard, nothing more - a MERE TECHIE MENIAL @ best/most!
(FACT: Minus coders like myself, you TECHIE or NETWORK ADMIN MENIALS ARE HELPLESS - just as you've SHOWN yourself to be in that link above!)
APK
P.S.=> Keep on shooting your blowhard done nothing in computing mouth off gweihir - I'll be RIGHT THERE AGAIN to expose your crap yet again (have fun with the shame you'll have to publicly endure here & YOU STARTED IT WITH ME YOU USELESS TROLLING LOSER WITH NO SKILLS BUT LOTS OF MERE "TALK", lmao)... apk
"Run, Forrest: RUN!!!" vs. a fair challenge http://news.slashdot.org/comme...
* I find it UTTERLY HILARIOUS seeing a bullshit artist mere talk TROLLING done zero loser like you has the NERVE to state what you did - especially after you RAN in that link above, gweihir... lol!
You don't HAVE the ability to code & the link above evidences it - you're a bullshit blowhard, nothing more - a MERE TECHIE MENIAL @ best/most!
(FACT: Minus coders like myself, you TECHIE or NETWORK ADMIN MENIALS ARE HELPLESS - just as you've SHOWN yourself to be in that link above!)
APK
P.S.=> Keep on shooting your blowhard done nothing in computing mouth off gweihir - I'll be RIGHT THERE AGAIN to expose your crap yet again (have fun with the shame you'll have to publicly endure here & YOU STARTED IT WITH ME YOU USELESS TROLLING LOSER WITH NO SKILLS BUT LOTS OF MERE "TALK", lmao)... apk