As was foretold, we've added advertisements to the forums! If you have questions, or if you encounter any bugs, please visit this thread: https://forums.penny-arcade.com/discussion/240191/forum-advertisement-faq-and-reports-thread/
Options

Let's all go post in the new STEAM thread and talk about Tom Clancy ♥

13468999

Posts

  • Options
    chocoboliciouschocobolicious Registered User regular
    So to be safe I'm going to do absolutely nothing, because I'm lazy and dumb. Read also I believe in the encryption. Hopefully I am not proven as dumb as I think I will be. I believe in you, Steam!

    steam_sig.png
  • Options
    TaranisTaranis Registered User regular
    So to be safe I'm going to do absolutely nothing, because I'm lazy and dumb. Read also I believe in the encryption. Hopefully I am not proven as dumb as I think I will be. I believe in you, Steam!

    In Gaben We Trust

    EH28YFo.jpg
  • Options
    busfahrerbusfahrer addict GermanyRegistered User regular
    So to be safe I'm going to do absolutely nothing, because I'm lazy and dumb. Read also I believe in the encryption. Hopefully I am not proven as dumb as I think I will be. I believe in you, Steam!

    My limited understanding of the matter is that the passwords themselves are relatively safe, since hashing with a salt is pretty good. But the credit card numbers themselves would have to be stored using some sort of symmetric encryption, and that has to mean that a key has to reside somewhere on their servers, too.

    B2b1M.gif
    Twitter: busfahrer -- Quake Live: busfahrer -- StarCraft II: busfahrer.184 (EU)
  • Options
    TaranisTaranis Registered User regular
    At the risk of derailing the thread: would anyone happen to know if it's feasible to minor in cryptography theory if one isn't a computer science major?

    EH28YFo.jpg
  • Options
    chocoboliciouschocobolicious Registered User regular
    busfahrer wrote:
    So to be safe I'm going to do absolutely nothing, because I'm lazy and dumb. Read also I believe in the encryption. Hopefully I am not proven as dumb as I think I will be. I believe in you, Steam!

    My limited understanding of the matter is that the passwords themselves are relatively safe, since hashing with a salt is pretty good. But the credit card numbers themselves would have to be stored using some sort of symmetric encryption, and that has to mean that a key has to reside somewhere on their servers, too.

    The key only has to reside somewhere in the payment system, which is likely on a completely different server than the databases used to store that kind of info. The odds of the two being within two steps of each other is pretty slim, at least if the company has any concept of security. Of course, without any real info to go on, or even knowing if my data was taken at all, all I can do is look derpy and be lazy.

    steam_sig.png
  • Options
    busfahrerbusfahrer addict GermanyRegistered User regular
    busfahrer wrote:
    So to be safe I'm going to do absolutely nothing, because I'm lazy and dumb. Read also I believe in the encryption. Hopefully I am not proven as dumb as I think I will be. I believe in you, Steam!

    My limited understanding of the matter is that the passwords themselves are relatively safe, since hashing with a salt is pretty good. But the credit card numbers themselves would have to be stored using some sort of symmetric encryption, and that has to mean that a key has to reside somewhere on their servers, too.

    The key only has to reside somewhere in the payment system, which is likely on a completely different server than the databases used to store that kind of info. The odds of the two being within two steps of each other is pretty slim, at least if the company has any concept of security. Of course, without any real info to go on, or even knowing if my data was taken at all, all I can do is look derpy and be lazy.

    Hopefully, yes.

    I just realized that the CC companies could implement a system where verified stores could process their payments by a common hashing method, instead of submitting the credit card numbers in plain text. That way they wouldn't have to store them at all. I think.

    B2b1M.gif
    Twitter: busfahrer -- Quake Live: busfahrer -- StarCraft II: busfahrer.184 (EU)
  • Options
    KisidanKisidan Registered User regular
    I am unnerved that after Steam was hacked, booting up Steam this morning it went through the 'this is a new computer' process despite me only ever having Steam on this computer.

    I hope this is a coincidental bizarre bug. I would be upset if I lost all of my money somehow.

  • Options
    AriviaArivia I Like A Challenge Earth-1Registered User regular
    Kisidan wrote:
    I am unnerved that after Steam was hacked, booting up Steam this morning it went through the 'this is a new computer' process despite me only ever having Steam on this computer.

    I hope this is a coincidental bizarre bug. I would be upset if I lost all of my money somehow.

    I think it is far more likely the Newell reset all access logs to make sure stuff is safe.

    huntresssig.jpg
  • Options
    KisidanKisidan Registered User regular
    Arivia wrote:
    Kisidan wrote:
    I am unnerved that after Steam was hacked, booting up Steam this morning it went through the 'this is a new computer' process despite me only ever having Steam on this computer.

    I hope this is a coincidental bizarre bug. I would be upset if I lost all of my money somehow.

    I think it is far more likely the Newell reset all access logs to make sure stuff is safe.

    Okay yeah that makes sense, I'm going to go with that happy thought. Hahah, paranoia.

  • Options
    SmokeStacksSmokeStacks Registered User regular
    Taranis wrote:
    So to be safe I'm going to do absolutely nothing, because I'm lazy and dumb. Read also I believe in the encryption. Hopefully I am not proven as dumb as I think I will be. I believe in you, Steam!

    In Gaben We Trust

    I have faith. The Newell hasn't done me wrong yet.

    My card info wasn't stored, so I'm not too concerned. Probably not a bad idea to get your cards replaced if it was. Not so much out of fear that haxx0rs will steal all of your Steams, but because it's not a bad idea to get a new card every now and then in general, especially if you're using it online.

  • Options
    CasualCasual Wiggle Wiggle Wiggle Flap Flap Flap Registered User regular
    I changed my steam client password but frankly I'm not worried. All this stuff is encrypted and hashed and salted and all that other shit. Even if the hackers do have a military spec super computer to break the code there's 30 million people on steam now, they can't get all our credit cards.

  • Options
    TiosanTiosan Registered User regular
    Taranis wrote:
    At the risk of derailing the thread: would anyone happen to know if it's feasible to minor in cryptography theory if one isn't a computer science major?

    Yes, but it means you'd have to be a Mathematics Major instead.

  • Options
    urahonkyurahonky Resident FF7R hater Registered User regular
    How do you change your password via their website? I'd rather not download steam to my work PC.

  • Options
    PeewiPeewi Registered User regular
    urahonky wrote:
    How do you change your password via their website? I'd rather not download steam to my work PC.

    You can't. Password changing is only in the client.

  • Options
    TetraNitroCubaneTetraNitroCubane The Djinnerator At the bottom of a bottleRegistered User regular
    The key only has to reside somewhere in the payment system, which is likely on a completely different server than the databases used to store that kind of info. The odds of the two being within two steps of each other is pretty slim, at least if the company has any concept of security. Of course, without any real info to go on, or even knowing if my data was taken at all, all I can do is look derpy and be lazy.

    You'd think that they'd keep such a key on a separate system - But then again, you'd think that they'd keep the FORUMS on a system completely separate from those databases as well. Forums are a HUGE risk of intrusion, because users can exploit them in goofy ways. I've learned the hard way that you want to keep your forums isolated from ANY sensitive information. Like, completely separate computer across the country separate.
    Kisidan wrote:
    I am unnerved that after Steam was hacked, booting up Steam this morning it went through the 'this is a new computer' process despite me only ever having Steam on this computer.

    I hope this is a coincidental bizarre bug. I would be upset if I lost all of my money somehow.

    If you want to feel more secure, go into the Steam Guard options under the Settings menu. Once you're in there, you can de-authorize every other computer besides the one you're currently using.

    Keep in mind this will prompt you for a Steam Guard key again when you try to log into the community, because the browser's cookie will be de-authorized, too.

  • Options
    RiokennRiokenn Registered User regular
    edited November 2011
    busfahrer wrote:
    ronya wrote:
    Is there a way to check whether we saved our CC info in Steam?

    In the client, in the top right corner, is a link saying "<username>'s account". If you click on that, in the right column it's listed if you saved it. It will show up as "<credit card type> ending in 1234". There's a delete link next to it.

    I thought steam unlinked everyones CC info from their account. I can't find traces of saved CC info on my account.

    Riokenn on
    OmSUg.pngrs3ua.pngvVAdv.png
  • Options
    TetraNitroCubaneTetraNitroCubane The Djinnerator At the bottom of a bottleRegistered User regular
    Riokenn wrote:
    busfahrer wrote:
    ronya wrote:
    Is there a way to check whether we saved our CC info in Steam?

    In the client, in the top right corner, is a link saying "<username>'s account". If you click on that, in the right column it's listed if you saved it. It will show up as "<credit card type> ending in 1234". There's a delete link next to it.

    I thought steam unlinked everyones CC info from their account. I can't find traces of saved CC info on my account.

    Everyone seems to be forgetting: Whether you saved your CC info on your client, and whether they stored the CC info on their databases are two completely separate things.

    Saying "Don't remember my CC info" in the client doesn't mean they don't have it on their databse somewhere.

  • Options
    Grey PaladinGrey Paladin Registered User regular
    edited November 2011
    Did they confirm that the breach has been closed? Is it safe to use new data without it being stolen too?

    Grey Paladin on
    "All men dream, but not equally. Those who dream by night in the dusty recesses of their minds wake in the day to find that it was vanity; but the dreamers of the day are dangerous men, for they may act their dream with open eyes to make it possible." - T.E. Lawrence
  • Options
    ShapeshifterShapeshifter Pants Optioanl Registered User regular
    so someone emailed gabe over this and he responded

    IMeWI.png

    steam_sig.png
  • Options
    bloodatonementbloodatonement Registered User regular
    Free portal 2? Glad I waited.

    Zdy0pmg.jpg
    Steam ID: Good Life
  • Options
    Lord_SnotLord_Snot Живу за выходные American ValhallaRegistered User regular
    edited November 2011
    so someone emailed gabe over this and he responded

    IMeWI.png

    Oh wow. Give me some sweet DoTA2. Glad they were heavily encrypted, knew I could trust Valve.

    I'd also like to reiterate that I have a free steam code for Ben There Dan That, and Time Gentleman Please. I also have a Steam code for Fate of the World. If anyone wants either PM me.

    Lord_Snot on
  • Options
    Grey PaladinGrey Paladin Registered User regular
    edited November 2011
    I.. think I am actually excited about getting hacked, if that means I have a chance to get a goddamned beta key.
    My experience with the internet, however, leads to a nudging feeling that this is an elaborate trolling attempt.

    Grey Paladin on
    "All men dream, but not equally. Those who dream by night in the dusty recesses of their minds wake in the day to find that it was vanity; but the dreamers of the day are dangerous men, for they may act their dream with open eyes to make it possible." - T.E. Lawrence
  • Options
    TetraNitroCubaneTetraNitroCubane The Djinnerator At the bottom of a bottleRegistered User regular
    edited November 2011
    Okay, freaking nice. I emailed him last night about what scheme they were using, and AES256 is more than enough to bolster my confidence. Shame that the free copies we'll be getting are games I already have and don't want, respectively, but it's still an awesome gesture.

    Despite the initial bungle, Valve have been handling this very well, I'd say.

    TetraNitroCubane on
  • Options
    BurnageBurnage Registered User regular
    Confirmation of encryption and free DOTA2? That's a pretty nice e-mail right there.

  • Options
    busfahrerbusfahrer addict GermanyRegistered User regular
    I.. think I am actually excited about getting hacked, if that means I have a chance to get a goddamned beta key.

    I was thinking a few hours ago "Knowing Valve, I bet they manage to swing this that people are actually glad about the hack". Let's hope they'll prove us right :-)

    B2b1M.gif
    Twitter: busfahrer -- Quake Live: busfahrer -- StarCraft II: busfahrer.184 (EU)
  • Options
    DrakeDrake Edgelord Trash Below the ecliptic plane.Registered User regular
    edited November 2011
    I'm getting a bit relieved about all this. I knew it was just a matter of time until someone hacked Steam, if it hadn't already happened. I'm not able to picture a better response than what I've seen from Valve, and all without any interruption of service so far. Plus the insight to how they run their security is pretty interesting and has also done nothing but confirm my confidence in them.

    Drake on
  • Options
    rikdalyrikdaly Registered User regular
    wasn't DOTA2 going to be free anyway? I was under the impression it was

    steam_sig.png
  • Options
    DrakeDrake Edgelord Trash Below the ecliptic plane.Registered User regular
    Maybe they'll give it out with some kind of credit.

  • Options
    SteevLSteevL What can I do for you? Registered User regular
    rikdaly wrote:
    wasn't DOTA2 going to be free anyway? I was under the impression it was

    I got that impression too. Maybe this will just be an acceleration of the beta rollout.

  • Options
    rikdalyrikdaly Registered User regular
    a
    SteevL wrote:
    rikdaly wrote:
    wasn't DOTA2 going to be free anyway? I was under the impression it was

    I got that impression too. Maybe this will just be an acceleration of the beta rollout.

    hmm, may have got the wrong impression, google seems to think its set to be $50 - $60

    steam_sig.png
  • Options
    Grey PaladinGrey Paladin Registered User regular
    Okay, freaking nice. I emailed him last night about what scheme they were using, and AES256 is more than enough to bolster my confidence.
    Could you explain to the uninitiated why this encryption scheme garners such a positive response?
    And I am sure one of your friends will be glad to, at the very least, swear allegiance to you and all of your children in return for a key.

    "All men dream, but not equally. Those who dream by night in the dusty recesses of their minds wake in the day to find that it was vanity; but the dreamers of the day are dangerous men, for they may act their dream with open eyes to make it possible." - T.E. Lawrence
  • Options
    DietarySupplementDietarySupplement Still not approved by the FDA Dublin, OHRegistered User regular
    Wait, what? Free games? What are our choices (work filters, etc)?

  • Options
    initiatefailureinitiatefailure Registered User regular
    I have a key for ben there, dan that and time gentlemen please is anyone wants it?

  • Options
    SteevLSteevL What can I do for you? Registered User regular
    rikdaly wrote:
    a
    SteevL wrote:
    rikdaly wrote:
    wasn't DOTA2 going to be free anyway? I was under the impression it was

    I got that impression too. Maybe this will just be an acceleration of the beta rollout.

    hmm, may have got the wrong impression, google seems to think its set to be $50 - $60

    I think Valve has come out and said that they haven't said anything about pricing yet, so what you found was probably speculation.

  • Options
    gilraingilrain Registered User regular
    Oh shit, it'd be a dick move for me to be happy about Steam getting hacked... but I've been wanting Portal 2 bad, unable to afford it. I'd been thinking probably during the Christmas sale, but... free? Awesome. Talk about a gesture of good faith. At least in my case. It'd be nice if they did something in addition for those who already have the game.

  • Options
    Grey PaladinGrey Paladin Registered User regular
    Doing a bit of research, the email appears to be from Reddit, which in turn has taken it from /v/ - a board in 4chan. My catlike instincts once again turn to save me from heartbreak. If you are unaware this pretty much means the probability of this being a troll is 99.repeating nines.

    "All men dream, but not equally. Those who dream by night in the dusty recesses of their minds wake in the day to find that it was vanity; but the dreamers of the day are dangerous men, for they may act their dream with open eyes to make it possible." - T.E. Lawrence
  • Options
    SteevLSteevL What can I do for you? Registered User regular
    Also, my credit card was never de-linked from my Steam account like it apparently happened with others here. I'm not going to bother with doing that either.

  • Options
    Dark Raven XDark Raven X Laugh hard, run fast, be kindRegistered User regular
    So! Do I get Modern Warfare 3 for the campaign alone, or Skyrim?

    If I get MW3, I probably won't be multiplaying much/at all.

    But I'm not exactly busting the elastic on my boxers for Skyrim either. I mean, it looks good! But I'm not hypedasallfuck to get it.

    Considering I can afford one now, and one next week, which should get my cash money first?

    Oh brilliant
  • Options
    SpoitSpoit *twitch twitch* Registered User regular
    Having not played either, I think if you're not going to play MP, skyrim is probably a better value

    steam_sig.png
  • Options
    GaslightGaslight Registered User regular
    So! Do I get Modern Warfare 3 for the campaign alone, or Skyrim?

    If I get MW3, I probably won't be multiplaying much/at all.

    But I'm not exactly busting the elastic on my boxers for Skyrim either. I mean, it looks good! But I'm not hypedasallfuck to get it.

    Considering I can afford one now, and one next week, which should get my cash money first?

    You will get many, many more hours out of Skyrim than MW3 if you're not going to do MW3 multiplayer at all. The MW3 campaign mode you can finish in, what, 10 hours tops?

Sign In or Register to comment.