As was foretold, we've added advertisements to the forums! If you have questions, or if you encounter any bugs, please visit this thread: https://forums.penny-arcade.com/discussion/240191/forum-advertisement-faq-and-reports-thread/
Options

Let's all go post in the new STEAM thread and talk about Tom Clancy ♥

1356799

Posts

  • Options
    LepwaveLepwave Registered User regular
    Yeah, changed my Steam password to be safe, will change my password to the forums once it's up.

    XBL/CoX tags - Lepwave/@Lepwave
    steam_sig.png
  • Options
    SteevLSteevL What can I do for you? Registered User regular
    We'll all get Episode 3 for free when it comes out.

    Hee hee hee.

  • Options
    TaranisTaranis Registered User regular
    edited November 2011
    Darlan wrote:
    Well, on the plus side, maybe we'll get a big apology sale or something.

    Every Steam account gets Black Hats for TF2!

    Edit: But yeah I definitely changed my password. Fuck now I'm paranoid.

    Taranis on
    EH28YFo.jpg
  • Options
    BullioBullio Registered User regular
    Darlan wrote:
    Well, on the plus side, maybe we'll get a big apology sale or something. I don't feel too worried, after the Sony hack I changed all of my passwords to be different things and it's easy enough to check for faulty CC charges.

    Free Ep3.

    Surprise!

    steam_sig.png
  • Options
    DarlanDarlan Registered User regular
    edited November 2011
    SteevL wrote:
    We'll all get Episode 3 for free when it comes out.

    Hee hee hee.
    Or maybe the hackers made off with some Ep. 3 info! It's about time we got a screenshot or trailer or something.

    Edit: And, come to think of it, long term goodwill in Steam is worth a LOT more than the money they'll see from Ep. 3. Not that it'll happen, but it might not be quite as crazy as the joke implies...

    Darlan on
  • Options
    minor incidentminor incident expert in a dying field njRegistered User regular
    Darlan wrote:
    Well, on the plus side, maybe we'll get a big apology sale or something. I don't feel too worried, after the Sony hack I changed all of my passwords to be different things and it's easy enough to check for faulty CC charges.

    Ooh, hot, steamy apology sale.

    Ah, it stinks, it sucks, it's anthropologically unjust
  • Options
    David_TDavid_T A fashion yes-man is no good to me. Copenhagen, DenmarkRegistered User regular
    Darlan wrote:
    Well, on the plus side, maybe we'll get a big apology sale or something. I don't feel too worried, after the Sony hack I changed all of my passwords to be different things and it's easy enough to check for faulty CC charges.

    Ooh, hot, steamy apology sale.

    Only the games you buy go into some other random persons account.

    euj90n71sojo.png
  • Options
    Lord_SnotLord_Snot Живу за выходные American ValhallaRegistered User regular
    edited November 2011
    David_T wrote:
    Darlan wrote:
    Well, on the plus side, maybe we'll get a big apology sale or something. I don't feel too worried, after the Sony hack I changed all of my passwords to be different things and it's easy enough to check for faulty CC charges.

    Ooh, hot, steamy apology sale.

    Only the games you buy go into some other random persons account.

    Unintended Generosity-em-up!

    Also, amongst this disturbing news, console yourself with either Ben There, Dan That & Time Gentleman, Please, or Fate of the World! PM me if you want either.

    Lord_Snot on
  • Options
    FugaFuga Registered User regular
    ugggh after battlefield was hacked i changed all my passwords. and now i have to do it a second time

  • Options
    emp123emp123 Registered User regular
    Fuga wrote:
    ugggh after battlefield was hacked i changed all my passwords. and now i have to do it a second time

    Battlefield was hacked?

  • Options
    TaranisTaranis Registered User regular
    emp123 wrote:
    Fuga wrote:
    ugggh after battlefield was hacked i changed all my passwords. and now i have to do it a second time

    Battlefield was hacked?

    I think they're talking about Battlefield Heroes.

    EH28YFo.jpg
  • Options
    DarlanDarlan Registered User regular
    emp123 wrote:
    Fuga wrote:
    ugggh after battlefield was hacked i changed all my passwords. and now i have to do it a second time

    Battlefield was hacked?
    I know Battlefield Heroes was hacked a few months ago, not sure about 3. Also, Fuga, it's probably worth it to change your passwords to different things this time so you don't have to change them all when this inevitably happens again.

  • Options
    BullioBullio Registered User regular
    David_T wrote:
    Darlan wrote:
    Well, on the plus side, maybe we'll get a big apology sale or something. I don't feel too worried, after the Sony hack I changed all of my passwords to be different things and it's easy enough to check for faulty CC charges.

    Ooh, hot, steamy apology sale.

    Only the games you buy go into some other random persons account.

    This would not be much of a change for some people here :P.

    Speaking of, I still have a key for Sanctum from the first IRB and now a key for Gish from the current HB. First to me PM can have one or both.

    steam_sig.png
  • Options
    MaddocMaddoc I'm Bobbin Threadbare, are you my mother? Registered User regular
    I have Steamguard set up, and two step authentication on my email, so meh...

    The fact that they have possible access to my CC information if they break the encryption is extremely troubling, but I'm not terribly concerned about them knowing my password.

  • Options
    minor incidentminor incident expert in a dying field njRegistered User regular
    edited November 2011
    The best solution is to have a different password for everything. There's an easy way to do this with no need for a password keeper app. The system I use (Which I think I picked up from Merlin Mann years ago) is to have a 3-part password:

    The first part is a generic word that will be the same in every login you use. For example, let's say you choose "terrible"

    The second part is a number (as is often required by most sites). For example we'll use "39"

    The last part is a couple of letters pulled from the site you're using. For example, you could use the 2nd and 3rd letters of the site. For Google.com this would be "oo"

    This would make your google password "terrible39oo"

    Chase Bank would be "terrible39ha"

    Steam would be "terrible39te"

    It's a system I swear by. Highly secure passwords, since there results basically never end up being dictionary words, and they're simple to remember no matter what site you're using. Plus, you'll never need a password manager app. If a password is ever compromised, you can just alter it by changing the order of the components ("terribleoo39"), or going to a backup number. For more security, you can also include a symbol which changes depending on the security level of the site, like a "%" for low security sites and a "#" for high security sites (bank, and anything with a stored credit card).

    /Password PSA

    minor incident on
    Ah, it stinks, it sucks, it's anthropologically unjust
  • Options
    ElvenshaeElvenshae Registered User regular
    edited November 2011
    Obligatory XKCD:

    password_strength.png

    Elvenshae on
  • Options
    DecoyDecoy Registered User regular
    edited November 2011
    Calling it now....
    "Sorry About The Security Hole" Bundle
    95% off: Brian Spencer's Hacker Evolution: Time Dimensions, Hacker Evolution Duality, and Uplink.

    :)

    Decoy on
  • Options
    schmadsschmads Registered User regular
    edited November 2011
    I don't know why it never occurred to me to use a technique like that. And you can mix it up if you like by doing a character shift on the letters you pick out of the site's name, for instance. Thanks for the good advice :)
    Edit: Referring to minor incident's technique of generating site-unique passwords that aren't impossible to remember.

    schmads on
    Battle.net/SC2: Kwisatz.868 | Steam/XBL/PSN/Gamecenter: schmads | BattleTag/D3: Schmads#1144 | Hero Academy & * With Friends: FallenKwisatz | 3DS: 4356-0128-9671
  • Options
    BethrynBethryn Unhappiness is Mandatory Registered User regular
    Another simple password system:

    Brand of alcohol + proof of alcohol = alphanumeric password. You can even keep the bottles around, and nobody will realise that your passwords are staring them in the face. 8D

    ...and of course, as always, Kill Hitler.
  • Options
    Lord_SnotLord_Snot Живу за выходные American ValhallaRegistered User regular
    edited November 2011
    Also, is this a glitch? According to the Steam news channel, there are three daily deals, but neither of the other two are showing as discounted on their store pages.

    Aaanndd: The weekend deal is up, Codemasters racing bundle, Formula 1 2011 and Dirt 3 66% off.

    Not interested in either, but someone might be. I'm guessing they've had their hands full dealing with the hacking problem.

    Lord_Snot on
  • Options
    Hahnsoo1Hahnsoo1 Make Ready. We Hunt.Registered User regular
    Yup. I no longer use passwords that have less than 16 characters anymore on sites that also have my credit card information. I also no longer use the same password twice for any site. If it's important enough to require my personal info and credit card info, it's important enough to memorize a new password.

    Throwaway accounts, though, I simply don't care about them. Like accounts for the forums on some game I'm playing.

    That XKCD comic fails to address dictionary attacks (which are substantially faster) or social engineering (it's way easier to hack into accounts by grabbing the sticky note with the password sitting there on the monitor or simply using the mark's personal info to guess the password), but length is still far more important than confusing shibboleths of syllables. I can reasonably "hack" my brother's passwords, for example, for his penchant of making passwords less than 10 characters in length (typically the absolute minimum) and the fact that he puts "79" in all his passwords (birth date 1979).

    8i1dt37buh2m.png
  • Options
    minor incidentminor incident expert in a dying field njRegistered User regular
    schmads wrote:
    I don't know why it never occurred to me to use a technique like that. And you can mix it up if you like by doing a character shift on the letters you pick out of the site's name, for instance. Thanks for the good advice :)
    Edit: Referring to minor incident's technique of generating site-unique passwords that aren't impossible to remember.

    Yep! What I described is the most basic method. It's easy to think up your own tweaks to further customize it, and keep it easy to remember. My personal version of this method involves a seemingly (although not actually) randomly placed capital letter, more than two characters from the site name, and the symbol trick I mentioned.

    Ah, it stinks, it sucks, it's anthropologically unjust
  • Options
    ElvenshaeElvenshae Registered User regular
    edited November 2011
    Hahnsoo1 wrote:
    That XKCD comic fails to address dictionary attacks (which are substantially faster)

    Except, even with a dictionary attack, you're looking at an indeterminate number of words in an indeterminate order, so ...

    So the OED has 171,476 words in common use (source). Take 5 random words, and your dictionary hacker has to pick from 171k^5 combinations, or 1.46*10^26 combinations. At 1,000 guesses per second, and assuming it, on average, finds your answer halfway through the full dictionary-picking-process, you're looking at 8.5*10^17 days to crack the code. At 4 random words, you've got 4.95*10^12 days to crack it.

    No, this is not particularly vulnerable to a dictionary hack.
    or social engineering (it's way easier to hack into accounts by grabbing the sticky note with the password sitting there on the monitor

    Which is a vulnerability of all passwords; thus, easier-to-remember = less-use-of-sticky-notes is even more secure.
    or simply using the mark's personal info to guess the password),

    Ditto.

    Elvenshae on
  • Options
    minor incidentminor incident expert in a dying field njRegistered User regular
    edited November 2011
    Elvenshae wrote:
    or simply using the mark's personal info to guess the password),

    Ditto.

    Basically, stop using any numbers/months that have any actual significance to you. Is your favorite number 13? Great! Now never, ever use it in a password. Were you born in '79? Congrats! Never in a password. November may be your anniversary, but it better not be your goddamn password!

    minor incident on
    Ah, it stinks, it sucks, it's anthropologically unjust
  • Options
    ElvenshaeElvenshae Registered User regular
    Elvenshae wrote:
    or simply using the mark's personal info to guess the password),

    Ditto.

    Basically, stop using any numbers/months that have any actual significance to you. Is your favorite number 13? Great! Now never, ever use it in a password. Were you born in '79? Congrats! Never in a password. November may be your anniversary, but it better not be your goddamn password!

    Ayep.

    ... and how did you know my anniversary was in November? [/estalker]

  • Options
    minor incidentminor incident expert in a dying field njRegistered User regular
    Elvenshae wrote:
    Elvenshae wrote:
    or simply using the mark's personal info to guess the password),

    Ditto.

    Basically, stop using any numbers/months that have any actual significance to you. Is your favorite number 13? Great! Now never, ever use it in a password. Were you born in '79? Congrats! Never in a password. November may be your anniversary, but it better not be your goddamn password!

    Ayep.

    ... and how did you know my anniversary was in November? [/estalker]

    I've been masquerading as your wife for the last year in an attempt to steal all your passwords.

    Ah, it stinks, it sucks, it's anthropologically unjust
  • Options
    Banzai5150Banzai5150 Registered User regular
    Elvenshae wrote:
    Elvenshae wrote:
    or simply using the mark's personal info to guess the password),

    Ditto.

    Basically, stop using any numbers/months that have any actual significance to you. Is your favorite number 13? Great! Now never, ever use it in a password. Were you born in '79? Congrats! Never in a password. November may be your anniversary, but it better not be your goddamn password!

    Ayep.

    ... and how did you know my anniversary was in November? [/estalker]

    I've been masquerading as your wife for the last year in an attempt to steal all your passwords.

    Oh the Mental image you have given me! :(

    50433.png?1708759015
  • Options
    Hahnsoo1Hahnsoo1 Make Ready. We Hunt.Registered User regular
    Elvenshae wrote:
    or social engineering (it's way easier to hack into accounts by grabbing the sticky note with the password sitting there on the monitor

    Which is a vulnerability of all passwords; thus, easier-to-remember = less-use-of-sticky-notes is even more secure.
    or simply using the mark's personal info to guess the password),

    Ditto.
    People will write down the simplest passwords. Conscientious people won't, obviously, but how many times is a hacker going to target a conscientious person who cares about password security? Social engineering also encompasses far more than grabbing the sticky note (which is only the classic example). It involves so many other tools, many of which are constantly used to gain personal information and passwords now, like phishing. It's manipulating the person, not manipulating the program, and people, in general, are fairly easy to hack.

    8i1dt37buh2m.png
  • Options
    GaslightGaslight Registered User regular
    Hmm. I have had my eye on DiRT3 for a while, but I bet it will be even cheaper over the holidays.

  • Options
    fadingathedgesfadingathedges Registered User regular
    edited November 2011
    What is best free/cheap indie(or not I guess?) business sim game? I have an itch.

    fadingathedges on
  • Options
    Triple BTriple B Bastard of the North MARegistered User regular
    edited November 2011
    So. Like.

    How worried should we be if our current credit/debit card info was linked to our Steam account?

    I just got this goddamn card when the neckbeards went after Sony back in April. Now it's happened to Steam? I'm normally not a huge proprietor of the death penalty, but...

    Triple B on
    Steam/XBL/PSN: FiveAgainst1
  • Options
    CorriganXCorriganX Jacksonville, FLRegistered User regular
    In lieu of further apologies, gabe can just give me dota 2. Right now. For free. I'll be happy. I promise.

    n1woEHJ.png
    CorriganX on Steam and just about everywhere else.
  • Options
    TetraNitroCubaneTetraNitroCubane The Djinnerator At the bottom of a bottleRegistered User regular
    edited November 2011
    Hey, Valve, I love you and everything... But why the fuck were the forums and the machine that stores all that information in any way connected?! Your forums are ones of the largest dens of misery, pestilence, and bored teenagers the world has ever seen. The machines that run those forums should be housed in an isolation chamber buried three miles below the surface of the arctic, far, far away from where anyone would even have the chance to look at them.

    TetraNitroCubane on
  • Options
    CadeCade Eppur si muove.Registered User regular
    Seem's like can't even change our passwords, huzzah.

    Me thinks people are going to be pissed.

    Also sending out emails to people about this whole matter might be a good idea.

  • Options
    Joe Camacho MKIIJoe Camacho MKII Registered User regular
    Well... Just changed my Steam password, I also checked my online bank account and nothing fishy, YET.

    Hopefully nothing wrong happens, because I'm currently pretty far away from my billing address and I don't want to order a new debit card.

    steam_sig.png I edit my posts a lot.
  • Options
    LuxLux Registered User regular
    Wait, so, what makes a better password:

    A long string of random letters & numbers

    A handful of random dictionary words

    or a couple random dictionary words paired with random letters & numbers?

  • Options
    minor incidentminor incident expert in a dying field njRegistered User regular
    Lux wrote:
    Wait, so, what makes a better password:

    A long string of random letters & numbers

    A handful of random dictionary words

    or a couple random dictionary words paired with random letters & numbers?

    For all practical purposes, both ways are pretty damn good. Really, anything over 10-12 characters is a big step up from most people, and puts you above the "low hanging fruit" to the point that you're not likely to get directly hacked anytime soon.

    Ah, it stinks, it sucks, it's anthropologically unjust
  • Options
    TetraNitroCubaneTetraNitroCubane The Djinnerator At the bottom of a bottleRegistered User regular
    edited November 2011
    I am of the opinion that entropy will forever be king in the realm of password security - hence, as many random characters as you can manage. Up to and including Alt-code characters that aren't on your keyboard. Of course, that's impractical for reasons of (1) never being able to remember shit, and (2) password requirements not allowing the characters you want. A sufficiently long passphrase is a good compromise, if the service in question will tolerate one. A stupid number of banks and other services won't allow spaces, after all.

    Also, I'd like to point to this artcle about password complexity, if anyone's interested. It's a good read.

    TetraNitroCubane on
  • Options
    VicWhitenVicWhiten Registered User regular
    I have a crisis Steam Thread, you're my only hope.

    I'm getting Skyrim at a midnight release with some friends @ gamestop, pc version. I was planning on getting it, installing from disk, registering with steam, and playing it all night (no classes tomorrow)

    What I forgot until now is that my computer doesn't have a disk drive!!!!! Is there anyway I could start the preload now to shave off some waiting time, or can you not preload until you own the game?

    I feel so dumb for leaving my disk drive at home now.....

    camo_sig2.png
  • Options
    DehumanizedDehumanized Registered User regular
    Changed my steam password out of an abundance of caution, but whatever I'm not worried.

Sign In or Register to comment.