Steam loses user database
gaming.icrontic.com
gaming.icrontic.com
The message communicates exactly what happened in clear terms that don't try to cover anyone's ass. They explain which data was compromised and the potential implications. No double-talk. This could be an email you got from a friend or colleague.
The message conveys Valve's hope that the credit cards are secure but makes clear that users should be nonetheless vigilant about watching for suspicious activity. Just in case.
The message is signed by the head honcho of the company. Not some communications or PR weasel. It's in your inbox, not on some obscure blog.
Finally, it closes with:
"I am truly sorry this happened, and I apologize for the inconvenience."
Accepting responsibility, acknowledging that it's a fuckup, and showing some empathy for the fact that this completely sucks for their customers.
Sony, Adobe and their ilk could learn a lot from this company.
> Sony, Adobe and their ilk could learn a lot from this company.
And unfortunately they won’t listen…
Edit: I should clarify - there certainly are examples of bcrypt being used, and I know there are tools available. But pick several random websites that have forums or user accounts and the number actually using it will be very small. That has been my experience once exposed to the code/infrastructure anyway.
has_secure_password
in the model and you're away.Clarification: has_secure_password does NOT mean you choose between secure or non-secure password, it just mean "I want a password on this model, and better make it secure guys!"
https://code.djangoproject.com/ticket/15367
edit Let me also add... this is for auth/password hashing, not data encryption. To any people reading this: if you don't understand the difference, and you are responsible for writing web applications, then please read up on it.
The data that Valve was storing (CC info) needs to be encrypted and I'm assuming that data then needs to be unencryptable. They have to store the key because they have to be able to recover the plain text. With password hashing, you will never need to be able to recover the password.
https://github.com/mozilla/playdoh
It's what we use at Mozilla as the basis for most of our Django-based stuff, and gets you bcrypt password hashing -- even on older Django releases -- for free, along with some other niceties that probably need to find their way upstream soon :)
I'm totally with you, and I suspect we may see a more technical explanation of the event in the coming days.
That said, this is a tough situation for Valve. They have many sorts of users, many of them who have no idea what MD5 hashing is or why it would be awful to use. You're already delivering bad news, so it may be wise not to make nontechnical users feel further discomfort at confronting terminology they don't understand.
In this, I feel like Valve has banked enough credibility for me to trust for the moment that they can evaluate their security and say "Oh, fuck, this will be cracked and it's only a matter of time," and then communicate that in clear terms in their message.
When you assume that the attackers would have, or could get, at least one account which they know the password for, then if the hashing scheme is something they'll be able to crack en masse, then they are probably going to be able to figure out what the hashing scheme is, from their known plaintext.
As an example, here is an attack you may not have considered. If you wanted to make an authentication system, you would want to compare a password with a stored password (or hash). Most people would do a byte by byte comparison of the passwords (or hashes). The problem is, a byte by byte comparison takes longer for a correct password (even if you use hashes), as the incorrect answer exits on the first compare failure. This is called a timing attack, and is an example of a side channel. Most people wouldn't even know that such an attack existed. This is why you want to use a known algorithm, because the people who wrote them know these kinds of attacks. So if people know your secure algorithm, they shouldn't be able to exploit that knowledge.
Here are two links posted here recently, which show these concepts very well. The third is an hour talk about cryptography in general, and I highly recommend it.
http://carlos.bueno.org/2011/10/timing.html
http://syhw.posterous.com/two-amusing-side-channel-attacks
http://fosslc.org/drupal/content/everything-you-need-know-ab...
You'd be surprised.
The Steam Community is (or was when I checked, about a month ago) vulnerable to CSRF everywhere. Valve might hold their own when it comes to games, but I'm not too confident when it comes to the web development side of things.
> He says passwords were "hashed and salted." This could be anything from the naïve MD5(pass+salt) to the more secure bcrypt or PBKDF2. Now, I have every reason to believe that Valve is smart enough to not use methods like the first, but information is always welcome in a scenario like this.
Do these details actually matter to you, a technically savvy user? If they told you they used bcrypt or PBKDF2 for their password hashed and salted passwords would you think to yourself: "oh well, in that case I don't need to change my password" or are you going to take the few moments and change you password anyway? I'd probably just change my password.
For even less savvy users, they're getting technical details that they don't really care about now. Depending on where those details are in the message they might miss important bits of useful information.
I suppose if they said it was MD5(salt:pass) and you used the same password for steam and something else you might have reason to be concerned, but probably not unless they are targeting you specifically.
That said, I think any company should provide a link to a blog that does dig into the important technical details for people that want to know. And keep updating it as new information is found.
The passwords are hashed and salted using this:
md5(md5(password + user_salt))That Steam forums requires a separate registration shows that there is unlikely to be any integration between Steam and the forum software.
However their point is that if you used the same username and password on both the Steam forums and Steam itself (with likely the same username) then by virtue of Steam forums being compromised, your main account should be considered compromised.
md5(md5(password) + user_salt)Just re-checked... the line is this:
md5(md5($vbulletin->GPC['password']) . $vbulletin->userinfo['salt']))
I got confused by the last bracket closing an outer conditional.Even though Sony didn't quite apologise, they tried to squash legal action through contract changes(?) and offering a free game download(?) as a form of settlement.
Sorry but real mensch in tech never has its database compromised.
It's nice to imagine but that's not really how the world works. Perfection is impossible after any system reaches a certain level of complexity. The technical security implementation might have been airtight, but then a human factor compromised things in the end. Tough to say. Nonetheless, "be perfect" is not a reasonable strategy – or expectation.
> Valve should have improved its security after such an incident.
You've typed words here without really saying anything. Improved it how? Who's to say they didn't? Until and unless Valve gives us a post-mortem, we'll have no idea what the cause of the breach is. Nonetheless, it may include factors they never thought to consider.
Once you can perform a select statement, extracting data becomes pretty easy.
Because while some people have apparently received an e-mail they certainly are not contacting all their customers.
Sorry, but this is more than an inconvenience. It's a violation of user privacy that Valve didn't prevent.
I thought that the response from Newell was right on until that point. Left me with a bad taste in my mouth.
Luckily I also don't have my CC number on my account since I use PayPal. I also enabled authentication via email a while ago so it sends me a code to log in.
I guess it's a good idea to change your password and check CC statements either way.
I assume "will" means that it hasn't been sent, yet, but it will be at some point in the future. I haven't gotten one either, FWIW.
I'll be watching to see if anyone starts spamming me, because that spamtrap email is unique to my Steam account and has not been published elsewhere.
Guess it pays to be paranoid.
Same here. But I am a bit sad that my paranoia has been confirmed yet again.
And with each major (and minor) data breach I'm more happy I use it.
I know for example that credit cards with expiration dates can still be charged for a couple of months after the expiration so that users who have not had the chance to update recurring services have more time to do so. Also, it is entirely possible that Apple had placed a hold on your account for the money and when it finally shipped it went from a hold to actual transaction and that is why it was still allowed through.
Microsoft charged me for two years after the card's expiration date until I noticed.
I gather that issuing banks are converging on limiting to one merchant and are phasing out other options for that. Remember that the banks are acting in their interest, not the consumers'. A merchant lock keeps you safe from a stolen number, and avoids most fraud scenarios; the banks do care about that since they're legally liable (in US law) for fraudulent charges. But this approach allows the single merchant to make recurring charges (which some customers want protection from); the banks of course have a vested interest in keeping a stream of transactions coming.
You create a number, you set a dollar limit and expiration date. If you close it no one can bill it. It's called a http://en.wikipedia.org/wiki/Controlled_payment_number
For a moment there I thought all my Steam purchases were, you know, lost.
Um. What? Assuming that a PCI-compliant level of encryption was used, "matter of time" is "heat death of the universe" if you don't have the encryption keys.
This isn't CSI. You don't just throw encrypted text at an implausibly attractive IT guy and wait for him to furrow his brow, declare that it's military-grade encryption that will take him a little while, and then have him decrypt it by the end of the next commercial break. PCI-compliant encryption is the sort of thing that, barring incredible leaps in technology or the discovery of a significant algorithmic weakness, will never be crackable in our lifetime.
That the information had encryption is a good sign.
You might want to rethink this. "Will probably not be crackable in the next twenty years" is more realistic.
One potential reason it's preferable to use an innocuous, generic text editor is the potential supposition by an attacker that they only need to infect and/or monitor the card processing application. If someone spreads a malicious update that has a built-in keylogger only for that application, for instance, copy+paste from the non-infected program would stop it from recording the data.
Though I think that's stretching it a bit. Maybe your auditors encountered something similar previously?
It was something the auditors just brought up on their own, so yeah, I'm assuming they'd run into it before.
Ok, the forum may need data from the account for validation, display name or else. You can still implement it securely. This is a big human oversight over what seems to be an insecure implementation. I just can't believe this.
I would have guessed they learned the lesson from when Gabe was hacked through an Outlook vulnerability (with the HL2 code leak afterwards). It should have made a paranoid out of him.
I think having chosen Paypal as a payment method was perhaps helpful for me.
PS: I do own a lot of games and I very much like the platform. I definitely don't have anything against them. They presented a good notice, their high level of responsibility over this incident is irrefutable. Also, props for them for having an encryption for their preloaded games that wasn't broken so far.
edit: formatting
All passwords are salted and hashed (hope they are using bcrypt), and all CC's are encrypted.
EDIT: updated comment to clarify what I meant with the bcrypt
I believe the point of storing CC data would be to retrieve it (impossible, typically, by the nature of hashing) to enable the user to purchase goods using this information stored without having to fetch their CC details.
1. http://en.wikipedia.org/wiki/Bcrypt
Edit: Ah. I seem to have correlated your note with the latter part of your sentence.
A cryptographic hash attempts to be as hard to reverse as possible (amongst other things).
So bcrypt has to do with cryptography, a bit.
Why?
My first thought is that it should be stored on, and never leave, a completely separate system where you have a very limited number of interactions available (reducing the attack vector and making it much easier to spot suspicious activity).
I.e. Charge customer x with y for game z. Refund customer for purchase i (only valid within the refund-period). Add(overwrite)/delete customer data. Where all interactions must be signed.
And nothing more.
Anything less than that and I'm skeptical as to whether you could be considered careful of you customers data. Storing credit card information in the same database as all other user data for a service like steam should be a crime and if it's closely coupled with the forum it's even worse (not that I know if that's the case).
Disclaimer: I don't know any details about this incident more than that Valve seems to be open about it taking place (great!).
There's also others like 1Password that are popular on OSX.
Edit: typo
I hadn't really used either account in years, so I never got around to enhancing my passwords.
It's great that Steam is letting me know that their database has been hacked. It's not so great when I can't even see if my billing information or credit card number (I obviously only want the last four digits) that Steam currently has on file for me. If I knew which credit card I had used with Steam, I could probably watch out for fraudulent charges. As it stands, there is no way for me to figure out what information I've given to Steam in the past.
Arg.
So your Steam account is save. Your email address probably isn't a secret anyway. The password is changed in a second.
Which leaves your payment (encrypted) and billing info. Personally I use Click&Buy which requires a separate authorization from me and I'm actually not sure if I have any billing address associated with Steam. So for me this whole thing is just a minor annoyance in changing my password.
Obviously I might treat the obtained user data different from other people.
If you are a Steam user I would recommend using the two-step verification process they have. It uses a password sent to your email to verify you when logging in using a new computer. Hopefully you're Steam and associated email passwords are not the same.
This is, of course, no replacement to changing your password - you should definitely do that - but allows us to relax a bit in case something similar happens again.
I am assuming here that this means certain passwords were cracked at that point - does this mean that the nonce/salt in their password storage was discovered? And how long until they have a cracked user/password file?
Even if your Steam client and forum passwords were the same, your client account still secure as long as your email password is different.
I would rather prefer to repost the needed details for every purchase.
Thanks.
Password stores are one possible improvement, but most people don't know enough to use one, and they are probably far too fiddly for most people anyway. And of course, ultimately you're still talking about using a single set of credentials to authorise everything in that case, it's just a different target (which if ever compromised will undermine your entire identity).
Multi-factor authentication is a much better solution, but the technology to make it ubiquitous in a way that is neither excessively expensive nor creepy on privacy grounds isn't there yet.
There are some problems in security that we know how to solve, at least to the extent that no-one has any idea how to crack them directly today and the effort to brute force them is effectively infinite. I'm really hoping that one of these days, the combination of mobile technology and the Internet will provide us with an easily portable device that can integrate with everything and render obsolete the current mess of hundreds of on-line identities, "memorable data" to authenticate for every financial service I use, etc.
EDIT: Found it! https://accounts.google.com/b/0/SmsAuthConfig
The interface for changing your Steam Forums password is not currently available.
Forum accounts are separate, after all.