Author Topic: Steam Has Lost Some Steam !  (Read 571 times)

0 Members and 1 Guest are viewing this topic.

Offline Aidan

  • Living Legend
  • *******
  • Posts: 2280
  • Karma: 41


Intel Core i7 @ 3.50GHz, AMD/ATI HD6990 LCS, Catalyst Control Center V12.3, 6GB Tri-Channel Dram, 640GB HD, 128GB SSD, DirectX 11,  Windows 7 Pro (64 bit), Corsair 1200 Watt Power Supply, Liquid Cooled GPU and CPU.

Offline CGB [Blackthorne]

  • Recruit
  • *
  • Posts: 125
  • Karma: 15
Re: Steam Has Lost Some Steam !
« Reply #1 on: November 11, 2011, 06:06:31 PM »
This is why I never click that "Save checkout details" box... I'm checking my bank details anyway...

Offline Ghiest

  • Star Captain
  • ***
  • Posts: 825
  • Karma: 12
Re: Steam Has Lost Some Steam !
« Reply #2 on: November 11, 2011, 06:32:25 PM »
I use paypal to exclusively pay on steam, I was wondering when they would be targeted tbh.

Offline Askis

  • Star Colonel
  • ****
  • Posts: 1893
  • Karma: 38
Re: Steam Has Lost Some Steam !
« Reply #3 on: November 11, 2011, 06:47:34 PM »
I use paypal to exclusively pay on steam, I was wondering when they would be targeted tbh.

Me too and for some stupid reason I've had the same password on both ::)
Once I read this, I changed my Paypal password immediately, better safe than really sorry...

Offline Wraythe

  • Recruit
  • *
  • Posts: 165
  • Karma: 15
Re: Steam Has Lost Some Steam !
« Reply #4 on: November 11, 2011, 08:04:28 PM »
My guess? They left a Valve open.

Offline SquareSphere }12thVR{

  • Living Legend
  • *******
  • Posts: 4518
  • Karma: 186
  • pancake slinging, Square (care) Bear of MWLL
    • 12th Vegan Rangers - Boards
Re: Steam Has Lost Some Steam !
« Reply #5 on: November 11, 2011, 08:20:01 PM »
already reset my passwords and such, never logged into the the steam forums though.
Want to give organized battles a spin?
Not sure about your skills but want to test them out?
Looking for a casual unit?
12th Vegan Rangers are recruiting!  Click here to check out our new boards!

FLAWLESS VICTORY


Offline Mitchpate

  • Star Colonel
  • ****
  • Posts: 1268
  • Karma: 39
    • NetBattletech
Re: Steam Has Lost Some Steam !
« Reply #6 on: November 11, 2011, 09:05:34 PM »
This is unlikely to ever be a real problem.  Steamguard requires email verification prior to a new computer accessing your account so even if they got your password they wouldn't be able to actually log into it.

The fact that the passwords are salted and hashed makes it unlikely they'll even be hacked at all.  It takes a large number of GPUs in tandem to crack a single salted/hashed password in any meaningful amount of time.  The likelyhood that they're going to crack more than a handful before getting bored is extremely low.

Now if they got the salt(s) then yeah I'm going to be a little concerned.  Otherwise it doesn't really bother me that I had my CC info stored on there.  Absolute worst case is I spend 10 minutes on the phone with my CC company and have to use debit for 2 weeks.  Inconvenience, yes.  Big deal, not really.  IMO, anyway.
« Last Edit: November 11, 2011, 09:11:17 PM by Mitchpate »
Mitchpate
FedCom of NBT-MP3
NBT Admin Team

Offline Taemien

  • Star Colonel
  • ****
  • Posts: 1888
  • Karma: 131
  • Less pew pew, More Dakka!
Re: Steam Has Lost Some Steam !
« Reply #7 on: November 12, 2011, 05:31:34 AM »


The fact that the passwords are salted and hashed makes it unlikely they'll even be hacked at all.  It takes a large number of GPUs in tandem to crack a single salted/hashed password in any meaningful amount of time.  The likelyhood that they're going to crack more than a handful before getting bored is extremely low.


I can personally crack a hashed password that is 8 characters long with special characters and numbers in about 5 minutes with a 10GB RAM, 2.8ghz quadcore with no GPU in a classroom environment using OphCrack. Depends on the rainbow table they are using. The good ones cost some serious cash. So its unlikely they'll use them for Steam Accounts, hopefully anyway.

Offline Mitchpate

  • Star Colonel
  • ****
  • Posts: 1268
  • Karma: 39
    • NetBattletech
Re: Steam Has Lost Some Steam !
« Reply #8 on: November 12, 2011, 11:59:32 AM »
The use of salts renders pre-generated rainbow tables useless, hence my comments about how unlikely they are to get cracked.  Salting combines a random string of bits with the passwords to create an entirely different string of characters which is then hashed.  Basically it's like scrambling them and then hashing them.

OPHcrack isn't really an accurate measure as to what would be required to do this as you are likely using a rainbow table and attacking the LM hash.  Try bruteforcing an NTLM hash using a CPU-based utility and you'll quickly see what I'm talking about.  NTLM CPU bruteforcing typically generates <20 million passwords/sec whereas my 5770 generates 1.6 billion passwords/sec.  An 8 character small/digit password takes about 20 minutes to bruteforce.  That's why I use a 21 character small/capital/digit/special windows password, >10000 years ;D

Salted, SHA-1 Oracle and mySQL passwords cut that speed by 2/3 and an 8 character small/digit password takes about an hour to crack on my GPU.  That's assuming you know the salt.  I don't know of any CPU or GPU-based hashing tools that can bruteforce a salted password in a fully automated fashion if the salt isn't known.  Without the salt, the crack program can only attack the "outer" MD5/SHA-1 hash which means no password it generates a hash for will match the overall hash being bruteforced.  Most forums tack on a 5 character small/cap/digit/special random salt on every user which means if you don't know the salt you'll have to generate hashes for the full range of characters at a length of 5 digits longer than the password itself.

TLDR: If the passwords were salted they can't use a rainbow table and it'll take an impractically long time to crack each one individually.
Mitchpate
FedCom of NBT-MP3
NBT Admin Team

Offline [NGNG] Cattra

  • Recruit
  • *
  • Posts: 55
  • Karma: 4
  • No Guts No Galaxy & A.C.E.S
    • World of Frak
Re: Steam Has Lost Some Steam !
« Reply #9 on: November 12, 2011, 09:49:52 PM »
Hackers gonna hack, crackers gonna crack and haters gonna hate.
If anything this will only make steam more secure which is always nice and I doubt that it will lose steam (Do-ho ho ho!) any time soon... I mean what else you going to use, Origin?
No Guts No Galaxy Pod Cast - Mr. Cattra Kell
Intel Core i7 870 2.93GHz, 8GB DDR3, 2x2TB Samsung HDD, ATI Radeon HD 5570

Offline Squibby

  • Star Captain
  • ***
  • Posts: 863
  • Karma: 39
  • Hanger to core breach in 30 seconds...
Re: Steam Has Lost Some Steam !
« Reply #10 on: November 12, 2011, 09:52:30 PM »
Well I suppose the best thing to do would be to keep an eye on your CC statements for the next few months.

But it is nice to hear those hackers will have a hard time cracking our account passwords. Of course none of that really means much to me, I always though salt was something you stuck on food :D.

Offline Wraythe

  • Recruit
  • *
  • Posts: 165
  • Karma: 15
Re: Steam Has Lost Some Steam !
« Reply #11 on: November 12, 2011, 11:23:06 PM »
Well I suppose the best thing to do would be to keep an eye on your CC statements for the next few months.

But it is nice to hear those hackers will have a hard time cracking our account passwords. Of course none of that really means much to me, I always though salt was something you stuck on food :D.

You should be fine providing you didn't use the same password on the forums as you do for steam.

Offline Mitchpate

  • Star Colonel
  • ****
  • Posts: 1268
  • Karma: 39
    • NetBattletech
Re: Steam Has Lost Some Steam !
« Reply #12 on: November 13, 2011, 12:36:44 AM »
If anything this will only make steam more secure
For most companies, something like this is a healthy learning experience.  They now know of vulnerabilities and can fix them.  So long as "best practices" are observed, which it sounds like they were, the potential damage and liability should be minimal.

I mean what else you going to use, Origin?
Which is why I think Steam is going to be unaffected even if the damages are severe.  There simply aren't any real competitors.
Mitchpate
FedCom of NBT-MP3
NBT Admin Team

Offline Stahlseele

  • Living Legend
  • *******
  • Posts: 4114
  • Karma: 43
  • 2nd Level TechSupport Agent(BOFH)
Re: Steam Has Lost Some Steam !
« Reply #13 on: November 13, 2011, 02:37:02 PM »
Don't have an account on the steam forums and i never bought anything over steam.
I am not concerned.
'any kind of discussion of randomness ALWAYS WILL EQUATE to being able to critically hit a mech's reactor by firing a micro beam laser while facing 80 degrees to the side, shooting the ground, which would cause a random explosion which would randomly crit his entire team's reactors which would randomly cause the server itself to explode which would randomly generate a strange quark which would randomly hit the earth and randomly randomness randomfapp the shit fapp random!'
------------------------------
CPU: Intel Core 2 Quad Q9650 @4x3GHz
Memory: GSkill 2x4Gb DDR3 1333Mhz
Video: MSI N580GTX Lightning Xtreme Edition 3072MB
HDD: 2xWD Velociraptor74Gig10k RPM SATA  RAID0; 1x WD Caviar Black 1TB, 1x WD Caviar Green 2TB
Monitor: 2x24" Widescreen 16:9 1920x1080 native resolution
Windows Vista

Offline Bloodycrow

  • Star Captain
  • ***
  • Posts: 762
  • Karma: 59
  • f = c/2 [ (n/L)² + (m/W)² + (p/H)² ] ½ Hz
    • Planetary League Enjin Page
Re: Steam Has Lost Some Steam !
« Reply #14 on: November 13, 2011, 07:30:33 PM »
I have an account on the Steam forums and have bought tons of stuff over Steam.
I am not concerned.