Valve Finally Releases An Apology to Users Regarding Christmas Issues

This topic is locked from further discussion.

Avatar image for lostrib
lostrib

49999

Forum Posts

0

Wiki Points

0

Followers

Reviews: 1

User Lists: 0

#1  Edited By lostrib
Member since 2009 • 49999 Posts

Today Valve has released a statement on steam regarding the cache issue that occurred on Christmas revealing personal user info at random

The full statement is below with some emphasis on important aspects

We'd like to follow up with more information regarding Steam's troubled Christmas.

What happened

On December 25th, a configuration error resulted in some users seeing Steam Store pages generated for other users. Between 11:50 PST and 13:20 PST store page requests for about 34k users, which contained sensitive personal information, may have been returned and seen by other users.

The content of these requests varied by page, but some pages included a Steam user’s billing address, the last four digits of their Steam Guard phone number, their purchase history, the last two digits of their credit card number, and/or their email address. These cached requests did not include full credit card numbers, user passwords, or enough data to allow logging in as or completing a transaction as another user.

If you did not browse a Steam Store page with your personal information (such as your account page or a checkout page) in this time frame, that information could not have been shown to another user.

Valve is currently working with our web caching partner to identify users whose information was served to other users, and will be contacting those affected once they have been identified. As no unauthorized actions were allowed on accounts beyond the viewing of cached page information, no additional action is required by users.

How it happened

Early Christmas morning (Pacific Standard Time), the Steam Store was the target of a DoS attack which prevented the serving of store pages to users. Attacks against the Steam Store, and Steam in general, are a regular occurrence that Valve handles both directly and with the help of partner companies, and typically do not impact Steam users. During the Christmas attack, traffic to the Steam store increased 2000% over the average traffic during the Steam Sale.

In response to this specific attack, caching rules managed by a Steam web caching partner were deployed in order to both minimize the impact on Steam Store servers and continue to route legitimate user traffic. During the second wave of this attack, a second caching configuration was deployed that incorrectly cached web traffic for authenticated users. This configuration error resulted in some users seeing Steam Store responses which were generated for other users. Incorrect Store responses varied from users seeing the front page of the Store displayed in the wrong language, to seeing the account page of another user.

Once this error was identified, the Steam Store was shut down and a new caching configuration was deployed. The Steam Store remained down until we had reviewed all caching configurations, and we received confirmation that the latest configurations had been deployed to all partner servers and that all cached data on edge servers had been purged.

We will continue to work with our web caching partner to identify affected users and to improve the process used to set caching rules going forward. We apologize to everyone whose personal information was exposed by this error, and for interruption of Steam Store service.

Source

TL;DR--Steam says 34K users affected, but no unauthorized actions. Cache glitch was a result of an attack on the Steam Store. Valve apologized.

Avatar image for hrt_rulz01
hrt_rulz01

22688

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

#2 hrt_rulz01
Member since 2006 • 22688 Posts

Hmmmm... well that's that then. Apparently.

Avatar image for speedfreak48t5p
speedfreak48t5p

14491

Forum Posts

0

Wiki Points

0

Followers

Reviews: 62

User Lists: 0

#3 speedfreak48t5p
Member since 2009 • 14491 Posts

Okay, moving on.

Avatar image for lamprey263
lamprey263

45472

Forum Posts

0

Wiki Points

0

Followers

Reviews: 10

User Lists: 0

#4  Edited By lamprey263
Member since 2006 • 45472 Posts

XBL and PSN survived against Whatever Squad's holiday attack. Maybe Valve will be next to tighten security to avoid a repeat.

Avatar image for NathanDrakeSwag
NathanDrakeSwag

17392

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

#5 NathanDrakeSwag
Member since 2013 • 17392 Posts

@lamprey263 said:

XBL and PSN survived against Whatever Squad's holiday attack. Maybe Valve will be next to tighten security to avoid a repeat.

XBL isn't popular enough anymore to be targeted.

Avatar image for Heil68
Heil68

60831

Forum Posts

0

Wiki Points

0

Followers

Reviews: 1

User Lists: 0

#6 Heil68
Member since 2004 • 60831 Posts

I demand free games as an apology.

Luckily both Live and PSN were up for me and held steady against these attacks. Wish Valve/Steam would of been as ready. Guess not.

Avatar image for lostrib
lostrib

49999

Forum Posts

0

Wiki Points

0

Followers

Reviews: 1

User Lists: 0

#7 lostrib
Member since 2009 • 49999 Posts

@NathanDrakeSwag: trololololol

Avatar image for lostrib
lostrib

49999

Forum Posts

0

Wiki Points

0

Followers

Reviews: 1

User Lists: 0

#8 lostrib
Member since 2009 • 49999 Posts

@Heil68: both xbl and PSN did have issues on Christmas

Avatar image for FireEmblem_Man
FireEmblem_Man

20388

Forum Posts

0

Wiki Points

0

Followers

Reviews: 7

User Lists: 0

#9 FireEmblem_Man
Member since 2004 • 20388 Posts

Took them long enough! They still suck!

Avatar image for Heil68
Heil68

60831

Forum Posts

0

Wiki Points

0

Followers

Reviews: 1

User Lists: 0

#10 Heil68
Member since 2004 • 60831 Posts

@lostrib said:

@Heil68: both xbl and PSN did have issues on Christmas

Not to me, so i was effected only for PC as I couldn't access my games, account and was taken offline. I want compensation.

you made a thread about Steam issue and yet you try to bring console online services in. If those were indeed effected, does that make this right and we shouldn't give a ****?

OK.

Instead, Valve tries to brush it under the rug in hope nobody would care and continue using their service, only in hopes one day they have the monopoly on DD solution and give gamers, devs and publishers, other than themselves of course a giant middle finger.

Well **** Valve too.

Avatar image for walloftruth
WallofTruth

3471

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 5

#11 WallofTruth
Member since 2013 • 3471 Posts

@Heil68 said:
@lostrib said:

@Heil68: both xbl and PSN did have issues on Christmas

Not to me, so i was effected only for PC as I couldn't access my games, account and was taken offline. I want compensation.

you made a thread about Steam issue and yet you try to bring console online services in. If those were indeed effected, does that make this right and we shouldn't give a ****?

OK.

Instead, Valve tries to brush it under the rug in hope nobody would care and continue using their service, only in hopes one day they have the monopoly on DD solution and give gamers, devs and publishers, other than themselves of course a giant middle finger.

Well **** Valve too.

Not sure why you couldn't play your games when Valve took the store page down.

Avatar image for Heil68
Heil68

60831

Forum Posts

0

Wiki Points

0

Followers

Reviews: 1

User Lists: 0

#12 Heil68
Member since 2004 • 60831 Posts

@walloftruth said:
@Heil68 said:
@lostrib said:

@Heil68: both xbl and PSN did have issues on Christmas

Not to me, so i was effected only for PC as I couldn't access my games, account and was taken offline. I want compensation.

you made a thread about Steam issue and yet you try to bring console online services in. If those were indeed effected, does that make this right and we shouldn't give a ****?

OK.

Instead, Valve tries to brush it under the rug in hope nobody would care and continue using their service, only in hopes one day they have the monopoly on DD solution and give gamers, devs and publishers, other than themselves of course a giant middle finger.

Well **** Valve too.

Not sure why you couldn't play your games when Valve took the store page down.

They took entire service down to address issue.

Avatar image for CountBleck12
CountBleck12

4726

Forum Posts

0

Wiki Points

0

Followers

Reviews: 9

User Lists: 0

#13 CountBleck12
Member since 2012 • 4726 Posts
@lostrib said:

Valve apologized.

Couldn't resist.

Avatar image for mr_huggles_dog
Mr_Huggles_dog

7805

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 5

#14 Mr_Huggles_dog
Member since 2014 • 7805 Posts

Not that it's a big deal to me....but if this was PSN or LIVE ppl would be crucifying the services.

But b/c it's PC/Valve.....this board goes "Oh....ok".

Avatar image for Heil68
Heil68

60831

Forum Posts

0

Wiki Points

0

Followers

Reviews: 1

User Lists: 0

#15 Heil68
Member since 2004 • 60831 Posts

@mr_huggles_dog said:

Not that it's a big deal to me....but if this was PSN or LIVE ppl would be crucifying the services.

But b/c it's PC/Valve.....this board goes "Oh....ok".

Yup, its ok if its PC but holy shit if it happens to consoles. Buncha fucking hypocrites. Least we have this issue to throw into any mix about online issues,

Avatar image for lostrib
lostrib

49999

Forum Posts

0

Wiki Points

0

Followers

Reviews: 1

User Lists: 0

#16 lostrib
Member since 2009 • 49999 Posts

@Heil68: you brought up xbl and PSN in relation to this

Avatar image for lostrib
lostrib

49999

Forum Posts

0

Wiki Points

0

Followers

Reviews: 1

User Lists: 0

#17 lostrib
Member since 2009 • 49999 Posts

@Heil68: @mr_huggles_dog: actually when it happened there were a lot of people calling out valve for fucking up

Avatar image for Heil68
Heil68

60831

Forum Posts

0

Wiki Points

0

Followers

Reviews: 1

User Lists: 0

#18 Heil68
Member since 2004 • 60831 Posts

@lostrib said:

@Heil68: @mr_huggles_dog: actually when it happened there were a lot of people calling out valve for fucking up

So we get free PC games then?!?!?

Avatar image for lostrib
lostrib

49999

Forum Posts

0

Wiki Points

0

Followers

Reviews: 1

User Lists: 0

#19 lostrib
Member since 2009 • 49999 Posts

@Heil68: yes there are a number of free games on steam

Avatar image for jereb31
Jereb31

2025

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

#20 Jereb31
Member since 2015 • 2025 Posts

@Heil68:

"Affected"

This thing affected this other thing.

This thing had an effect.

:)

Avatar image for jereb31
Jereb31

2025

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

#21 Jereb31
Member since 2015 • 2025 Posts

@Heil68:

Wasnt down for like a couple of hours? Wow, what an inconvenience.

Avatar image for jereb31
Jereb31

2025

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

#22 Jereb31
Member since 2015 • 2025 Posts

@Heil68:

I think its not a big deal because only 35k people had some random near useless information released. And it went was only down for what, 3 hours?

As opposed to psn 70 million peopel leak.

Avatar image for Heil68
Heil68

60831

Forum Posts

0

Wiki Points

0

Followers

Reviews: 1

User Lists: 0

#23 Heil68
Member since 2004 • 60831 Posts

@jereb31 said:

@Heil68:

I think its not a big deal because only 35k people had some random near useless information released. And it went was only down for what, 3 hours?

As opposed to psn 70 million peopel leak.

So PC just forget about it?

Avatar image for Heil68
Heil68

60831

Forum Posts

0

Wiki Points

0

Followers

Reviews: 1

User Lists: 0

#24  Edited By Heil68
Member since 2004 • 60831 Posts

@jereb31 said:

@Heil68:

"Affected"

This thing affected this other thing.

This thing had an effect.

:)

The whole point of people writing anything, whether it be on the forums, an essay for school or a blog post is to convey a message or a point to their intended audience.

If you don't pay attention to your grammar, you make the message a lot harder to read. I think everyone judges based on grammar - perhaps not judging the person behind it, but the value of the post and how well articulated it is. A well thought out post is much more likely to attract attention and discussion compared to one which is written poorly. I also see it as common courtesy - if you expect someone to read your post, and respond to it in a thoughtful manner, then you should be putting in some effort into making said post as easy to read and understand as possible.

I understand there's people who might not be as familiar with the English language as others so I understand it's not reasonable to expect perfect grammar, but I like to see people at least give it some effort / attention.

If someone is evidently being lazy with their grammar, writing shorthand and/or not properly articulating themselves, I'll pretty much disregard what they have to say.

And no, my grammar isn't perfect either, but I do pay attention to it, and think about what I want to say before I type it out. Sometimes I make mistakes, but I never said I was perfect. Guess you are and are a practicing English professor at a higher education institution.

Avatar image for hrt_rulz01
hrt_rulz01

22688

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

#25  Edited By hrt_rulz01
Member since 2006 • 22688 Posts

@mr_huggles_dog: Lol yeah funny that, hey.

Avatar image for KHAndAnime
KHAndAnime

17565

Forum Posts

0

Wiki Points

0

Followers

Reviews: 1

User Lists: 0

#26 KHAndAnime
Member since 2009 • 17565 Posts

Yet people's XBL accounts continue to get mysteriously hacked every day

Avatar image for jereb31
Jereb31

2025

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

#27  Edited By Jereb31
Member since 2015 • 2025 Posts

@Heil68:

No, forget about it because this is a tiny leak. Or go nuts do what you have to do man.

Avatar image for jereb31
Jereb31

2025

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

#28 Jereb31
Member since 2015 • 2025 Posts

@Heil68:

Haha Chillllll Winston. I'm just being a nuisance.

Avatar image for howmakewood
Howmakewood

7838

Forum Posts

0

Wiki Points

0

Followers

Reviews: 1

User Lists: 0

#29 Howmakewood
Member since 2015 • 7838 Posts

@Heil68 said:
@jereb31 said:

@Heil68:

I think its not a big deal because only 35k people had some random near useless information released. And it went was only down for what, 3 hours?

As opposed to psn 70 million peopel leak.

So PC just forget about it?

Highly doubt this is going to be forgotten. But there were people here spouting how sony's credit card txt fiasco was nowhere as big as this.

Avatar image for darklight4
darklight4

2094

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

#30  Edited By darklight4
Member since 2009 • 2094 Posts

Valve's communication with customers should have been better to alleviate peoples fears and explain the situation. They could face a lawsuit here in UK under the data protection act if someone takes them to court. It would be for negligence to protect people info as this was of their own doing and not a third party.

Avatar image for jereb31
Jereb31

2025

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

#31 Jereb31
Member since 2015 • 2025 Posts

@darklight4:

Errr it was a third party. Read the article.

Avatar image for blueeyedcasva
BlueEyedCasva

599

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

#32 BlueEyedCasva
Member since 2015 • 599 Posts

@mr_huggles_dog: Considering it was a small leak of information that was useless compared to 70 million who may have had their information compromised on PSN.

Avatar image for GarGx1
GarGx1

10934

Forum Posts

0

Wiki Points

0

Followers

Reviews: 4

User Lists: 0

#33 GarGx1
Member since 2011 • 10934 Posts

@KHAndAnime said:

Yet people's XBL accounts continue to get mysteriously hacked every day

Big difference between hacking and muppets falling for Phishing scams