Re: [hlds_linux] Valve Security Breach

2011-11-11 Thread m33crob
dedicated Linux server mailing list Subject: Re: [hlds_linux] Valve Security Breach Never has a more irrational or reactionary mail been posted to this list. On Thu, Nov 10, 2011 at 7:52 PM, Danneeda...@ntlworld.com wrote: On 10/11/2011 23:55, DontWannaName! wrote: If you haven't noticed, most

Re: [hlds_linux] Valve Security Breach

2011-11-11 Thread gameadmin
, 11 November 2011 8:59 AM To: Half-Life dedicated Linux server mailing list Subject: Re: [hlds_linux] Valve Security Breach Never has a more irrational or reactionary mail been posted to this list. On Thu, Nov 10, 2011 at 7:52 PM, Danneeda...@ntlworld.com wrote: On 10/11/2011 23:55

Re: [hlds_linux] Valve Security Breach

2011-11-11 Thread Saint K .
: [hlds_linux] Valve Security Breach Hey VALVe, Why isn't there an option of resetting ones' password outside of the Steam client itself? On Thu, Nov 10, 2011 at 7:50 PM, ics i...@ics-base.net wrote: If you do a lot of Steam purchases, it's a conviniency issue. Few clicks and you are done. After

Re: [hlds_linux] Valve Security Breach

2011-11-11 Thread Michael Johansen
To: hlds_linux@list.valvesoftware.com Subject: Re: [hlds_linux] Valve Security Breach If you do a lot of Steam purchases, it's a conviniency issue. Few clicks and you are done. After entering the stuff 360 times you really rethink twice but being security paranoid, you don't fill anything

Re: [hlds_linux] Valve Security Breach

2011-11-11 Thread dmex
@list.valvesoftware.com Subject: Re: [hlds_linux] Valve Security Breach The Norwegian newspaper VG announced that VALVE had been compromised and that they gained access to the master-Steam database, where everything is stored.http://www.vg.no/spill/artikkel.php?artid=10015971 Anyone clear this up? Date: Fri

Re: [hlds_linux] Valve Security Breach

2011-11-11 Thread Eric Riemers
...@list.valvesoftware.com [mailto:hlds_linux-boun...@list.valvesoftware.com] On Behalf Of Michael Johansen Sent: Friday, 11 November 2011 11:10 PM To: hlds_linux@list.valvesoftware.com Subject: Re: [hlds_linux] Valve Security Breach The Norwegian newspaper VG announced that VALVE had been

Re: [hlds_linux] Valve Security Breach

2011-11-11 Thread Bacon Cat
Subject: Re: [hlds_linux] Valve Security Breach The Norwegian newspaper VG announced that VALVE had been compromised and that they gained access to the master-Steam database, where everything is stored.http://www.vg.no/spill/artikkel.php?artid=10015971 Anyone clear this up? Date

Re: [hlds_linux] Valve Security Breach

2011-11-10 Thread gameadmin
2011 20:28 To: Half-Life dedicated Linux server mailing list Subject: Re: [hlds_linux] Valve Security Breach Without rancor or anger, I tell you this is very unhelpful, regardless of what your position is on the SPUF closure. On Wed, Nov 9, 2011 at 12:23 PM, Dan needa...@ntlworld.com wrote

Re: [hlds_linux] Valve Security Breach

2011-11-10 Thread Nicolas NykO18 Grevet
...@list.valvesoftware.com [mailto:hlds_linux- boun...@list.valvesoftware.com] On Behalf Of Jesse Porter Sent: 09 November 2011 20:28 To: Half-Life dedicated Linux server mailing list Subject: Re: [hlds_linux] Valve Security Breach Without rancor or anger, I tell you this is very

Re: [hlds_linux] Valve Security Breach

2011-11-10 Thread px
: Re: [hlds_linux] Valve Security Breach Without rancor or anger, I tell you this is very unhelpful, regardless of what your position is on the SPUF closure. On Wed, Nov 9, 2011 at 12:23 PM, Dan needa...@ntlworld.com wrote: On 09/11/2011 19:18, Mart-Jan Reeuwijk wrote: Well

Re: [hlds_linux] Valve Security Breach

2011-11-10 Thread DontWannaName!
list Subject: Re: [hlds_linux] Valve Security Breach Without rancor or anger, I tell you this is very unhelpful, regardless of what your position is on the SPUF closure. On Wed, Nov 9, 2011 at 12:23 PM, Dan needa...@ntlworld.com wrote: On 09/11/2011 19:18, Mart-Jan Reeuwijk wrote

Re: [hlds_linux] Valve Security Breach

2011-11-10 Thread Marcus Posey
Sent: 09 November 2011 20:28 To: Half-Life dedicated Linux server mailing list Subject: Re: [hlds_linux] Valve Security Breach Without rancor or anger, I tell you this is very unhelpful, regardless of what your position is on the SPUF closure. On Wed, Nov 9, 2011 at 12:23 PM

Re: [hlds_linux] Valve Security Breach

2011-11-10 Thread Nathan Radcliffe
[mailto:hlds_linux- boun...@list.valvesoftware.com] On Behalf Of Jesse Porter Sent: 09 November 2011 20:28 To: Half-Life dedicated Linux server mailing list Subject: Re: [hlds_linux] Valve Security Breach Without rancor or anger, I tell you this is very unhelpful, regardless of what your

Re: [hlds_linux] Valve Security Breach

2011-11-10 Thread DontWannaName!
- From: hlds_linux-boun...@list.valvesoftware.com [mailto:hlds_linux- boun...@list.valvesoftware.com] On Behalf Of Jesse Porter Sent: 09 November 2011 20:28 To: Half-Life dedicated Linux server mailing list Subject: Re: [hlds_linux] Valve Security Breach Without rancor or anger, I tell you

Re: [hlds_linux] Valve Security Breach

2011-11-10 Thread dmex
server mailing list' Subject: Re: [hlds_linux] Valve Security Breach Confirmation that the attack breached more than their forums: http://www.rockpapershotgun.com/2011/11/10/steam-hacked/ -Original Message- From: hlds_linux-boun...@list.valvesoftware.com [mailto:hlds_linux- boun

Re: [hlds_linux] Valve Security Breach

2011-11-10 Thread Bruno Garcia
...@list.valvesoftware.com [mailto:hlds_linux-boun...@list.valvesoftware.com] On Behalf Of gamead...@127001.org Sent: Friday, 11 November 2011 7:01 AM To: 'Half-Life dedicated Linux server mailing list' Subject: Re: [hlds_linux] Valve Security Breach Confirmation that the attack breached more

Re: [hlds_linux] Valve Security Breach

2011-11-10 Thread Marcus Posey
list' Subject: Re: [hlds_linux] Valve Security Breach Confirmation that the attack breached more than their forums: http://www.rockpapershotgun.com/2011/11/10/steam-hacked/ -Original Message- From: hlds_linux-boun...@list.valvesoftware.com [mailto:hlds_linux- boun

Re: [hlds_linux] Valve Security Breach

2011-11-10 Thread Dan
On 10/11/2011 23:55, DontWannaName! wrote: If you haven't noticed, most credit card companies have very good fraud prevention now. What's the worst they can do? I mean it's bad, but really not the end of the world. You guys are just causing unneeded drama about an issue that they are handling

Re: [hlds_linux] Valve Security Breach

2011-11-10 Thread msleeper
Never has a more irrational or reactionary mail been posted to this list. On Thu, Nov 10, 2011 at 7:52 PM, Dan needa...@ntlworld.com wrote: On 10/11/2011 23:55, DontWannaName! wrote: If you haven't noticed, most credit card companies have very good fraud prevention now. What's the worst they

Re: [hlds_linux] Valve Security Breach

2011-11-10 Thread dmex
...@list.valvesoftware.com] On Behalf Of msleeper Sent: Friday, 11 November 2011 8:59 AM To: Half-Life dedicated Linux server mailing list Subject: Re: [hlds_linux] Valve Security Breach Never has a more irrational or reactionary mail been posted to this list. On Thu, Nov 10, 2011 at 7:52 PM, Dan

Re: [hlds_linux] Valve Security Breach

2011-11-10 Thread Dan
On 11/11/2011 00:59, msleeper wrote: Never has a more irrational or reactionary mail been posted to this list. Well if there's a prize, I hope your posts pretending it's only the forum that has been hacked should win. -- Dan. ___ To unsubscribe,

Re: [hlds_linux] Valve Security Breach

2011-11-10 Thread Marcus Posey
number. -Original Message- From: hlds_linux-boun...@list.valvesoftware.com [mailto:hlds_linux-boun...@list.valvesoftware.com] On Behalf Of msleeper Sent: Friday, 11 November 2011 8:59 AM To: Half-Life dedicated Linux server mailing list Subject: Re: [hlds_linux] Valve Security Breach

Re: [hlds_linux] Valve Security Breach

2011-11-10 Thread Dan
On 11/11/2011 01:26, dmex wrote: I am a bit annoyed Gabe didn't mention all the unencrypted personal information stored on the same Steam database the hackers now have, It's more than enough to pull off really good social engineering/phishing attacks and maybe even some ID theft. At minimum

Re: [hlds_linux] Valve Security Breach

2011-11-10 Thread msleeper
Also from the same message: We do not have evidence that encrypted credit card numbers or personally identifying information were taken by the intruders So, not sure why you're assuming they have all of that information. I'm assuming personally identifying information means personally

Re: [hlds_linux] Valve Security Breach

2011-11-10 Thread dmex
Sent: Friday, 11 November 2011 9:31 AM To: Half-Life dedicated Linux server mailing list Subject: Re: [hlds_linux] Valve Security Breach How do you know it's unencrypted? On Thu, Nov 10, 2011 at 7:26 PM, dmex dme...@gmail.com wrote: Don't worry, He'll be fine after his nappy gets changed

Re: [hlds_linux] Valve Security Breach

2011-11-10 Thread Dan
On 11/11/2011 01:39, msleeper wrote: Also from the same message: We do not have evidence that encrypted credit card numbers or personally identifying information were taken by the intruders So, not sure why you're assuming they have all of that information. I'm assuming personally

Re: [hlds_linux] Valve Security Breach

2011-11-10 Thread Chris Brunelle
] Valve Security Breach Never has a more irrational or reactionary mail been posted to this list. On Thu, Nov 10, 2011 at 7:52 PM, Dan needa...@ntlworld.com wrote: On 10/11/2011 23:55, DontWannaName! wrote: If you haven't noticed, most credit card companies have very good fraud prevention now

Re: [hlds_linux] Valve Security Breach

2011-11-10 Thread ics
:59 AM To: Half-Life dedicated Linux server mailing list Subject: Re: [hlds_linux] Valve Security Breach Never has a more irrational or reactionary mail been posted to this list. On Thu, Nov 10, 2011 at 7:52 PM, Danneeda...@ntlworld.com wrote: On 10/11/2011 23:55, DontWannaName! wrote: If you

Re: [hlds_linux] Valve Security Breach

2011-11-09 Thread Dan
On 09/11/2011 02:42, Nathan Radcliffe wrote: If email address have been exposed and passwords have been exposed, then all account details for anyone with no password management system have been exposed. I don't run a service for computer security professionals - I run a service for gamers.

Re: [hlds_linux] Valve Security Breach

2011-11-09 Thread Mart-Jan Reeuwijk
needa...@ntlworld.com To: Half-Life dedicated Linux server mailing list hlds_linux@list.valvesoftware.com Sent: Wednesday, 9 November 2011, 19:49 Subject: Re: [hlds_linux] Valve Security Breach On 09/11/2011 02:42, Nathan Radcliffe wrote: If email address have been exposed and passwords have been

Re: [hlds_linux] Valve Security Breach

2011-11-09 Thread Dan
On 09/11/2011 19:18, Mart-Jan Reeuwijk wrote: Well, some of his community gamers may well be also users on SPUF Some of his users may have bought batches of tinned spam from Crayed mentos starting #219-245. If they eat it, there's a chance it was contaminated with e-coli virus and they might

Re: [hlds_linux] Valve Security Breach

2011-11-09 Thread Jesse Porter
Without rancor or anger, I tell you this is very unhelpful, regardless of what your position is on the SPUF closure. On Wed, Nov 9, 2011 at 12:23 PM, Dan needa...@ntlworld.com wrote: On 09/11/2011 19:18, Mart-Jan Reeuwijk wrote: Well, some of his community gamers may well be also users on

Re: [hlds_linux] Valve Security Breach

2011-11-08 Thread Emil Larsson
...@list.valvesoftware.com [mailto:hlds_linux-boun...@list.valvesoftware.com] On Behalf Of m33crob Sent: Monday, November 07, 2011 22:08 To: Half-Life dedicated Linux server mailing list; Half-Life dedicated Win32 server mailing list Subject: [hlds_linux] Valve Security Breach Hello

Re: [hlds_linux] Valve Security Breach

2011-11-08 Thread dmex
[mailto:hlds_linux-boun...@list.valvesoftware.com] On Behalf Of Emil Larsson Sent: Tuesday, 8 November 2011 4:07 PM To: Half-Life dedicated Linux server mailing list Subject: Re: [hlds_linux] Valve Security Breach Indeed, as far I heard the forums are on a wholly separate server, the forums

Re: [hlds_linux] Valve Security Breach

2011-11-08 Thread James Botting
[mailto:hlds_linux-boun...@list.valvesoftware.com] On Behalf Of Emil Larsson Sent: Tuesday, 8 November 2011 4:07 PM To: Half-Life dedicated Linux server mailing list Subject: Re: [hlds_linux] Valve Security Breach Indeed, as far I heard the forums are on a wholly separate server, the forums

Re: [hlds_linux] Valve Security Breach

2011-11-08 Thread Russell Smith
[mailto:hlds_linux-boun...@list.valvesoftware.com] On Behalf Of m33crob Sent: Monday, November 07, 2011 22:08 To: Half-Life dedicated Linux server mailing list; Half-Life dedicated Win32 server mailing list Subject: [hlds_linux] Valve Security Breach Hello Valve, I'd like to request notification via

Re: [hlds_linux] Valve Security Breach

2011-11-08 Thread DontWannaName!
Subject: [hlds_linux] Valve Security Breach Hello Valve, I'd like to request notification via these mailing lists once/if Valve makes a statement about todays security breach and subsequent downtime. http://www.pcgamer.com/2011/11/07/steam-forums-down-after-possible-hacker-at tack

Re: [hlds_linux] Valve Security Breach

2011-11-08 Thread Mart-Jan Reeuwijk
@list.valvesoftware.com Sent: Tuesday, 8 November 2011, 16:18 Subject: Re: [hlds_linux] Valve Security Breach Lol please stop making terrible excuses to connect any Steam issue with the forum issue. They are completely unrelated. You need to contact support. Everyone else just needs to be patient

Re: [hlds_linux] Valve Security Breach

2011-11-08 Thread msleeper
This is not relevant to server administration. On Tue, Nov 8, 2011 at 1:07 AM, m33crob ad...@m33crob.com wrote: Hello Valve,  I'd like to request notification via these mailing lists once/if Valve makes a statement about todays security breach and subsequent downtime.

Re: [hlds_linux] Valve Security Breach

2011-11-08 Thread Flubber
Server being linked to Steam Account, i'd say it's linked somehow. 2011/11/8 msleeper mslee...@ismsleeperwrong.com This is not relevant to server administration. On Tue, Nov 8, 2011 at 1:07 AM, m33crob ad...@m33crob.com wrote: Hello Valve, I'd like to request notification via these

Re: [hlds_linux] Valve Security Breach

2011-11-08 Thread msleeper
Assuming that your SPUF login and password is the same as your Steam login and password, 1.) that's not Valve's fault that you are literally the worst at the password game, but 2.) it's only a problem if you are in the 0.001% of people who don't use Steam Guard. On Tue, Nov 8, 2011 at 3:41 PM,

Re: [hlds_linux] Valve Security Breach

2011-11-08 Thread coffee problem
Unfortunately, they are probably going to just let it stay hacked. Since they have said they aren't going to chase the fake clients issue due to more bugs being introduced by patching against it, why bother with the forums? Fix one hole, someone finds another. Oh well, it was a good community

Re: [hlds_linux] Valve Security Breach

2011-11-08 Thread DontWannaName!
Looks like its disabled now... http://sourceop.com/modules.php?name=Forumsfile=viewtopict=90261postdays=0postorder=ascstart=75 On Tue, Nov 8, 2011 at 3:58 PM, coffee problem spoofedpac...@gmail.comwrote: Unfortunately, they are probably going to just let it stay hacked. Since they have said

Re: [hlds_linux] Valve Security Breach

2011-11-08 Thread Nathan Radcliffe
Correct, but where else should it be posted? On the forums maybe? It's been nearly two days, and still no official press release. A few people have reported receiving spam emails and I've seen unconfirmed reports of password databases being leaked. I don't have much doubt that most people on

Re: [hlds_linux] Valve Security Breach

2011-11-08 Thread DontWannaName!
I think you are thinking the worst. All someone needs to post what they did is access to the VB admin CP which just requires an admin. My guess is it isnt as bad as people are making it out to be and right now everyone is speculating the worst. Just chill On Tue, Nov 8, 2011 at 4:51 PM,

Re: [hlds_linux] Valve Security Breach

2011-11-08 Thread bottige...@gmail.com
This is related to server administration. Some people use Steam groups to make administrators. Many people are also running TF2 websites that use Steam openid, and if that is compromised, then impersonation can occur which results in scams. On Tue, Nov 8, 2011 at 12:05 PM, msleeper

Re: [hlds_linux] Valve Security Breach

2011-11-08 Thread Nathan Radcliffe
Thinking the worst is the best thing to do in this situation. Until Valve release some indication of what account details (if any) have been compromised it's easiest to assume all details have been, and advise all users to look over their account security. Steamguard works great if you have

Re: [hlds_linux] Valve Security Breach

2011-11-08 Thread msleeper
Yes, panicking and being reactionary is always the best course of action. On Tue, Nov 8, 2011 at 8:38 PM, Nathan Radcliffe kugr...@gmail.com wrote: Thinking the worst is the best thing to do in this situation.  Until Valve release some indication of what account details (if any) have been

Re: [hlds_linux] Valve Security Breach

2011-11-08 Thread Necavi
: hlds_linux-boun...@list.valvesoftware.com [mailto:hlds_linux-boun...@list.valvesoftware.com] On Behalf Of msleeper Sent: Tuesday, November 08, 2011 17:45 To: Half-Life dedicated Linux server mailing list Subject: Re: [hlds_linux] Valve Security Breach Yes, panicking and being reactionary is always the best

Re: [hlds_linux] Valve Security Breach

2011-11-08 Thread Jesse Porter
] On Behalf Of msleeper Sent: Tuesday, November 08, 2011 17:45 To: Half-Life dedicated Linux server mailing list Subject: Re: [hlds_linux] Valve Security Breach Yes, panicking and being reactionary is always the best course of action. On Tue, Nov 8, 2011 at 8:38 PM, Nathan Radcliffe kugr...@gmail.com

Re: [hlds_linux] Valve Security Breach

2011-11-08 Thread Nathan Radcliffe
Feel free to suggest a better option. Should I ignore the still as yet unknown (and unconfirmed by the company) security breach that has rendered a major section of it's website offline for near on two days, or warn the several hundred of my users that they should look over their account and

Re: [hlds_linux] Valve Security Breach

2011-11-08 Thread msleeper
As I said: Assuming that your SPUF login and password is the same as your Steam login and password, 1.) that's not Valve's fault that you are literally the worst at the password game, but 2.) it's only a problem if you are in the 0.001% of people who don't use Steam Guard. So unless your

Re: [hlds_linux] Valve Security Breach

2011-11-08 Thread coffee problem
I wonder why the Valve TF2 servers themselves have been offline since yesterday. On Tue, Nov 8, 2011 at 9:09 PM, msleeper mslee...@ismsleeperwrong.comwrote: As I said: Assuming that your SPUF login and password is the same as your Steam login and password, 1.) that's not Valve's fault that

Re: [hlds_linux] Valve Security Breach

2011-11-08 Thread 1nsane
Wow, clearly it's a conspiracy. Valve must be completely compromised. Except I see hundreds (thousands?) of Valve TF2 servers in my server browser. They are not down. On Tue, Nov 8, 2011 at 9:12 PM, coffee problem spoofedpac...@gmail.comwrote: I wonder why the Valve TF2 servers themselves

Re: [hlds_linux] Valve Security Breach

2011-11-08 Thread msleeper
Oh no, 1nsane, you left your Jump To Conclusions mat at home! On Tue, Nov 8, 2011 at 9:39 PM, 1nsane 1nsane...@gmail.com wrote: Wow, clearly it's a conspiracy. Valve must be completely compromised. Except I see hundreds (thousands?) of Valve TF2 servers in my server browser. They are not

Re: [hlds_linux] Valve Security Breach

2011-11-08 Thread Nathan Radcliffe
And as I said: Steamguard works great if you have different passwords for your steam account and steam forums and email, but I still know a lot of users both in gaming areas and real life areas that use the same password for everything (despite how much I discourage it). If email

Re: [hlds_linux] Valve Security Breach

2011-11-08 Thread msleeper
If you have the same password for your Steam forum account, for your Steam login, and for the email address that Steam is tied to (and by proxy, the same email address on file on SPUF) then - and I'm just gonna say it - you probably deserve to have something bad like this happen so you wisen up to

Re: [hlds_linux] Valve Security Breach

2011-11-08 Thread gameadmin
. -Original Message- From: hlds_linux-boun...@list.valvesoftware.com [mailto:hlds_linux- boun...@list.valvesoftware.com] On Behalf Of msleeper Sent: 09 November 2011 03:40 To: Half-Life dedicated Linux server mailing list Subject: Re: [hlds_linux] Valve Security Breach If you have the same

Re: [hlds_linux] Valve Security Breach

2011-11-08 Thread Nomaan Ahmad
dedicated Linux server mailing list Subject: Re: [hlds_linux] Valve Security Breach If you have the same password for your Steam forum account, for your Steam login, and for the email address that Steam is tied to (and by proxy, the same email address on file on SPUF) then - and I'm just

Re: [hlds_linux] Valve Security Breach

2011-11-08 Thread msleeper
2011 03:40 To: Half-Life dedicated Linux server mailing list Subject: Re: [hlds_linux] Valve Security Breach If you have the same password for your Steam forum account, for your Steam login, and for the email address that Steam is tied to (and by proxy, the same email address on file on SPUF

Re: [hlds_linux] Valve Security Breach

2011-11-08 Thread gameadmin
-boun...@list.valvesoftware.com [mailto:hlds_linux- boun...@list.valvesoftware.com] On Behalf Of Nomaan Ahmad Sent: 09 November 2011 04:11 To: Half-Life dedicated Linux server mailing list Subject: Re: [hlds_linux] Valve Security Breach Since when is vBulletin part of Steam systems? On 9

[hlds_linux] Valve Security Breach

2011-11-07 Thread m33crob
Hello Valve, I'd like to request notification via these mailing lists once/if Valve makes a statement about todays security breach and subsequent downtime. http://www.pcgamer.com/2011/11/07/steam-forums-down-after-possible-hacker-attack/ ___ To

Re: [hlds_linux] Valve Security Breach

2011-11-07 Thread Necavi
; Half-Life dedicated Win32 server mailing list Subject: [hlds_linux] Valve Security Breach Hello Valve, I'd like to request notification via these mailing lists once/if Valve makes a statement about todays security breach and subsequent downtime. http://www.pcgamer.com/2011/11/07/steam-forums

Re: [hlds_linux] Valve Security Breach

2011-11-07 Thread Richard GrosJean
[mailto:hlds_linux-boun...@list.valvesoftware.com] On Behalf Of m33crob Sent: Monday, November 07, 2011 22:08 To: Half-Life dedicated Linux server mailing list; Half-Life dedicated Win32 server mailing list Subject: [hlds_linux] Valve Security Breach Hello Valve,  I'd like to request notification via

Re: [hlds_linux] Valve Security Breach

2011-11-07 Thread ics
...@list.valvesoftware.com [mailto:hlds_linux-boun...@list.valvesoftware.com] On Behalf Of m33crob Sent: Monday, November 07, 2011 22:08 To: Half-Life dedicated Linux server mailing list; Half-Life dedicated Win32 server mailing list Subject: [hlds_linux] Valve Security Breach Hello Valve, I'd like to request

Re: [hlds_linux] Valve Security Breach

2011-11-07 Thread Necavi
, November 07, 2011 22:17 To: Half-Life dedicated Linux server mailing list Subject: Re: [hlds_linux] Valve Security Breach The site that the article mentions - i got one of those e-mails and it was sent from webmas...@steampowered.com. I checked the headers data, it came from Valve. I'm assuming