Steam password exploit discovered

Published by

teaser

Until recently it was possible to access someone's steam account with only a username. Basically, the authentification process needed to change an account password could be bypassed by... simply ignoring it.



Clicking "continue" without entering the password change verification code offered express access to the user's account. That means if someone had your username (and were aware of the exploit) they could have accessed your account in a few clicks.

Kotaku got in touch with Valve about the issue – which was discovered and fixed last week – and this is how they responded:

To protect users, we are resetting passwords on accounts with suspicious password changes during that period or may have otherwise been affected. Relevant users will receive an email with a new password. Once that email is received, it is recommended that users login to their account via the Steam client and set a new password.

Please note that while an account password was potentially modified during this period the password itself was not revealed. Also, if Steam Guard was enabled, the account was protected from unauthorized logins even if the password was modified. We apologize for any inconvenience.

If you've received an email from Steam at the weekend requesting a password change – that's why. if you look at the video below, you'll be baffled as to how simple this exploit was.

Steam password exploit discovered


Share this content
Twitter Facebook Reddit WhatsApp Email Print