
On November 11, 2011 - Steam's main user information severs were hacked by unknown intruders who gained access to an encrypted database of personal information including passwords and credit card info. Valve officially confirmed this security breach yesterday afternoon to all users of the platform and forums. The forum accounts were the main focus of concern - with Valve requiring password changes for users but they are still assessing the potential damages to the Steam users outside of the forums as well. Basically, they are unsure at the moment of how much was actually stolen or if the encrypted information could be cracked open.

To avoid being the low hanging fruit that actually gets picked. When a massive user database of random low-target (non-celebrity) people is compromised - the most secure accounts will be tossed aside.
1. Change your passwords for both Steam and their forums asap. They have a password strength assessment tool when you create a new password and I suggest you make one that fills the entire strength rating. Be sure to use random text (upper and lower case), numbers, & special characters.

3. Set your accounts to private or friends-only. Many web search tools such as Google are notorious for being so powerful that they can also exploit sensitive data from "publicly shared" accounts. This is especially true with things like "cached websites" in the search. Unless your absolutely sure the information is intended to be public, don't make it public.

5. Don't share the email account used to manage other accounts. For instance with Facebook, it's best to not share the email you use to manage your Facebook account. Hackers can easily target the emails a user shares as a first step to gaining access to their passwords for other applications associated with the email. If you really want to be safe, create a separate confidential email with a really difficult password to only manage your user accounts. Also change its password every couple of months.
No comments:
Post a Comment