7/28/2015

Steam Account Recovery Code Bug How Accounts Were Getting Hacked

Steam was shut down on 26th of July as valve engineers were working on the security bug which lead to the hacking of several steam accounts, many people reported that there accounts were recently accessed by multiple devices and there password was changed due to the security breach in steam.

The Security Bug Explained-


The security bug was a pretty simple tricks which could be used by anyone to easily hack someones steam account just by knowing there username. Elm Hoe, a Steam gamer and YouTuber first spotted it and the spread the word against the security breach on 25th July with his video.

Once you knew someones user name you just had to visit Steam's forgot password page and Select the victims email id as the form of account recovery, then you are redirected to a page where it asks you to fill in the recovery code which was then send to your mail, security was compromised at this part instead of whenchecking if the code was right or wrong steam accepted the code without even checking it.

The bug was however fixed on 26th of July by Valve engineers when steam was fully shut down, however no such things has been publicly revealed that how such a critical bug took place, how was it resolved and what measures should be taken place to resolve such situations in the future.

Steam is the biggest gaming networks currently available which provides digital rights management (DRM),millions of people use it everyday and spends thousands of dollars and such a security bug was a very critical issue and valve must provide legitimate answer to why this took place.

No comments:

Post a Comment