i have always been a big fan of steam, valve, and everything linked to it. its stood as a shiny light in the dingy pool of gaming crap
but i have found one fatal flaw in its system, that leaves me glaring at it in disgust. odd, even im surprised im thinking this
i recently got my account hijacked, by a website that looked almost identical to the genuine steam website, but with .ca instead of .com at the end. well, human error. i know. i screwed up.
so i go to retrieve my account. my hotmail address is linked to it, should work fine.
i get in, and have to enter in a security question answer. easy stuff. name of my dog, i think i know that.
but wait, its been changed.
and 2mins later, the email address linked to my account, has been changed too.
in otherwords, in order to take FULL control of any steam account, all you need is the password and username. because the two ONLY security countermeasures, can be changed without authorisation from the original email address. for an organisation as large as valve, i would have at least thought they had basic security measures tightened that even hotmail have mastered
i sent out a message to steam support line. maybe they are the knights in shining armour afterall. but from reading posts online of people in the exact same situation, i doubt it
any clues?
oh and if you have a steam account, add mr_trooper. say hello on my behalf
but i have found one fatal flaw in its system, that leaves me glaring at it in disgust. odd, even im surprised im thinking this
i recently got my account hijacked, by a website that looked almost identical to the genuine steam website, but with .ca instead of .com at the end. well, human error. i know. i screwed up.
so i go to retrieve my account. my hotmail address is linked to it, should work fine.
i get in, and have to enter in a security question answer. easy stuff. name of my dog, i think i know that.
but wait, its been changed.
and 2mins later, the email address linked to my account, has been changed too.
in otherwords, in order to take FULL control of any steam account, all you need is the password and username. because the two ONLY security countermeasures, can be changed without authorisation from the original email address. for an organisation as large as valve, i would have at least thought they had basic security measures tightened that even hotmail have mastered
i sent out a message to steam support line. maybe they are the knights in shining armour afterall. but from reading posts online of people in the exact same situation, i doubt it
any clues?
oh and if you have a steam account, add mr_trooper. say hello on my behalf