Valve Fixes Steam Crypto Bug That Exposed Passwords in Plaintext


Userlevel 7
Badge +54

19-year-old college student fixes Steam's crypto

 
                                    http://i1-news.softpedia-static.com/images/fitted/340x180/valve-fixes-steam-crypto-bug-that-exposed-passwords-in-plaintext.png
 
May 1, 2016 19:20 GMT  ·  By Catalin Cimpanu Valve updated the Steam gaming client to fix a severe security issue in the application's crypto package that under certain conditions would have allowed an attacker to view a user's password in plaintext if observing network traffic when the user was authenticating on the platform.
 
Security researcher Nathaniel Theis (XMPPwocky) is the one that discovered the issue and also wrote an advanced technical write-up detailing the attack's steps.
 
To understand the attack, users first need to know how Steam's cryptography works. Valve designed the Steam crypto module to keep data secret and to authenticate connections so nobody can pass as another user.
 
Full Article

3 replies

Userlevel 7
Thanks, Jasper...a very interesting tale...the 19 year old obviously has a very bright future in the world of threat research & security software based on his recent success.
Userlevel 7
Badge +54
@ wrote:
Thanks, Jasper...a very interesting tale...the 19 year old obviously has a very bright future in the world of threat research & security software based on his recent success.
It is good to see a person doing something decent after all the bad news lately.
Userlevel 7
Badge +11
Thanks for the good news Jasper
 
Its about time Valve sorted this issue even if it took a little bit of help from a student (Who they should look to employ). With this bug out of the way and the new authentication log-in system that Valve have put into Steam's purchasing, trading and login servers it should be much safer now for us gamers :D
 
Brad
 
 

Reply