4 ms·
I don't know how they'll resolve this... Ban all the steam accounts of people who've activated the keys? They'll get a whole lot of people who legitimately sub
by genbattle 15y ago
I don't know how they'll resolve this...
Ban all the steam accounts of people who've activated the keys? They'll get a whole lot of people who legitimately submitted hardware keys at the same time.
Invalidate/revoke the keys from steam? The hardware IDs they were using to run the promotion are still going to be out there in the wild, so they can't re-run the promotion, this would just minimize their losses in terms of lost profit.
As far as the keys being in plain text on the server, this doesn't even make sense from the perspective of how you design a web app; why not put the data on a separate remote/secure server? Why not at least encrypt it? Also, how are they matching the hardware IDs to the keys when people submit the official promo; are they actually doing a search through each text file to find the matching hardware key? The .htaccess mis-configuration is bad enough, but it's not the only issue here.