Activision can be added to that list too. If I buy CoD I shouldn't have to buy a damn battle pass to get GUNS IN COD THAT I SHOULD ALREADY HAVE. I wouldn't complain so much if they did like a challenge to unlock it. I don't wanna pay 60 dollars for stuff that's already in the game
Reminds me of the time that Need for Speed had an in-game button that directed you to the Playstation storepage to buy the game you are currently playing and therefore already own
Jimmy De'Souza In germany it's usually english for all and then another language. Usually French, Spanish or italian. Not everyone speaks it well of course, but a vast majority does at least understand basics.
+liquidminds Not in the former GDR part of Germany. Most people over there didn't have English in school. And though most people of my age had it at school, many of my peers at university struggle with it.
People claiming that "someone" bought a load of shitty games on their accounts aren't necessarily lying, the might be just stupid. I had the brilliant Idea of adding some shitty games to someone else's wishlist and as I saw today, they endet up on mine. So if somebody tried to screw a random user by buying al lot of games for them, they might just have bought them for themselves and with their own money. Some might call this karma...
This makes perfect sense actually. Because it was just a cache, that means you saw the wrong page, but you were still logged into your real account. So when you go to the settings, buying something, adding something to the wishlist. All those requests you make are pushed to your own account; not the account shown in error. It's like putting a sticker with a different number onto your credit card, then going to the store and buying with it thinking you're taking money from someone else's card.
All the claims that people had stuff bought on their accounts are complete BS. As you said, the pages were just returning errors if you tried to change anything and credit card numbers were not leaked in full, just the last two digits. It was a pretty massive screw up, but thankfully it wasn't nearly as bad as it could have been.
+DasVERMiT It's more than enough information to trick some moron in a call centre into resetting your accounts and giving access to people who shouldn't have it.
No it's not... How would you even know where the random user had other accounts? You wouldn't. Then you don't have their name or their address. You only have 2 digits of a credit card, not 4 which is pretty much the bare minimum everyone takes. Don't be silly.
Well, I have to admit: the second thing I thought of when learning of this Steam bug - right after "oh God does that mean that everybody can see my - oh wait no I'm not logged in, let's not log in" - was "I wonder if Tom Scott's gonna make a video about this". Love your stuff, as always!
This video was great. Everything explained so neatly and tying the end to the beginning was absolutely lovely. I'm gonna just have to marathon all your videos now.
I love watching these videos. Even today, they're very useful. I'm a programmer myself, and watching these videos are great ways to make sure I don't make the same silly and devastating mistakes. I've made a few of these dumb mistakes before, and this channel (and others like it) are very entertaining and educational too. Personally, I use caches for static data. My websites are nearly always dynamically loaded. So if I was running steam, the basic boilerplate website would be sent to your browser (cached), and your browser would start running some JavaScript. This JavaScript would start loading in all the dynamic content. So, it might call the server asking for the top 100 games, and this data would be cached since top 100 won't change often. If it asked for recommended games, this data would be cached, but cached for that user only. By having all my pages split into static and dynamic content, I can cache a lot of the website. Like the page to buy a game, I can cache nearly all of the website, the image, the description, the price, all that. I just won't cache the portion that says if the game is purchased or not.
Not a terrible human being in or near London? That's a tall order friend, a tall order! I'm just kidding, I loved the time I spent working in London :P
London is great in small doses but after living in and later leaving London it is good to meet friends but the endless blocks made me miss home where I could walk 3 minutes to miles of open fields and woods or a quick drive to family owned land to drive heavy machinery. The tibe is fast and easy but after an event when someone yelled bomb I was nervous. The people are nice when you get to meet them or in an emergency but on average are unfriendly, in the countys you nod and greet strangers, London is too busy for that.
Neither! I haven't played video games in years (Portal 2 was the last one, I think, and that's five years old now). Coding's some of my day, but lately RU-vid's been taking up more and more time!
+Nostro200 it's nowhere near programming related (like saying that stealing money is related to the company that makes pennies) but it's still interesting
+Nostro200 Honestly you're not going to be able to make your own cracks without a lot of work. Most cracks made today are made by groups of fairly skilled programmers, and more recent software is becoming increasingly difficult (or even impossible) to feasibly crack.
I love how these videos on the one hand make me feel like a total idiot (I don't know anything about computers or the internet), but on the other hand manages to make me understand what is going on after a while.
I really like this channel, I really appreciate the way you go about everything with out the screaming, shouting, swearing, hating, I just really appreciate that.
I think the only thing missing was the phrase "idempotent". Requests that are eligible for caching are generally ones that are idempotent; that is, the data you get back generally won't change regardless of what state you're currently in. Overall, good video, and Happy Holidays.
I have no idea who are you are Tom, and I'm not big into your subject matter above gaming quiet a bit myself but you have the nicest delivery of any human being I have ever seen. Listening to you is like liquid velvet for my ears. Merry Belated Christmas and Happy New Year! Much love from Southampton
Disney+ managed to go one better. A nice big breach that meant that someone else logs into your account, changes the names of your family members, and starts adding their favourite content to your lists.
So... I know of a RU-vidr that matches the requirements (not sure about where he lives though; his accent sounds British, anyway), but I don't personally know him... His channel is called A+Start, I hope I'm not completely wrong about him being British.
There was a time where any user could ask for a password change with the secret questions, even a wrong answer would let you ask for a password change. (thought the video would be about that :D)
I remember this. I was so confused , because I wanted to add some money to buy something and each time I clicked my vallet someone elses name showed up and their money. I never got to buy whatever it was I wanted that day :(
6:18 might be worth mentioning that the cached data includes a csrf token which is used to authorize the post request. Without it, any website can tell steam that you want to buy a game using your cookie and thus it was possible until they invalidated the sessionids that someone could have bought games with your account.
Yeah, but that doesn't change the fact a hack like this could happen. No chance of such problems with cards. Security upon security. You make a good point.
+William Hendick I dont think he matches the things Tom wrote ^^ he is pretty much the most shouty/sweary Person on this Planet but ye he does awesome subjective and Thoughtful game reviews and game shows on Twitch :)
What about Dad³? ... Oh "*smart* and *not sweary/shouty*" well I guess I answered my own question :) Serious answers though: TotalBiscuit (EDIT: Didn't know he moved) TheMightyJingles Hat Films (EDIT: Yes they can be "sweary") EDIT: FrankieonPC (Not sure where he lives, and he won't show his face) 2kliksphilip/3kliksphilip (Again not sure where he lives)
The two youtubers/streamers I personally really like are The Mighty Jingles and Quickybaby. I do not know their excact living area except that it is in Britian. Nor do I know their shedule. However they do qualify for the rest of the criteria. They are very famous within the World of Tanks community to the extent of being guest commentators for the World of Tanks Grand Finals in Poland. They are gentleman. And some of the most decent poeple I know. The biggest example is the charity event quickybaby organized which raised over 22 thousend pounds. Jingles also helped with this. I think they are amazing, but that is just a personal opinion. Next to that thanks for taaking the extra time of on christmas for this video
Probably worth mentioning that everyone trying to check their account details to see if they were safe... we're ensuring that their account details page got cached too, hence people being able to see full names, addressed, and the last 2-4 digits of their card numbers. Whoops.
Always at least "good" videos. Most times they are great. 2 videos in 1, thanks for the heads up about Steam. Bonus on the Chiny Wonder part (I think that's what you said, I have a cold I'm getting over). Here in the U.S., back in the 80s, we used Sike. That's how most spelled it. Sometimes I saw it spelled (years later in books) as Psych, or Syke. Which, you can understand where it came from. As in, "Are you trying to mess with my mind and psych me out?" We just said "sike". Usually, drawn out, with an elongated "si" & a very hard "k".
Hey Scott! Nice video, very well explained. I even understood over half the words! I'm no bigshot RU-vidr but I live in Essex (about an hour outside London) and I'm a gaming RU-vidr/streamer. I believe I would match your criteria and would love to discuss maybe doing a collab with you! I hit you up on Twitter too, Cheers mate, Merry Christmas.
+foxdropLoL - Be a Better League Player YES, I advice working with Foxdrop! He is both intelligent and funny!... as well as pretty skilled at the ol' video games ;) ;)
+Nelson Isaacs I thought this. He'd be happy to be in a video and he's not a dumbass. He is, however, semi incommunicado right now. Don't know how long for, mainly because I can't be arsed to find out.
Lathland! He lives in Manchester, which is.. almost London. He is a bit more of a technical gamer, most certainly not a terrible human being and his accent is to die for. (seriously, that alone makes his videos worth-a-while).
It was just a joke of his. If you watch his videos from the past year or so, it's very clear he's still in the UK, and probably still in the London area. Just in his own apartment now.
I totally remember chinny reckon. And Jackanory. I also wish I had enough of a following to be useful for your collaboration mentioned at the end. Great video - another sub gained.
I'd like to recommend TotalBiscuit. He's a very intelligent game journalist who would probably be ideal for anything you are planning. Big fan for a long time, keep up the funny and informative videos! Really enjoy the Citation Needed series too!
+Random Person Nope. They werent hacked. DoS is as much of a hack as harsh words are bombs... They were overloaded and their caching service was badly implemented. This video exactly explains what happened next.
So, my Steam account was not online during this shitstorm, would that mean my info is pretty much safe? I changed my password (via the steam client), so I know it is secure in that regard.
+Sawed Off Laser Indeed, if you weren't online when all this was going on (like me :D), your account info was never requested (unless you've got a much bigger problem!), and thus never cached, and thus not even potentially viewed by anyone else.
+Sawed Off Laser Even if you were online during the happening your info would still be pretty much safe. The only problem would have been getting a bit more spam on your main email address
+GwresYnKernow If it cached 1 request every minute for less than an hour (let's say 50 minutes), then only 50 people's personal details were leaked. If it was 100 servers then 5,000 people. There could have been five hundred thousand requests in that hour so the odds of it being you in that time frame is maybe 1:1000
If your requirement wasn't "in or near london" I would have suggested Totalbiscuit (TotalHalibut on youtube). Maybe you can have him on a skype call :D Another person that (as far as I know) actually lives in london is Sacriel (twitch.tv/sacriel and sacriel42 on youtube). He has a decent following and might be up for some collabs.
Web servers in the '90s were essentially the doing the same job as a cache server does today, except they did not poll for updates: they just served a static pre generated html page until the webmaster wrote or updated a page by writing html and uploading it.
imthemistermaster the reason Americans call them bucks is because back when America was the "new world" they traded livestock, not money, so I'd agree, bucks IS an american thing
+That Fat British Kid he's a bit sweary, and also doesn't do face cam, right? He ticks the other boxes though, I think... I swear he mentioned streaming somewhere at some point, but that might just be me getting people mixed up.
HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA HA Oh, your serious?