ricevuta da security@isthereanydeal.com 3/4 d'ora fa. che dite, ci fidiamo che sia tutto a posto?


Hello,

I'm writing you to disclose a Steam login vulnerability on our website that we have been notified about and already fixed.

The vulnerability allowed attacker to spoof login via Steam and access any account that was using Steam Single Sign-on on IsThereAnyDeal.
Attacker could be able to access only your ITAD account, your Steam account is safe!

We have no evidence that any of your accounts were accessed this way, we believe only admin accounts were targeted.

Although the issue is fixed, if you would like to switch from Steam Single Sign-On to email and password login, you can do that at any time in your settings:
https://isthereanydeal.com/settings/account/

I am very sorry about this and we will do everything in our power to prevent any other future vulnerability.

Best regards,
Tomas