Kill Switch update: The issue affecting Baermar Uraz's Ugly Sweater has been fixed and the cosmetic has been reenabled in all queues with this update.

13th March.

Ok, so long story short; I've read the in game news.

Yes, DbD was hacked. They gained around 30,000 player ID's, which apparently cannot be used to identify us. See the in game news for yourselves, please.

Not trying to scaremonger or freak people out, but could someone please tell me why the Dev's waited it out so long to tell us this?

This happened nearly a week ago and you are telling us this now? I get not wanting to cause an unecessary stir within the community, but that was the wrong way to go about it.

Correct me if I'm wrong, but according to the General Data Protection Laws (GPDR), a company that holds its users data needs to inform them immediately if any of their data has been leaked; regardless of whether it can be used to identify them or not (including personal data such as ID's).

Could a moderator or developer get in touch with us on the forum in public because we need honest answers about what happened on the 13th of March, please.

Also could you explain how a player ID cannot be used to identify us when its primary means of existence is to identify and help differentiate players?

Thank you in advance.

Comments

  • [Deleted User]
    [Deleted User] Posts: 5,229
    edited March 2021

    I think they meant as in you as a person.

    Your player ID is that string of characters in settings menu, that's unique to DBD. So all it does is identify the account itself. So nothing about even your steam account would be gleamed from that just that this particular DBD account exists.

    However yes, General Data Protection Laws require you to be notified without delay; however if they can prove that delay was necessary or unavoidable, it would be permitted. They only have to notify proper authorities within 72 hours; the general public must be notified as soon as possible; this also only applies when the information could risk your "Rights or freedoms" so only serious information is governed as such.

    Edit: To those who are curious and would like to know more, I will leave a link of a summary here.

  • _NIGHTMARE_
    _NIGHTMARE_ Member Posts: 727

    Thing is, I would have expected an Official Statement on what occurred, exactly what data was taken and what measures they are planning on putting in place to prevent it from happening again, from BHVR.

    We've had radio silence on this up until now as far as I'm aware of; surely the most plausible thing to do would have been to write a quick overview of things so that people don't start blowing things out of proportion?

    Also a big thanks for sharing the link :)

  • [Deleted User]
    [Deleted User] Posts: 5,229

    It would be nice, I just wanted to make two things fairly clear. One that the information really is not of any consequence to us, and two, that they likely didn't actually violate any laws, regulations or anything of that sort.

    That is usually just where these kind of topics derail to so I had to get that out of the way first; with that being said yes knowing more would be nice; but they can also only tell us so much. I mean the more they tell us about how they are solving the problem, the more the people who hacked them in the first place can see what they are doing and start planning a new avenue of attack.

    I imagine if people make enough noise, as I am sure they will, BHVR will make a larger statement in the near future though.

  • _NIGHTMARE_
    _NIGHTMARE_ Member Posts: 727

    Thanks dude. Yep, topics like this can derail so fast that there's not even enough time for it to be like watching a train wreck :)

    True that actually, I didn't think of that in that way. But I wouldn't want them to go too into depth about what happened, the technological side of things would just confuse me even more to be honest.

    Yeah, it's starting to become pretty clear that they'll have to release a statement sooner or later...

    Thanks again for the info and quick response.

  • onemind
    onemind Member Posts: 3,089

    1 it is possible that they have told every account that was leaked hey we are temporary disabling your account to contained and secure any accounts that were hacked

    2 they would have to verify that the issue was on their end so that would take time and they would have to patch it first if you have a leaks that are easy access wouldn't you fix it first then announce it because announcing it before fix would make the issue worse