By Default:
Never ever put any profile information into anything other than http:s systems when it comes to Steam, Valve, Credit Cards or other sensitive site networks (e.g. Online shopping).
Browsing:
Firefox3 has a strong security package and with the noscript addon you should be pretty much good to go. I'd seriously take the time to stress the point that people should look in the corners of your browser when hovering a link, it will typically tell you "where" it's going and if it looks foreign; google has amazing toolkits in their search engine to see what it is and where it may be a fake-phisher re-direct link to another network. Long story short; don't go to things that seem untrustworthy without a decent amount of know-how of the site. I know this sounds like the whole "Don't trust strangers with candy", but these days you really have no idea if even your best friend has become a zombiebot for some network.
Linksets:
Tinyurls has features that show the link of the site and gives the source information (if you know how to read it) before you load the site, so you can get a general idea of whether or not the thing is a info phisher or may potentially house malicious code.
If any of you get into a situation like this, or just need general tech-assist guru. Feel free to send me a PM here and I'll be sure to reply.
As for the situation with Razzle. So long as he has a record of the purchases made. He may very well require a FAX-able receipt w/ License/ID, or something of the like. I'm uncertain as to valves methodology when it comes to legal suit for customers. I'm rather sure that Valve will do something along the lines of reimbursing the new CDK so that his stolen things will become voided and hopefully he'll be able to retain normal play.