Live data from Hacker News

Researcher banned on Valve's bug bounty program publishes second Steam 0-day

zdnet.com

11–20 of 214 posts

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#11

Earlier quoted context omitted.

I had the same argument with Coinbase about this one... Ended up naming it 'Bad QR', putting this page together and sending them a private link ( https://writecodeeveryday.github.io/projects/badqr/ )

Please fix your jquery import, it's being blocked b/c it's coming over http not https

Sorry about that, probably gonna switch to VanillaJS.

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#12
post #9
post #4

The salient part seems to be that the researcher reported the first vulnerability through HackerOne and was (reportedly) told by Steam it wouldn’t be fixed. He then published it after being instructed that was against the rules and was banned

"Please don't do thing" does thing gets banned shocked

It wasn't going to be fixed, you can't ship vulnerable software, it's not okay. He was in every right to publish it and to keep shaming Valve.

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#13
post #9
post #4

The salient part seems to be that the researcher reported the first vulnerability through HackerOne and was (reportedly) told by Steam it wouldn’t be fixed. He then published it after being instructed that was against the rules and was banned

"Please don't do thing" does thing gets banned shocked

"Not a bug, wontfix."

"Fine, I'll tell the world."

"We fixed it."

Their ask was self-serving and dangerous, and deserved to be declined.

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#14
post #3

This story continues to be so sad. Steam is reprising the role of Adobe who, for quite a while, refused to acknowledge that being able to use FlashPlayer as a tool to get you something on Windows was just as bad as breaking FlashPlayer. I heard one Adobe executive say, "Hey you can use a baseball bat to bludgeon someone but that isn't the bat maker's fault is it? If they are forced to make foam bats their product is…

Knowledgeable people can just add Steam to the set of applications that must be installed in its own isolated environment. How would the typical Steam user know to do that? Is there a prominent warning on the install screen informing users that Steam will be used to hack their machine and anything they have stored on it?

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#15
From what I've read, the original bug involved malware already installed on the PC using the Steam client to run other code. While I'm not a security expert in any way, that doesn't seem to me like a huge exploit. If the attack requires installing malware on the victim's computer, why not just do the evil stuff directly with that malware? If that's the case and I'm not just remembering it wrong, then I could see why Valve wouldn't want to pay up and could see why this guy would go on a social media rant to slander Valve either hoping they'll pay up or just to get petty revenge.

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#16
post #6

a) Program has scope that doesn't include X b) Researcher reports vulnerability that falls under X c) Since it's out of scope, it's closed as N/A d) Report is locked because company doesn't want to publicly disclose a vulnerability in their system via the Hackerone platform What's the problem here? Just go with normal vulnerability disclosure. Bug bounty programs are a two way street, and respecting the scope is part…

Well, they did go with normal vulnerability disclosure, and were retaliated against. That's not okay.

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#17
post #8
post #2

I mean, you can't have your cake and eat it too - if you claim that a particular issue is not a bug and you won't fix it, then you have no ethical grounds to say that it shouldn't be disclosed. Responsible disclosure expects delaying public disclosure to protect the users while the vendor prepares a fix. If the vendor says that they won't fix it, then it's not only a right, but a moral duty to disclose that vulnerabi…

The researcher can still disclose it, they just aren't going to get permission to disclose it on the Hackerone program. Most things out of scope don't get publicly disclosed as far as I know. Doesn't seem too unreasonable.

> Kravets said he was banned from the platform following the public disclosure of the first zero-day. His bug report was heavily covered in the media, and Valve did eventually ship a fix, more as a reaction to all the bad press the company was getting.

> The patch was almost immediately proved to be insufficient, and another security researcher found an easy way to go around it almost right away.

You might want to read the article.

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#18
post #6

a) Program has scope that doesn't include X b) Researcher reports vulnerability that falls under X c) Since it's out of scope, it's closed as N/A d) Report is locked because company doesn't want to publicly disclose a vulnerability in their system via the Hackerone platform What's the problem here? Just go with normal vulnerability disclosure. Bug bounty programs are a two way street, and respecting the scope is part…

Acknowledgement is one thing. Disclosure is another.

If Steam had no problem acknowledging that this functionality exists, they should have had no problem with it being disclosed. There lies the problem. In the bathroom with the needle in their arm; "...there's no problem here..." but if you swing the door open they'll still try to shut it. Because they know they're wrong.

If HackerOne isn't going to help you they have no right to hinder you. If they want to strongarm everyone into effectively the same agreement as an NDA then there literally is no point in turning vulnerabilities into HackerOne.

They seem to only exist as a cow-catcher on the locomotive of software vendors too lazy to actually fix crappy code.

"Who needs to fix code and shell out bounty if you can pinpoint and silence the researcher?"

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#19
post #15

From what I've read, the original bug involved malware already installed on the PC using the Steam client to run other code. While I'm not a security expert in any way, that doesn't seem to me like a huge exploit. If the attack requires installing malware on the victim's computer, why not just do the evil stuff directly with that malware? If that's the case and I'm not just remembering it wrong, then I could see why…

> Kravets did eventually publish details about the Steam zero-day, which was an elevation of privilege (also known as a local privilege escalation) bug that allowed other apps or malware on a user's computer to abuse the Steam client to run code with admin rights.

No, using this 0-day malware, with lower privilege level, could do stuff it could not do.

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#20

Earlier quoted context omitted.

I had the same argument with Coinbase about this one... Ended up naming it 'Bad QR', putting this page together and sending them a private link ( https://writecodeeveryday.github.io/projects/badqr/ )

Please fix your jquery import, it's being blocked b/c it's coming over http not https

TLS errors are out of scope. #WONTFIX. Don't you dare to talk about this publically.

http://writecodeeveryday.github.io/projects/badqr/

Post reply on HN