Live data from Hacker News

Researcher banned on Valve's bug bounty program publishes second Steam 0-day

zdnet.com

21–30 of 214 posts

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#21
post #15

From what I've read, the original bug involved malware already installed on the PC using the Steam client to run other code. While I'm not a security expert in any way, that doesn't seem to me like a huge exploit. If the attack requires installing malware on the victim's computer, why not just do the evil stuff directly with that malware? If that's the case and I'm not just remembering it wrong, then I could see why…

It was a priviledge escalation. An attacker could go from running as a compromised user to running with system priviledges.

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#22
post #15

From what I've read, the original bug involved malware already installed on the PC using the Steam client to run other code. While I'm not a security expert in any way, that doesn't seem to me like a huge exploit. If the attack requires installing malware on the victim's computer, why not just do the evil stuff directly with that malware? If that's the case and I'm not just remembering it wrong, then I could see why…

Using the Steam client to run other code at an escalated privilege level.

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#23
post #9

Earlier quoted context omitted.

"Please don't do thing" does thing gets banned shocked

It wasn't going to be fixed, you can't ship vulnerable software, it's not okay. He was in every right to publish it and to keep shaming Valve.

And Valve has ever right to ban him from their program, right?

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#24

Earlier quoted context omitted.

It wasn't going to be fixed, you can't ship vulnerable software, it's not okay. He was in every right to publish it and to keep shaming Valve.

And Valve has ever right to ban him from their program, right?

Yep, and we have every right to laugh at their stupidity.

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#26
post #15

From what I've read, the original bug involved malware already installed on the PC using the Steam client to run other code. While I'm not a security expert in any way, that doesn't seem to me like a huge exploit. If the attack requires installing malware on the victim's computer, why not just do the evil stuff directly with that malware? If that's the case and I'm not just remembering it wrong, then I could see why…

Lets say you and your brother share a PC, but you're the admin. You both play Steam. His account has no password. I steal the laptop. I log in as him. I pop a SYSTEM shell using Steam. I reset your admin password.

"Damn, you watch some weird porn."

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#27
post #6

a) Program has scope that doesn't include X b) Researcher reports vulnerability that falls under X c) Since it's out of scope, it's closed as N/A d) Report is locked because company doesn't want to publicly disclose a vulnerability in their system via the Hackerone platform What's the problem here? Just go with normal vulnerability disclosure. Bug bounty programs are a two way street, and respecting the scope is part…

Well, they did go with normal vulnerability disclosure, and were retaliated against. That's not okay.

Retailiated as in he was banned from their bug bounty program. The program with a scope that they went outside of. I think it's reasonable to be banned.

Obviously it would be better if Valve fixed the issue and gave a (possibly reduced due to out of scope) bounty.

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#28
post #3

This story continues to be so sad. Steam is reprising the role of Adobe who, for quite a while, refused to acknowledge that being able to use FlashPlayer as a tool to get you something on Windows was just as bad as breaking FlashPlayer. I heard one Adobe executive say, "Hey you can use a baseball bat to bludgeon someone but that isn't the bat maker's fault is it? If they are forced to make foam bats their product is…

You're beating a dead horse. Flash served a purpose once, and now it's reached end-of-life.

> You're beating a dead horse

With a foam bat. Just because the flash horse is dead doesn't mean it didn't deserve it's beating or can't continue to be a potent reminder of how bad Adobe was at handling security issues and why other platforms, like Steam, should learn instead of emulate.

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#29

Earlier quoted context omitted.

It wasn't going to be fixed, you can't ship vulnerable software, it's not okay. He was in every right to publish it and to keep shaming Valve.

And Valve has ever right to ban him from their program, right?

[deleted]

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#30
post #3

This story continues to be so sad. Steam is reprising the role of Adobe who, for quite a while, refused to acknowledge that being able to use FlashPlayer as a tool to get you something on Windows was just as bad as breaking FlashPlayer. I heard one Adobe executive say, "Hey you can use a baseball bat to bludgeon someone but that isn't the bat maker's fault is it? If they are forced to make foam bats their product is…

You're beating a dead horse. Flash served a purpose once, and now it's reached end-of-life.

No, they're making a point about Valve by comparing them to Adobe.
Post reply on HN