Live data from Hacker News

Researcher banned on Valve's bug bounty program publishes second Steam 0-day

zdnet.com

31–40 of 214 posts

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#31
post #8

Earlier quoted context omitted.

The researcher can still disclose it, they just aren't going to get permission to disclose it on the Hackerone program. Most things out of scope don't get publicly disclosed as far as I know. Doesn't seem too unreasonable.

> Kravets said he was banned from the platform following the public disclosure of the first zero-day. His bug report was heavily covered in the media, and Valve did eventually ship a fix, more as a reaction to all the bad press the company was getting. > The patch was almost immediately proved to be insufficient, and another security researcher found an easy way to go around it almost right away. You might want to re…

I was responding to a comment that (I interpreted) to be talking in more general terms than the scope of the article.

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#32
post #8
post #2

I mean, you can't have your cake and eat it too - if you claim that a particular issue is not a bug and you won't fix it, then you have no ethical grounds to say that it shouldn't be disclosed. Responsible disclosure expects delaying public disclosure to protect the users while the vendor prepares a fix. If the vendor says that they won't fix it, then it's not only a right, but a moral duty to disclose that vulnerabi…

The researcher can still disclose it, they just aren't going to get permission to disclose it on the Hackerone program. Most things out of scope don't get publicly disclosed as far as I know. Doesn't seem too unreasonable.

Without seeing the communications it's hard to say, but "When the security researcher -- named Vasily Kravets-- wanted to publicly disclose the vulnerability, a HackerOne staff member forbade him from doing so, even if Valve had no intention of fixing the issue" sounds like more than just not being able to disclose on the H1 program.

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#33

Earlier quoted context omitted.

It wasn't going to be fixed, you can't ship vulnerable software, it's not okay. He was in every right to publish it and to keep shaming Valve.

And Valve has ever right to ban him from their program, right?

And the rest of us have the right to tell Valve, as their paying customers, we're very disappointed in their behavior and find it unacceptable.

I expect them to take security flaws seriously if they want my continued patronage - and that includes EoPs.

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#34
post #18
post #6

a) Program has scope that doesn't include X b) Researcher reports vulnerability that falls under X c) Since it's out of scope, it's closed as N/A d) Report is locked because company doesn't want to publicly disclose a vulnerability in their system via the Hackerone platform What's the problem here? Just go with normal vulnerability disclosure. Bug bounty programs are a two way street, and respecting the scope is part…

Acknowledgement is one thing. Disclosure is another. If Steam had no problem acknowledging that this functionality exists, they should have had no problem with it being disclosed. There lies the problem. In the bathroom with the needle in their arm; "...there's no problem here..." but if you swing the door open they'll still try to shut it. Because they know they're wrong. If HackerOne isn't going to help you they ha…

> If HackerOne isn't going to help you they have no right to hinder you. If they want to strongarm everyone into effectively the same agreement as an NDA then there literally is no point in turning vulnerabilities into HackerOne.

The article gets this part wrong: the hacker isn't banned from H1, which he says in his blog post -- "Eventually things escalated with Valve and I got banned by them on HackerOne — I can no longer participate in their vulnerability rejection program (the rest of H1 is still available though)." HackerOne is in no way punishing the hacker for his reports and/or public disclosures, for what it's worth.

(Disclosure: I am on the community team at H1, though I've had effectively zero involvement with this.)

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#35
post #6

a) Program has scope that doesn't include X b) Researcher reports vulnerability that falls under X c) Since it's out of scope, it's closed as N/A d) Report is locked because company doesn't want to publicly disclose a vulnerability in their system via the Hackerone platform What's the problem here? Just go with normal vulnerability disclosure. Bug bounty programs are a two way street, and respecting the scope is part…

Bug bounty programs exist primarily for the companies’ benefit. If you do not respect the security community, the best you can expect is for researchers to publicly disclose the vulnerabilities. At worst, black hats will find them and sell them since they can be very valuable.

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#36
post #6

a) Program has scope that doesn't include X b) Researcher reports vulnerability that falls under X c) Since it's out of scope, it's closed as N/A d) Report is locked because company doesn't want to publicly disclose a vulnerability in their system via the Hackerone platform What's the problem here? Just go with normal vulnerability disclosure. Bug bounty programs are a two way street, and respecting the scope is part…

You can define whatever you want for your project's scope, but when you're distributing self updating binaries to an audience the size of steam's and you act this casual about an admin escalation exploit, you deserve whatever damage to your reputation that you get.

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#37

Earlier quoted context omitted.

It wasn't going to be fixed, you can't ship vulnerable software, it's not okay. He was in every right to publish it and to keep shaming Valve.

And Valve has ever right to ban him from their program, right?

"muh rights!!!!"

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#38

Earlier quoted context omitted.

Please fix your jquery import, it's being blocked b/c it's coming over http not https

Sorry about that, probably gonna switch to VanillaJS.

a great library.

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#39

Earlier quoted context omitted.

It wasn't going to be fixed, you can't ship vulnerable software, it's not okay. He was in every right to publish it and to keep shaming Valve.

And Valve has ever right to ban him from their program, right?

They do, and the obvious and inevitable outcome of that is that Twitter is now their bug bounty program for some researchers.

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#40
post #3

This story continues to be so sad. Steam is reprising the role of Adobe who, for quite a while, refused to acknowledge that being able to use FlashPlayer as a tool to get you something on Windows was just as bad as breaking FlashPlayer. I heard one Adobe executive say, "Hey you can use a baseball bat to bludgeon someone but that isn't the bat maker's fault is it? If they are forced to make foam bats their product is…

You're beating a dead horse. Flash served a purpose once, and now it's reached end-of-life.

Now I’m just waiting for Steam to follow their lead.
Post reply on HN