Earlier quoted context omitted.
The researcher can still disclose it, they just aren't going to get permission to disclose it on the Hackerone program. Most things out of scope don't get publicly disclosed as far as I know. Doesn't seem too unreasonable.
> Kravets said he was banned from the platform following the public disclosure of the first zero-day. His bug report was heavily covered in the media, and Valve did eventually ship a fix, more as a reaction to all the bad press the company was getting. > The patch was almost immediately proved to be insufficient, and another security researcher found an easy way to go around it almost right away. You might want to re…
Researcher banned on Valve's bug bounty program publishes second Steam 0-day
31–40 of 214 posts
Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day
#32I mean, you can't have your cake and eat it too - if you claim that a particular issue is not a bug and you won't fix it, then you have no ethical grounds to say that it shouldn't be disclosed. Responsible disclosure expects delaying public disclosure to protect the users while the vendor prepares a fix. If the vendor says that they won't fix it, then it's not only a right, but a moral duty to disclose that vulnerabi…
The researcher can still disclose it, they just aren't going to get permission to disclose it on the Hackerone program. Most things out of scope don't get publicly disclosed as far as I know. Doesn't seem too unreasonable.
Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day
#33Earlier quoted context omitted.
It wasn't going to be fixed, you can't ship vulnerable software, it's not okay. He was in every right to publish it and to keep shaming Valve.
And Valve has ever right to ban him from their program, right?
I expect them to take security flaws seriously if they want my continued patronage - and that includes EoPs.
Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day
#34a) Program has scope that doesn't include X b) Researcher reports vulnerability that falls under X c) Since it's out of scope, it's closed as N/A d) Report is locked because company doesn't want to publicly disclose a vulnerability in their system via the Hackerone platform What's the problem here? Just go with normal vulnerability disclosure. Bug bounty programs are a two way street, and respecting the scope is part…
Acknowledgement is one thing. Disclosure is another. If Steam had no problem acknowledging that this functionality exists, they should have had no problem with it being disclosed. There lies the problem. In the bathroom with the needle in their arm; "...there's no problem here..." but if you swing the door open they'll still try to shut it. Because they know they're wrong. If HackerOne isn't going to help you they ha…
The article gets this part wrong: the hacker isn't banned from H1, which he says in his blog post -- "Eventually things escalated with Valve and I got banned by them on HackerOne — I can no longer participate in their vulnerability rejection program (the rest of H1 is still available though)." HackerOne is in no way punishing the hacker for his reports and/or public disclosures, for what it's worth.
(Disclosure: I am on the community team at H1, though I've had effectively zero involvement with this.)
Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day
#35a) Program has scope that doesn't include X b) Researcher reports vulnerability that falls under X c) Since it's out of scope, it's closed as N/A d) Report is locked because company doesn't want to publicly disclose a vulnerability in their system via the Hackerone platform What's the problem here? Just go with normal vulnerability disclosure. Bug bounty programs are a two way street, and respecting the scope is part…
Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day
#36a) Program has scope that doesn't include X b) Researcher reports vulnerability that falls under X c) Since it's out of scope, it's closed as N/A d) Report is locked because company doesn't want to publicly disclose a vulnerability in their system via the Hackerone platform What's the problem here? Just go with normal vulnerability disclosure. Bug bounty programs are a two way street, and respecting the scope is part…
Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day
#37Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day
#38Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day
#39Earlier quoted context omitted.
It wasn't going to be fixed, you can't ship vulnerable software, it's not okay. He was in every right to publish it and to keep shaming Valve.
And Valve has ever right to ban him from their program, right?
Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day
#40This story continues to be so sad. Steam is reprising the role of Adobe who, for quite a while, refused to acknowledge that being able to use FlashPlayer as a tool to get you something on Windows was just as bad as breaking FlashPlayer. I heard one Adobe executive say, "Hey you can use a baseball bat to bludgeon someone but that isn't the bat maker's fault is it? If they are forced to make foam bats their product is…
You're beating a dead horse. Flash served a purpose once, and now it's reached end-of-life.