Live data from Hacker News

Researcher banned on Valve's bug bounty program publishes second Steam 0-day

zdnet.com

41–50 of 214 posts

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#41

Earlier quoted context omitted.

It wasn't going to be fixed, you can't ship vulnerable software, it's not okay. He was in every right to publish it and to keep shaming Valve.

And Valve has ever right to ban him from their program, right?

Did you read his first report? In scope or not, their right or not, how is a ban without proper dialogue (threats don't fall in that category) the reasonable reaction here? That's not how you interact with a pretty tight knit community, even if you're the one sitting on the pile of money.

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#42

Earlier quoted context omitted.

Well, they did go with normal vulnerability disclosure, and were retaliated against. That's not okay.

Retailiated as in he was banned from their bug bounty program. The program with a scope that they went outside of. I think it's reasonable to be banned. Obviously it would be better if Valve fixed the issue and gave a (possibly reduced due to out of scope) bounty.

That makes sense if the application is, like, a SAAS app, and the scope is, like, "don't employ credential stuffing or test any of our 3rd party dependencies that have not given us permission to be included in this scope".

But this is software people install on their desktops, and Valve has no say in how security researchers approach that stuff. Valve can and maybe even should exclude LPEs from their bounty scope (if that's not what they're focusing on right now), but they can't reasonably ban people for publishing vulnerabilities they've scoped out of the only mechanism they've provided for submitting and tracking vulnerabilities.

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#43
Valve figured out how to print money by hooking teenagers with gambling on loot boxes. They stopped having to create AAA titles, they stopped having to do anything remotely creative, and now they are a giant cancer with no value left to add. Their client is an insecure, slow, instable piece of shit and has been this way for well over a decade. I regret being a customer of theirs.

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#45
post #6

a) Program has scope that doesn't include X b) Researcher reports vulnerability that falls under X c) Since it's out of scope, it's closed as N/A d) Report is locked because company doesn't want to publicly disclose a vulnerability in their system via the Hackerone platform What's the problem here? Just go with normal vulnerability disclosure. Bug bounty programs are a two way street, and respecting the scope is part…

Thing is, as a result of the ban the next disclosure was immediately public. This left more people vulnerable than the responsible disclosure method would have.

Hence, this practice by steam makes all users of steam less secure (doubly so as they actually don't want to fix these issues). This is something the public deserves to know, so they can act accordingly.

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#46

Valve figured out how to print money by hooking teenagers with gambling on loot boxes. They stopped having to create AAA titles, they stopped having to do anything remotely creative, and now they are a giant cancer with no value left to add. Their client is an insecure, slow, instable piece of shit and has been this way for well over a decade. I regret being a customer of theirs.

I remember listening to some of their commentary tracks where the employees talk about how their desks had wheels, there's no managers, and there's no deadlines and no stress. They also at one time had higher profit per employee than Google! [1]

Turns out that all along having no accountability in your company would result in complacency and a critical lack of production. I'm curious to see how Valve Software as a company is going to climb over this security wall they've found themselves in front of if seemingly nobody has to answer to anyone and everybody gets to do what they want in a leisurely fashion. I mean we give Chinese IoT vendors crap all day long, and it turns out Steam might be just as bad!

[1] https://www.forbes.com/sites/stevedenning/2012/04/27/a-glimp...

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#47
I see this as an example where the system works. Valve has an incentive to pay for bugs. The researcher than has an incentive to disclose them privately. If Valve doesn't pay fairly, the bug is disclosed, Valve pays the price and is forced to fix it, and be running a scam of a bug bounty program, they've exposed themselves to more disclosures. Valve now has an incentive to fix their program either by working with this bug hunter or increasing payouts so other hunters beat him to the point. This is how the system should work. Decentralized self-regulation needs people like Valve to fuck up once in a while so that the forces at play sufficiently punish them until they improve their process.

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#48

Earlier quoted context omitted.

> Kravets said he was banned from the platform following the public disclosure of the first zero-day. His bug report was heavily covered in the media, and Valve did eventually ship a fix, more as a reaction to all the bad press the company was getting. > The patch was almost immediately proved to be insufficient, and another security researcher found an easy way to go around it almost right away. You might want to re…

I was responding to a comment that (I interpreted) to be talking in more general terms than the scope of the article.

Even in the scope of the original comment, doesn't it create a pretty perverse incentive to allow companies to mark HackerOne bugs as WONTFIX and then ban researchers who disclose them?

Isn't security through obscurity largely to be avoided? I thought the working model for most security researchers was: if it's not worth fixing, it's not worth hiding.

More to the point, I thought that responsible disclosure always came with an expectation of public disclosure. The advice I've always been given is that you should never disclose with conditions -- ie. "fix this and I won't tell anyone."

It should always be, "I am going to tell everyone, but I'm telling you first so you can push a fix before I do."

Does HackerOne operate under different rules?

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#49
post #8

Earlier quoted context omitted.

The researcher can still disclose it, they just aren't going to get permission to disclose it on the Hackerone program. Most things out of scope don't get publicly disclosed as far as I know. Doesn't seem too unreasonable.

Without seeing the communications it's hard to say, but "When the security researcher -- named Vasily Kravets-- wanted to publicly disclose the vulnerability, a HackerOne staff member forbade him from doing so, even if Valve had no intention of fixing the issue" sounds like more than just not being able to disclose on the H1 program.

I submitted an XSS on the tesla website to hackerone, it was marked as a duplicate. A week later, shared it with an XSS mailing list and got an angry email from HackerOne soon after. Public disclosure violates the terms of their reporting program EVEN if they reject your report.

I'm really curious how much of what is reported to HackerOne ever gets and actual patch. It kind of seems like there are bunch of known vulnerabilities idling on their platform without quick fixes. Should be interesting once the HackerOne database is inevitably leaked.

HackerOne should start requiring companies pay researchers for duplicates - that the company already knew of a flaw should make them more liable, not less.

Post reply on HN