Live data from Hacker News

Researcher banned on Valve's bug bounty program publishes second Steam 0-day

zdnet.com

71–80 of 214 posts

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#71
post #58
post #49

Earlier quoted context omitted.

I submitted an XSS on the tesla website to hackerone, it was marked as a duplicate. A week later, shared it with an XSS mailing list and got an angry email from HackerOne soon after. Public disclosure violates the terms of their reporting program EVEN if they reject your report. I'm really curious how much of what is reported to HackerOne ever gets and actual patch. It kind of seems like there are bunch of known vuln…

Hackers and crackers can't be controlled. It seems weird that HackerOne put themselves in such a deeply loser position to try to be the ones to prevent submitters from revealing security issues. Why not be a neutral party, and let the companies try to enforce rules on the hackers in these cases?

[deleted]

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#72
post #3

This story continues to be so sad. Steam is reprising the role of Adobe who, for quite a while, refused to acknowledge that being able to use FlashPlayer as a tool to get you something on Windows was just as bad as breaking FlashPlayer. I heard one Adobe executive say, "Hey you can use a baseball bat to bludgeon someone but that isn't the bat maker's fault is it? If they are forced to make foam bats their product is…

Knowledgeable people can just add Steam to the set of applications that must be installed in its own isolated environment. How would the typical Steam user know to do that? Is there a prominent warning on the install screen informing users that Steam will be used to hack their machine and anything they have stored on it?

How would one achieve this on Windows short of having the entire Windows install be isolated from your main OS? I would assume most users would not want to run their games in a VM inside Windows for performance reasons.

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#73
post #70

Earlier quoted context omitted.

Frankly, I think HackerOne deserves a bit of blame for that. Any WONTFIX ought to be made public automatically unless there are extenuating circumstances (like the vulnerability being reported against the wrong product).

H1 itself has no WONTFIX status, FYI. A bug that's not considered to be a bug by the program will either be closed N/A or informative. Ultimately, disclosures are handled and controlled by the program, not by H1; this is both a good and bad thing (and I say that as both a HackerOne employee and a hacker on the platform -- it's a complicated issue from both sides).

It's complicated on both sides means there is politics involved. Being blunt, that sounds like a cop out to me.

This sounds to me like an edge case that H1 should address if it really wants to be taken seriously.

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#74
post #65
post #49

Earlier quoted context omitted.

I submitted an XSS on the tesla website to hackerone, it was marked as a duplicate. A week later, shared it with an XSS mailing list and got an angry email from HackerOne soon after. Public disclosure violates the terms of their reporting program EVEN if they reject your report. I'm really curious how much of what is reported to HackerOne ever gets and actual patch. It kind of seems like there are bunch of known vuln…

Eh that one is on you I think. How long did you wait? If we have 5 researchers report the same vulnerability in 30 days we're going to count it as duplicate and still expect to have a full 60-90 days from the first report to deploy a fix.

Waited a couple weeks.

It was pretty low hanging fruit. I was going through an XSS tutorial and used their site for practice. `alert(1)` could be saved into several user fields including Name and would then be executed on every subsequent pageload around the site.

If there was some indication that someone had reported it recently I maybe would have waited longer, but I suspect this bug had been known for months.

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#75

Earlier quoted context omitted.

It wasn't going to be fixed, you can't ship vulnerable software, it's not okay. He was in every right to publish it and to keep shaming Valve.

And Valve has ever right to ban him from their program, right?

What's the point of stating these obvious tautologies? Yes, they have that right, he has the right to post on Twitter, someone has the right to post that on HN, we have the right to call Valve out, you have the right to defend Valve, we have the right to reply to your defence, and so on ad inf.

All true and utterly worthless to point out.

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#76
post #26
post #15

From what I've read, the original bug involved malware already installed on the PC using the Steam client to run other code. While I'm not a security expert in any way, that doesn't seem to me like a huge exploit. If the attack requires installing malware on the victim's computer, why not just do the evil stuff directly with that malware? If that's the case and I'm not just remembering it wrong, then I could see why…

Lets say you and your brother share a PC, but you're the admin. You both play Steam. His account has no password. I steal the laptop. I log in as him. I pop a SYSTEM shell using Steam. I reset your admin password. " Damn , you watch some weird porn."

Wouldn't you be able to do the same simply by looking at the file system without any access to admin privileges?

I'm not arguing that this vulnerability isn't one, it's a privilege escalation vulnerability, however in your situation you got physical access which is as far as I know, pretty much game over for your system.

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#77
post #2

I mean, you can't have your cake and eat it too - if you claim that a particular issue is not a bug and you won't fix it, then you have no ethical grounds to say that it shouldn't be disclosed. Responsible disclosure expects delaying public disclosure to protect the users while the vendor prepares a fix. If the vendor says that they won't fix it, then it's not only a right, but a moral duty to disclose that vulnerabi…

I uninstalled Steam the moment I read the previous disclosure and Valve's approach to it. Any company that treats security as it used to be in the 90s ought to be shunned.

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#78
post #73
post #70

Earlier quoted context omitted.

H1 itself has no WONTFIX status, FYI. A bug that's not considered to be a bug by the program will either be closed N/A or informative. Ultimately, disclosures are handled and controlled by the program, not by H1; this is both a good and bad thing (and I say that as both a HackerOne employee and a hacker on the platform -- it's a complicated issue from both sides).

It's complicated on both sides means there is politics involved. Being blunt, that sounds like a cop out to me. This sounds to me like an edge case that H1 should address if it really wants to be taken seriously.

There is definitely politics involved, but not H1 internal. The issue is that every program handles disclosure itself, so H1 itself doesn't really have the power. That could be changed at a policy level, but I'm not sure that'll happen (or should happen, honestly; I don't really know where I land on it).

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#80

Earlier quoted context omitted.

a great library.

I couldn't find/install it via npm or yarn :-( ;-)

You should consider The JAMstack, a new web paradigm where a user requests an HTML file and the server gives it to them.
Post reply on HN