Live data from Hacker News

Researcher banned on Valve's bug bounty program publishes second Steam 0-day

zdnet.com

81–90 of 214 posts

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#81
post #3

This story continues to be so sad. Steam is reprising the role of Adobe who, for quite a while, refused to acknowledge that being able to use FlashPlayer as a tool to get you something on Windows was just as bad as breaking FlashPlayer. I heard one Adobe executive say, "Hey you can use a baseball bat to bludgeon someone but that isn't the bat maker's fault is it? If they are forced to make foam bats their product is…

You're beating a dead horse. Flash served a purpose once, and now it's reached end-of-life.

.... Hit the dead horse with the foam bat and win an iPod?

Those were the old days. Or, that damned monkey!

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#82
post #50

I wonder if this is a product of Valve's free-form company structure. If as a Valve employee, you have the autonomy to float between projects, how do you maintain a strong security team? Do they even have a dedicate security team?

I've worked with extremely competent security professionals before. Those people love and are fanatical about security. Based on my experience, it seems a near certainty that Valve doesn't employee even a single such person. These people raise hell if security is ignored and have a job freedom that makes typical software engineers look like panhandlers.

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#83
post #76
post #26

Earlier quoted context omitted.

Lets say you and your brother share a PC, but you're the admin. You both play Steam. His account has no password. I steal the laptop. I log in as him. I pop a SYSTEM shell using Steam. I reset your admin password. " Damn , you watch some weird porn."

Wouldn't you be able to do the same simply by looking at the file system without any access to admin privileges? I'm not arguing that this vulnerability isn't one, it's a privilege escalation vulnerability, however in your situation you got physical access which is as far as I know, pretty much game over for your system.

Not if they haven't granted access to the files to you. In fact by default the files in a user's home folder (including Documents, Videos etc.) are inaccessible to other (non-privileged) users on Windows.

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#84
post #70

Earlier quoted context omitted.

Frankly, I think HackerOne deserves a bit of blame for that. Any WONTFIX ought to be made public automatically unless there are extenuating circumstances (like the vulnerability being reported against the wrong product).

H1 itself has no WONTFIX status, FYI. A bug that's not considered to be a bug by the program will either be closed N/A or informative. Ultimately, disclosures are handled and controlled by the program, not by H1; this is both a good and bad thing (and I say that as both a HackerOne employee and a hacker on the platform -- it's a complicated issue from both sides).

How is N/A not a synonym for WONTFIX?

There comes a moment when inaction translates to deception, and if you need clarification for what that looks like in the wild, look no further than Facebook.

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#85
post #78
post #73

Earlier quoted context omitted.

It's complicated on both sides means there is politics involved. Being blunt, that sounds like a cop out to me. This sounds to me like an edge case that H1 should address if it really wants to be taken seriously.

There is definitely politics involved, but not H1 internal. The issue is that every program handles disclosure itself, so H1 itself doesn't really have the power. That could be changed at a policy level, but I'm not sure that'll happen (or should happen, honestly; I don't really know where I land on it).

H1 could make it a proviso if using their service that rejected but reports are automatically disclosed.

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#86

Earlier quoted context omitted.

And Valve has ever right to ban him from their program, right?

What's the point of stating these obvious tautologies? Yes, they have that right, he has the right to post on Twitter, someone has the right to post that on HN, we have the right to call Valve out, you have the right to defend Valve, we have the right to reply to your defence, and so on ad inf. All true and utterly worthless to point out.

I'm not trying to defend Valve, I'm just surprised that everyone seems to be so upset about the ban.

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#87
post #3

This story continues to be so sad. Steam is reprising the role of Adobe who, for quite a while, refused to acknowledge that being able to use FlashPlayer as a tool to get you something on Windows was just as bad as breaking FlashPlayer. I heard one Adobe executive say, "Hey you can use a baseball bat to bludgeon someone but that isn't the bat maker's fault is it? If they are forced to make foam bats their product is…

You're beating a dead horse. Flash served a purpose once, and now it's reached end-of-life.

Flash died because Adobe failed in the most obvious ways--even to lay outsiders at the time. They could never be bothered to fix the pervasive performance or security issues. It started to die, slowly at first: the desktop flash blocker plugins. Then very quickly: the lack of support from mobile OS--even though those companies practically begged Adobe to get its act together.

Adobe had a practical monopoly on the interactive web and blew it.

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#88
post #3

This story continues to be so sad. Steam is reprising the role of Adobe who, for quite a while, refused to acknowledge that being able to use FlashPlayer as a tool to get you something on Windows was just as bad as breaking FlashPlayer. I heard one Adobe executive say, "Hey you can use a baseball bat to bludgeon someone but that isn't the bat maker's fault is it? If they are forced to make foam bats their product is…

You're beating a dead horse. Flash served a purpose once, and now it's reached end-of-life.

It reached its EOL because Steve Jobs considered it a buggy security threat.

If no one will use or manufacture your baseball bat, then the danger of the bat is moot.

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#89
post #77
post #2

I mean, you can't have your cake and eat it too - if you claim that a particular issue is not a bug and you won't fix it, then you have no ethical grounds to say that it shouldn't be disclosed. Responsible disclosure expects delaying public disclosure to protect the users while the vendor prepares a fix. If the vendor says that they won't fix it, then it's not only a right, but a moral duty to disclose that vulnerabi…

I uninstalled Steam the moment I read the previous disclosure and Valve's approach to it. Any company that treats security as it used to be in the 90s ought to be shunned.

If you don't need it, why did you have it installed in the first place?

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#90
post #67

My opinion, not my (HackerOne customer) employer's: I know this will be unpopular with folks like tptacek, but I've always felt strongly that bug bounty programs offer too many perverse incentives to all parties. More often than not it becomes a tool for companies to sweep issues like this under the rug and then use HackerOne's system to force the reporters to play ball (because they want to keep getting paid). I hat…

I agree with you from the other side. Before these programs people would disclose issues to the public. The company found out like everyone else. They would fix it immediately because they had to. Now they can hide it for months(ever) allowing others to discover them and keeping the researchers quiet.

A normal process goes like this:

- Researcher finds bug

- Researcher discloses to vendor

- Vendor fixes (or not)

- Researcher discloses bug publically once vendor has fixed, or after X time (whichever is first)

This is roughly how Project Zero goes, and it's a good mix between giving the vendor the opportinity to fix it and deploy the update before it gets exploited.

It's very naive to assume that bugs can be fixed before others can exploit them. Bugs take time to fix, and the process takes time, especially when dealing with large enterprises.

Post reply on HN