Live data from Hacker News

Researcher banned on Valve's bug bounty program publishes second Steam 0-day

zdnet.com

91–100 of 214 posts

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#91

They're arrogant and lazy. Just say thank you and fix it. I hope GOG and HumbleBundle get a nice boost in sales.

> I hope GOG and HumbleBundle get a nice boost in sales.

While there are some DRM-free games, majority of games on HumbleBundle are sold as Steam keys, so you still need Steam to launch them.

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#92
post #79

Drama aside. Valve...I have your software installed. It has a hole. Fix it. This mudslinging isn't helping your PR or making me feel more secure about my steam install regardless of the details.

I agree. As a user, I do not care who is at fault much, but I do expect the platform you provide to be somewhat secure.. especially after you are told it is not.

I basically uninstalled Steam client after first 0day was found. At least with gog I don't have install galaxy. But thats a different rant..

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#93

Valve figured out how to print money by hooking teenagers with gambling on loot boxes. They stopped having to create AAA titles, they stopped having to do anything remotely creative, and now they are a giant cancer with no value left to add. Their client is an insecure, slow, instable piece of shit and has been this way for well over a decade. I regret being a customer of theirs.

> Their client is an insecure, slow, instable piece of shit

And yet, it's still the best client out there.

If you want slow and instable(sic!) try competition. Steam client is actually fast and stable compared to what else is on offer.

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#94
post #76

Earlier quoted context omitted.

Wouldn't you be able to do the same simply by looking at the file system without any access to admin privileges? I'm not arguing that this vulnerability isn't one, it's a privilege escalation vulnerability, however in your situation you got physical access which is as far as I know, pretty much game over for your system.

Not if they haven't granted access to the files to you. In fact by default the files in a user's home folder (including Documents, Videos etc.) are inaccessible to other (non-privileged) users on Windows.

If they have physical access, then they don't need to boot into Windows. They could boot from a flashdrive and access any files they want.

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#95
post #82
post #50

I wonder if this is a product of Valve's free-form company structure. If as a Valve employee, you have the autonomy to float between projects, how do you maintain a strong security team? Do they even have a dedicate security team?

I've worked with extremely competent security professionals before. Those people love and are fanatical about security. Based on my experience, it seems a near certainty that Valve doesn't employee even a single such person. These people raise hell if security is ignored and have a job freedom that makes typical software engineers look like panhandlers.

That is why many people hate security cybersecurity professionals: https://thenextweb.com/security/2019/01/25/everybody-hates-c...

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#96
post #67

Earlier quoted context omitted.

I agree with you from the other side. Before these programs people would disclose issues to the public. The company found out like everyone else. They would fix it immediately because they had to. Now they can hide it for months(ever) allowing others to discover them and keeping the researchers quiet.

A normal process goes like this: - Researcher finds bug - Researcher discloses to vendor - Vendor fixes (or not) - Researcher discloses bug publically once vendor has fixed, or after X time (whichever is first) This is roughly how Project Zero goes, and it's a good mix between giving the vendor the opportinity to fix it and deploy the update before it gets exploited. It's very naive to assume that bugs can be fixed b…

Why is it whichever is first and not after a fixed time? I see a benefit to waiting X time regardless, because it allows more time for the patch to circulate to everyone. What is the benefit to disclosing it immediately after it is "fixed"?

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#97
post #77

Earlier quoted context omitted.

I uninstalled Steam the moment I read the previous disclosure and Valve's approach to it. Any company that treats security as it used to be in the 90s ought to be shunned.

If you don't need it, why did you have it installed in the first place?

Not sure what you're getting at. There's very few things we need, sounds like they're sacrificing a little to avoid giving a company they deem unethical any money.

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#98
post #77

Earlier quoted context omitted.

I uninstalled Steam the moment I read the previous disclosure and Valve's approach to it. Any company that treats security as it used to be in the 90s ought to be shunned.

If you don't need it, why did you have it installed in the first place?

I love games and can’t play my steam collection now. But if I have to give that up so that some silly bug elsewhere in my system doesn’t expose me to a ransomware attack (or worse), so be it. I’ll find another way.

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#99
Since Valve stopped producing games, I wonder what their net income per employee is based on assets they own less revenue produced by third-parties through Steam.

If you look at just the assets Valve produces minus rent seeking, are they losing money?

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#100
post #70

Earlier quoted context omitted.

H1 itself has no WONTFIX status, FYI. A bug that's not considered to be a bug by the program will either be closed N/A or informative. Ultimately, disclosures are handled and controlled by the program, not by H1; this is both a good and bad thing (and I say that as both a HackerOne employee and a hacker on the platform -- it's a complicated issue from both sides).

How is N/A not a synonym for WONTFIX? There comes a moment when inaction translates to deception, and if you need clarification for what that looks like in the wild, look no further than Facebook.

I think WONTFIX is 'yes I see what you mean but we're not going to change how that works', N/A is 'this isn't relevant why are you posting it here.'
Post reply on HN