Earlier quoted context omitted.
Without seeing the communications it's hard to say, but "When the security researcher -- named Vasily Kravets-- wanted to publicly disclose the vulnerability, a HackerOne staff member forbade him from doing so, even if Valve had no intention of fixing the issue" sounds like more than just not being able to disclose on the H1 program.
I submitted an XSS on the tesla website to hackerone, it was marked as a duplicate. A week later, shared it with an XSS mailing list and got an angry email from HackerOne soon after. Public disclosure violates the terms of their reporting program EVEN if they reject your report. I'm really curious how much of what is reported to HackerOne ever gets and actual patch. It kind of seems like there are bunch of known vuln…
Researcher banned on Valve's bug bounty program publishes second Steam 0-day
111–120 of 214 posts
Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day
#112Earlier quoted context omitted.
I love games and can’t play my steam collection now. But if I have to give that up so that some silly bug elsewhere in my system doesn’t expose me to a ransomware attack (or worse), so be it. I’ll find another way.
You should be able to play games in your steam library. Just open your Steam\steamapps\common\ folder and find the exe for the game you want to play.
Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day
#113Earlier quoted context omitted.
The meta-process might work, Valve's process is still broken.
Everybody makes mistakes, lets see if they can learn from theirs. I haven't heard that they keep making this same mistake (but I could be wrong.)
Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day
#114Earlier quoted context omitted.
A normal process goes like this: - Researcher finds bug - Researcher discloses to vendor - Vendor fixes (or not) - Researcher discloses bug publically once vendor has fixed, or after X time (whichever is first) This is roughly how Project Zero goes, and it's a good mix between giving the vendor the opportinity to fix it and deploy the update before it gets exploited. It's very naive to assume that bugs can be fixed b…
Why is it whichever is first and not after a fixed time? I see a benefit to waiting X time regardless, because it allows more time for the patch to circulate to everyone. What is the benefit to disclosing it immediately after it is "fixed"?
Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day
#115Earlier quoted context omitted.
I love games and can’t play my steam collection now. But if I have to give that up so that some silly bug elsewhere in my system doesn’t expose me to a ransomware attack (or worse), so be it. I’ll find another way.
You should be able to play games in your steam library. Just open your Steam\steamapps\common\ folder and find the exe for the game you want to play.
Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day
#116This sucks. We run steam on some public PCs with unprivileged accounts and we wouldn't be very happy to find that users were able to gain admin access and steal other people's passwords through a keylogger. Sigh.
Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day
#117Valve figured out how to print money by hooking teenagers with gambling on loot boxes. They stopped having to create AAA titles, they stopped having to do anything remotely creative, and now they are a giant cancer with no value left to add. Their client is an insecure, slow, instable piece of shit and has been this way for well over a decade. I regret being a customer of theirs.
> Their client is an insecure, slow, instable piece of shit And yet, it's still the best client out there. If you want slow and instable(sic!) try competition. Steam client is actually fast and stable compared to what else is on offer.
Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day
#118Earlier quoted context omitted.
You're beating a dead horse. Flash served a purpose once, and now it's reached end-of-life.
> You're beating a dead horse With a foam bat. Just because the flash horse is dead doesn't mean it didn't deserve it's beating or can't continue to be a potent reminder of how bad Adobe was at handling security issues and why other platforms, like Steam, should learn instead of emulate.
...perhaps I'm taking the analogy too far?
Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day
#119Earlier quoted context omitted.
You should be able to play games in your steam library. Just open your Steam\steamapps\common\ folder and find the exe for the game you want to play.
Steam's DRM (CEG) customizes the executables so it won't play without the Steam client running and logged in to the correct account. There are lots of not-DRM-enabled games on Steam, but they're decidedly in the minority.
Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day
#120Earlier quoted context omitted.
I submitted an XSS on the tesla website to hackerone, it was marked as a duplicate. A week later, shared it with an XSS mailing list and got an angry email from HackerOne soon after. Public disclosure violates the terms of their reporting program EVEN if they reject your report. I'm really curious how much of what is reported to HackerOne ever gets and actual patch. It kind of seems like there are bunch of known vuln…
> HackerOne should start requiring companies pay researchers for duplicates That would create a perverse incentive for researchers to tell their friends about the vulnerability so that they can resubmit it and also get a bounty. The problem could be solved on the side of the researchers by splitting the bounty among all submissions of the same bug, but anyone else with access to the report (employees of either Hacker…
For external parties, yes. However it's the easiest to game for those liable, since you can just mark whatever you want as a "duplicate" and refuse to pay the bounty.
Offering bounties for public disclosures helps remove a lot of perverse incentives.