Live data from Hacker News

Researcher banned on Valve's bug bounty program publishes second Steam 0-day

zdnet.com

121–130 of 214 posts

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#121

Earlier quoted context omitted.

You should be able to play games in your steam library. Just open your Steam\steamapps\common\ folder and find the exe for the game you want to play.

Steam's DRM (CEG) customizes the executables so it won't play without the Steam client running and logged in to the correct account. There are lots of not-DRM-enabled games on Steam, but they're decidedly in the minority.

There are a number of tools called “steamworks emulators” that allow one to bypass this outright for many games. These are generally seen as piracy tools, but there’s no good reason you couldn’t use them when you wanted to play your purchased game collection without DRM.

Be a bit careful when experimenting, though. You may run into problems syncing your cloud saves for some games if/when you go back to the official client.

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#122
This wouldn't be anywhere near as severe a problem as it is if Steam's service wasn't running as something as ridiculously privileged as NTAUTHORITY\SYSTEM.

On the plus side, reading the writeup [0] it seems unlikely that this affects the Linux client (or even if it does, it's at least limited to the current user account). So I guess Steam can continue to live on my machine for another day.

[0]: https://amonitoring.ru/article/onemore_steam_eop_0day/

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#123
post #69
post #63

Earlier quoted context omitted.

Could steam be legally liable for the issues bugs give to the end users if they know of the issud. I know they have TOS forbidding this but ToS need to take into account laws.

At some point this is less of a steam issue and more of a Windows issue. An OS shouldn't allow applications to compromise eachother. Steam should maybe be liable if they are actively thwarting disclosure that would protect users but that's a tough thing to establish legally.

It's a Steam issue, given that background services don't have to run as SYSTEM, and yet Valve decided to have Steam's background service do precisely that.

Thankfully, the Linux version doesn't seem to have this problem (AFAICT).

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#124
post #72

Earlier quoted context omitted.

How would one achieve this on Windows short of having the entire Windows install be isolated from your main OS? I would assume most users would not want to run their games in a VM inside Windows for performance reasons.

Disable the Steam service. Run Steam only on a separate user session with limited rights (no admin and no access to your files). So essentially you'd have to manually switch user, via the login screen, to play your games.

You've missed "Install Steam somewhere inside separate user's home directory" to not dealing with UAC on each update.

I moved to separate Wintendo box which is the best solution.

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#125
post #3

This story continues to be so sad. Steam is reprising the role of Adobe who, for quite a while, refused to acknowledge that being able to use FlashPlayer as a tool to get you something on Windows was just as bad as breaking FlashPlayer. I heard one Adobe executive say, "Hey you can use a baseball bat to bludgeon someone but that isn't the bat maker's fault is it? If they are forced to make foam bats their product is…

No that position is wrong, because the analogy is wrong. If the baseball bat would hit the customer in the face every time he tries to hit the ball, that would get fixed pretty quick. Allowing privilege escalation is an unintended side effect of the product being used and should be fixed because the customer never asked to be exposed to that risk.

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#126

Earlier quoted context omitted.

You should be able to play games in your steam library. Just open your Steam\steamapps\common\ folder and find the exe for the game you want to play.

Steam's DRM (CEG) customizes the executables so it won't play without the Steam client running and logged in to the correct account. There are lots of not-DRM-enabled games on Steam, but they're decidedly in the minority.

As you'd expect there are (or were, a few years ago when my account was temporarily banned for a few days) cracks to unlock the executables. You might need Steam still installed for this to work the first time, I'm not sure.

Legally I don't know where that stands, but morally I'd say we have a right to play the games we paid for.

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#127

Earlier quoted context omitted.

I'm not trying to defend Valve, I'm just surprised that everyone seems to be so upset about the ban.

I don't know how many people care about the ban, per se, but Valve's strategy here is an extremely bad and pointless one. Was Valve technically within their rights to ban this researcher? Sure. Was it a move that advanced Valve's interests in any way? Obviously not.

I'm having trouble articulating this, so bear with me.

In general, having a Bug Bounty program is good. We can agree on that, right?

Most Bug Bounty programs have a scope, and staying inside the scope is important to the business for reasons. My guess is that most scopes are defined by a combination of confidence in the security of the code, resources to triage vulnerabilities in that part of the code, and the risk to the business from vulnerabilities found in different parts of the code.

That is to say, I suspect that either Valve doesn't have many developers well versed in that part of the code base, or they are not confident in the security of that code base, or they considered it a low priority (even if we disagree about the priority of this vulnerability).

Now, let's pretend that I'm right about those reasons. Even further, let's pretend that they did not include it in the scope because they don't want to pay a bunch of bounties on code they knew was insecure.

(Aside, I'd much rather have companies only include things in bug bounty programs once they're confident they are secure, relying on BB to do your security for you is begging for trouble because then the company isn't taking responsibility for, or even trying, to do things securely)

Given this train of thought, which is making more than a couple assumptions, I don't think their actions are extremely bad or pointless. They are trying to keep their bug bounty program in scope. Bug bounty programs involve a fair amount of trust. If that trust is broken and they don't want that researcher anymore, then that's fair.

There probably should have been better communication. It probably (definitely) shouldn't have been a WONTFIX. Overall, terrible outcome for everybody.

It's just one of those things where every decision looks reasonable in isolation and leads to a really bad outcome and the company looking terrible.

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#128

Earlier quoted context omitted.

What's the point of stating these obvious tautologies? Yes, they have that right, he has the right to post on Twitter, someone has the right to post that on HN, we have the right to call Valve out, you have the right to defend Valve, we have the right to reply to your defence, and so on ad inf. All true and utterly worthless to point out.

I'm not trying to defend Valve, I'm just surprised that everyone seems to be so upset about the ban.

Your first post acted like people were calling the ban unexpected.

Your second post acted like people were calling the ban not-allowed.

Neither is accurate, so your surprise is misplaced.

Even though it was clear that this might happen, it's such a blatant bad decision, for both ethics and customer security, that people are fighting back loudly.

You haven't given a single reason people shouldn't be upset by it.

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#129

Earlier quoted context omitted.

I don't know how many people care about the ban, per se, but Valve's strategy here is an extremely bad and pointless one. Was Valve technically within their rights to ban this researcher? Sure. Was it a move that advanced Valve's interests in any way? Obviously not.

I'm having trouble articulating this, so bear with me. In general, having a Bug Bounty program is good. We can agree on that, right? Most Bug Bounty programs have a scope, and staying inside the scope is important to the business for reasons . My guess is that most scopes are defined by a combination of confidence in the security of the code, resources to triage vulnerabilities in that part of the code, and the risk…

> Most Bug Bounty programs have a scope, and staying inside the scope is important to the business for reasons.

Scopes are fine.

But if it wasn't in scope, then clearly none of the program's rules apply to the bug, right? That bug isn't part of the program.

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#130
post #2

I mean, you can't have your cake and eat it too - if you claim that a particular issue is not a bug and you won't fix it, then you have no ethical grounds to say that it shouldn't be disclosed. Responsible disclosure expects delaying public disclosure to protect the users while the vendor prepares a fix. If the vendor says that they won't fix it, then it's not only a right, but a moral duty to disclose that vulnerabi…

Frankly, I think HackerOne deserves a bit of blame for that. Any WONTFIX ought to be made public automatically unless there are extenuating circumstances (like the vulnerability being reported against the wrong product).

HackerOne should be getting slated a lot more than they are.

They are selling their bug bounty program to their customers (e.g. Valve) as offering the equivalent control to a traditional pen test contract (with confidentiality) while also trying to sell the spec work/no findings, no pay price advantage of a bug bounty program. It's scummy as hell.

Post reply on HN