Live data from Hacker News

Researcher banned on Valve's bug bounty program publishes second Steam 0-day

zdnet.com

161–170 of 214 posts

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#161

Earlier quoted context omitted.

H1 could make it a proviso if using their service that rejected but reports are automatically disclosed.

1. The overwhelming majority of rejected H1 reports are garbage. 2. It is not the case that all reporters want their findings disclosed publicly, even if they're rejected. 3. Reporters already retain the right to publish findings however they'd like. The worst H1 or a client can do is kick you off the platform. 4. A bug bounty platform that mandated disclosure of any sort would lose all its customers to the platform…

I can see how automatic disclosure may not be a good fit.

However, why doesn't H1 expressly allow reporters the option of public disclosure for all NA or WONTFIX reports?

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#162
post #151

Earlier quoted context omitted.

"The worst H1 or a client can do is kick you off the platform." As a hacker on hackerone, this is not my understanding of the relationship. Generally speaking the programs give you "authorized access" under the CFAA conditional on following the disclosure guidelines . I don't know about for other countries, but for the US I'm pretty sure this means that breaking the guidelines means you've retroactively committed a f…

And this is why many of the researchers I know are based outside of or have left the United States and work out of places like Thailand.

I'm having trouble thinking of a single researcher that has left the US for legal reasons. There are lots of researchers now in Southeast Asia! But that's because bounty programs like H1 let those people work remotely.

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#163
post #161

Earlier quoted context omitted.

1. The overwhelming majority of rejected H1 reports are garbage. 2. It is not the case that all reporters want their findings disclosed publicly, even if they're rejected. 3. Reporters already retain the right to publish findings however they'd like. The worst H1 or a client can do is kick you off the platform. 4. A bug bounty platform that mandated disclosure of any sort would lose all its customers to the platform…

I can see how automatic disclosure may not be a good fit. However, why doesn't H1 expressly allow reporters the option of public disclosure for all NA or WONTFIX reports?

Among other reasons, because the site is literally stuffed to its gills full of people reporting bullshit security issues, like "user impersonation possible" (if you convince a user to open developer tools and give you their session cookie), and H1 wouldn't be doing any good if it generated a constant stream of people "WONTFIX-disclosing" those reports.

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#164
post #62

This sucks. We run steam on some public PCs with unprivileged accounts and we wouldn't be very happy to find that users were able to gain admin access and steal other people's passwords through a keylogger. Sigh.

Cybercafes, LAN gaming centers, and PC bangs are about to have some interesting times.

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#165
post #161

Earlier quoted context omitted.

I can see how automatic disclosure may not be a good fit. However, why doesn't H1 expressly allow reporters the option of public disclosure for all NA or WONTFIX reports?

Among other reasons, because the site is literally stuffed to its gills full of people reporting bullshit security issues, like "user impersonation possible" (if you convince a user to open developer tools and give you their session cookie), and H1 wouldn't be doing any good if it generated a constant stream of people "WONTFIX-disclosing" those reports.

I don't quite follow this reasoning. Are you saying that by allowing people to make their NA / WONTFIX reports public, it will dilute the H1 brand? Does association with H1 have a significant effect of the perceived legitimacy of individual public disclosures? Why does this matter?

My presumption is that the "other reasons" are business/political and centered around the desire to provide value to or establish goodwill with corporate partners.

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#166

Earlier quoted context omitted.

You should be able to play games in your steam library. Just open your Steam\steamapps\common\ folder and find the exe for the game you want to play.

Steam's DRM (CEG) customizes the executables so it won't play without the Steam client running and logged in to the correct account. There are lots of not-DRM-enabled games on Steam, but they're decidedly in the minority.

Uhg, this drives me nuts. Apparently I'm not allowed to play Sepiko: Shadows Die Twice while traveling outside of the country. A VPN can temporarily get things going again, or staying in Offline mode, but what a pain in the ass...

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#167
post #152

Earlier quoted context omitted.

Won't sandboxes impact performance of video games? I don't know much about sandboxes except that VMs are often used as sandboxes, and I definitely don't want video games running inside of VMs

Games typically need only access to video adapter, sound card and maybe network. They do not need access to your browser's cookies or history, or documents folder, for example. This probably doesn't require using VM.

> They do not need access to your browser's cookies or history, or documents folder, for example

Well, some do... like Doki Doki Literature Club

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#169
post #165

Earlier quoted context omitted.

Among other reasons, because the site is literally stuffed to its gills full of people reporting bullshit security issues, like "user impersonation possible" (if you convince a user to open developer tools and give you their session cookie), and H1 wouldn't be doing any good if it generated a constant stream of people "WONTFIX-disclosing" those reports.

I don't quite follow this reasoning. Are you saying that by allowing people to make their NA / WONTFIX reports public, it will dilute the H1 brand? Does association with H1 have a significant effect of the perceived legitimacy of individual public disclosures? Why does this matter? My presumption is that the "other reasons" are business/political and centered around the desire to provide value to or establish goodwil…

People can publish whatever they want, and the only thing H1 can do about it is disinvite them from their platform. But anyone who suggests that H1 encourage people to publish NA/WONTFIX bugs probably hasn't had much contact with H1 bounty reports.

In reality, valid bugs being quashed by vendors is not the real problem H1 has.

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#170
post #160

Maybe it is also time to switch from the prehistoric model of "hey let's download a .exe on the web, execute it without any sandbox, and let that .exe install other .exe from thousands of other unknown sources around the world and run them without any sandbox either." Steam or any other app should always run sandboxed with no root access, no file access, no camera access, no access to other process, etc. For most use…

> prehistoric model of "hey let's download a .exe on the web, execute it without any sandbox, and let that .exe install other .exe from thousands of other unknown sources around the world and run them without any sandbox either." What year is it? To me prehistoric means buying a nice big box with a CDROM or some floppies and installing with no internet required at all. Shell exes that want to download crap is the cur…

See also: https://brew.sh/
Post reply on HN