Live data from Hacker News

Researcher banned on Valve's bug bounty program publishes second Steam 0-day

zdnet.com

171–180 of 214 posts

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#171
post #165

Earlier quoted context omitted.

I don't quite follow this reasoning. Are you saying that by allowing people to make their NA / WONTFIX reports public, it will dilute the H1 brand? Does association with H1 have a significant effect of the perceived legitimacy of individual public disclosures? Why does this matter? My presumption is that the "other reasons" are business/political and centered around the desire to provide value to or establish goodwil…

People can publish whatever they want, and the only thing H1 can do about it is disinvite them from their platform. But anyone who suggests that H1 encourage people to publish NA/WONTFIX bugs probably hasn't had much contact with H1 bounty reports. In reality, valid bugs being quashed by vendors is not the real problem H1 has.

I would rather suggest that H1 discourage (or even prohibit) their partners from dis-inviting reporters for publicizing NA/WONTFIX bugs.

In this particular case, is sounds like H1 (or an employee thereof) actively discouraged disclosure, which seems like a problem.

> In reality, valid bugs being quashed by vendors is not the real problem H1 has.

There can clearly be more than one problem. I still fail to see the relevance of the "bug report quality" problem to this discussion (beyond explaining why automatic disclosure of NA/WONTFIX reports is not helpful.)

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#172

Earlier quoted context omitted.

If they have physical access, then they don't need to boot into Windows. They could boot from a flashdrive and access any files they want.

That won't help in the case of full-disk encryption.

And Windows has useful account-based file encryption too.

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#173
post #167

Earlier quoted context omitted.

Games typically need only access to video adapter, sound card and maybe network. They do not need access to your browser's cookies or history, or documents folder, for example. This probably doesn't require using VM.

> They do not need access to your browser's cookies or history, or documents folder, for example Well, some do... like Doki Doki Literature Club

I would think it would work in practice closer to mobile apps, where their access requirements are explicitly stated upfront (eg: needs access to documents folder).

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#174

Earlier quoted context omitted.

I don't know how many people care about the ban, per se, but Valve's strategy here is an extremely bad and pointless one. Was Valve technically within their rights to ban this researcher? Sure. Was it a move that advanced Valve's interests in any way? Obviously not.

I'm having trouble articulating this, so bear with me. In general, having a Bug Bounty program is good. We can agree on that, right? Most Bug Bounty programs have a scope, and staying inside the scope is important to the business for reasons . My guess is that most scopes are defined by a combination of confidence in the security of the code, resources to triage vulnerabilities in that part of the code, and the risk…

What trust is involved in this instance? No special access was given to the researcher AFAIK. Anyone with the skills and interest could have found the bug, regardless of the bounty program. The bounty in this case seems like an incentive to report instead of selling an exploit.

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#175

Earlier quoted context omitted.

HackerOne should be getting slated a lot more than they are. They are selling their bug bounty program to their customers (e.g. Valve) as offering the equivalent control to a traditional pen test contract (with confidentiality) while also trying to sell the spec work/no findings, no pay price advantage of a bug bounty program. It's scummy as hell.

If you don't want to participate in bug bounties, don't participate in them. It's not like it's hard out there in 2019 for application pentesters. This is a "world's tiniest violin" argument.

It's still interesting to hear comments like in the GP for an unknowing person like me.

Your comment is interesting as well, if only for the defensive reaction without addressing the "being scummy" claim. I'm basically hearing, yeah it's scummy, now get off my lawn.

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#176
post #151

Earlier quoted context omitted.

1. The overwhelming majority of rejected H1 reports are garbage. 2. It is not the case that all reporters want their findings disclosed publicly, even if they're rejected. 3. Reporters already retain the right to publish findings however they'd like. The worst H1 or a client can do is kick you off the platform. 4. A bug bounty platform that mandated disclosure of any sort would lose all its customers to the platform…

"The worst H1 or a client can do is kick you off the platform." As a hacker on hackerone, this is not my understanding of the relationship. Generally speaking the programs give you "authorized access" under the CFAA conditional on following the disclosure guidelines . I don't know about for other countries, but for the US I'm pretty sure this means that breaking the guidelines means you've retroactively committed a f…

> you've retroactively committed a felony.

There is no such thing as a retroactive crime in rule of law systems. Disclosure could be a considered an offense in its own, though.

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#177
post #167

Earlier quoted context omitted.

> They do not need access to your browser's cookies or history, or documents folder, for example Well, some do... like Doki Doki Literature Club

I would think it would work in practice closer to mobile apps, where their access requirements are explicitly stated upfront (eg: needs access to documents folder).

Yes please. Still most apps don’t need access to the documents directory or the camera.

They want to “open a file” which’s means file open dialog

Or: upload your profile picture, which’s means a one time upload of a file. Right now you give access to the camera and it can be used for anything

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#178
post #46

Earlier quoted context omitted.

I remember listening to some of their commentary tracks where the employees talk about how their desks had wheels, there's no managers, and there's no deadlines and no stress. They also at one time had higher profit per employee than Google! [1] Turns out that all along having no accountability in your company would result in complacency and a critical lack of production. I'm curious to see how Valve Software as a co…

I heard somewhere it's very stressful, toxic politics and so on. Not sure where but it's interesting to see a report to the contrary. Personally I always thought it would be cool to work at Valve, but not anymore. I don't see them doing anything broadly relevant that doesn't involve coasting on the momentum/market share of ancient products. Their VR stuff is cool, but even there it feel like they're lagging behind e.…

Eh, every review of the index has put it head and shoulders over any rift version so far. I'm not sure if we'd consider that "lagging behind oculus"

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#179
post #49

Earlier quoted context omitted.

Without seeing the communications it's hard to say, but "When the security researcher -- named Vasily Kravets-- wanted to publicly disclose the vulnerability, a HackerOne staff member forbade him from doing so, even if Valve had no intention of fixing the issue" sounds like more than just not being able to disclose on the H1 program.

I submitted an XSS on the tesla website to hackerone, it was marked as a duplicate. A week later, shared it with an XSS mailing list and got an angry email from HackerOne soon after. Public disclosure violates the terms of their reporting program EVEN if they reject your report. I'm really curious how much of what is reported to HackerOne ever gets and actual patch. It kind of seems like there are bunch of known vuln…

Could you tell me what this mailing list is? I'd be interested in joining it.

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#180

They're arrogant and lazy. Just say thank you and fix it. I hope GOG and HumbleBundle get a nice boost in sales.

> I hope GOG and HumbleBundle get a nice boost in sales. While there are some DRM-free games, majority of games on HumbleBundle are sold as Steam keys, so you still need Steam to launch them.

oh, i didn't know that. that kinda sucks. well, anyway, valve will probably be changing their tune from now on
Post reply on HN