Earlier quoted context omitted.
That's why GOG.com is my first choice. They even provide a nice Steam-like installer (unfortunately, no Linux version of the installer), while letting you download your games DRM-free, archivable and standalone.
Not all of the games on GOG are DRM-free at this point. Some require GOGGalaxy, their version of the steam client. I went through a frustrating refund process after learning about this after making a purchase.
Researcher banned on Valve's bug bounty program publishes second Steam 0-day
181–190 of 214 posts
Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day
#182This story continues to be so sad. Steam is reprising the role of Adobe who, for quite a while, refused to acknowledge that being able to use FlashPlayer as a tool to get you something on Windows was just as bad as breaking FlashPlayer. I heard one Adobe executive say, "Hey you can use a baseball bat to bludgeon someone but that isn't the bat maker's fault is it? If they are forced to make foam bats their product is…
Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day
#183Earlier quoted context omitted.
H1 itself has no WONTFIX status, FYI. A bug that's not considered to be a bug by the program will either be closed N/A or informative. Ultimately, disclosures are handled and controlled by the program, not by H1; this is both a good and bad thing (and I say that as both a HackerOne employee and a hacker on the platform -- it's a complicated issue from both sides).
It's complicated on both sides means there is politics involved. Being blunt, that sounds like a cop out to me. This sounds to me like an edge case that H1 should address if it really wants to be taken seriously.
Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day
#184Earlier quoted context omitted.
At some point this is less of a steam issue and more of a Windows issue. An OS shouldn't allow applications to compromise eachother. Steam should maybe be liable if they are actively thwarting disclosure that would protect users but that's a tough thing to establish legally.
It's a Steam issue, given that background services don't have to run as SYSTEM, and yet Valve decided to have Steam's background service do precisely that. Thankfully, the Linux version doesn't seem to have this problem (AFAICT).
In the end, Microsoft will get bad reputation for having an insecure OS (not to even mention Valve here, and in the long run it will hurt them as same as it did Adobe with their Flash stubbornness).
Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day
#185Earlier quoted context omitted.
Frankly, I think HackerOne deserves a bit of blame for that. Any WONTFIX ought to be made public automatically unless there are extenuating circumstances (like the vulnerability being reported against the wrong product).
H1 itself has no WONTFIX status, FYI. A bug that's not considered to be a bug by the program will either be closed N/A or informative. Ultimately, disclosures are handled and controlled by the program, not by H1; this is both a good and bad thing (and I say that as both a HackerOne employee and a hacker on the platform -- it's a complicated issue from both sides).
Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day
#186Earlier quoted context omitted.
It's complicated on both sides means there is politics involved. Being blunt, that sounds like a cop out to me. This sounds to me like an edge case that H1 should address if it really wants to be taken seriously.
There is definitely politics involved, but not H1 internal. The issue is that every program handles disclosure itself, so H1 itself doesn't really have the power. That could be changed at a policy level, but I'm not sure that'll happen (or should happen, honestly; I don't really know where I land on it).
Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day
#187From what I've read, the original bug involved malware already installed on the PC using the Steam client to run other code. While I'm not a security expert in any way, that doesn't seem to me like a huge exploit. If the attack requires installing malware on the victim's computer, why not just do the evil stuff directly with that malware? If that's the case and I'm not just remembering it wrong, then I could see why…
From Microsoft's perspective, they consider local privilege elevation on a client computer an "important" vulnerability that requires patching and paying a bug bounty: https://msrc-blog.microsoft.com/2018/09/10/microsoft-securit... So some companies consider LPE to be serious.
Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day
#188I wonder if this is a product of Valve's free-form company structure. If as a Valve employee, you have the autonomy to float between projects, how do you maintain a strong security team? Do they even have a dedicate security team?
Let's remember that Valve is the oldest there is in a business they pretty much pioneered with Steam over 15 years ago.
As somebody who's had an account there since day 1, I'm still amazed by how tight they've managed to keep their ship for all these years, even tho plenty of people have been trying to break into that very worthwhile target for over a decade.
If I contrast that to my experiences with services like Uplay, and Origin, then those differences are like night&day, because with both my accounts on these services I had lot's of issues due to my accounts getting hijacked (probably trough support) several times.
In 15+ years of using Steam, this hasn't happened once to me, so whatever Valve is doing at that end, it seems to have worked well for them and their customers.
That's not meant to defend their stance on this particular issue, but imho it's also kinda dishonest to now frame Valve as a company where nobody cares about security.
If that'd be really the case then they would have gone out of business over a decade ago.
Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day
#189Earlier quoted context omitted.
It's complicated on both sides means there is politics involved. Being blunt, that sounds like a cop out to me. This sounds to me like an edge case that H1 should address if it really wants to be taken seriously.
There is definitely politics involved, but not H1 internal. The issue is that every program handles disclosure itself, so H1 itself doesn't really have the power. That could be changed at a policy level, but I'm not sure that'll happen (or should happen, honestly; I don't really know where I land on it).
This effect (no matter the cause) of incident is about the worst thing that could happen to a company whose value proposition is that. It's like the bad old days where companies would legally threaten you if you found a bug, and from an outside perspective, Hackerone seems to promote it.
If I were an ethical hacker, I'd think twice before using your bug bounty program for fear of that treatment.
If I were a potential customer (or even a current customer), I don't know if I'd want to be associated with a company that tolerates veiled threats against ethical hackers.
Edit: I should add from this, it actually looks like its Hackerone making the veiled legal threat: https://mobile.twitter.com/enigma0x3/status/1160961861560479...
Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day
#190Earlier quoted context omitted.
It's complicated on both sides means there is politics involved. Being blunt, that sounds like a cop out to me. This sounds to me like an edge case that H1 should address if it really wants to be taken seriously.
You're probably outside the security sphere, but H1 is already taken seriously. There is no per-requisit for them to do so to be taken seriously as you state.