Live data from Hacker News

Researcher banned on Valve's bug bounty program publishes second Steam 0-day

zdnet.com

191–200 of 214 posts

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#191

Earlier quoted context omitted.

Not all of the games on GOG are DRM-free at this point. Some require GOGGalaxy, their version of the steam client. I went through a frustrating refund process after learning about this after making a purchase.

I have yet to find a game that absolutely requires Galaxy. Could you share which game was it?

Only game that requires Galaxy is Gwent, and it's free to play.

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#192
post #6

a) Program has scope that doesn't include X b) Researcher reports vulnerability that falls under X c) Since it's out of scope, it's closed as N/A d) Report is locked because company doesn't want to publicly disclose a vulnerability in their system via the Hackerone platform What's the problem here? Just go with normal vulnerability disclosure. Bug bounty programs are a two way street, and respecting the scope is part…

The next time that researcher finds a vulnerability he's definitively not going to report it "responsibly" even if it is "within scope".

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#193
post #2

I mean, you can't have your cake and eat it too - if you claim that a particular issue is not a bug and you won't fix it, then you have no ethical grounds to say that it shouldn't be disclosed. Responsible disclosure expects delaying public disclosure to protect the users while the vendor prepares a fix. If the vendor says that they won't fix it, then it's not only a right, but a moral duty to disclose that vulnerabi…

You would think that any platform/app that actually contains the ability to load currency into itself would take any security threat seriously regardless of the scope.

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#194

Earlier quoted context omitted.

And this is why many of the researchers I know are based outside of or have left the United States and work out of places like Thailand.

I'm having trouble thinking of a single researcher that has left the US for legal reasons. There are lots of researchers now in Southeast Asia! But that's because bounty programs like H1 let those people work remotely.

There are plenty of researchers not in the US saying "don't do your research in the US".

You don't have to get into legal trouble to see which way the wind is blowing.

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#195

Earlier quoted context omitted.

> Kravets did eventually publish details about the Steam zero-day, which was an elevation of privilege (also known as a local privilege escalation) bug that allowed other apps or malware on a user's computer to abuse the Steam client to run code with admin rights. No, using this 0-day malware, with lower privilege level, could do stuff it could not do.

> could do stuff it could not do I have trouble parsing this. Did you mean "could do stuff it couldn't have done" perhaps?

It gets to do fancy admin stuff that regular malware without permissions can't.

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#196
post #151

Earlier quoted context omitted.

1. The overwhelming majority of rejected H1 reports are garbage. 2. It is not the case that all reporters want their findings disclosed publicly, even if they're rejected. 3. Reporters already retain the right to publish findings however they'd like. The worst H1 or a client can do is kick you off the platform. 4. A bug bounty platform that mandated disclosure of any sort would lose all its customers to the platform…

"The worst H1 or a client can do is kick you off the platform." As a hacker on hackerone, this is not my understanding of the relationship. Generally speaking the programs give you "authorized access" under the CFAA conditional on following the disclosure guidelines . I don't know about for other countries, but for the US I'm pretty sure this means that breaking the guidelines means you've retroactively committed a f…

CFAA could (and likely would) apply for remote vulnerabilities i.e. exploiting SQLi on someone else's servers; but in the case of local privilege escalation like this particular case all the exploiting/testing happens on systems owned and controlled by the researcher, so it doesn't violate CFAA and doesn't need any permission from Valve - the breach happened with authorization from the system owner.

You need permission to pentest someone else's systems, you don't need permission to pentest software on your own systems even if that software is written by someone else. In an enterprise setting it's possible that you have signed a contract where you agree not to do such testing or not to publicize its results; but violating that would be a civil matter regarding the terms of that contract, not a felony in respect to CFAA.

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#197
post #178

Earlier quoted context omitted.

I heard somewhere it's very stressful, toxic politics and so on. Not sure where but it's interesting to see a report to the contrary. Personally I always thought it would be cool to work at Valve, but not anymore. I don't see them doing anything broadly relevant that doesn't involve coasting on the momentum/market share of ancient products. Their VR stuff is cool, but even there it feel like they're lagging behind e.…

Eh, every review of the index has put it head and shoulders over any rift version so far. I'm not sure if we'd consider that "lagging behind oculus"

It's a premium product, and if I were going to buy a new VR headset right now it'd be the Index, but it's not a generational leap (it's basically a Vive++) and I've lost confidence in Valve to produce such a leap, let alone to bring VR gaming to the mainstream.

I'd love to be proven wrong, because I dislike Oculus. I am simply stating my observation that Valve seems to be in decline.

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#198
post #151

Earlier quoted context omitted.

"The worst H1 or a client can do is kick you off the platform." As a hacker on hackerone, this is not my understanding of the relationship. Generally speaking the programs give you "authorized access" under the CFAA conditional on following the disclosure guidelines . I don't know about for other countries, but for the US I'm pretty sure this means that breaking the guidelines means you've retroactively committed a f…

> you've retroactively committed a felony. There is no such thing as a retroactive crime in rule of law systems. Disclosure could be a considered an offense in its own, though.

[deleted]

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#199
post #151

Earlier quoted context omitted.

"The worst H1 or a client can do is kick you off the platform." As a hacker on hackerone, this is not my understanding of the relationship. Generally speaking the programs give you "authorized access" under the CFAA conditional on following the disclosure guidelines . I don't know about for other countries, but for the US I'm pretty sure this means that breaking the guidelines means you've retroactively committed a f…

> you've retroactively committed a felony. There is no such thing as a retroactive crime in rule of law systems. Disclosure could be a considered an offense in its own, though.

How?

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#200

Earlier quoted context omitted.

I'm having trouble thinking of a single researcher that has left the US for legal reasons. There are lots of researchers now in Southeast Asia! But that's because bounty programs like H1 let those people work remotely.

There are plenty of researchers not in the US saying "don't do your research in the US". You don't have to get into legal trouble to see which way the wind is blowing.

So what you're saying is you can't name many researchers who have left the US either.
Post reply on HN