Live data from Hacker News

Researcher banned on Valve's bug bounty program publishes second Steam 0-day

zdnet.com

201–210 of 214 posts

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#201

Earlier quoted context omitted.

It's a Steam issue, given that background services don't have to run as SYSTEM, and yet Valve decided to have Steam's background service do precisely that. Thankfully, the Linux version doesn't seem to have this problem (AFAICT).

I think it should become a Windows/Microsoft issue, to be honest. A good example is the recent Zoom vulnerability, the software made it possible to perform certain exploits on the user and operating system, so Apple stepped in and disabled the exploit. In this case, I think Microsoft should do the same in order to protect their users. My guess would be that the install base of Steam on Windows is as least on par with…

True; it'd be really nice if Microsoft started deprecating running non-essential things under the SYSTEM user. Windows could/should emulate the OpenBSD strategy of running services/daemons as unprivileged users dedicated to those services instead of as root.

Windows does support this functionality, and ultimately Valve's to blame for not using it, but you're right that Microsoft should be more proactive in encouraging good design and discouraging bad design.

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#202

Earlier quoted context omitted.

That won't help in the case of full-disk encryption.

And Windows has useful account-based file encryption too.

> And Windows has useful account-based file encryption too.

Is this on by default on Windows? I haven't needed to access my files from another Windows installation for a long time, but I'm pretty sure the last time I tried on my good old hard drive with Windows 7, they weren't encrypted and I had no trouble to access them.

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#203

Earlier quoted context omitted.

If they have physical access, then they don't need to boot into Windows. They could boot from a flashdrive and access any files they want.

This is true, and also why I lock down my BIOSs and set the OS as the only boot device. TRK is a bootable portable linux specifically for resetting and unlocking local admin accounts. Encryption, however, cannot be broken without your credentials. These can be obtained from default running instance of Windows with Mimikatz if the admin credentials are still in memory from an earlier session.

> In fact by default the files in a user's home folder (including Documents, Videos etc.) are inaccessible to other (non-privileged) users on Windows.

Sure that's certainly right but physical access doesn't force you to be "on Windows".

> This is true, and also why I lock down my BIOSs and set the OS as the only boot device.

I never talked about you specifically, you are a tiny tiny minority. Even then, that just block your computer. If you can't bypass that BIOS (seriously doubtful), the hard drive is still accessible.

> Encryption, however, cannot be broken without your credentials.

Is there an encryption on by default? That must be new because I'm pretty sure I never had trouble to access my user folders on some of my old Windows 7 installation (that's would be a good 20% of Steams users).

I can't find anything about this, if I have time tonight I'll try to see if I can access my user folder through another OS.

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#204

Earlier quoted context omitted.

HackerOne should be getting slated a lot more than they are. They are selling their bug bounty program to their customers (e.g. Valve) as offering the equivalent control to a traditional pen test contract (with confidentiality) while also trying to sell the spec work/no findings, no pay price advantage of a bug bounty program. It's scummy as hell.

If you don't want to participate in bug bounties, don't participate in them. It's not like it's hard out there in 2019 for application pentesters. This is a "world's tiniest violin" argument.

I guess if you don't have an argument, "hurr durr angry pen tester" is what you bring to the party.

(I'm not.)

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#205
post #202

Earlier quoted context omitted.

And Windows has useful account-based file encryption too.

> And Windows has useful account-based file encryption too. Is this on by default on Windows? I haven't needed to access my files from another Windows installation for a long time, but I'm pretty sure the last time I tried on my good old hard drive with Windows 7, they weren't encrypted and I had no trouble to access them.

No, but it only takes a minute to turn on if you're going to be sharing unsupervised access to a computer.

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#206
post #49

Earlier quoted context omitted.

I submitted an XSS on the tesla website to hackerone, it was marked as a duplicate. A week later, shared it with an XSS mailing list and got an angry email from HackerOne soon after. Public disclosure violates the terms of their reporting program EVEN if they reject your report. I'm really curious how much of what is reported to HackerOne ever gets and actual patch. It kind of seems like there are bunch of known vuln…

Could you tell me what this mailing list is? I'd be interested in joining it.

"Cheapbugs" but it appears it is abandoned.

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#207

Earlier quoted context omitted.

There are plenty of researchers not in the US saying "don't do your research in the US". You don't have to get into legal trouble to see which way the wind is blowing.

So what you're saying is you can't name many researchers who have left the US either.

I mean, the grugq is a really obvious and notable one.

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#208
post #202

Earlier quoted context omitted.

> And Windows has useful account-based file encryption too. Is this on by default on Windows? I haven't needed to access my files from another Windows installation for a long time, but I'm pretty sure the last time I tried on my good old hard drive with Windows 7, they weren't encrypted and I had no trouble to access them.

No, but it only takes a minute to turn on if you're going to be sharing unsupervised access to a computer.

> No, but it only takes a minute to turn on if you're going to be sharing unsupervised access to a computer.

This is not something that 99.99% of Steam users would do though...

It would still be possible to retrieve the encryption keys too if the PC is still running (which is also the only ways to make Steam vulnerability viable) using a can of compressed air [1].

As I said, physical access to a computer is pretty much already game over... The Steam vulnerability is quite useful while being connected remotely though (which is really the most likely scenario either way).

[1] https://www.zdnet.com/article/cryogenically-frozen-ram-bypas...

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#209
post #67

Earlier quoted context omitted.

I agree with you from the other side. Before these programs people would disclose issues to the public. The company found out like everyone else. They would fix it immediately because they had to. Now they can hide it for months(ever) allowing others to discover them and keeping the researchers quiet.

A normal process goes like this: - Researcher finds bug - Researcher discloses to vendor - Vendor fixes (or not) - Researcher discloses bug publically once vendor has fixed, or after X time (whichever is first) This is roughly how Project Zero goes, and it's a good mix between giving the vendor the opportinity to fix it and deploy the update before it gets exploited. It's very naive to assume that bugs can be fixed b…

Couldn't the researcher have just sold his finding to Project Zero?

If so, that seems like a superior alternative to immediate public disclosure.

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#210
post #137

Earlier quoted context omitted.

There are a number of tools called “steamworks emulators” that allow one to bypass this outright for many games. These are generally seen as piracy tools, but there’s no good reason you couldn’t use them when you wanted to play your purchased game collection without DRM. Be a bit careful when experimenting, though. You may run into problems syncing your cloud saves for some games if/when you go back to the official c…

Now you've swapped one attack surface for another (of a dubious origin).

Open source. https://gitlab.com/Mr_Goldberg/goldberg_emulator
Post reply on HN