Valve and HackerOne: how not to handle vulnerability reports
blog.jakegealer.me
Valve and HackerOne: how not to handle vulnerability reports
1–10 of 162 posts
Re: Valve and HackerOne: how not to handle vulnerability reports
#2Unfortunately, despite all the HackerOne claims, it still seems to take public disclosure and embarrassment to make companies actually take things seriously. Seems sunlight is still the best disinfectant.
Re: Valve and HackerOne: how not to handle vulnerability reports
#3Re: Valve and HackerOne: how not to handle vulnerability reports
#4Re: Valve and HackerOne: how not to handle vulnerability reports
#5HackerOne started with such promise, but stories like this keep coming out. It makes you wonder how many people were even more patient than OP. Unfortunately, despite all the HackerOne claims, it still seems to take public disclosure and embarrassment to make companies actually take things seriously. Seems sunlight is still the best disinfectant.
Not paying out the promised bounty, to me, basically spits in the face of independent (and ethical) security researchers.
Re: Valve and HackerOne: how not to handle vulnerability reports
#6Important life lesson: drop 0days on twitter, you wont get bounties, but at least you will get recognition and job offers.
Re: Valve and HackerOne: how not to handle vulnerability reports
#7Make sure to deal with an actual human and that everything is done according to best practice. You may even get publicity this way and even if it's unethical it can be sold or used to your advantage.
If they care, trust me when I say they will make an effort. Most places (like Google) have effective systems in place for dealing with such queries.
Re: Valve and HackerOne: how not to handle vulnerability reports
#8From what I understand. It seems the steam app is connecting to plain http http://store.steampowered.com/ so it could be man in the middled.
Unless I am missing something, it's way overblown. Valve please fix the URL to https and send that guy a $50 Amazon voucher.
Re: Valve and HackerOne: how not to handle vulnerability reports
#9Re: Valve and HackerOne: how not to handle vulnerability reports
#10How is that vulnerability? If the ISP DNS gets hacked people can intercept traffic. Seriously this is the best attack scenario he could come with with? From what I understand. It seems the steam app is connecting to plain http http://store.steampowered.com/ so it could be man in the middled. Unless I am missing something, it's way overblown. Valve please fix the URL to https and send that guy a $50 Amazon voucher.