Live data from Hacker News

Valve and HackerOne: how not to handle vulnerability reports

blog.jakegealer.me

1–10 of 162 posts

Re: Valve and HackerOne: how not to handle vulnerability reports

#2
HackerOne started with such promise, but stories like this keep coming out. It makes you wonder how many people were even more patient than OP.

Unfortunately, despite all the HackerOne claims, it still seems to take public disclosure and embarrassment to make companies actually take things seriously. Seems sunlight is still the best disinfectant.

Re: Valve and HackerOne: how not to handle vulnerability reports

#5
post #2

HackerOne started with such promise, but stories like this keep coming out. It makes you wonder how many people were even more patient than OP. Unfortunately, despite all the HackerOne claims, it still seems to take public disclosure and embarrassment to make companies actually take things seriously. Seems sunlight is still the best disinfectant.

And if the claims of HackerOne/Valve trying to get out of paying a bounty, that's just terrible, because a lot of these exploits can be sold to nefarious actors for much much more.

Not paying out the promised bounty, to me, basically spits in the face of independent (and ethical) security researchers.

Re: Valve and HackerOne: how not to handle vulnerability reports

#7
Just drop a line on twitter saying you've discovered a vulnerability in $popularSoftware and mention $company. Say you'll be disclosing in 90 days if $company doesn't issue a reply publicly.

Make sure to deal with an actual human and that everything is done according to best practice. You may even get publicity this way and even if it's unethical it can be sold or used to your advantage.

If they care, trust me when I say they will make an effort. Most places (like Google) have effective systems in place for dealing with such queries.

Re: Valve and HackerOne: how not to handle vulnerability reports

#8
How is that vulnerability? If the ISP DNS gets hacked people can intercept traffic. Seriously this is the best attack scenario he could come with with?

From what I understand. It seems the steam app is connecting to plain http http://store.steampowered.com/ so it could be man in the middled.

Unless I am missing something, it's way overblown. Valve please fix the URL to https and send that guy a $50 Amazon voucher.

Re: Valve and HackerOne: how not to handle vulnerability reports

#10

How is that vulnerability? If the ISP DNS gets hacked people can intercept traffic. Seriously this is the best attack scenario he could come with with? From what I understand. It seems the steam app is connecting to plain http http://store.steampowered.com/ so it could be man in the middled. Unless I am missing something, it's way overblown. Valve please fix the URL to https and send that guy a $50 Amazon voucher.

at this point they should send him $250 for having to deal with their atrocious bureaucracy
Post reply on HN