Valve is notorious for ignoring any vulnerability reports
Valve and HackerOne: how not to handle vulnerability reports
11–20 of 162 posts
Re: Valve and HackerOne: how not to handle vulnerability reports
#12Re: Valve and HackerOne: how not to handle vulnerability reports
#13HackerOne started with such promise, but stories like this keep coming out. It makes you wonder how many people were even more patient than OP. Unfortunately, despite all the HackerOne claims, it still seems to take public disclosure and embarrassment to make companies actually take things seriously. Seems sunlight is still the best disinfectant.
And if the claims of HackerOne/Valve trying to get out of paying a bounty, that's just terrible, because a lot of these exploits can be sold to nefarious actors for much much more. Not paying out the promised bounty, to me, basically spits in the face of independent (and ethical) security researchers.
As a security team employee, I think it's easy to react defensively to every vulnerability report, to take them as critiques of the quality of your work. So it's natural for the first reaction to be jumping to "this is not a real report" or "this is a dupe".
But people in this position should think about the upside/downside of their actions.
ACCEPT - Upside: You show that your security team is responsive, you build trust with an active security community member. Downside: Your company pays out some fee (so tiny in big picture)
DENY - Upside: Your company doesn't pay out a fee. Downside: Usually a net negative for your company's reputation in security community, some chance you cause PR issues for your company.
Re: Valve and HackerOne: how not to handle vulnerability reports
#14Re: Valve and HackerOne: how not to handle vulnerability reports
#15I tend to sneak these little things into my PRs cause I cant stand to see them linger w/o cause
Re: Valve and HackerOne: how not to handle vulnerability reports
#16I know barely anything about encryption, but this reads to me like the parties involved don't understand that public key cryptography defeats MITM attacks (at least as I understand it)?
Re: Valve and HackerOne: how not to handle vulnerability reports
#17Valve is notorious for ignoring any vulnerability reports
any other sources?
Re: Valve and HackerOne: how not to handle vulnerability reports
#18Re: Valve and HackerOne: how not to handle vulnerability reports
#19HackerOne started with such promise, but stories like this keep coming out. It makes you wonder how many people were even more patient than OP. Unfortunately, despite all the HackerOne claims, it still seems to take public disclosure and embarrassment to make companies actually take things seriously. Seems sunlight is still the best disinfectant.
But occasionally the “oh f#%^” report comes in...
Re: Valve and HackerOne: how not to handle vulnerability reports
#20Just drop a line on twitter saying you've discovered a vulnerability in $popularSoftware and mention $company. Say you'll be disclosing in 90 days if $company doesn't issue a reply publicly. Make sure to deal with an actual human and that everything is done according to best practice. You may even get publicity this way and even if it's unethical it can be sold or used to your advantage. If they care, trust me when I…
That's blackmail. An expedient way of getting your door breached.