Live data from Hacker News

Counter-Strike Global Offsets: reliable remote code execution

secret.club

41–50 of 94 posts

Re: Counter-Strike Global Offsets: reliable remote code execution

#41

Another example is why app level security is so important. Why shouldn’t games allow arbitrary code execution? It only matters because the access space for programs is still so broad. People complain when applications on Mac request permission to access files, but that makes such a huge difference. It’s time for kernel level permissions to be standard on desktops.

> It’s time for kernel level permissions to be standard on desktops.

And then the games industry starts deploying vulnerability-as-a-service kernel modules in order to bypass all of those controls.

https://mobile.twitter.com/TheWack0lian/status/7793978407622...

Re: Counter-Strike Global Offsets: reliable remote code execution

#42
post #33

Burying the lead here! > in over 4 months, we did not even receive an acknowledgment by a Valve representative. After public pressure, when it became apparent that Valve had also ignored other Security Researchers with similar impact, Valve finally fixed numerous security issues Also, can we all agree "DD/MM/YYYY" is the worst possible date format?

MM/DD/YYYY is clearly worse. Not only is it only used in a tiny number of places, making it more likely to cause confusion, but it doesn’t go consistently from smaller unit to bigger unit or vice-versa. YYYY-MM-DD is ideal, of course, due to easy sorting and no ambiguity over the order of MM and DD, but I’d take DD/MM/YYYY over MM/DD/YYYY any day.

The only problem with YYYY-MM-DD is that most of my non-digital use-cases don't require the year, and often not the month. Truncating information from the front-end isn't as intuitive.

Re: Counter-Strike Global Offsets: reliable remote code execution

#44
post #26

Valve should be kicked off HackerOne. They seem to abusing the service to trick researchers into submitting vulnerabilities without providing any sort of compensation. Does anyone here work at HackerOne?

I like Valve's approach. Who is the real bad guy here? Why should they prioritize people who break their hard work and coerce them into paying for protection? I might be biased; always wanted to work @ Valve Software since HL1.

> Why should they prioritize people who break their hard work and coerce them into paying for protection?

Because they voluntarily joined responsible disclosure programs and promised rewards?

Their hard work wasn't good enough to survive in the extremely hostile world out there. The fact is online gaming is a form of distributed computing and so people are exposed to network attacks. By failing to prioritize security they are putting their customers at risk. They can either start taking this seriously or watch people make money off of the vulnerabilities in their hard work.

Re: Counter-Strike Global Offsets: reliable remote code execution

#45

Burying the lead here! > in over 4 months, we did not even receive an acknowledgment by a Valve representative. After public pressure, when it became apparent that Valve had also ignored other Security Researchers with similar impact, Valve finally fixed numerous security issues Also, can we all agree "DD/MM/YYYY" is the worst possible date format?

> Also, can we all agree "DD/MM/YYYY" is the worst possible date format?

No, we can't. That format is properly ordered, unlike MM/DD/YYYY which makes absolutely no sense.

Re: Counter-Strike Global Offsets: reliable remote code execution

#46
post #3

How can people contact big corporations and get no response? Are the messages not being read? Or is there a weird culture of fear where you’d rather silently try to fix it without acknowledging that it exists, because acknowledging a problem means taking some legal responsibility? It wouldn’t be the first instance of US law having weird effects on human behavior but it does seem a bit far fetched.

Valve is a big company, but it has very small teams for CS GO and Dota relative to the industry.

Re: Counter-Strike Global Offsets: reliable remote code execution

#47

Valve as a company needs fundamental change. It’s pure luck that CS and Dota2 are still #1 and #2 on steam. I don’t even know if I would call valve a game developer anymore. They are mostly a service provider who happens to own some profitable IP.

Luck...? Dota2 is an extremely well managed esport. Have you seen literally any of their productions on youtube?

Re: Counter-Strike Global Offsets: reliable remote code execution

#48

Valve as a company needs fundamental change. It’s pure luck that CS and Dota2 are still #1 and #2 on steam. I don’t even know if I would call valve a game developer anymore. They are mostly a service provider who happens to own some profitable IP.

> Valve as a company needs fundamental change.

Counterpoint: No, they really don't.

> They are mostly a service provider who happens to own some profitable IP.

They are a staggeringly profitable service provider who occasionally has their employees work on games as a hobby. They just are not a game dev company anymore, and that's okay.

Re: Counter-Strike Global Offsets: reliable remote code execution

#49
meanwhile they spend billions with VR nobody wants, controllers nobody wants, linux OS nobody uses, smart tv integration nobody cares about, etc

cs:go at this point is a cheater's game.

because valve's server ain't reliable at all, some people choose to play on third party servers, and not surprisingly a lot of players had the third party client mining bitcoin on their computer [0]. much blame the service, but it's obvious to me it's Valve's responsability.

0: https://www.theverge.com/2013/5/2/4292672/esea-gaming-networ...

Re: Counter-Strike Global Offsets: reliable remote code execution

#50

meanwhile they spend billions with VR nobody wants, controllers nobody wants, linux OS nobody uses, smart tv integration nobody cares about, etc cs:go at this point is a cheater's game. because valve's server ain't reliable at all, some people choose to play on third party servers, and not surprisingly a lot of players had the third party client mining bitcoin on their computer [0]. much blame the service, but it's o…

Valve doesn't even fix VAC bypasses you can find on github
Post reply on HN