Live data from Hacker News

Valve accused of ignoring existing RCE vulnerability in Source games for 2 years

twitter.com

101–110 of 122 posts

Re: Valve accused of ignoring existing RCE vulnerability in Source games for 2 years

#101

Earlier quoted context omitted.

No anti cheat for FPS games has ever "worked", it can't. The best you can do is make it a little hard for the cheats to keep up with your detectors or protocol changes.

That's absolutely true! Valve anti-cheat has entirely failed at that. Free open source cheats exist that VAC just cannot detect. Period. Wanna know the secret? The fact that it's a Java cheat.

What's the magic of Java? Is it just that VAC doesn't/can't inspect the jvm?

Re: Valve accused of ignoring existing RCE vulnerability in Source games for 2 years

#102
post #93
post #67

Earlier quoted context omitted.

Valve has been pretty aggressive about rolling out these kinds of policies compared to the rest of the industry. (E.g. they were wery early with requiring 2FA to be enabled for a period of time before doing sensitive actions like trades, adding warning interstitials on links that leave Steam). I don't think the incentives have changed that much. So, here's what makes me confused about your story: 1. I don't see any k…

> Valve has been pretty aggressive about rolling out these kinds of policies compared to the rest of the industry. True indeed. > Are you saying that they're polling all the hijacked accounts at a high frequency to detect trades they could intercept? Yes. I have to admit, the "milliseconds before" part was just wrong because I failed when trying to oversimplify for attention. > it's "a trade with foo (whom you've had…

>means, the website itself draws (depending on your OS and browser) a perfectly fine looking Browser popup window inside the legit page

The one I am always sent just shows a W10 decorated window. I've reported this same exact fake steam login popup thing to Cloudflare many times, yet the attackers seem to be deploying almost the same exact site time after time. Thankfully, Cloudflare eventually gets around to taking them down, but they aren't doing anything proactive to stop it from happening again.

Re: Valve accused of ignoring existing RCE vulnerability in Source games for 2 years

#103
post #101

Earlier quoted context omitted.

That's absolutely true! Valve anti-cheat has entirely failed at that. Free open source cheats exist that VAC just cannot detect. Period. Wanna know the secret? The fact that it's a Java cheat.

What's the magic of Java? Is it just that VAC doesn't/can't inspect the jvm?

Some speculation it is Java, some that it is Java's license, some that it is the license the cheat is under (open source), etc. No one really knows why.

Strangely the only difference between one java cheat that was detected and one that has been undetected for four years, is that the original, old java one that got detected was licensed upder GPL, and the newer one is licensed under AGPL. Then there's a newer fork with a GUI that is undetected for ~2 years.

VAC seems to be... unable or unwilling to detect Java cheats. The original, old one got detected, though, and it was Java. so there is a tad of confusion.

I have sent countless messages to valve offering patches for several current exploits, like the current server lagger/crasher that allows teleportation. They literally just do NOT care. At all.

Re: Valve accused of ignoring existing RCE vulnerability in Source games for 2 years

#104

Earlier quoted context omitted.

> due to Valve's internal structure (or lack thereof) there really isn't any incentive for anyone to fix them This seems to be a common theme with problems at Valve.

This seems common in the industry at large. At my job it's impossible to fix an issue unless someone specifically puts in a ticket for it. I look at all the bugs in the code taunting me. Little landmines either nobody has stepped on yet or was too lazy to write a ticket for. Some tickets languish for years in the tracking system we use until the almighty scrum master doles it out. I am in hell.

At my previous client, the scrum master didn't decide 100% of the work, we could pick a small percentage of technical items to work on.

Re: Valve accused of ignoring existing RCE vulnerability in Source games for 2 years

#105

Earlier quoted context omitted.

Normally, I can handle some cheating in games, you just kinda deal with it, but holy fuck csgo was just nope. Between foul mouthed children and essentially watching God hackers play against eachother while you just die over and over. Yeah....no not exactly fun.

> foul mouthed children Luckily you can now report accounts for this, and with enough reports they will be auto-muted now.

That's good to know. Hearing the squeaky voice of a prepubescent child repeating racial slurs incessantly for 10 minutes straight while giggling to themselves like it's the funniest fucking thing in the world gets a bit grating and kind of tries ones patience. It's not exactly what one typically enjoys listening to while trying to relax and kill some time gaming.

Re: Valve accused of ignoring existing RCE vulnerability in Source games for 2 years

#106
post #104

Earlier quoted context omitted.

This seems common in the industry at large. At my job it's impossible to fix an issue unless someone specifically puts in a ticket for it. I look at all the bugs in the code taunting me. Little landmines either nobody has stepped on yet or was too lazy to write a ticket for. Some tickets languish for years in the tracking system we use until the almighty scrum master doles it out. I am in hell.

At my previous client, the scrum master didn't decide 100% of the work, we could pick a small percentage of technical items to work on.

The scrum master decides the work? Why has agile become such a mess?

Re: Valve accused of ignoring existing RCE vulnerability in Source games for 2 years

#107
post #76

Earlier quoted context omitted.

and, as evidenced by Grand Theft Auto and Counter-Strike, players continue playing with hackers. There is even reason for (say, for example) Rockstar to leave hackers alone in GTA : they act as artificial whales to lure real players into buying in-game currency in order to keep up/seek revenge. There are a few games I can think of off the top of my head that have a symbiotic relationship with hackers.

The kind of hacking that happens in first person shooters has nothing to do with security failures. It is fundamentally impossible to stop aim bots. All you can do is continually play cat and mouse games to make it harder.

Why is it fundamentally impossible to stop aimbots?

Re: Valve accused of ignoring existing RCE vulnerability in Source games for 2 years

#108

Earlier quoted context omitted.

Normally, I can handle some cheating in games, you just kinda deal with it, but holy fuck csgo was just nope. Between foul mouthed children and essentially watching God hackers play against eachother while you just die over and over. Yeah....no not exactly fun.

> foul mouthed children Luckily you can now report accounts for this, and with enough reports they will be auto-muted now.

Pity you need the computer to press mute for you. I do it myself but I don't have a butler either.

Re: Valve accused of ignoring existing RCE vulnerability in Source games for 2 years

#109

Earlier quoted context omitted.

The kind of hacking that happens in first person shooters has nothing to do with security failures. It is fundamentally impossible to stop aim bots. All you can do is continually play cat and mouse games to make it harder.

Why is it fundamentally impossible to stop aimbots?

because it requires you to distinguish between a human's aim and a bot's aim, which is pretty much impossible with a good enough bot

Re: Valve accused of ignoring existing RCE vulnerability in Source games for 2 years

#110
At this point, just leak it to Project Zero anonymously and let them wring Valve's hand for you.

There's a small chance you might still get the bounty, because you reported it first. And if not, because it's already disclosed by another party, you can cry foul on social media.

Post reply on HN