Live data from Hacker News

Researcher banned on Valve's bug bounty program publishes second Steam 0-day

zdnet.com

111–120 of 214 posts

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#111
post #49

Earlier quoted context omitted.

Without seeing the communications it's hard to say, but "When the security researcher -- named Vasily Kravets-- wanted to publicly disclose the vulnerability, a HackerOne staff member forbade him from doing so, even if Valve had no intention of fixing the issue" sounds like more than just not being able to disclose on the H1 program.

I submitted an XSS on the tesla website to hackerone, it was marked as a duplicate. A week later, shared it with an XSS mailing list and got an angry email from HackerOne soon after. Public disclosure violates the terms of their reporting program EVEN if they reject your report. I'm really curious how much of what is reported to HackerOne ever gets and actual patch. It kind of seems like there are bunch of known vuln…

If they get a duplicate report they should let you know the disclosure timeline and keep you posted on progress fixing it. If they're not doing that they have no right to prevent disclosure.

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#112
post #98

Earlier quoted context omitted.

I love games and can’t play my steam collection now. But if I have to give that up so that some silly bug elsewhere in my system doesn’t expose me to a ransomware attack (or worse), so be it. I’ll find another way.

You should be able to play games in your steam library. Just open your Steam\steamapps\common\ folder and find the exe for the game you want to play.

Steam's DRM (CEG) customizes the executables so it won't play without the Steam client running and logged in to the correct account. There are lots of not-DRM-enabled games on Steam, but they're decidedly in the minority.

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#113
post #68

Earlier quoted context omitted.

The meta-process might work, Valve's process is still broken.

Everybody makes mistakes, lets see if they can learn from theirs. I haven't heard that they keep making this same mistake (but I could be wrong.)

This happened end of June, they should have had ample time to reach out to @viss, make amends and change their process.

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#114
post #96

Earlier quoted context omitted.

A normal process goes like this: - Researcher finds bug - Researcher discloses to vendor - Vendor fixes (or not) - Researcher discloses bug publically once vendor has fixed, or after X time (whichever is first) This is roughly how Project Zero goes, and it's a good mix between giving the vendor the opportinity to fix it and deploy the update before it gets exploited. It's very naive to assume that bugs can be fixed b…

Why is it whichever is first and not after a fixed time? I see a benefit to waiting X time regardless, because it allows more time for the patch to circulate to everyone. What is the benefit to disclosing it immediately after it is "fixed"?

The vulnerability can often be discerned from the patch. Burying it amidst lots of unrelated bogus changes and not calling out its security relevance is going to annoy your users.

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#115
post #98

Earlier quoted context omitted.

I love games and can’t play my steam collection now. But if I have to give that up so that some silly bug elsewhere in my system doesn’t expose me to a ransomware attack (or worse), so be it. I’ll find another way.

You should be able to play games in your steam library. Just open your Steam\steamapps\common\ folder and find the exe for the game you want to play.

Nope, that won't work for most Steam games. However, that's why there's GOG (gog.com), DRM free games. You can download the game installation kits using your browser and if you ever decide to stop accessing their site (or stop having access to the Internet) you can still play/install downloaded games.

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#116
post #62

This sucks. We run steam on some public PCs with unprivileged accounts and we wouldn't be very happy to find that users were able to gain admin access and steal other people's passwords through a keylogger. Sigh.

That seems to me the most obvious problem use case here. How can Valve possibly think that isn't important?

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#117

Valve figured out how to print money by hooking teenagers with gambling on loot boxes. They stopped having to create AAA titles, they stopped having to do anything remotely creative, and now they are a giant cancer with no value left to add. Their client is an insecure, slow, instable piece of shit and has been this way for well over a decade. I regret being a customer of theirs.

> Their client is an insecure, slow, instable piece of shit And yet, it's still the best client out there. If you want slow and instable(sic!) try competition. Steam client is actually fast and stable compared to what else is on offer.

It's actually not better than Blizzard or EA's client at this point. I will agree it is better than Epic and Bethesda launchers.

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#118

Earlier quoted context omitted.

You're beating a dead horse. Flash served a purpose once, and now it's reached end-of-life.

> You're beating a dead horse With a foam bat. Just because the flash horse is dead doesn't mean it didn't deserve it's beating or can't continue to be a potent reminder of how bad Adobe was at handling security issues and why other platforms, like Steam, should learn instead of emulate.

I'd prefer to describe it as slashing a dead horse's rotten corpse with a katana. As the bloat and flesh of the ecosystem has disintegrated we're able to observe the framework more clearly - the bone structure of the horse, if you will. Using the katana we are making precise, incisive blows to the remnants as we extract meaning from it's corpse - or lessons learned, if you will.

...perhaps I'm taking the analogy too far?

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#119

Earlier quoted context omitted.

You should be able to play games in your steam library. Just open your Steam\steamapps\common\ folder and find the exe for the game you want to play.

Steam's DRM (CEG) customizes the executables so it won't play without the Steam client running and logged in to the correct account. There are lots of not-DRM-enabled games on Steam, but they're decidedly in the minority.

That's why GOG.com is my first choice. They even provide a nice Steam-like installer (unfortunately, no Linux version of the installer), while letting you download your games DRM-free, archivable and standalone.

Re: Researcher banned on Valve's bug bounty program publishes second Steam 0-day

#120
post #64
post #49

Earlier quoted context omitted.

I submitted an XSS on the tesla website to hackerone, it was marked as a duplicate. A week later, shared it with an XSS mailing list and got an angry email from HackerOne soon after. Public disclosure violates the terms of their reporting program EVEN if they reject your report. I'm really curious how much of what is reported to HackerOne ever gets and actual patch. It kind of seems like there are bunch of known vuln…

> HackerOne should start requiring companies pay researchers for duplicates That would create a perverse incentive for researchers to tell their friends about the vulnerability so that they can resubmit it and also get a bounty. The problem could be solved on the side of the researchers by splitting the bounty among all submissions of the same bug, but anyone else with access to the report (employees of either Hacker…

> First come, first served seems like it would be the hardest to game

For external parties, yes. However it's the easiest to game for those liable, since you can just mark whatever you want as a "duplicate" and refuse to pay the bounty.

Offering bounties for public disclosures helps remove a lot of perverse incentives.

Post reply on HN