Live data from Hacker News

Valve and HackerOne: how not to handle vulnerability reports

blog.jakegealer.me

161–162 of 162 posts

Re: Valve and HackerOne: how not to handle vulnerability reports

#161

Earlier quoted context omitted.

No, not at all: the same LAN access that allows him to spoof DNS also allows him to spoof the authenticated-data bit in the DNS header to bypass DNSSEC. This is one of the great failings of DNSSEC. DoH: different story.

I'm prefacing this with I'm VERY new to DNSSEC (apologies). I guess I always assumed that DNSSEC would blow up when changing the destination of the point but have never really dealt with may DNSSEC rollouts outside of light maintenance. Thanks for a great response, I'm going to formally learn on DNSSEC because this is a good flag that I need better understanding. Also DoH is a new topic to me too so definitely going…

The right way to think of it is that DNSSEC is a server-to-server protocol. It makes it difficult for an upstream authority server to cache a spoofed record in your recursive server. It provides basically no on-the-wire security between your browser and your DNS server.

Re: Valve and HackerOne: how not to handle vulnerability reports

#162
post #4

Important life lesson: drop 0days on twitter, you wont get bounties, but at least you will get recognition and job offers.

Apparently Microsoft hired SandboxEscaper, notorious non responsible disclosure 0day dropper, proving my point rather succinctly. https://twitter.com/SandboxBear/status/1210133985478791171

No tedious 3 day whiteboard interviews there I bet.

Post reply on HN