Live data from Hacker News

Counter-Strike Global Offsets: reliable remote code execution

secret.club

51–60 of 94 posts

Re: Counter-Strike Global Offsets: reliable remote code execution

#52

Another example is why app level security is so important. Why shouldn’t games allow arbitrary code execution? It only matters because the access space for programs is still so broad. People complain when applications on Mac request permission to access files, but that makes such a huge difference. It’s time for kernel level permissions to be standard on desktops.

> It’s time for kernel level permissions to be standard on desktops. And then the games industry starts deploying vulnerability-as-a-service kernel modules in order to bypass all of those controls. https://mobile.twitter.com/TheWack0lian/status/7793978407622...

That ship has long sailed. All the major anti cheat systems do this now, and have done for years.

Re: Counter-Strike Global Offsets: reliable remote code execution

#53

meanwhile they spend billions with VR nobody wants, controllers nobody wants, linux OS nobody uses, smart tv integration nobody cares about, etc cs:go at this point is a cheater's game. because valve's server ain't reliable at all, some people choose to play on third party servers, and not surprisingly a lot of players had the third party client mining bitcoin on their computer [0]. much blame the service, but it's o…

I don't know about you but I use linux. I was pleasantly surprised to find CSGO running smoothly on it.

Re: Counter-Strike Global Offsets: reliable remote code execution

#54
post #39

Another example is why app level security is so important. Why shouldn’t games allow arbitrary code execution? It only matters because the access space for programs is still so broad. People complain when applications on Mac request permission to access files, but that makes such a huge difference. It’s time for kernel level permissions to be standard on desktops.

> Why shouldn’t games allow arbitrary code execution? Well, for one thing, to maintain the integrity of online games, protect personal data from the game itself and help prevent theft of in game assets... so I think there’s no strong win here. Yes it would be good if CS:GO exploits couldn’t reach out and hit your Bitcoin wallet or what have you, but you can’t really just give up entirely either. There’s by-design goi…

TLDR, but I think ancestor was talking about games being permitted to execute arbitrary code, as opposed to privileged users being able to inject code into a game process…

Re: Counter-Strike Global Offsets: reliable remote code execution

#55

meanwhile they spend billions with VR nobody wants, controllers nobody wants, linux OS nobody uses, smart tv integration nobody cares about, etc cs:go at this point is a cheater's game. because valve's server ain't reliable at all, some people choose to play on third party servers, and not surprisingly a lot of players had the third party client mining bitcoin on their computer [0]. much blame the service, but it's o…

This is a bit selfish view. I loved their controller, I love steam link allowing me to seamlessly play from any room (with whatever controller I want). I use Linux and think that vr is something everyone should try at some point. I know that you maybe couldn't care less about these things, but don't exacerbate the argument by saying "nobody".

Besides, cs started with 3rd party servers and have always been there. Many people have never transitioned to the official matchmaking and I don't think that's necessarily a bad thing.

I just think that your comment is a bit too salty on HN's standards.

Re: Counter-Strike Global Offsets: reliable remote code execution

#56

meanwhile they spend billions with VR nobody wants, controllers nobody wants, linux OS nobody uses, smart tv integration nobody cares about, etc cs:go at this point is a cheater's game. because valve's server ain't reliable at all, some people choose to play on third party servers, and not surprisingly a lot of players had the third party client mining bitcoin on their computer [0]. much blame the service, but it's o…

This is a bit selfish view. I loved their controller, I love steam link allowing me to seamlessly play from any room (with whatever controller I want). I use Linux and think that vr is something everyone should try at some point. I know that you maybe couldn't care less about these things, but don't exacerbate the argument by saying "nobody". Besides, cs started with 3rd party servers and have always been there. Many…

Good for you mate that you enjoyed all that. I'm just pointing out they do a poor job on cs security and anti-cheat and communication in contrast to other efforts on the company like these, and it's cs who made steam possible, not that other stuff.

3rd party servers are different from 3rd party services.

Re: Counter-Strike Global Offsets: reliable remote code execution

#57

Another example is why app level security is so important. Why shouldn’t games allow arbitrary code execution? It only matters because the access space for programs is still so broad. People complain when applications on Mac request permission to access files, but that makes such a huge difference. It’s time for kernel level permissions to be standard on desktops.

I haven't dug very much into it (in fact mainly because I couldn't find much detailed/technical information) but Windows 10 has this "core isolation" feature, which I believe tries to achieve a system/apps isolation by virtualizing everything.

It used to be a little buggy, but I now have it enabled all the time and don't necessarily feel any performance issue - on a powerful laptop with reasonable usage.

If anyone has more technical information about the feature I'd be very interested to see more about it and what it exactly does - is it really effective or just a lure?

Re: Counter-Strike Global Offsets: reliable remote code execution

#58

Valve should be kicked off HackerOne. They seem to abusing the service to trick researchers into submitting vulnerabilities without providing any sort of compensation. Does anyone here work at HackerOne?

No experience with Valve but are not alone in being cheap:

I submitted the bug where you I proved you could make predictions about a password in Microsoft just by using ctrl + arrow keys.

It wouldn't have been much anyway but I wouldn't have been surprised if they sent me some swag or something - instead I was surprised about how short the thank you mail was ;-)

(They said it wasn't a security issue but at least it was fixed in the next release :-P)

Edit: I later found a reliable way to run the encryption tools the correct way with the tooling in Azure Information Protection that still leaves the files unencrypted (so simple it can happen by accident, that's how I found it, useful for data exfiltration with plausible deniability) and besides the integration of information protection in Sharepoint is so extremely broken that depending on how you log in, SharePoint will easily serve you the files unprotected.

Between not finding the correct way the report it and the very "meh" feeling on my first find I only tried to report those onve or twice and then gave up.

Re: Counter-Strike Global Offsets: reliable remote code execution

#59

meanwhile they spend billions with VR nobody wants, controllers nobody wants, linux OS nobody uses, smart tv integration nobody cares about, etc cs:go at this point is a cheater's game. because valve's server ain't reliable at all, some people choose to play on third party servers, and not surprisingly a lot of players had the third party client mining bitcoin on their computer [0]. much blame the service, but it's o…

I use linux and appreciate that Steam has support for it. Fact: their Linux OS is the primary reason why I use Steam.

Re: Counter-Strike Global Offsets: reliable remote code execution

#60

Another example is why app level security is so important. Why shouldn’t games allow arbitrary code execution? It only matters because the access space for programs is still so broad. People complain when applications on Mac request permission to access files, but that makes such a huge difference. It’s time for kernel level permissions to be standard on desktops.

> It’s time for kernel level permissions to be standard on desktops. And then the games industry starts deploying vulnerability-as-a-service kernel modules in order to bypass all of those controls. https://mobile.twitter.com/TheWack0lian/status/7793978407622...

This can’t be more horrifying
Post reply on HN