Live data from Hacker News

Valve accused of ignoring existing RCE vulnerability in Source games for 2 years

twitter.com

71–80 of 122 posts

Re: Valve accused of ignoring existing RCE vulnerability in Source games for 2 years

#71
post #64

Earlier quoted context omitted.

> CSGO player will tell you the anti-cheat doesn't work, I know first-hand. > It is in my opinion the greatest loss to gaming that a classic, legendary game like Counter-strike got completely ruined by lack of care by a company that profits millions off of the case unboxings. have you played the game in recent years? this has not been the case for me or the people I play with at all. when playing on high trust-factor…

Just 2 days ago on prime I ran into a string of cheaters. At one point we had 2 on the enemy team and it caused someone on my team to go toggle. 3 cheaters in one match. On old accounts with everything. I know he couldn't be an expert but the person on my team says he can he blatant every game and never get banned because we're on prime. I don't want to believe that but then he had a lot of items and didn't mind spin…

From my understanding the CS:GO matchmaking basically ranks how likely of a cheater it thinks you are, and matches you with people of a similar ranking. If you're queuing with people that are bragging about blatantly cheating you're probably in the "likely cheater" group.

This is all really just anecdotes, but here's my counter anecdote. I play csgo on and off with friends. None of us have ever cheated in csgo (or any other competitive online game for that matter). I'd say we get about 1 obvious cheater every 50 games, with 2-3 less obvious "maybe they're using wallhacks" as well. This is significantly improved from 3-4 years ago where we got a cheater once every 4-5 games.

Re: Valve accused of ignoring existing RCE vulnerability in Source games for 2 years

#73

Dozens of Counter-strike exploits exist and the cheating scene has just grown too rampantly. Valve simply doesn't care about the source engine. Any new CSGO player will tell you the anti-cheat doesn't work, I know first-hand. The lack of care regarding source engine netcode extends to every part of the source engine, including Valve Anti-cheat. The anti-cheat is trivial to reverse (several PUBLIC bypasses have existe…

You found a video that says that they detect most old cheats from hl2 days and ban them and then the video just goes to show random github repos. What is that even supposed to prove? Theres nothing stopping anyone from creating repos with cheats that get detected or don't even work. Like it's just a super cringe "gotcha" type video

Re: Valve accused of ignoring existing RCE vulnerability in Source games for 2 years

#74
post #40
post #26

Earlier quoted context omitted.

> Some game companies (riot games) even install their anti-cheat software so that is loads in the ring 0 space. Why are separate machines required, rather than dual-booting? (i.e. Windows for games, Linux for everything else)

Because Linux and windows bootloaders routinely screw with each other. I am NEVER losing another weekend to that crap again. Dedicated windows gaming PC is the correct way to deal with this.

That's not the case for a long time. I have rEFInd that started life in windows 7 esp with freebsd dual booting, now the same hard-drive booting windows 10 (upgraded from 7, not fresh installation) and nixos, all with the same rEFInd from the same.

The correct way to do so, is to have separate hard-drives for different OS. Then there is zero chance of them stepping on each other.

Re: Valve accused of ignoring existing RCE vulnerability in Source games for 2 years

#76
post #30

Earlier quoted context omitted.

Game devs don't optimize for security, because they're not incentivised to.

And then their MMO/MMORPG server gets p0wned, with everyone taking advantage of extra virtual money, adding assets to their characters for free and auto aiming packet correction.

and, as evidenced by Grand Theft Auto and Counter-Strike, players continue playing with hackers.

There is even reason for (say, for example) Rockstar to leave hackers alone in GTA : they act as artificial whales to lure real players into buying in-game currency in order to keep up/seek revenge.

There are a few games I can think of off the top of my head that have a symbiotic relationship with hackers.

Re: Valve accused of ignoring existing RCE vulnerability in Source games for 2 years

#77
post #3

According to a tweet that was also retweeted by the user @floesen_ who was mentioned in the original thread, the initial report 2 years ago was done using HackerOne but has probably not seen any helpful response from Valve [1]. There are also other reports of Valve not reacting to HackerOne reports appropriately [2]. It is currently unclear whether there is a publicly available PoC or any exploitation going on in the…

HackerOne also at least strongly discourages publishing your findings if the developers refuse to take action.

https://www.hackerone.com/disclosure-guidelines states that "After the Report has been closed, Public disclosure may be requested by either the Finder or the Security Team." - so if the report just doesn't get closed, you can't disclose through the platform, and https://www.hackerone.com/policies/code-of-conduct says "Disclosing report information without previous authorization is not permitted."

To me, that seems that you're not permitted to disclose the issue at all until the report has been closed and either 1) 30 days have passed and the security team hasn't requested an extension, or 2) "180 days have elapsed with the Security Team being unable or unwilling to provide a vulnerability disclosure timeline".

Due to this, I refuse to report through HackerOne.

Re: Valve accused of ignoring existing RCE vulnerability in Source games for 2 years

#78
post #76
post #30

Earlier quoted context omitted.

And then their MMO/MMORPG server gets p0wned, with everyone taking advantage of extra virtual money, adding assets to their characters for free and auto aiming packet correction.

and, as evidenced by Grand Theft Auto and Counter-Strike, players continue playing with hackers. There is even reason for (say, for example) Rockstar to leave hackers alone in GTA : they act as artificial whales to lure real players into buying in-game currency in order to keep up/seek revenge. There are a few games I can think of off the top of my head that have a symbiotic relationship with hackers.

The kind of hacking that happens in first person shooters has nothing to do with security failures. It is fundamentally impossible to stop aim bots. All you can do is continually play cat and mouse games to make it harder.

Re: Valve accused of ignoring existing RCE vulnerability in Source games for 2 years

#79

Dozens of Counter-strike exploits exist and the cheating scene has just grown too rampantly. Valve simply doesn't care about the source engine. Any new CSGO player will tell you the anti-cheat doesn't work, I know first-hand. The lack of care regarding source engine netcode extends to every part of the source engine, including Valve Anti-cheat. The anti-cheat is trivial to reverse (several PUBLIC bypasses have existe…

No anti cheat for FPS games has ever "worked", it can't. The best you can do is make it a little hard for the cheats to keep up with your detectors or protocol changes.

Re: Valve accused of ignoring existing RCE vulnerability in Source games for 2 years

#80
post #60
post #55

It would be a shame if an "anonymous hacker" "hacked" @floesen_, found their notes about the RCE and released it to public, accidentally of course.

It would probably also be a shame when floesen_ got sued for an NDA violation and had to spend tens of thousands of dollars in civil court explaining that they got hacked and it's not their fault.

Someone would have to do the suing though. Who would that be? It could be either Valve, or HackerOne.

HackerOne is almost certainly smarter than doing that because this would immediately ruin their reputation as a bug reporting platform (and expose that they're complicit in suppressing disclosure). They're much more likely to just ban the H1 account or issue some limited penalty.

Valve could potentially try, but the risk here also seems minimal: They also have a reputation to uphold, are experienced enough to know that suing security researchers paints a really bad picture and would draw attention to their vulnerabilities, and especially if their software is full of holes, this would almost certainly cause many people to disclose information about those.

Post reply on HN