3 ms·
The vulnerability, on the high level, is that the Steam app doesn't verify that the store page comes from Valve, meaning that if you own a Wifi hotspot you can
by tadzik_ 6y ago
The vulnerability, on the high level, is that the Steam app doesn't verify that the store page comes from Valve, meaning that if you own a Wifi hotspot you can potentially scam and cheat the users of the Steam app. This wouldn't have been possible with basic use of SSL by the app.
That's what makes this bizarre – the negligence of developers, the triviality of the fix and the complete lack of understanding from people who are supposed to be reviewing security issues.
- user5994461 6y agoThe report could have been better worded IMO, it hardly explains the trivial issue or the trivial fix. Preferring to go at length about what if the ISP is hacked and other crazy scenarios. It wouldn't hurt to say that they simply have a typo in the URL. http instead of https.