5 ms·
Companies receive so many "First, you have to be on the other side of this airtight hatch, then you..." reports that anything that looks even remotely like it w
by Saaster 6y ago
Companies receive so many "First, you have to be on the other side of this airtight hatch, then you..." reports that anything that looks even remotely like it will just get summarily closed. My personal favorite ones start with some form of "I copied the user's cookies from device A's file-system, and..."
Just some suggestion on how to report these kind of things, because there is an actual underlying issue here worth fixing. It's good that you didn't mention the reverse proxy. Next, don't say "spoofing an HTTP request" in your first sentence of the report, that's an immediate red flag. If you have access to spoof something on the network, it's already not an issue for 99% of people and an instant low priority. Instead, say "Steam insecurely relies on a redirect response to upgrade the hosted content from HTTP to HTTPS, instead of directly establishing the HTTPS connection". How this can be exploited is now much more general than just being a spoofing issue, with both the problem and solution clearly stated.
- user5994461 6y agoSimply say that there is a typo in the steam configuration, it is connecting to the (insecure) URL http://.. http://... This allows steam network traffic to be intercepted. It can be fixed by correcting the URL to https. For example, somebody using steam from a coffee shop could have his credentials/cookies/accounts intercepted by the coffee shop operator or any other visitor. I believe coffees and other gaming venues are a supported use case for steam and you do not wish to leave your users at risk. IMO There is really no need to blow this out of proportion. It's just a typo. Developers make typos all the time. Bet they're more likely to double check something trivial like that if pointed to.
- restingrobot 6y agoThis is most likely not a typo. The redirect from http to http is most likely due to valve using a self signed ssl certificate and not directly exposing it to ATS, (iPhone). If they went directly to the https endpoint the OS would block the traffic to an invalid, (not CA authority signed), SSL certificate.
- kbenson 6y agostore.steampowered.com is a fully web accessible site with a CA signed certificate though. It's the main steam marketplace. I think the whole point is that they are leveraging this for their app, so using a self-signed CA doesn't make a lot of sense in that case (not that I'm sure it ever would for a company these days, SSL certs are cheap).
- restingrobot 6y agoI don't think you understand. There is no such thing as a "self-signed" CA cert, (its one or the other). This not about money, it's about control. There are many benefits to using a self-signed SSL cert over purchasing a CA one. However, Apple and Android inherently distrust self-signed certs so you have to actually provide the cert directly to ATS/Android OS which involves bundling it within the app, (a messy process). The current industry "hack" is to use http within the app, and then re-direct to https, (which is exactly what the steam app does).
- Arnavion 6y ago>There is no such thing as a "self-signed" CA cert, (its one or the other). Not sure what you're trying to say here. What a cert is signed by and what a cert's usage is set to are orthogonal things. There are CA certs that are self-signed (look in your OS's trusted roots cert store) and there are CA certs that are signed by other CA certs (intermediate CA certs).
- detaro 6y agoWhy does the redirected request accept a self-signed cert, but the initial request doesn't? That seems weird.
- restingrobot 6y agoIt depends on how the app is displaying the link. They could be setting all sorts of cookie info/metadata in the original http request. There are many answers as to why it is accepted. I'm obviously not the developer of the valve app so I can't tell you exactly.
- dsl 6y agoI've been on both sides of this, and sadly having HackerOne/BugCrowd as intermediaries often hurts more than it helps. On one hand I've had to sort through the never ending stream of "if you bypass the safeguards first" issues and some guy in India copying and pasting open source vuln scanner reports. I get why people don't want to deal with this and outsource it. On the other hand, I have a legitimate exploit against GitHub that is "working as intended" for months now. No amount of back and forth is going to convince them that leaking commit messages on enterprise accounts is serious apparently.
- Cpoll 6y ago> No amount of back and forth is going to convince them that leaking commit messages on enterprise accounts is serious apparently. If true, this deserves a write-up. I'm sure a few enterprise accounts might agree, if anyone can see their dev-branch commit named "feature xyz" a month before they announce it.
- chias 6y agoJoke's on you: trying to fix bug maybe this? fuck idk idk idk maybe works k ready now
- Cpoll 6y agoBut also: "fix stupid fucking sql injection"
- avianlyric 6y agoThis sounds far worse than just leaking branch names. They said it’s leaking entire commit messages. Those messages could contain very detailed descriptions of how a companies product works, or how a companies fraud controls operated.
- Cpoll 6y agoSorry, that's what I meant. I should rephrase: a commit message for a commit on the dev branch. I was assuming a relatively lazy commit message as an example. You're correct in identifying that certain organizations might put a lot of information into a commit message.
- staz 6y ago> Companies receive so many [...] reports If only Valve could hire a subcontractor whose task it was to triage and clarify theses reports...
- buildbot 6y agoThe domain and what they are reading off of that filesystem matters though. Like for example, if there was a credential that is in the clear/poorly encrypted and used in other parts of your system.