3 ms·
>For a simple MITM exploit that can be fixed by replacing "http://" http://" with "https://" https://", this is simply unacceptable. I think the author is real
by restingrobot 6y ago
>For a simple MITM exploit that can be fixed by replacing "http://" http://" with "https://" https://", this is simply unacceptable.
I think the author is really not understanding the complexity of updating to an https:// https:// url inside of a mobile applicaiton. Valve is most likely using a self signed cert so that would require bundling the certification in with the app so that Apple/Android allowed it to load inside of a webview. This is not nearly as simple as just updating all of the urls in the app to https:// https:// and the fix could very well take a few months. Furthermore, loading the store page is not necessarily a vulnerability to valve as if you are able to re-direct it, you wouldn't have access to any of the Steam user specifics, (like account data). It wouldn't be much different than putting a shady link somewhere on the internet, and people navigating to it.
- odensc 6y agoSteam is not using self-signed certs. store.steampowered.com is their main user-facing storefont. Why would they "most likely" be using a self-signed cert? That would be an extreme edge-case in my mind, not the standard.
- restingrobot 6y agoI meant most likely as in a as to why they do the http to https redirect. I have seen this from several other apps, I don't think its extreme, but my guess is just based on the redirect seeming to be intentional. I should probably have said "this could possibly be because", rather than "most likely".
- djsumdog 6y agoWhy would they use a self signing cert? They could use a real Cert. It's Steam. They can afford real certs, or just use LetsEncrypt. There is absolutely no reason for the app to connect to a login/authentication service (or any service) over plain text, period! There should be unit tests that scan for http:// http:// and will fail the build if found in the code or resources. I know some things are not simple fixes, but this is absolutely a fix that can be done and we should all know how to do. It should have also been made a security priority and pushed through.
- restingrobot 6y agoA self signed cert is a a real cert, its just not provided by an CA authority. I guarantee you this http just redirects to an https location, (just tested it on my own device), so there is no plain text transfer. In the mobile industry this happens all the time as backend endpoints grow and change.
- nicholashead 6y agoThe bottom line is, there's no reason to request the non-HTTPS connection in the first place. And there's apparently no checks in the app to make sure it's connected to their real server.
- restingrobot 6y ago>The bottom line is, there's no reason to request the non-HTTPS connection in the first place. The example I gave wasn't to excuse the issue, it was to maybe explain why the fix is taking so long. > And there's apparently no checks in the app to make sure it's connected to their real server. I don't think you can make that statement. The description of the issue only attempts to hi-jack the session, he didn't actually try to do anything with it. There may very well be checks in place.
- pgo 6y agoWhat you are saying makes no sense, why does android only accept the self signed certificate when it redirects from http and not for direct https connections. Can you provide a source, a stackoverflow link maybe where this problem is discussed ?