4 ms·
My experience with valve on HackerOne was when I discovered an easy way to lag, and if exploited crash, a dota 2 server. It was nothing technically fancy, but s
by throwawaythekey 5y ago
My experience with valve on HackerOne was when I discovered an easy way to lag, and if exploited crash, a dota 2 server. It was nothing technically fancy, but something that made it easy for griefers to ruin the game for everyone. I think even spectators to the match could trigger the functionality.
They turned me down for any reward - I don't remember the exact wording in their policy but I think it was a generic exclusion of DOS and DDOS vectors. I thought I should've still been eligible as my exploit was simple and only required a low input frequency. The bureaucratic process of the whole thing scared me from doing anything more and I was happy enough that they would fix the vulnerability and I could get back to enjoying the game.
I think it's five years later and the problem still exists, and regularly reduces the quality of my games.
- rasz 5y agoIt would be awful if after 5 years someone independently rediscovered this vulnerability and tweeted reproduction steps.
- anonymousab 5y agoAt some point it is more responsible to make the exploit public and spark public pressure for a fix, than to let Valve ignore exploits while each day is a roll of the dice on a bad actor discovering them. If they don't feel the pain, again and again for things like this then there will never be any impetus to change. This isn't your responsibility of course. I'm just saying that disclosure at this point would be anything but irresponsible. Maybe not in the middle of a big tournament, I suppose.