meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Friday, August 23rd 2019

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 23 August 2019

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Steam Double 0; Malicious npm Packages; Branded Outlook 365 Phishing Pages

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Friday, August 23rd, 2019 edition of the Sands and at Storm Center's Stormcast.

0:08.1

My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida.

0:13.5

Today I'll start out with a story that has sort of been developing all weekend.

0:17.7

That's about, well, how Valve kind of misstepped in bug bounties.

0:25.3

Valve is the company behind the popular online gaming platform, Steam, and Steam is offering

0:31.3

a bug bounty via the Hacker One platform.

0:35.1

Vasily Kravitz is a researcher that recently found a privilege escalation flaw in

0:41.4

Steam and reported it via the Hackerman platform, of course expecting a reward. What instead happened

0:49.1

was that Valve told him that the privilege escalation flaws are really sort of out of scope for Steam.

0:56.6

So he shouldn't expect any bug bounty for this particular flaw.

1:02.7

And that's sort of where some arguing apparently started between cravets and Valve,

1:07.0

which resulted in cravets being kicked out of the Buck Bounty Program.

1:13.2

It's of course always a difficult decision here to accurately identify the value of particular

1:19.6

vulnerabilities and has happened before that the reporter of a vulnerability and the company

1:25.6

that owns the product don't necessarily agree on the severity.

1:30.2

To put us a little bit in perspective, Steam is really a platform to run code. As a developer,

1:36.6

you can develop a game that runs within this Steam, essentially virtual machine, and with that,

1:43.6

your game can run on whatever platform is supported by Steam, which virtual machine, and with that, your game can run on whatever platform is

1:46.2

supported by Steam, which of course, no sort of increases the reach of a particular game.

1:52.4

But this makes it really difficult for Steam to actually prevent pervage escalation flaws,

1:58.2

in particular since some components in Steam run as administrator

2:03.5

so they have full low level access to things like graphics drivers and the like, which of course

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.