protonscr

[Vulnerability] Webpage where downloads of steam are is not encryped

steamclosed reviewed
ValveSoftware/steam-for-linux#4276 · opened 2016-01-23 by ghost · updated 2019-02-22 · 12 comments · github
?ghost 2016-01-23 github

This makes a rather easy man in the middle attack to change the urls and deliver mallware instead of the steam client
http://store.steampowered.com/about/

Xxplt 2016-01-24 github

a) This is not "vulnerability"
b) This is duplicate of your own https://github.com/ValveSoftware/steam-for-linux/issues/4216

?ghost 2016-01-24 github

a) It could lead to a possible security compromise of a computer
b) This isn’t a duplicate of my other bug as the other calls for all pages to be encrypted

Xxplt 2016-01-24 github

a) This is incorrect. Rephrasing one person that said in yet another of
your recent bugs: if you don't trust your ISP (,or use open WiFi or smth),
then nothing will protect you. Is it Steam's vulnerability, that you use
connection, which cannot be trusted? No, it isn't, though usage of HTTPS
would be a nice privacy feature.
b) Of course, it's up to VALVe, but in my eyes, a ticket which is a subset
of already reported issue is exact duplicate.

24 янв. 2016 г. 11:15 PM пользователь "ekaris" [email protected]
написал:

a) It could lead to a possible security compromise of a computer
b) This isn’t a duplicate of my other bug as the other calls for all
pages to be encrypted


Reply to this email directly or view it on GitHub.

?ghost 2016-01-24 github

a) No, it's correct. So according to you it's the users fault that live in china of having an insecure internet because of the government for example or the USA with the NSA and valve should not make any changes that could help.
It's seems you’re not here to help so I invite you to go comment on bug reports from other users instead.

MMrSchism 2016-01-24 github

One of the issues here is that Valve's downloads go through a verification before being setup. If your download was hijacked, when the game went to install, it would fail the check and be deleted and the client would try again.

It's also worth mentioning that Valve could enable encryption, yes. However, they could catch some major flack from governments where encryption is outlawed. They'd have to compromise and make a localized encryption and if you bypass that, you not only break the law, but violate the Subscriber Agreement and risk losing your games anyways.

?ghost 2016-01-25 github

Encryption in HTTPS isn’t being undermined, actually that would be rather stupid because same technology protects critical stuff, banks,etc what is protested by some governments is encryption by default on apple and google user devices like cellphones and that has nothing to do with the internet websites

MMrSchism 2016-02-03 github

Except that encryption --entirely-- is state-controlled in Myanmar, Israel, China, Pakistan, Russia, Saudi Arabia, and Tunisia. That's ignoring countries where Valve shows no traffic on their global map, countries with embargoes between themselves and the US, or have vague legislation.

It's not an exhaustive list, either. There are others. For those countries, Valve would have to apply for license in those countries and surrender security keys (which, why bother at that point?). Valve functions internationally and has to deal with the governments of the people they serve.

On a broad level, encryption isn't being undermined by governments so much as... it was undermined long ago (even by the US) and it's only recently becoming more acceptable as global cyber threats make it obvious to be needed.

Xxplt 2016-02-03 github

"Except that encryption --entirely-- is state-controlled in <...> Russia <...>."

This is not true, unless VALVe want to communicate with Central Bank of Russia, Pension Fund or other government services [or develop their own suit of crypto-stuff] :) I haven't heard about any issues about companies which use non-GOST crypto algorithms. Though, some companies fear that it puts Russia into the "vague legislation" basket.
[But all of this is offtopic, maybe we should continue conversation somewhere else?]
Edit: Ok, things are getting complicated and you were a bit more farsighted than me...

Mmdeguzis 2016-02-17 github

You might as well submit a plethora of bug reports to the official Debian mirrors page. Half of them are http downloads.

?ghost 2016-02-17 github

You might as well go fill them yourself and comment elsewhere

CCommanderAlchemy 2016-02-19 github

@MrSchism Though because of few countries undermine their citizens privacy doesn't mean that it should be a common rule for all other customers. Why not add HTTPS to everyone else if this is such a big trouble?

I mean, should everyone on the web ditch HTTPS just because of these few countries?

Kkisak-valve maintainer 2019-02-22 github

Migration to HTTPS happened a fair while ago, closing.