Hello @TiagoTiago, without a better explanation on how this is a problem, I'm not seeing an actionable issue here.
Minidumps should not have sensitive information in them and it should be going to a crash report collection server that already needs to guard against malicious intent regardless of protocol used.
Hello @TiagoTiago, without a better explanation on how this is a problem, I'm not seeing an actionable issue here.
Minidumps should not have sensitive information in them and it should be going to a crash report collection server that already needs to guard against malicious intent regardless of protocol used.
They include all sorts of details about the hardware, folder structure, settings, drivers and software versions etc; way more than enough to fingerprint a computer, and potentially revealing information that may make things easier for a hacker. Even if Valve's servers are secure, there's still the whole rest of the Internet to worry about if the information is transmitted in plaint text.
Not to mention that by listing hardware components in the open, there's the risk some disgruntled ISP worker could use the data to figure out who got more money, and since the ISP knows where you live, the disgruntled worker might even be able to copy-paste your address on Google Maps when planning the burglary...
Nothing extracted yet.