Apparently the dev used <script> tags to put the Harlem Shake in an Announcement. The dev did it to try to bring attention to the fact <script> tags can be abused. The problem has been around for a while i hear.

Now the dev is banned from steam AND the partner site for a whole year. Link to tweet from dev. I think it is a overreaction from steam imo.

10 years ago*

Comment has been collapsed.

Deleted

This comment was deleted 3 years ago.

10 years ago
Permalink

Comment has been collapsed.

If you find an exploit, shouldn't you get in touch with Valve's developers directly, instead of publicly showing how the exploit works and thereby violating the Steam ToS?

Just saying ...

10 years ago
Permalink

Comment has been collapsed.

Deleted

This comment was deleted 3 years ago.

10 years ago
Permalink

Comment has been collapsed.

That's the case. He tried to contact Valve about it months ago but they said responded that it didn't needed to get fixed. But it's a very serious issue, so this developer tried to get Valve to fix it by using it in a harmless way.

10 years ago
Permalink

Comment has been collapsed.

Except he did, multiple times

10 years ago
Permalink

Comment has been collapsed.

Most of the times, someone needs to be hurt to see something fixed.

Which reminds me of those people fighting for traffic lights for few years and getting them now, AFTER some kid was killed...

10 years ago
Permalink

Comment has been collapsed.

Wrong it doesn't always work that way

10 years ago
Permalink

Comment has been collapsed.

+1 on this. Better to contact Valve about the exploit using a demonstration as opposed to being a stupid troll.

10 years ago
Permalink

Comment has been collapsed.

He did, several times. They never listened.

10 years ago
Permalink

Comment has been collapsed.

to put the Harlem Shake in an Announcement
Now the dev is banned from steam AND the partner site for a whole year

Seems like a fair punishment

10 years ago
Permalink

Comment has been collapsed.

What's the punishment for green text?

10 years ago
Permalink

Comment has been collapsed.

LOng story short, there was an exploit on Steam which allowed the use of <script> tags in announcements and Timmy saw that as a big security flaw and how it could be misused for nefarious purposes. He mailed Valve and warned them multiple times about it and their response was something along the lines of "we are aware of it but we trust devs to no abuse it so everything will be fine"
So last night he edited his old announcement and made the whole page do the harlem shake, with audio and shaking letters and everything (i'm not kidding). Now after few months or even more of allowing that exploit, Valve immediatelly fixed it and gives him a year long community ban and revoked his Steamworks partner access

10 years ago
Permalink

Comment has been collapsed.

thanks for the explanation :)

10 years ago
Permalink

Comment has been collapsed.

Volvo doing it's job again.

10 years ago
Permalink

Comment has been collapsed.

Stupid Volvo's...

10 years ago
Permalink

Comment has been collapsed.

Linky for steam harlem shake
Haha omfg. Quite funny.

10 years ago
Permalink

Comment has been collapsed.

Thanks for the link, never seen an exploit like it

10 years ago
Permalink

Comment has been collapsed.

Okay, that's hilarious. Best use of that stupid song I've seen, by far.

10 years ago
Permalink

Comment has been collapsed.

thanks for the video. awesome.

10 years ago
Permalink

Comment has been collapsed.

IMO he was dumb to bother about it anyway. It wasn't HIS thing to fix how Steam works anyway. If Steam staff thought it didn't have any dangers to their platform, I don't know why a game dev would bother to put his nose where it doesn't belong.

10 years ago
Permalink

Comment has been collapsed.

If Steam staff thought it didn't have any dangers to their platform, I don't know why a game dev would bother to put his nose where it doesn't belong

LOL

"It permitted running arbitrary JavaScript within the page. Considering there are cookies involved in the authentication, a malevolent script could likely steal session information or maybe even login data. In general, running JavaScript within a secured session (SSL) is about the worst that can happen for a site with login security.
Timmy showcased this by running some Harlem Shake script (nuisance only - not malevolent otherwise) in an older announcement after Valve did nothing in respect to resolve the hole.
So yeah, anyone permitted to post community announcements was able to run scripts within your browser session. Now, somebody who obtained such access by for example breaching a Steamworks partner's login information - you know just the way it happened a few months ago when Valve's servers were hit by Heartbleed exploits could in theory sniff login information of Steam users"

Yeah no dangers at all except maybe sniffing out your session ID or redirect you to a phishing site

10 years ago
Permalink

Comment has been collapsed.

You'd hope that session id's be limited to single IP or people check SSL certificate and URL before giving login info.

10 years ago
Permalink

Comment has been collapsed.

So, if someone finds out there's a fault with a car/plane but the manufacturer says's there's nothing wrong with it he should just shut up and do nothing?
Oh, wait a minute, isn't GM in the news a lot lately? Hmm, if only someone had gone public earlier ...

10 years ago
Permalink

Comment has been collapsed.

Dev abuses a security flaw, publicly ridicules Valve, wonders why he's now banned. Sounds legit.

10 years ago
Permalink

Comment has been collapsed.

^ sounds stupid because Valve support permitted to use that script

10 years ago
Permalink

Comment has been collapsed.

Yes and? They said they knew it was a flaw but trusted devs.

Just because Valve acknowledges it and says it trusts devs, does not mean it is not a security flaw. They trusted devs in spite of it being a flaw. English comprehension fail.

10 years ago
Permalink

Comment has been collapsed.

What is not forbidden is allowed (c)

10 years ago
Permalink

Comment has been collapsed.

Valve are bastards. Who would have thought?

10 years ago
Permalink

Comment has been collapsed.

TIMMY!!!!! NOOOOO!!!!

On a side note, Steam already hated ETS2 and Timmy, they keept banning his artwork. D:

10 years ago
Permalink

Comment has been collapsed.

Why did/do they hate him? Some context please.

10 years ago
Permalink

Comment has been collapsed.

I just said? :p

They banned a ton of his ETS2 artwork.

10 years ago
Permalink

Comment has been collapsed.

That doesn't explain why they hate him.

10 years ago
Permalink

Comment has been collapsed.

dafuq

10 years ago
Permalink

Comment has been collapsed.

Deleted

This comment was deleted 3 years ago.

10 years ago
Permalink

Comment has been collapsed.

Wow dude, just chill.

10 years ago
Permalink

Comment has been collapsed.

You said: 'should' be well mannered. Think about it.

Remember Muxwell? Since greenlight it's impossible to trust them :p

10 years ago
Permalink

Comment has been collapsed.

And if a Steamworks Partner's login info is compromised? Always better to patch holes than ignore them.

10 years ago
Permalink

Comment has been collapsed.

Deleted

This comment was deleted 3 years ago.

10 years ago
Permalink

Comment has been collapsed.

What if someone manages to steal cookies (that include steam guard data)?

It's not like it hasn't happend before.

http://steamdb.info/app/202970/history/

10 years ago
Permalink

Comment has been collapsed.

You can't just leave major security flaws in because you think nobody will ever abuse it. When hundreds/thousands of people become involved, it's just a matter of time.

10 years ago
Permalink

Comment has been collapsed.

...so I guess this means ATS is delayed for a year? ;P

10 years ago
Permalink

Comment has been collapsed.

Yeah, Steam tends to like banning people for stupid reasons. Oh well.

10 years ago
Permalink

Comment has been collapsed.

They made an example of him, so other devs won't try to make Valve look stupid in the future. They'll probably unban him once attention is turned away.

10 years ago
Permalink

Comment has been collapsed.

☐ not rekt ☑ rekt

10 years ago
Permalink

Comment has been collapsed.

10 years ago
Permalink

Comment has been collapsed.

THIS IS VALVE!

bunch of morons

10 years ago
Permalink

Comment has been collapsed.

what do script tags actually do?

10 years ago
Permalink

Comment has been collapsed.

Deleted

This comment was deleted 3 years ago.

10 years ago
Permalink

Comment has been collapsed.

Are there screens / footage? I am CURIOUUUS. Yees.

10 years ago
Permalink

Comment has been collapsed.

Well, google bans forever, at least VALVE bans for 52 weeks

10 years ago
Permalink

Comment has been collapsed.

http://en.wikipedia.org/wiki/Responsible_disclosure <<<
He says that he "...talked about this with a Valve guy few months ago," but that could mean anything. Unless he gives more information about his communication, I don't see how it isn't deserved (though it might not be; as of now I don't know what he did).

Regardless, he's an idiot to post it on an account with such such publicity. Doing things like this are what alts are for.

10 years ago
Permalink

Comment has been collapsed.

Considering the only people with access to the exploit are presumably trustworthy developers, it probably wasn't a top priority. I mean why would you jeopardize your livelihood over something so dumb? I just don't get it.

10 years ago
Permalink

Comment has been collapsed.

Did you forget about greenlight? Look at Earth 2066 or so.. It's just a matter of time till someone with bad intentions was gonna do it.

10 years ago
Permalink

Comment has been collapsed.

Well. The lightning quick response from Valve was surprising.

10 years ago
Permalink

Comment has been collapsed.

We need to sigh some petition to help this guy out! The whole story makes Valve a bunch of morons

10 years ago
Permalink

Comment has been collapsed.

so does this mean no more updates?

10 years ago
Permalink

Comment has been collapsed.

Looks like he deleted the tweets

10 years ago
Permalink

Comment has been collapsed.

link is broken, feel sorry for him......

10 years ago
Permalink

Comment has been collapsed.

10 years ago
Permalink

Comment has been collapsed.

Deleted

This comment was deleted 3 years ago.

10 years ago
Permalink

Comment has been collapsed.

Closed 10 years ago by Gramis.