(no title)
EnFinlay | 6 years ago
Obviously it would be better if Valve fixed the issue and gave a (possibly reduced due to out of scope) bounty.
EnFinlay | 6 years ago
Obviously it would be better if Valve fixed the issue and gave a (possibly reduced due to out of scope) bounty.
tptacek|6 years ago
But this is software people install on their desktops, and Valve has no say in how security researchers approach that stuff. Valve can and maybe even should exclude LPEs from their bounty scope (if that's not what they're focusing on right now), but they can't reasonably ban people for publishing vulnerabilities they've scoped out of the only mechanism they've provided for submitting and tracking vulnerabilities.