Valve patches recent Steam 0-days, calls turning away researcher who found them “a mistake”, and updates bug bounty program to start accepting “LPE"-class bugs
The whole approach, if you're a major software dev company who has the resources to do your own security disclosure & bug bounty programs, of relying on a third party firm to determine what your relationship with the security research community will be like is ... questionable. h…
Valve patches recent Steam zero-days (both of them), calls turning away researcher ‘a mistake’ -also updates bug bounty program rules to accept LPEs -is also reviewing researcher's ban https://www.zdnet.com/... https://twitter.com/...