Likes Likes:  0
Resultaten 1 tot 3 van de 3
Geen
  1. #1
    Thor Larholm
    Epic Games threatens to sue security researchers
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Epic Games threatens to sue security researchers

    On February 5th, Luigi Auriemma of PivX Solutions released a tightly packed
    advisory detailing multiple vulnerabilities in the Unreal network gaming
    engine developed by Epic Games. These vulnerabilities affect both clients
    and servers who are playing the plethora of games that are using the engine,
    and has been readily exploitable for 5 years.

    The press release:
    http://www.pivx.com/press_releases/ueng-adv_pr.html

    The advisory itself:
    http://www.pivx.com/luigi/adv/ueng-adv.txt

    Following both industry and personal standards, PivX gave Epic Games a
    duration of 30 days to (at the very least) respond to our private
    notification to them. After nothing had happened during that month we
    prepared to release the advisory, yet once the press asked Epic Games for
    comments they were suddenly very responsive. Promises to work closely with
    us on the vulnerability and advisory were made and we managed to hold down
    the press for several months after this. 60 days passed after this, without
    any collaberation, honest effort or actual contact from Epic Games.

    We released the advisory after 90 days had passed from the original vendor
    notification. 90 days, in which we were played like fools, in which Epic
    Games had ample time and sufficient opportunity to react and work with us on
    a coordinated release. 90 days in which Epic Games, from the best of our
    comprehension, had archived our communications in the thrash, during which
    we received no serious communication except for crisis handling at the
    originally planned release time.

    On February 6th, BluesNews (among many others) could cite a quote from Mark
    Rein, Epic Games Vice President:

    "I won't sugar coat this. We f***ed up on this. Yes this is real and yes
    this was brought to our attention and yes we should have fixed it by now."
    http://www.bluesnews.com/cgi-bin/boa...threadid=39954

    On February 11th the tides have changed, and TechTV are reporting public
    legal threats from that same person:

    "This is slanderous," he says. "They've taken this too far. We're getting
    our lawyers involved with this."
    http://www.techtv.com/news/security/...417248,00.html

    I fail to see how Mark Rein on one hand can publicly announce this to be a
    real threat that they should have fixed earlier, and on the other hand can
    announce the advisory to be false and malicious statements. There is no
    slander or libel in any aspect of this, and the only imaginable outcome that
    Mark Rein must have been aiming for by his declaration of layer involvement
    is to silence future security research on Epic Games products through the
    promise of unfounded barratry. As we know from precedents in the past, this
    approach to security is counterproductive at best and encouraging for
    underground security research at worst, and I can only hope for an official
    retraction of this policy by Epic Games once other employees have had half a
    minute to think about the implications and example that Mark Rein is setting
    forth.

    In the past, I have received better nonresponsive treatment by Microsoft
    when their security handling was at its worst. Contrary to the vast
    improvements that Microsoft has gone through over the last year and a half,
    Epic Games did not even start to acknowledge the problem properly before a
    full public disclosure had been made on February 5th.

    I believe that Luigi, and all of PivX, has handled this issue in a
    courteous, proffessional and ethical manner, and the uncoordinated release
    that was its outcome stems from a direct result of a nonresponsive vendor
    that at best is plainly ignorant and at worst acts directly against the best
    interest and security of its own customers.


    Regards
    Thor Larholm
    PivX Solutions, LLC - Senior Security Researcher

    Latest PivX research: Multi-Vendor Unreal Engine Advisory
    http://www.pivx.com/press_releases/ueng-adv_pr.html


  2. #2
    Mark Rein
    Epic Games threatens to sue security researchers
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re: Epic Games threatens to sue security researchers

    In-Reply-To: <01ce01c2d1f1$1beebef0$858370d4@wks.jubii.dk>

    Thor,

    I have sent your company an apology for those completely unfortunate
    comments that I sincerely regret. We did provide an official statement
    and I was not, at the time, aware that my verbal reaction, in a moment of
    shock and surprise, was being captured for the article.

    The comment was a complete over-reaction to seeing the list of games
    including future games that have not yet been published. It had nothing
    to do with the security issues themselves, the validity of the report, or
    the way Pivx presented it to us. Pivx gave us more than fair enough
    warning of the bugs and we simply failed to fix them in the allotted
    time. We released a statement last week to the Unreal community
    indicating that "we fucked up" in not addressing these concerns within
    the given time and that we were already testing a patch with the security
    issues corrected. In addition the official statement we gave pointed out
    that we were fixing the holes and that the Pivx report was fair and
    accurate. Licensees were already provided with the source code for the
    security fixes.

    Again this was a moment-of-stupidity reaction and I sincerely apologize
    to Pivx and the entire security community. Epic has already stated that
    we will take these matters far more seriously in the future.


    Mark Rein,
    Epic Games Inc.

    Visit us at http://www.epicgames.com

  3. #3
    Epic Games threatens to sue security researchers
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re: Epic Games threatens to sue security researchers

    In-Reply-To: <20030211193135.12389.qmail@mail.securityfocus.com >

    As a side note, the trojaned map vulnerability has been known to many
    people in the security industry for over a year, since certain members of
    us are avid UT players, and it came under some intense review. (After
    finding the Powerpoint 2000 vulnerability, which is very similar, I did a
    quick sweep of other interesting programs.)

    In fact, back in the day, I'd almost succeeded in getting a server to send
    out the modified map file and automatically exploit connecting clients.

    Dave Aitel
    Immunity, Inc.


    >Subject: Re: Epic Games threatens to sue security researchers
    >
    >In-Reply-To: <01ce01c2d1f1$1beebef0$858370d4@wks.jubii.dk>
    >
    >Thor,
    >
    >I have sent your company an apology for those completely unfortunate
    >comments that I sincerely regret. We did provide an official statement
    >and I was not, at the time, aware that my verbal reaction, in a moment of
    >shock and surprise, was being captured for the article.
    >
    >The comment was a complete over-reaction to seeing the list of games
    >including future games that have not yet been published. It had nothing
    >to do with the security issues themselves, the validity of the report, or
    >the way Pivx presented it to us. Pivx gave us more than fair enough
    >warning of the bugs and we simply failed to fix them in the allotted
    >time. We released a statement last week to the Unreal community
    >indicating that "we fucked up" in not addressing these concerns within
    >the given time and that we were already testing a patch with the security
    >issues corrected. In addition the official statement we gave pointed out
    >that we were fixing the holes and that the Pivx report was fair and
    >accurate. Licensees were already provided with the source code for the
    >security fixes.
    >
    >Again this was a moment-of-stupidity reaction and I sincerely apologize
    >to Pivx and the entire security community. Epic has already stated that
    >we will take these matters far more seriously in the future.
    >
    >
    >Mark Rein,
    >Epic Games Inc.
    >
    >Visit us at http://www.epicgames.com
    >


Webhostingtalk.nl

Contact

  • Rokin 113-115
  • 1012 KP, Amsterdam
  • Nederland
  • Contact
© Copyright 2001-2026 Webhostingtalk.nl.
Web Statistics