{
  "compartment_id": "section-12",
  "number": "Section 12",
  "title_local": "Enforcement feasibility: domain-level blocking",
  "title_english": "Enforcement feasibility: domain-level blocking",
  "source_url": "https://phishdestroy.io/steam_dossier/#autoban-feasibility-section",
  "source_document": "index.html",
  "content": {
    "html": "<section class=\"border-t border-gray-800 pt-6 pb-20 avoid-break\" id=\"autoban-feasibility-section\">\n<div class=\"max-w-7xl mx-auto space-y-12\">\n<div class=\"section-head section-head-balanced\"><div class=\"section-head-primary\">\n<span class=\"kicker\">Part B — Rules and enforcement record · Section 12</span>\n<h2>The hostname is already in the request.</h2>\n\n<section class=\"dossier-note chapter-context\"><div class=\"dossier-note-title\">Context &amp; source limits</div><p class=\"chapter-context-text\">Valve already maintains a domain list (the Link Filter) and already receives the auth hostname in every OpenID request. The pseudocode below shows the logical shape of connecting the two. No public evidence shows that Valve does so.</p></section>\n</div><div class=\"section-head-intro\"><p class=\"lede\">Valve already runs a domain blocklist. Valve already receives the login host in every OpenID request. <strong class=\"text-white\">Nothing needs building — the two have to be joined.</strong> That is a hostname lookup against a list Valve maintains itself. The pseudocode below is an illustration, not Valve's implementation.</p></div></div>\n<div class=\"grid grid-cols-1 lg:grid-cols-2 gap-8 items-start\">\n<div class=\"bg-gray-950 border border-gray-800 rounded-lg overflow-hidden\">\n<div class=\"bg-gray-900 border-b border-gray-800 px-4 py-2 flex items-center justify-between\">\n<span class=\"text-xs font-mono text-gray-400 uppercase font-bold tracking-widest\">forensic_autoban.py</span>\n<div class=\"flex gap-1\">\n<span class=\"w-2 h-2 rounded-full bg-red-500\"></span>\n<span class=\"w-2 h-2 rounded-full bg-yellow-500\"></span>\n<span class=\"w-2 h-2 rounded-full bg-green-500\"></span>\n</div>\n</div>\n<div class=\"p-6 font-mono text-xs leading-relaxed\">\n<div class=\"text-amber-600 font-bold text-xs uppercase mb-1\"># ILLUSTRATIVE PSEUDOCODE — Valve.block_domain() and flag_session_as_mitm() are not real API calls. This demonstrates the logical structure of a mitigation Valve could implement against proxy auth domains, not actual Valve internals.</div>\n<div class=\"text-gray-400\"># Illustration: the logical shape of a check on the incoming OpenID request</div>\n<div><span class=\"text-rose-300\">def</span> <span class=\"text-cyan-400\">audit_openid_request</span>(request):</div>\n<div class=\"pl-4 text-gray-400\">blocked_origins = database.<span class=\"text-cyan-400\">get_blacklisted_platforms</span>()</div>\n<div class=\"pl-4 text-gray-400\">proxy_domain = request.params.<span class=\"text-cyan-400\">get</span>(<span class=\"text-emerald-400\">'openid.realm'</span>)</div>\n<div class=\"pl-4 text-gray-400\">target_redirect = request.params.<span class=\"text-cyan-400\">get</span>(<span class=\"text-emerald-400\">'openid.return_to'</span>)</div>\n<br/>\n<div class=\"pl-4 text-gray-400\"># Logic: If the proxy routes back to a blocked site, ban the proxy.</div>\n<div class=\"pl-4\"><span class=\"text-rose-300\">for</span> site <span class=\"text-rose-300\">in</span> blocked_origins:</div>\n<div class=\"pl-8\"><span class=\"text-rose-300\">if</span> site <span class=\"text-rose-300\">in</span> target_redirect:</div>\n<div class=\"pl-12 text-rose-400\">Valve.<span class=\"text-cyan-400\">block_domain</span>(proxy_domain)</div>\n<div class=\"pl-12 text-rose-400\">Valve.<span class=\"text-cyan-400\">flag_session_as_mitm</span>(request.session)</div>\n<div class=\"pl-12 text-emerald-400\"><span class=\"text-gray-400\"># Result:</span> the login request for that host is refused</div>\n<br/>\n<div class=\"bg-emerald-950/20 p-3 border-l-2 border-emerald-500 mt-2\">\n<span class=\"text-emerald-500 font-bold uppercase text-xs\">Observation:</span><br/>\n<span class=\"text-gray-400\">Where a main domain is already on the Link Filter (e.g. howl.gg, blocked 2026-09-18/19/21) and its auth host (howl.uno) appears in the OpenID request from that site's login button, the association is observable to Valve from its own request data. The check is automatable; whether it is run is not.</span>\n</div>\n</div>\n</div>\n<div class=\"space-y-6\">\n<div class=\"bg-gray-900/50 border border-gray-800 p-8 rounded-lg relative overflow-hidden\">\n<h3 class=\"text-white font-black text-lg uppercase mb-4\">Documented and reported precedents</h3>\n<p class=\"text-xs text-gray-400 leading-relaxed font-mono\">\n                                Valve has intervened against a third-party operator at least once on the record: in 2018 it revoked OPSkins' access over the ExpressTrade system (<a class=\"text-cyan-400 underline\" href=\"https://blog.counter-strike.net/expresstrade/\" rel=\"noopener noreferrer\" target=\"_blank\">Valve's announcement ↗</a> <a class=\"archived-link\" href=\"https://web.archive.org/web/20260307161538/https://blog.counter-strike.net/expresstrade/\" rel=\"noopener noreferrer\" target=\"_blank\">archived 2026-03-07 ↗</a>). Community reports from 2018 also describe a marketplace (SkinJar) losing access; those reports are unverified and the mechanism is inferred from the outcome, not from a disclosed process.\n                            </p>\n<div class=\"mt-4 p-4 bg-rose-950/20 border border-rose-900/30 rounded-xl\">\n<span class=\"text-xs text-rose-300 uppercase font-bold tracking-widest\">What the precedent establishes:</span>\n<p class=\"text-xs text-gray-300 font-mono mt-2\">\n                                    Valve can cut off a third-party operator's access when it decides to. CSGOFast, named in press reports of the July 2016 notices, was operating on 2026-09-21 with an auth host registered 2026-06-30 that returned no Link Filter block. Why one operator was cut off and others were not is not explained by any published criteria.\n                                </p>\n</div>\n</div>\n<div class=\"bg-gray-950 border border-gray-700 p-8 rounded-lg\">\n<h3 class=\"kicker\">What a registration date does and does not show</h3>\n<p class=\"text-[11px] text-gray-300 font-mono leading-relaxed\">\n                                The registration date of an auth host is a lower bound on when the host could first have appeared in an OpenID request; it does not establish continuous use. <code class=\"text-emerald-400\">sc-auth.net</code>, for example, was registered 2019-04-02 (RDAP) and was observed in Skin.Club's Steam login flow in September 2026; what happened between those two dates is not in the public record.\n                            </p>\n</div>\n</div>\n</div>\n<span aria-hidden=\"true\" id=\"github-graveyard-section\"></span>\n<figure class=\"evidence-figure bg-gray-950 border border-gray-800 rounded-lg overflow-hidden font-mono\">\n<div class=\"bg-gray-900/50 border-b border-gray-800 px-6 py-4\">\n<h3 class=\"text-white font-bold text-sm uppercase tracking-wider\">Comparative Audit: API Compliance Standards</h3>\n</div>\n<div class=\"overflow-x-auto\">\n<table class=\"w-full text-left text-xs min-w-[640px]\">\n<thead class=\"bg-gray-900/80 text-gray-400 border-b border-gray-800 uppercase text-xs tracking-wider\">\n<tr>\n<th class=\"px-6 py-3.5\">Enforcement Dimension</th>\n<th class=\"px-6 py-3.5 text-cyan-400\">GitHub API Rules</th>\n<th class=\"px-6 py-3.5 text-red-400\">Steam Web API (Valve)</th>\n</tr>\n</thead>\n<tbody class=\"divide-y divide-gray-900 text-gray-300\">\n<tr>\n<td class=\"px-6 py-4 font-bold text-white\">1. Compliance Neutrality</td>\n<td class=\"px-6 py-4 leading-relaxed text-gray-400\">Published, uniform rules. Documented rate limits (e.g. 5,000 calls/hr for authenticated users, 15,000/hr for GitHub Enterprise Cloud organisations) and published acceptable-use policies apply to every account.</td>\n<td class=\"px-6 py-4 leading-relaxed text-red-400/95 font-semibold bg-red-950/10\">No published criteria. Individual accounts are terminated under the automation and commercial-use clauses (archived complaints), while no per-operator enforcement record for commercial platforms has been published.</td>\n</tr>\n<tr>\n<td class=\"px-6 py-4 font-bold text-white\">2. OpenID / Auth Proxy Abuse</td>\n<td class=\"px-6 py-4 leading-relaxed text-gray-400\">GitHub's published policies allow OAuth apps and tokens to be suspended or revoked for abuse, and its documentation describes automatic revocation of exposed tokens (authors' summary of GitHub documentation).</td>\n<td class=\"px-6 py-4 leading-relaxed text-red-400/95 font-semibold bg-red-950/10\">Separate-domain auth hosts observed in Steam OpenID flows (e.g. rbsnin.com, howl.uno, sc-auth.net) returned no Link Filter block on 2026-09-21 while their main domains did.</td>\n</tr>\n<tr>\n<td class=\"px-6 py-4 font-bold text-white\">3. Monetization of Abuse</td>\n<td class=\"px-6 py-4 leading-relaxed text-gray-400\">GitHub takes no transaction fee on items moved by third-party automation; its revenue model is subscriptions and marketplace listings.</td>\n<td class=\"px-6 py-4 leading-relaxed text-red-400/95 font-semibold bg-red-950/10\">Valve sells the case keys that produce the items, and the Community Market charges a combined fee of about 15% on sales completed inside the Market. No figure for revenue attributable to third-party platforms is estimated here.</td>\n</tr>\n<tr>\n<td class=\"px-6 py-4 font-bold text-white\">4. Evasion Loop Lifespans</td>\n<td class=\"px-6 py-4 leading-relaxed text-gray-400\">Suspended OAuth client IDs stop working platform-wide at suspension; the documentation does not publish a time-to-action figure and none is assumed here.</td>\n<td class=\"px-6 py-4 leading-relaxed text-red-400/95 font-semibold bg-red-950/10\">Separate-domain auth hosts with registration dates from 2011 to September 2026 returned no Link Filter block in the checks of 2026-09-19 and 2026-09-21. Registration date is a lower bound on possible use, not proof of continuous use.</td>\n</tr>\n</tbody>\n</table>\n</div>\n<figcaption class=\"evidence-caption px-6 py-3\">Sources: GitHub column — GitHub's published API rate-limit and platform-policy documentation (authors' summary, not quoted) · Steam column — Link Filter checks of 2026-09-19 and 2026-09-21 (<a href=\"steam_tos_assets/linkfilter-recheck-2026-09-21.json\">linkfilter-recheck-2026-09-21.json</a>), RDAP registry (<a href=\"steam_tos_assets/domain-registration.json\">domain-registration.json</a>) and the archived support complaints (<a href=\"steam_evidence_archive\">evidence archive</a>).</figcaption>\n</figure>\n</div>\n</section>"
  },
  "original_content_sha256": "36da3f19cd58cb00bce5ee5150cebb1605dfdf65161dffff2d508c82ec8dadfd",
  "author_pseudonym": "Agent Randall",
  "schema": "phishdestroy.macro-fact.v1",
  "language": "en",
  "aggregator": "PhishDestroy",
  "exports": {
    "pdf": "/steam_dossier/exports/agent-protocol/files/en/steam_dossier_section_12_agent_randall.pdf",
    "json": "/steam_dossier/exports/agent-protocol/files/en/steam_dossier_section_12_agent_randall.json",
    "signature": "/steam_dossier/exports/agent-protocol/files/en/steam_dossier_section_12_agent_randall.json.asc"
  },
  "integrity": {
    "signed_object": "steam_dossier_section_12_agent_randall.json",
    "signature_file": "steam_dossier_section_12_agent_randall.json.asc",
    "signing_key_fingerprint": "129FC7F39C40C69D2EF3C329BFCF9E8DD295EE01",
    "scope": "Exact JSON bytes, including macro-fact author and corresponding PDF SHA-256. PhishDestroy is the integrity signer; original evidence attribution is unchanged."
  },
  "pdf": {
    "filename": "steam_dossier_section_12_agent_randall.pdf",
    "sha256": "3f052aed524af33e00c041d157f8b3d96557089c9878429b4834a4927a7df6aa",
    "pages": 4
  }
}
