{
  "compartment_id": "section-19",
  "number": "Section 19",
  "title_local": "The Subscriber Agreement against the platform's own architecture",
  "title_english": "The Subscriber Agreement against the platform's own architecture",
  "source_url": "https://phishdestroy.io/steam_dossier/#tos-structural-void",
  "source_document": "index.html",
  "content": {
    "html": "<section class=\"border-t border-gray-800 pt-6 accountability-section\" id=\"tos-structural-void\">\n<div class=\"max-w-7xl mx-auto space-y-8\">\n<div class=\"case-section-heading section-head section-head-balanced\"><div class=\"section-head-primary\">\n<span class=\"kicker\">Part C — Legal frameworks · Section 19 · Contract law</span>\n<h2>The Subscriber Agreement against the platform's own architecture</h2>\n\n<section class=\"dossier-note chapter-context\"><div class=\"dossier-note-title\">Context &amp; source limits</div><p class=\"chapter-context-text\">The authors are not lawyers and none of this is legal advice. The SSA is quoted from the revision of 10 September 2026; a different revision may read differently, and clause numbering has changed across revisions — check the clause against the version that governed the conduct in question. The Articles 25 and 32 arguments state what the regulation requires, not that a supervisory authority has found a breach. The figures in Argument 1 carry the scope limits set out in Section 13.</p></section>\n</div><div class=\"section-head-intro\"><p class=\"lede\">Three of the SSA's central provisions sit awkwardly with how the platform is built: the commercial-use prohibition against a Market price ceiling that pushes high-value sales off-platform; the user-liability clause for API keys against a key endpoint that, before 2023, required no second factor; and the enforcement language against a public record that shows no per-operator enforcement. Whether these tensions affect enforceability is a question for a court; this section sets out the facts a court would have before it.</p></div></div>\n<div class=\"grid grid-cols-1 lg:grid-cols-2 gap-6 items-start\">\n<div class=\"bg-gray-950 border border-red-900/30 rounded-2xl p-6 space-y-4\">\n<span class=\"text-xs font-mono text-red-400 uppercase tracking-widest font-bold\">Argument 1 / Market Cap Architecture</span>\n<h3 class=\"text-lg font-black text-white\">The Market ceiling and the commercial-use prohibition</h3>\n<p class=\"text-xs text-gray-400 leading-relaxed\">The Steam Community Market has a listing ceiling of about $1,800. Across five marketplaces in a dated snapshot (23 Sep 2026), 248 CS2 item categories are independently priced above that ceiling by two or more of them; such items <strong class=\"text-white\">cannot be sold at those prices on Valve's own platform</strong>. Owners who want those prices use third-party markets, which run on Steam accounts and the Steam API — use that the SSA classes as commercial unless expressly permitted.</p>\n<div class=\"bg-red-950/30 border border-red-800/30 rounded p-3 text-[11px] font-mono text-red-300\">\n                            Items exceed the Market ceiling → third-party markets fill the gap → those markets use Steam accounts and the Steam API → the SSA prohibits commercial use without permission → no register of permissions has been published. The Community Market's combined fee of about 15% applies only to sales completed inside the Market, not to these external trades.\n                        </div>\n</div>\n<div class=\"bg-gray-950 border border-amber-900/30 rounded-2xl p-6 space-y-4\">\n<span class=\"text-xs font-mono text-amber-400 uppercase tracking-widest font-bold\">Argument 2 / API Key Security Architecture</span>\n<h3 class=\"text-lg font-black text-white\">The API-key vulnerability as a platform design question rather than user negligence</h3>\n<p class=\"text-xs text-gray-400 leading-relaxed\">Before 2023, Steam's API key creation endpoint accepted a POST with a stolen sessionid and generated a high-privilege credential <strong class=\"text-white\">without e-mail confirmation, a second factor or device verification</strong>. The API hijack complaints collected in this investigation follow one pattern: attacker script, stolen session cookie, silent key creation, trade interception (the request payload is shown in Section 8).</p>\n<p class=\"text-[11px] text-gray-400\">GDPR Article 25 (data protection by design) and Article 32 (security of processing) require technical measures appropriate to the risk. Issuing a credential capable of trade interception without a second factor or owner notification is a design question for the controller. Whether the SSA clause placing liability on the user can be relied on against that background is a question for a court and the supervisory authority.</p>\n</div>\n</div>\n<div class=\"grid grid-cols-1 lg:grid-cols-2 gap-6 items-start\">\n<div class=\"bg-gray-950 border border-cyan-900/30 rounded-2xl p-6 space-y-4\">\n<span class=\"text-xs font-mono text-cyan-400 uppercase tracking-widest font-bold\">Argument 3 / Real-Time Visibility</span>\n<h3 class=\"text-lg font-black text-white\">Valve receives the auth hostname on every login</h3>\n<p class=\"text-[11px] text-gray-400 leading-relaxed\">The auth hostname arrives at Valve's OpenID endpoint in plaintext in <code>openid.return_to</code> and <code>openid.realm</code> (the request shape is shown in Section 3). Extracting it is a standard operation. As of 2026-09-22, in 26 pairs the main domain was on the Link Filter while the host carrying its Steam login was not. Valve has published no per-operator enforcement record, so whether any measure other than the Link Filter has been applied to these hosts cannot be established from public data.</p>\n</div>\n<div class=\"bg-gray-950 border border-gray-800 rounded-2xl p-6 space-y-4\">\n<span class=\"text-xs font-mono text-gray-400 uppercase tracking-widest font-bold\">Who bears the cost</span>\n<h3 class=\"text-lg font-black text-white\">The pattern in the archived complaints</h3>\n<p class=\"text-[11px] text-gray-400 leading-relaxed\">In the reviewed complaints, Steam Support's response to an API-key hijack claim follows one form: decline restoration, cite the user's responsibility for the account and its API key, close the ticket. No aggregate figure for accounts affected or value lost is estimated in this dossier; no source for such a figure has been located.</p>\n<div class=\"bg-gray-900 rounded p-3 text-[11px] text-gray-400 border-l-2 border-red-500\">\n                            The question is not whether individual users made mistakes. The question is who is responsible for an architecture that, until 2023, allowed a POST request with a stolen cookie to create a high-privilege trading credential with no notification and no second factor.\n                        </div>\n</div>\n</div>\n<div class=\"evidence-conclusion\">\n<div>\n<span class=\"case-kicker\">The SSA as a document vs the SSA as a contract</span>\n<h3>A court evaluating this record would not read the SSA in isolation.</h3>\n<p>It would read it alongside counsel's October 2025 letter describing device-level correlation, the auth-host registration dates, the batch registration timestamps, the API-key request payload, and the ten years between the July 2016 notices and the platforms still operating in September 2026. That is the record Valve would have to address.</p>\n</div>\n<div class=\"case-legal-note\">\n<span class=\"case-kicker\">SSA against the record / key points</span>\n<ul class=\"text-xs text-gray-400 space-y-1 list-disc pl-4\">\n<li>\"No commercial use\" — the Market ceiling pushes high-value sales to commercial third-party markets</li>\n<li>\"Users liable for API keys\" — no second factor on the key endpoint before 2023</li>\n<li>\"We enforce against violators\" — no per-operator enforcement record published since July 2016</li>\n<li>\"You agreed to terms\" — in the hijack pattern the acceptance is submitted by a script, not the account holder</li>\n</ul>\n</div>\n</div>\n</div>\n</section>"
  },
  "original_content_sha256": "8ee927a8d6d4fa1b2a787067e3bcb58f20f2afa9da10909694574f3edb9f4d8b",
  "author_pseudonym": "Agent Beatrix",
  "schema": "phishdestroy.macro-fact.v1",
  "language": "en",
  "aggregator": "PhishDestroy",
  "exports": {
    "pdf": "/steam_dossier/exports/agent-protocol/files/en/steam_dossier_section_19_agent_beatrix.pdf",
    "json": "/steam_dossier/exports/agent-protocol/files/en/steam_dossier_section_19_agent_beatrix.json",
    "signature": "/steam_dossier/exports/agent-protocol/files/en/steam_dossier_section_19_agent_beatrix.json.asc"
  },
  "integrity": {
    "signed_object": "steam_dossier_section_19_agent_beatrix.json",
    "signature_file": "steam_dossier_section_19_agent_beatrix.json.asc",
    "signing_key_fingerprint": "129FC7F39C40C69D2EF3C329BFCF9E8DD295EE01",
    "scope": "Exact JSON bytes, including macro-fact author and corresponding PDF SHA-256. PhishDestroy is the integrity signer; original evidence attribution is unchanged."
  },
  "pdf": {
    "filename": "steam_dossier_section_19_agent_beatrix.pdf",
    "sha256": "3aed511325c1bbf8bb5bf050cb7d0262bc23750d3506041e68e3a2c1ad9d2723",
    "pages": 4
  }
}
