{
  "compartment_id": "section-1",
  "number": "Section 1",
  "title_local": "Case briefing and executive summary",
  "title_english": "Case briefing and executive summary",
  "source_url": "https://phishdestroy.io/steam_dossier/#briefing-section",
  "source_document": "index.html",
  "content": {
    "html": "<div class=\"max-w-7xl mx-auto\" id=\"briefing-section\">\n<div class=\"bg-gray-950 p-6 rounded-lg border border-gray-700 relative overflow-hidden\">\n<div class=\"section-head ds-20ce54f7a997 section-head-balanced\"><div class=\"section-head-primary\">\n<span class=\"kicker\">Section 1 — Case briefing</span>\n<h2 id=\"briefing-heading\">The rule. The record. The unanswered questions.</h2>\n<section class=\"dossier-note chapter-context\"><div class=\"dossier-note-title\">Context &amp; source limits</div><p class=\"chapter-context-text\">Six findings, each tied to a dated public record. The detailed sections follow the same order: technical record (Part A), rules and enforcement record (Part B), legal frameworks (Part C), then the appendices with the primary exhibits.</p></section>\n</div><div class=\"section-head-intro\"><p class=\"lede\">Six findings. Each connects a written rule to a dated record and a question the evidence can test.</p></div></div>\n<div class=\"briefing-findings grid grid-cols-1 lg:grid-cols-2 xl:grid-cols-3 gap-4 font-mono text-xs text-gray-300 no-gloss\">\n<div class=\"pd-finding-card space-y-1.5 p-4 rounded border ds-70abd4fe917a\">\n<span class=\"pd-finding-title text-gray-200 font-bold block text-xs uppercase tracking-wider\">1. Separate-domain auth hosts — 44 routes · 26 split pairs</span>\n<p class=\"pd-finding-desc text-gray-400 font-sans text-[11px] leading-relaxed\">The live register records <strong class=\"text-white\" data-count=\"44\">44 platforms authenticating through a separate registrable domain</strong>. <small>Five further routes sit in pending verification awaiting an RDAP date; promoting them would take the total to 47. They are excluded from 44 and from the age chart.</small> — <strong class=\"text-white\">27 with a published per-route evidence file</strong> and 17 added from manual collection, listed apart. In <strong class=\"text-white\" data-count=\"26\">26 filter-split pairs</strong> the main domain is <strong class=\"text-red-400\">BLOCKED</strong> in the Steam Link Filter while the proxy carrying its login is not. These are not burner domains: csgogem.com is blocked while <code class=\"text-white token-nowrap\">api.csgem.com</code>, the host carrying its Steam login, has been registered since March 2014 — <strong class=\"text-white\">12 years 6 months</strong>. Valve receives that hostname in every OpenID request, and renders it back to the user on its own login page. Full table, per-route ages and sourcing in Section 3. </p><div class=\"pd-finding-actions\"><a class=\"pd-finding-btn\" href=\"#proxy-bypass-explainer\">Follow the route →</a></div>\n</div>\n<div class=\"pd-finding-card space-y-1.5 p-4 rounded border ds-d52426109866\">\n<span class=\"pd-finding-title text-gray-200 font-bold block text-xs uppercase tracking-wider\">2. 2016: the mechanism was named, the deadline set</span>\n<p class=\"pd-finding-desc text-gray-300 font-sans text-[11px] leading-relaxed\">On <strong class=\"text-white\">13 July 2016</strong> Valve publicly described how gambling sites used Steam OpenID and automated trading accounts, and its counsel's notices of <strong class=\"text-white\">20 July 2016</strong> set a ten-day deadline. No per-operator enforcement record has been published since. Ten years after that deadline was issued, the same named mechanism is in use on separate-domain auth hosts that returned no Link Filter block on 2026-09-21. </p><div class=\"pd-finding-actions\"><a class=\"pd-finding-btn\" href=\"#wsgc-public-address\">Read the open letter to the WSGC →</a></div>\n</div>\n<div class=\"pd-finding-card space-y-1.5 p-4 rounded border ds-58061ef61ff9\">\n<span class=\"pd-finding-title text-gray-200 font-bold block text-xs uppercase tracking-wider\">3. Device correlation, on counsel's letterhead</span>\n<p class=\"pd-finding-desc text-gray-400 font-sans text-[11px] leading-relaxed\">In the correspondence reproduced here, Valve's counsel described device-level correlation linking one device to multiple accounts — a capability Steam Support had previously told users was not technically possible. The open question is which device-level records Valve holds and on what basis account holders are refused access to them. </p><div class=\"pd-finding-actions\"><a class=\"pd-finding-btn\" href=\"#official-memorandum\">Read the memorandum →</a></div>\n</div>\n<div class=\"pd-finding-card space-y-1.5 p-4 rounded border ds-7c0000690437\">\n<span class=\"pd-finding-title text-gray-200 font-bold block text-xs uppercase tracking-wider\">4. Two access responses. One withheld the data, one leaked it.</span>\n<p class=\"pd-finding-desc text-gray-400 font-sans text-[11px] leading-relaxed\"><strong class=\"text-white\">October 2025:</strong> Valve's counsel answered an Art. 15 request with an 830-page appendix whose redactions are painted over the text instead of removing it — <strong class=\"text-white\">902,270 characters</strong> come back out with a standard extraction tool, including the third-party identifiers the bars were there to withhold. Art. 15(4) is the reason those bars exist. <strong class=\"text-white\">September 2026:</strong> ticket HT-2YBP-F7JP-D4VB was closed after three days with a link to the self-service Account Data page — no data, no stated legal basis. The one-month period under Art. 12(3) had not expired at publication; the objection is to the substance. </p><div class=\"pd-finding-actions\"><a class=\"pd-finding-btn redaction-reveal\" href=\"#academic-response\">Read the redaction check →</a><a class=\"pd-finding-btn\" href=\"#gdpr-live-case\">Read the ticket record →</a></div>\n</div>\n<div class=\"pd-finding-card space-y-1.5 p-4 rounded border ds-cc6639a150ec\">\n<span class=\"pd-finding-title text-gray-200 font-bold block text-xs uppercase tracking-wider\">5. The market above Steam's ceiling</span>\n<p class=\"pd-finding-desc text-gray-300 font-sans text-[11px] leading-relaxed\">Steam caps a Market listing at about <strong>$1,800</strong>. Across five marketplaces in a dated snapshot (<strong class=\"text-white\">23 Sep 2026</strong>), <strong>248 CS2 item categories</strong> are priced above that cap by two or more of them independently, and <strong>all 248 are absent from Steam</strong>; a Factory New Dragon Lore starts at <strong>$10,941</strong> across 389 copies listed on all five (the CSFloat-only figure in Section 13, from the 20 Sep snapshot, is $10,623.95 across 62 offers). Selling at those prices requires an outside venue, while item transfer still runs through Steam. </p><div class=\"pd-finding-actions\"><a class=\"pd-finding-btn\" href=\"#market-gap-section\">Follow the price and transfer →</a></div>\n</div>\n<div class=\"pd-finding-card space-y-1.5 p-4 rounded border ds-403a8d384c07\">\n<span class=\"pd-finding-title text-gray-200 font-bold block text-xs uppercase tracking-wider\">6. The rule is explicit; the audit trail is not</span>\n<p class=\"pd-finding-desc text-gray-300 font-sans text-[11px] leading-relaxed\">The Subscriber Agreement reserves Steam for personal, non-commercial use, bars commercial exploitation except as expressly permitted, prohibits scripts and bots, and allows account termination. Valve applied that language to gambling operators in 2016. Separately, according to CSFloat's engineering account, Valve closed <code>IEconItems_730/GetPlayerItems</code> in 2017, removing public access to original item IDs (no Valve changelog located). </p><div class=\"pd-finding-actions\"><a class=\"pd-finding-btn\" href=\"#enforcement-standard\">Put the rule beside the network →</a></div>\n</div>\n</div>\n</div>\n</div>"
  },
  "original_content_sha256": "ac6c50d95d46685dca380bd83801ba7a9cdce2c573aa620a92a52d3e59ce4130",
  "author_pseudonym": "Agent Austin",
  "schema": "phishdestroy.macro-fact.v1",
  "language": "en",
  "aggregator": "PhishDestroy",
  "exports": {
    "pdf": "/steam_dossier/exports/agent-protocol/files/en/steam_dossier_section_1_agent_austin.pdf",
    "json": "/steam_dossier/exports/agent-protocol/files/en/steam_dossier_section_1_agent_austin.json",
    "signature": "/steam_dossier/exports/agent-protocol/files/en/steam_dossier_section_1_agent_austin.json.asc"
  },
  "integrity": {
    "signed_object": "steam_dossier_section_1_agent_austin.json",
    "signature_file": "steam_dossier_section_1_agent_austin.json.asc",
    "signing_key_fingerprint": "129FC7F39C40C69D2EF3C329BFCF9E8DD295EE01",
    "scope": "Exact JSON bytes, including macro-fact author and corresponding PDF SHA-256. PhishDestroy is the integrity signer; original evidence attribution is unchanged."
  },
  "pdf": {
    "filename": "steam_dossier_section_1_agent_austin.pdf",
    "sha256": "7e23e03c01436b98a4a4f85d9b0b811e1a459e5111043126bc04fb55a62629cb",
    "pages": 4
  }
}
