{
  "compartment_id": "section-3-1",
  "number": "Section 3.1",
  "title_local": "Inside Steam, Valve's list is the only list",
  "title_english": "Inside Steam, Valve's list is the only list",
  "source_url": "https://phishdestroy.io/steam_dossier/#inside-steam-filter",
  "source_document": "index.html",
  "content": {
    "html": "<article class=\"cef-exhibit\" id=\"inside-steam-filter\">\n<div class=\"section-head ds-992b7d83bdd9\">\n<span class=\"kicker\">Part A — Technical record · Section 3.1</span>\n<h3>Inside Steam, Valve's list is the only list.</h3>\n<p class=\"lede\">A link clicked in the Steam client, the in-game overlay or Big Picture mode does not open in the user's browser. It renders inside Steam's own embedded browser — where the warning layers a browser would apply are not present. <strong>The Link Filter is not one safeguard among several. It is the whole of it.</strong></p>\n</div>\n<div class=\"cef-compare\">\n<div class=\"cef-col\" data-side=\"browser\">\n<div class=\"cef-col-head\"><b>In a normal browser</b><span>Three independent layers</span></div>\n<ol class=\"cef-layers\">\n<li><b>Google Safe Browsing</b><span>A full-page interstitial for hosts on Google's phishing and malware lists, updated continuously and independent of the site being visited.</span></li>\n<li><b>The antivirus browser extension</b><span>Most consumer endpoint products ship a browser add-on that checks the destination against the vendor's own reputation list.</span></li>\n<li><b>Endpoint HTTPS inspection</b><span>Where the product performs TLS inspection, page content is scanned before it reaches the user.</span></li>\n</ol>\n</div>\n<div class=\"cef-col\" data-side=\"steam\">\n<div class=\"cef-col-head\"><b>In the Steam client, overlay and Big Picture</b><span>One layer</span></div>\n<ol class=\"cef-layers\">\n<li data-state=\"absent\"><b>Google Safe Browsing</b><span>Not present. The check requires Google API keys that are not provisioned in embedded Chromium builds; where they are absent, Chromium's own design documentation records that the Safe Browsing handler is simply never added to the request chain.</span></li>\n<li data-state=\"absent\"><b>The antivirus browser extension</b><span>Not present. Steam's renderer is not the user's browser and loads no extension from the user's browser profile, so no add-on runs against the page.</span></li>\n<li data-state=\"partial\"><b>Endpoint HTTPS inspection</b><span>Product-dependent. The traffic terminates inside a code-signed Valve process rather than a recognised browser, and a number of endpoint products exempt signed applications from TLS inspection.</span></li>\n<li data-state=\"present\"><b>The Steam Link Filter</b><span>Valve's own blocklist, consulted when a link leaves the Steam ecosystem. This is the sole check that runs — and the table above records what it returns for the auth hosts documented in this section.</span></li>\n</ol>\n</div>\n</div>\n<div class=\"cef-test\">\n<div class=\"cef-test-head\">A test any reader can run, and the finding falls if it fails</div>\n<p>Open one of Google's published Safe Browsing test URLs (<code>testsafebrowsing.appspot.com</code>) in Chrome: a full-page red interstitial appears. Open the same URL from a Steam chat message, so that it renders in the Steam client or the overlay: no interstitial appears. The only warning Steam can produce is its own Link Filter page, and only for hosts on Valve's list.</p>\n</div>\n<div class=\"cef-bounty\">\n<div class=\"cef-bounty-head\"><span>Valve's own bug-bounty record</span><b>The one layer has been got around before — on Valve's own record</b></div>\n<p class=\"cef-bounty-lede\">If the Link Filter is the only check that runs inside the client, its own failure modes are not a side issue. Two reports on Valve's HackerOne programme, both accepted, both resolved, both since disclosed in full:</p>\n<ol class=\"cef-bounty-list\">\n<li>\n<div class=\"cef-bounty-id\"><a href=\"https://hackerone.com/reports/291750\" rel=\"noopener noreferrer\" target=\"_blank\">#291750</a> <a class=\"archived-link\" href=\"https://web.archive.org/web/20251116185046/https://hackerone.com/reports/291750\" rel=\"noopener noreferrer\" target=\"_blank\">archived 2025-11-16 ↗</a><span>Open Redirect · medium</span></div>\n<div>\n<h3 class=\"font-bold text-white text-base\">Link filter protection bypass</h3>\n<p>Reported 19 November 2017, resolved, disclosed 9 May 2018. The report's own proof of concept: substituting the ideographic full stop <code>。</code> (<code>%E3%80%82</code>) for the dot in a hostname — <q>it is possible to bypass the blocking.</q> The interstitial this section is about did not appear.</p>\n</div>\n</li>\n<li>\n<div class=\"cef-bounty-id\"><a href=\"https://hackerone.com/reports/1079561\" rel=\"noopener noreferrer\" target=\"_blank\">#1079561</a> <a class=\"archived-link\" href=\"https://web.archive.org/web/20260924181830/https://hackerone.com/reports/1079561\" rel=\"noopener noreferrer\" target=\"_blank\">archived 2026-09-24 ↗</a><span>Information Disclosure · high</span></div>\n<div>\n<h3 class=\"font-bold text-white text-base\">Big Picture web browser leaks login cookies and discloses sensitive information (may lead to account takeover)</h3>\n<p>Reported 15 January 2021, resolved, disclosed 21 September 2021. Valve's own severity rating is high, and the title states the consequence. The disclosed record carries the title, rating and dates; the technical write-up is not in the published payload, so nothing further is quoted from it here.</p>\n</div>\n</li>\n</ol>\n<p class=\"cef-bounty-read\"><b>The authors' reading, not a finding of either report:</b> the two sit on either side of the same gate. One is the warning failing to appear before the destination opens; the other is the session leaving the client once a page is open inside it. The sequence that follows a stolen session — key registered without a prompt, the real trade cancelled, a duplicate sent to a clone — is the pattern set out in <a href=\"#vulnerability-profile\">Section 5</a> to <a href=\"#consent-analysis\">Section 8</a>. Both reports are closed; neither is offered as a live vulnerability. What they establish is narrower and enough: the single remaining layer has a documented history of being got around, on Valve's own record.</p>\n<p class=\"cef-bounty-src\">Source: the HackerOne disclosure record for each report, retrieved 2026-09-22 — number, title, team, weakness, severity, report and disclosure dates and state as published by HackerOne. Retrieval record: <a href=\"steam_tos_assets/hackerone-reports.json\">hackerone-reports.json</a>. No bounty figure is stated here; none appears in the disclosed record retrieved.</p>\n</div>\n<div class=\"cef-field\">\n<div class=\"cef-field-head\"><span>Field observation · PhishDestroy</span><b>Detections that normally end a campaign did not end these</b></div>\n<p>We watched phishing hosts keep pulling traffic while carrying <strong>20 or more vendor detections</strong>. Delivered by web or email, a campaign in that state dies in days — the browser and the antivirus both act on those verdicts. Inside Steam neither does. The verdicts existed the whole time. Nothing in the client ever asked.</p>\n</div>\n<div class=\"cef-consequence\">\n<h3>What this means for a minor with an antivirus installed</h3>\n<p>He ignores no warning and disables nothing. A message arrives inside Steam — a free knife, a vote for a friend's team — and the page opens inside Steam. He never opens a browser, so the browser never protects him. His antivirus is running and may already rate that domain malicious; it is never asked. <strong>Every warning that could have stopped him already exists. None of it reaches him.</strong> He believes he never left Steam, and he did not.</p>\n<p>The giveaway is not the phisher's invention — free Valve items are how the skin and gambling sites advertise, which is exactly why the message reads as ordinary. Complaints: <a href=\"steam_enforcement_evidence#support-records\">the enforcement archive</a>. Age and children's data: <a href=\"#minors-protection\">Section 17</a>.</p>\n</div>\n<p class=\"evidence-caption\">Sources: Steam renders web content through the Chromium Embedded Framework in the <code>steamwebhelper</code> process — see <a href=\"https://www.darknavy.org/blog/exploiting_steam_usual_and_unusual_ways_in_the_cef_framework/\" rel=\"noopener noreferrer\" target=\"_blank\">DARKNAVY's technical analysis of 27 June 2024 ↗</a> and Valve's own <a href=\"https://steamcommunity.com/groups/SteamClientBeta/discussions/0/3365901765276206401/\" rel=\"noopener noreferrer\" target=\"_blank\">Steam Client Beta forum ↗</a> <a class=\"archived-link\" href=\"https://web.archive.org/web/20250804051514/https://steamcommunity.com/groups/SteamClientBeta/discussions/0/3365901765276206401/\" rel=\"noopener noreferrer\" target=\"_blank\">archived 2025-08-04 ↗</a>. No CEF version is relied on: embedded Chromium is not Chrome and ships none of Chrome's Google services. Safe Browsing without API keys: <a href=\"https://www.chromium.org/developers/design-documents/safebrowsing/\" rel=\"noopener noreferrer\" target=\"_blank\">Chromium design document ↗</a> <a class=\"archived-link\" href=\"https://web.archive.org/web/20260821101616/https://www.chromium.org/developers/design-documents/safebrowsing/\" rel=\"noopener noreferrer\" target=\"_blank\">archived 2026-08-21 ↗</a>, <a href=\"https://www.chromium.org/developers/how-tos/api-keys/\" rel=\"noopener noreferrer\" target=\"_blank\">Chromium API keys ↗</a> <a class=\"archived-link\" href=\"https://web.archive.org/web/20260830122831/https://www.chromium.org/developers/how-tos/api-keys/\" rel=\"noopener noreferrer\" target=\"_blank\">archived 2026-08-30 ↗</a> (“Many of the Google APIs used by Chrome are specific to Google and not intended for use in derived products”), and the same effect in other unkeyed builds — <a href=\"https://github.com/Homebrew/homebrew-cask/issues/193814\" rel=\"noopener noreferrer\" target=\"_blank\">Homebrew cask #193814 ↗</a>. Test URLs: <a href=\"https://testsafebrowsing.appspot.com/\" rel=\"noopener noreferrer\" target=\"_blank\">testsafebrowsing.appspot.com ↗</a>.</p>\n</article>"
  },
  "original_content_sha256": "7f147c68f16840bcd1088432ba46c2e1f9ab741f7918184993dd96362afd0743",
  "author_pseudonym": "Agent June",
  "schema": "phishdestroy.macro-fact.v1",
  "language": "en",
  "aggregator": "PhishDestroy",
  "exports": {
    "pdf": "/steam_dossier/exports/agent-protocol/files/en/steam_dossier_section_3_1_agent_june.pdf",
    "json": "/steam_dossier/exports/agent-protocol/files/en/steam_dossier_section_3_1_agent_june.json",
    "signature": "/steam_dossier/exports/agent-protocol/files/en/steam_dossier_section_3_1_agent_june.json.asc"
  },
  "integrity": {
    "signed_object": "steam_dossier_section_3_1_agent_june.json",
    "signature_file": "steam_dossier_section_3_1_agent_june.json.asc",
    "signing_key_fingerprint": "129FC7F39C40C69D2EF3C329BFCF9E8DD295EE01",
    "scope": "Exact JSON bytes, including macro-fact author and corresponding PDF SHA-256. PhishDestroy is the integrity signer; original evidence attribution is unchanged."
  },
  "pdf": {
    "filename": "steam_dossier_section_3_1_agent_june.pdf",
    "sha256": "4a60ba03da376f885ff322dbb877bd7df04ea639719e7928fa5a0c6897ea26c1",
    "pages": 4
  }
}
