{
  "compartment_id": "section-3-2",
  "number": "Section 3.2",
  "title_local": "The Big Picture Trap: Multi-Year Longitudinal Phishing Audit (120 Domains)",
  "title_english": "The Big Picture Trap: Multi-Year Longitudinal Phishing Audit (120 Domains)",
  "source_url": "https://phishdestroy.io/steam_dossier/#linkfilter-coverage",
  "source_document": "index.html",
  "content": {
    "html": "<div class=\"bg-gray-950 border border-gray-700 rounded-lg p-6 my-8\" id=\"linkfilter-coverage\">\n<span class=\"kicker\">Primary Empirical Audit · Multi-Year Date Range</span>\n<h3 class=\"text-xl font-bold text-white mt-2 mb-3\">The Big Picture Trap: Link Filter is Compliance Theater, Not a Shield</h3>\n<p class=\"text-sm text-gray-300 leading-relaxed mb-4\">On desktop browsers, users are shielded by external defenses: Google Safe Browsing and Microsoft SmartScreen intercept known phishing with full-screen red warnings. <strong class=\"text-white\">Inside Steam's Big Picture mode, the in-game overlay (Shift+Tab), and the Steam Deck (SteamOS), those defenses do not exist.</strong> The embedded browser supports zero extensions, disables external Safe Browsing engines, and leaves the user with exactly one defensive barrier: Valve's <code>linkfilter</code> interstitial.</p>\n<p class=\"dossier-cohort-hint\">Swipe to compare all four results →</p>\n<div class=\"grid grid-cols-1 lg:grid-cols-2 xl:grid-cols-4 gap-3 mb-6 dossier-cohort-stats\" role=\"group\" aria-label=\"Four Link Filter audit results, in a horizontal row\" tabindex=\"0\">\n<div class=\"bg-black/40 border border-red-800/50 rounded p-4 text-center\"><div class=\"text-3xl font-black text-red-400 font-mono\">92.5%</div><div class=\"text-[11px] text-gray-400 mt-1\">2025–2026 modern edge phishing <strong class=\"text-gray-200\">passed clean</strong> (37/40)</div></div>\n<div class=\"bg-black/40 border border-red-800/50 rounded p-4 text-center\"><div class=\"text-3xl font-black text-red-400 font-mono\">77.5%</div><div class=\"text-[11px] text-gray-400 mt-1\">2023–2024 CS2 era phishing <strong class=\"text-gray-200\">passed clean</strong> (31/40)</div></div>\n<div class=\"bg-black/40 border border-amber-800/50 rounded p-4 text-center\"><div class=\"text-3xl font-black text-amber-400 font-mono\">70.0%</div><div class=\"text-[11px] text-gray-400 mt-1\">2021–2022 legacy phishing <strong class=\"text-gray-200\">passed clean</strong> (28/40)</div></div>\n<div class=\"bg-black/40 border border-emerald-800/50 rounded p-4 text-center\"><div class=\"text-3xl font-black text-emerald-400 font-mono\">7 / 7</div><div class=\"text-[11px] text-gray-400 mt-1\">gambling mains blocked (positive control)</div></div>\n</div>\n<div class=\"bg-black/50 border border-gray-800 rounded p-5 space-y-3 mb-4\">\n<div class=\"text-xs font-mono text-cyan-400 uppercase tracking-widest font-bold\">Multi-Year Longitudinal Audit: 120 Pure Steam Phishing Domains Tested Live (24 Sep 2026)</div>\n<p class=\"text-xs text-gray-300 leading-relaxed\">To test whether Valve's filter is simply slow to ingest new threats or fundamentally blind to them, we audited <strong>120 confirmed Steam-specific phishing domains</strong> across three historical cohorts against <code>steamcommunity.com/linkfilter</code>:</p>\n<ul class=\"text-xs text-gray-400 space-y-2 list-disc list-inside font-mono\">\n<li><strong class=\"text-gray-200\">Cohort 1: 2021–2022 (Classic Trade-Offer &amp; Item Drops) — 70.0% Clean Pass (28/40).</strong> Even 4 to 5 years after being cataloged by community watchdogs, 7 out of 10 legacy phishing hosts still open without any block.</li>\n<li><strong class=\"text-gray-200\">Cohort 2: 2023–2024 (CS2 Beta Hype &amp; Fake Support Appeals) — 77.5% Clean Pass (31/40).</strong> Campaigns impersonating Counter-Strike 2 releases and fake community appeals (e.g. <code>cs2-steam.com</code>, <code>appealsteamcommunity.help</code>) pass straight through.</li>\n<li><strong class=\"text-gray-200\">Cohort 3: 2025–2026 (Serverless Edge Deploys &amp; Favicon Clones) — 92.5% Clean Pass (37/40).</strong> Modern phishing kits deploying on EdgeOne, Vercel, and Cloudflare Pages (e.g. <code>steamgifter.online</code>, <code>steam-dp4lt5b8fnez.edgeone.dev</code>) pass virtually unobstructed.</li>\n</ul>\n</div>\n<div class=\"space-y-3 text-sm text-gray-300 leading-relaxed mb-4\">\n<p><strong class=\"text-white\">Telemetry &amp; Liability Shield, Not Protection.</strong> Why does the Link Filter exist if it passes 70% to 92.5% of pure Steam phishing? It functions as a corporate liability disclaimer and an outbound click telemetry sensor. By presenting a polite <em>\"You are leaving Steam\"</em> notice with a clickable green proceed button, Valve shifts legal blame onto the victim under the Steam Subscriber Agreement (*\"the user voluntarily navigated outside Steam\"*). Valve collects the telemetry of the click, but does not block the theft.</p>\n<p><strong class=\"text-white\">The Favicon Hash Proof: Zero Ingestion of Threat Feeds.</strong> Independent threat intelligence platforms (urlscan.io, Shodan, Censys) identify live Steam phishing kits using a simple search for Steam's official favicon hash (<code class=\"text-cyan-300\">page.favicon.hash:9f890a9debcdfccc339149a7943be9aff9e4c9203c2fa37d5671a5b2c88503ad NOT domain:*.steampowered.com</code>). This basic automated check surfaces active phishing clusters in seconds. Valve does not sync with external feeds, does not run hash-based threat hunting, and only manually intervenes when compelled by regulators (the 2016 WSGC gambling order) or to protect its trademarked domain strings.</p>\n</div>\n<p class=\"text-[11px] text-gray-400 leading-relaxed border-t border-gray-800 pt-3\"><strong class=\"text-gray-400\">Primary audit evidence artifacts:</strong> Longitudinal 120-domain multi-year audit: <a class=\"underline text-gray-400\" href=\"steam_tos_assets/longitudinal-steam-phishing-audit.json\">longitudinal-steam-phishing-audit.json</a> · 100 dedicated Steam phishing sample: <a class=\"underline text-gray-400\" href=\"steam_tos_assets/linkfilter-steam-phishing-100.json\">linkfilter-steam-phishing-100.json</a> · Broad feed audit (n=250): <a class=\"underline text-gray-400\" href=\"steam_tos_assets/linkfilter-coverage-2026-09-22.json\">linkfilter-coverage-2026-09-22.json</a>.</p>\n</div>"
  },
  "original_content_sha256": "4def8361e1d01086a3f490b21c2cbd72e77df63fc2287a039cca1ca2bbe5f55f",
  "author_pseudonym": "Agent Ignatus",
  "schema": "phishdestroy.macro-fact.v1",
  "language": "en",
  "aggregator": "PhishDestroy",
  "exports": {
    "pdf": "/steam_dossier/exports/agent-protocol/files/en/steam_dossier_section_3_2_agent_ignatus.pdf",
    "json": "/steam_dossier/exports/agent-protocol/files/en/steam_dossier_section_3_2_agent_ignatus.json",
    "signature": "/steam_dossier/exports/agent-protocol/files/en/steam_dossier_section_3_2_agent_ignatus.json.asc"
  },
  "integrity": {
    "signed_object": "steam_dossier_section_3_2_agent_ignatus.json",
    "signature_file": "steam_dossier_section_3_2_agent_ignatus.json.asc",
    "signing_key_fingerprint": "129FC7F39C40C69D2EF3C329BFCF9E8DD295EE01",
    "scope": "Exact JSON bytes, including macro-fact author and corresponding PDF SHA-256. PhishDestroy is the integrity signer; original evidence attribution is unchanged."
  },
  "pdf": {
    "filename": "steam_dossier_section_3_2_agent_ignatus.pdf",
    "sha256": "1fe6669d0eb91dbb3782e24bc8fc49f55752be21e350769b1e23be4543ee33b6",
    "pages": 4
  }
}
