{
  "compartment_id": "section-8",
  "number": "Section 8",
  "title_local": "Machine-injected consent",
  "title_english": "Machine-injected consent",
  "source_url": "https://phishdestroy.io/steam_dossier/#consent-analysis",
  "source_document": "index.html",
  "content": {
    "html": "<section class=\"border-t border-gray-800 pt-6 avoid-break\" id=\"consent-analysis\">\n<div class=\"max-w-7xl mx-auto grid grid-cols-1 lg:grid-cols-12 gap-8 items-center\">\n<div class=\"lg:col-span-7 space-y-6\">\n<div class=\"section-head ds-fa769ae03572 section-head-balanced\"><div class=\"section-head-primary\">\n<span class=\"kicker\">Part A — Technical record · Section 8 · GDPR Article 7</span>\n<h2>A checked box. Whose action?</h2>\n\n<section class=\"dossier-note chapter-context\"><div class=\"dossier-note-title\">Context &amp; source limits</div><p class=\"chapter-context-text\">In declining reimbursement, Steam Support replies preserved in the archive take the position that the account holder created the API key and, by checking the box, accepted the terms.</p></section>\n</div><div class=\"section-head-intro\"><p class=\"lede\">The support response attributes the key to the account holder. The question is whether the record establishes who actually created it.</p></div></div>\n<p class=\"text-sm text-gray-400 leading-relaxed\">\n                        In the observed API-key hijack pattern, however, the victim never saw or navigated to the API key creation page. The consent field is submitted by a script executing a headless POST with the stolen session cookie.\n                    </p>\n<div class=\"border-l-4 border-rose-500 pl-4 space-y-2\">\n<p class=\"text-xs text-gray-300\">\n                            Under GDPR Article 7 and Article 4(11), consent must be a freely given, specific, informed and unambiguous indication of the data subject's wishes. The authors' position is that a terms-acceptance field submitted by a hostile script with a stolen cookie, with no page shown to the account holder, cannot meet that definition. Whether it does is for the supervisory authority.\n                        </p>\n</div>\n</div>\n<div class=\"lg:col-span-5 bg-gray-950 border border-gray-800 rounded-lg overflow-hidden\">\n<div class=\"bg-gray-900 border-b border-gray-800 px-4 py-2 flex items-center justify-between\">\n<span class=\"text-xs font-mono text-gray-400\">Forensic Payload Analysis: Key Registration</span>\n<div class=\"flex gap-1.5\">\n<span class=\"w-2.5 h-2.5 rounded-full bg-red-500\"></span>\n<span class=\"w-2.5 h-2.5 rounded-full bg-yellow-500\"></span>\n<span class=\"w-2.5 h-2.5 rounded-full bg-green-500\"></span>\n</div>\n</div>\n<div class=\"p-5 font-mono text-xs text-gray-300 space-y-3 overflow-x-auto\">\n<div>\n<span class=\"text-rose-300 payload-method\">POST</span> <span class=\"text-gray-400 payload-url\">https://steamcommunity.com/dev/ajaxregisterkey</span>\n</div>\n<div class=\"text-gray-400\">// Request Payload (Injected via hijacking script)</div>\n<div class=\"bg-gray-900/60 p-4 rounded border border-gray-800/80 space-y-1\">\n<div>{</div>\n<div class=\"pl-4 payload-critical payload-critical-consent text-red-300 border-l-2 border-red-500 py-0.5\"><strong class=\"payload-key\">\"agreeToTerms\"</strong>: <span class=\"text-emerald-400 payload-critical-value\">\"agreed\"</span>, <span class=\"text-xs text-red-400 font-bold ml-2 machine-injected-note\">&lt;-- machine-injected, no human interaction</span></div>\n<div class=\"pl-4 payload-critical payload-critical-domain text-gray-400\"><strong class=\"payload-key\">\"domain\"</strong>: <span class=\"text-emerald-400 payload-critical-value\">\"localhost\"</span>, <span class=\"text-xs text-gray-400\">← not validated — any value accepted, including localhost</span></div>\n<div class=\"pl-4\">\"sessionid\": <span class=\"text-emerald-400\">\"8f0d8ef763ab2140bf89de2a\"</span></div>\n<div>}</div>\n</div>\n<div class=\"bg-red-950/25 border border-red-800/40 p-3 rounded text-[11px] text-red-400\">\n<strong>The question for the supervisory authority:</strong> where the account holder never clicked the consent field, whether the terms-acceptance recorded against the account meets Article 7's requirement of a freely given, specific, informed and unambiguous indication of the data subject's wishes, and whether Steam Support may rely on it to decline a claim.\n                        </div>\n<p class=\"evidence-caption\">Source: request shape of key registration as reconstructed from the public endpoint and from hijack reports preserved in the evidence archive (<a href=\"steam_evidence_archive\">searchable build of 2026-09-17</a>) · the session identifier shown is a placeholder, not a captured value.</p>\n</div>\n</div>\n</div>\n</section>"
  },
  "original_content_sha256": "309c8b440bd5e36681e7bdfa50a0c072ba63f060a42446e3ced8f0b28d2ea47f",
  "author_pseudonym": "Agent Aaron",
  "schema": "phishdestroy.macro-fact.v1",
  "language": "en",
  "aggregator": "PhishDestroy",
  "exports": {
    "pdf": "/steam_dossier/exports/agent-protocol/files/en/steam_dossier_section_8_agent_aaron.pdf",
    "json": "/steam_dossier/exports/agent-protocol/files/en/steam_dossier_section_8_agent_aaron.json",
    "signature": "/steam_dossier/exports/agent-protocol/files/en/steam_dossier_section_8_agent_aaron.json.asc"
  },
  "integrity": {
    "signed_object": "steam_dossier_section_8_agent_aaron.json",
    "signature_file": "steam_dossier_section_8_agent_aaron.json.asc",
    "signing_key_fingerprint": "129FC7F39C40C69D2EF3C329BFCF9E8DD295EE01",
    "scope": "Exact JSON bytes, including macro-fact author and corresponding PDF SHA-256. PhishDestroy is the integrity signer; original evidence attribution is unchanged."
  },
  "pdf": {
    "filename": "steam_dossier_section_8_agent_aaron.pdf",
    "sha256": "424f17491cff709ae21be7f52ccf453b7b7a021494d058a2b379e276c233aff4",
    "pages": 3
  }
}
