posted by Dopefish on Tuesday February 18 2014, @05:00AM   Printer-friendly
from the move-along-nothing-to-see-here dept.

Lagg writes:

"We're in a climate where it's easy to accuse a company of spying on you by various means with a distinct possibility that you could be right, but sometimes a reality check is needed. A Reddit user recently posted a thread accusing Valve of writing code for VAC that iterates your DNS cache and sends the hashed entries to their server. The proof provided of this was a prettied disassembly (that was not easily reproducible due to how VAC loads symbols) that showed only that VAC was indeed iterating the DNS cache, which any knowledgeable programmer understands is not exactly an uncommon thing to do, as no socket code was to be seen. Today, Gabe Newell responded to these allegations by confirming that no they do not in fact snoop your cache entries.

There are probably a few things to learn from this, including not trusting a screenshot of code that looks complex without actually understanding what it's doing. A lack of any level-headed investigation is a bad idea and it's important to handle these situations before they snowball into a mob (as Redditors are bound to do)."

  • (Score: 5, Informative) by kru on Tuesday February 18 2014, @05:26AM

    by kru (795) on Tuesday February 18 2014, @05:26AM (#1422)

    I read TFA (are we allowed to do that here?) and it has this bit in it.

    "VAC checked for the presence of [kernel-level] cheats. If they were detected VAC then checked to see which cheat DRM server was being contacted. This second check was done by looking for a partial match to those (non-web) cheat DRM servers in the DNS cache. If found, then hashes of the matching DNS entries were sent to the VAC servers. "

    So, from the horse's mouth comes the story that Valve does indeed snoop on DNS entries when it think it has detected a potential cheat. Valve has somewhere north of 10 million clients, so that it at least 10k people who have had their DNS caches snooped. Are they snooping on you and me? I doubt it, but I don't know for certain. I have no idea what it takes to trip VAC into peeking at my dns cache.

    I do appreciate the integrity of Valve with the quick, concise and transparent announcement made in the wake of this news. The NSA could learn something from Gabe.

  • (Score: 1) by sar on Tuesday February 18 2014, @07:51PM

    by sar (507) on Tuesday February 18 2014, @07:51PM (#1849)

    Not only was original "accusation" right on. It is very good it snowballed.
    It is possible that Valve use this snooping with good intents. Nonetheless this story may detract some other companies from doing something evil if they now know it could be easily discovered...