Skip to main content

Teen hacker exposes security flaws by publishing unapproved game on Steam

steam
Image used with permission by copyright holder
A teenager revealed security holes in Valve’s developer site that allowed him to upload a game about watching paint dry to Steam without any approval.

Ruby Nealon, a computer science student in the U.K., discovered that the Steamworks site’s approval process could be skipped when he uploaded his game Watch Paint Dry, a riveting role-playing adventure in which the gamer watches paint dry.

steam-watch-paint-dry
Image used with permission by copyright holder

Nealon detailed his experiment on Medium. First he managed to obtain an account on Steamworks and some in-game trading cards last month. Then he found flaws in the HTML form data that was being sent to Valve’s servers, which allowed him to alter the code into the thinking his cards had been approved by an editor. After that he was able to spoof his session ID number and publish the game.

Recommended Videos

The student has already been in contact with Valve and the holes were plugged before he went public. It was never his plan to cause any problems for other users or attempt to sell the game to anyone, he added. (And after all, who would buy it?) It was instead always his intention to expose the holes and he has also purposefully omitted some particular details on how he pulled this off.

Please enable Javascript to view this content

“Something I’ve definitely learned from doing this is when working with user-generated content that first needs to be approved, do not have ‘Review Ready’ and ‘Reviewed’ as two states of existence for the content,” said Nealon in his advice to Valve and other sites in the future.

“Instead, maybe take an approach where the review of the item has an audit trail by giving each piece of content a ‘review ticket’ or something similar and not allowing the content to switch to the Released state until there is a review ticket for the content,” he said. “Or just don’t allow users to set the item to ‘Released.’”

Jonathan Keane
Former Digital Trends Contributor
Jonathan is a freelance technology journalist living in Dublin, Ireland. He's previously written for publications and sites…
Why I sold my gaming laptop to buy a Steam Deck
A Steam Deck sitting on top of a PC.

After waiting for almost a year, I finally have a Steam Deck. I've been excited about this device since Valve first announced it, and although the Steam Deck has some problems, I love using Valve's handheld gaming PC. I love it so much, in fact, that the Steam Deck is replacing my Razer Blade 15 -- a gaming laptop that costs over four times as much.

I won't pretend like the Steam Deck is as powerful as a proper gaming laptop, or that it will kill gaming laptops overall. Calm down. But for me, I can't find a reason to open the lid on my Blade now that the Steam Deck is in my hands. Here's why.
Less powerful, more practical

Read more
Pre-ordered a Steam Deck? Here are the first Deck Verified games you should play
A Steam Deck sitting on top of a PC.

The Steam Deck has been out for months, but many hopeful buyers are still waiting on their handheld. Valve hasn't been idly shipping units, though. The company continues to add games to its list of Deck Verified titles, which Valve itself has verified to work with the Deck.

This list is mainly focused on games that you can't play on another handheld (and in some cases, on any other platform). Although Deck Verified games offer the best experience, there are thousands of additional titles that still work on the Steam Deck. Make sure to read our roundup of the best Steam Deck games for a few options. To get the most out of your new handheld, here are the Steam Deck Verified games you should play first.

Read more
Steam Deck vs. cloud gaming: How do they compare?
Steam Deck being held in two hands.

Before I actually got my hands on a Steam Deck, I was skeptical of the concept. It’s not that I thought it wouldn’t work. In fact, the idea of having my entire Steam library available on a handheld was extremely appealing. My only question was whether or not the gadget was necessary.

Ever since the Nintendo Switch redefined how we play games, companies have tried to replicate its flexibility in their own ways. One of the earliest, and most experimental, attempts was cloud gaming. Companies like Google and Amazon bet big on streaming, envisioning a future where you don’t need a powerful PC or console to run games at all: You just need the devices you already own.

Read more