This behavior was seen before too with the devs behind the new Gmod in Source 2 (Alyx engine). They spent months trying to get in touch with access and it came down to an employee who ended up getting fired for neglecting responsibilities. Now everything seems to be working out and open tooling is being developed.
They turned me down for any reward - I don't remember the exact wording in their policy but I think it was a generic exclusion of DOS and DDOS vectors. I thought I should've still been eligible as my exploit was simple and only required a low input frequency. The bureaucratic process of the whole thing scared me from doing anything more and I was happy enough that they would fix the vulnerability and I could get back to enjoying the game.
I think it's five years later and the problem still exists, and regularly reduces the quality of my games.
If they don't feel the pain, again and again for things like this then there will never be any impetus to change.
This isn't your responsibility of course. I'm just saying that disclosure at this point would be anything but irresponsible. Maybe not in the middle of a big tournament, I suppose.
I submitted the bug where you I proved you could make predictions about a password in Microsoft just by using ctrl + arrow keys.
It wouldn't have been much anyway but I wouldn't have been surprised if they sent me some swag or something - instead I was surprised about how short the thank you mail was ;-)
(They said it wasn't a security issue but at least it was fixed in the next release :-P)
Edit: I later found a reliable way to run the encryption tools the correct way with the tooling in Azure Information Protection that still leaves the files unencrypted (so simple it can happen by accident, that's how I found it, useful for data exfiltration with plausible deniability) and besides the integration of information protection in Sharepoint is so extremely broken that depending on how you log in, SharePoint will easily serve you the files unprotected.
Between not finding the correct way the report it and the very "meh" feeling on my first find I only tried to report those onve or twice and then gave up.
I had one server bug in HackerOne’s “mediation” for over a month, after 4-6mo of no reply, which did nothing until mentioning it to a Valve employee on another report they had actually responded to.
Disappointing for a program that has paid $1m+ in its lifetime.
Why should they prioritize people who break their hard work and coerce them into paying for protection?
I might be biased; always wanted to work @ Valve Software since HL1.
They've had pre-launch source codes leaked by hackers, gameplay ruined by hackers; they probably don't like hackers.
I wouldn't be surprised if they signed up purely out of spite to tarpit and frustrate hackers.
Valve's stance on hackers won't change the fact they exist and are out there doing their thing. Valve's stance can now be the deciding factor between exploits being disclosed to them for a reward, or sold on black markets as cheats.
If you don't want people "breaking your hard work", don't release software. However, being on hackerone can help alleviate the negatives.
Many of their breadwinners were made by 'hackers'.
Valve are, leaving millions of users at risk, despite having been informed of an issue.
Because they voluntarily joined responsible disclosure programs and promised rewards?
Their hard work wasn't good enough to survive in the extremely hostile world out there. The fact is online gaming is a form of distributed computing and so people are exposed to network attacks. By failing to prioritize security they are putting their customers at risk. They can either start taking this seriously or watch people make money off of the vulnerabilities in their hard work.