I can launch Steam games from my browser without any plugins.
https://developer.valvesoftware.com/wiki/Steam_browser_proto...
The question is: do you believe the perpetrator to be malicious or dumb?
...where at last he installed his Russian Rootkit.
Or maybe some programmer added a feature that was insecure and they moved on to work on some bug that was crashing level three?
I was saying it seems more likely to me that any random developer making a stupid mistake like this seems more likely than a company having real motivation to create this kind of security hole.
I suppose, alternatively, this could have been an individual developer's intent. An exploit like this would get a pretty penny on the exploit market, I'd think.
Instead, they ask for their interns to build the "solution" that makes my computer part of the Borg.
I really don't feel compassion in this case towards the company (towards the users is a different story, no doubt)
Companies are often incompetant with security code. If you are expecting high quality secure code with consumer level software, you will often be disappointed.