Wolzette Feb 24, 2017 @ 6:45am
A secure (HTTPS) way to download Steam client?
Hello, folks! The question is: is there Steam client downloading link, a HTTPS link on an HTTPS page owned by Steam (with their HTTPS certificate)?

The "Install Steam" at the page's top leads to http://store.steampowered.com/about/ , which obviously isn't HTTPS. And the client downloading link on that page, while being HTTPS, doesn't belong to any of Steam/Valve domains: https://steamcdn-a.akamaihd.net/client/installer/SteamSetup.exe .

It may look paranoid, to demand all links to be secure while "hey, it's the Steam site!"
But I know cases when providers redirect or alter traffic, including insertions from a third party, like ad partners. So the installer can be replaced with something else when downloaded from an insecure page.

So it would be cool to just have HTTPS enabled all the way, and that means a Steam-owned secure page with a secure link to download the client. Have you seen one?

UPD: Well, the installer I just downloaded has Valve's digital signature, so I feel slightly better.
Last edited by Wolzette; Feb 24, 2017 @ 8:50am

Something went wrong while displaying this content. Refresh

Error Reference: Community_9708323_
Loading CSS chunk 7561 failed.
(error: https://community.cloudflare.steamstatic.com/public/css/applications/community/communityawardsapp.css?contenthash=789dd1fbdb6c6b5c773d)
Showing 1-10 of 10 comments
mimizukari Feb 24, 2017 @ 6:53am 
that is a steams website.... it's right there in the name, steamcdn-a
The End Feb 24, 2017 @ 6:55am 
There is no risk in getting the client, the download link/file is hosted at Akamai, they host all Valves/Steam files, and the downloadlink is https.

It's safe.
Last edited by The End; Feb 24, 2017 @ 6:55am
Wolzette Feb 24, 2017 @ 6:57am 
Originally posted by Shiki Ryougi:
that is a steams website.... it's right there in the name, steamcdn-a
Not everything you can read "Steam" on, actually belongs to Steam. Domains are read from the end, and the final link is steamcdn-a.akamaihd.net , that means it leads to akamaihd.net . Akamaihd.net doesn't belong to Steam, does it?
Wolzette Feb 24, 2017 @ 6:59am 
Originally posted by 🌜Rockon🌛:
There is no risk in getting the client, the download link/file is hosted at Akamai, they host all Valves/Steam files, and the downloadlink is https.

It's safe.
It's just about I'd like to see that link on a secure page. To make sure it's what Steam gives me.
mimizukari Feb 24, 2017 @ 7:00am 
Originally posted by Wolzette:
Originally posted by 🌜Rockon🌛:
There is no risk in getting the client, the download link/file is hosted at Akamai, they host all Valves/Steam files, and the downloadlink is https.

It's safe.
It's just about I'd like to see that link on a secure page. To make sure it's what Steam gives me.
there is no link other than akamaihd, because that's what steam uses to distribute everything from pictures/screenshots to their client.
Wolzette Feb 24, 2017 @ 7:06am 
Originally posted by Shiki Ryougi:
Originally posted by Wolzette:
It's just about I'd like to see that link on a secure page. To make sure it's what Steam gives me.
there is no link other than akamaihd, because that's what steam uses to distribute everything from pictures/screenshots to their client.
I don't mind Steam delivers everything via a certain CDN, the problem is that the download link is placed on an untrusted page, and technically can be replaced. So I asked if anyone knows a secure page with the link.

Yeah I know it looks paranoid, but when I see an ad instead of a page I go to (that turns out to be blocked), and that's legally inserted by my provider or their friends, I just want nobody to get into my traffic. That's why I asked about HTTPS.
mimizukari Feb 24, 2017 @ 7:09am 
Originally posted by Wolzette:
Originally posted by Shiki Ryougi:
there is no link other than akamaihd, because that's what steam uses to distribute everything from pictures/screenshots to their client.
I don't mind Steam delivers everything via a certain CDN, the problem is that the download link is placed on an untrusted page, and technically can be replaced. So I asked if anyone knows a secure page with the link.

Yeah I know it looks paranoid, but when I see an ad instead of a page I go to (that turns out to be blocked), and that's legally inserted by my provider or their friends, I just want nobody to get into my traffic. That's why I asked about HTTPS.
no. there is no other link. akamaihd is steam's provider and they only use those links. you always want to grab the latest from steam itself, you're too paranoid. just run it through virustotal if you have to.
Last edited by mimizukari; Feb 24, 2017 @ 7:09am
ReBoot Feb 24, 2017 @ 7:15am 
Originally posted by Wolzette:
Originally posted by Shiki Ryougi:
there is no link other than akamaihd, because that's what steam uses to distribute everything from pictures/screenshots to their client.
I don't mind Steam delivers everything via a certain CDN, the problem is that the download link is placed on an untrusted page, and technically can be replaced. So I asked if anyone knows a secure page with the link.

Yeah I know it looks paranoid, but when I see an ad instead of a page I go to (that turns out to be blocked), and that's legally inserted by my provider or their friends, I just want nobody to get into my traffic. That's why I asked about HTTPS.
Replaced by whom? Yes, you are being paranoid. Is your provider blocking Steam? Do you have a real case here? Because so far, it looks like principles -only.
Wolzette Feb 24, 2017 @ 7:16am 
Originally posted by Shiki Ryougi:
Originally posted by Wolzette:
I don't mind Steam delivers everything via a certain CDN, the problem is that the download link is placed on an untrusted page, and technically can be replaced. So I asked if anyone knows a secure page with the link.

Yeah I know it looks paranoid, but when I see an ad instead of a page I go to (that turns out to be blocked), and that's legally inserted by my provider or their friends, I just want nobody to get into my traffic. That's why I asked about HTTPS.
no. there is no other link. akamaihd is steam's provider and they only use those links. you always want to grab the latest from steam itself, you're too paranoid. just run it through virustotal if you have to.
Yeah, maybe a tiny bit too much.

Okay, thank you for replying, have a nice day :)
Wolzette Feb 24, 2017 @ 7:22am 
Originally posted by ReBoot:
Originally posted by Wolzette:
I don't mind Steam delivers everything via a certain CDN, the problem is that the download link is placed on an untrusted page, and technically can be replaced. So I asked if anyone knows a secure page with the link.

Yeah I know it looks paranoid, but when I see an ad instead of a page I go to (that turns out to be blocked), and that's legally inserted by my provider or their friends, I just want nobody to get into my traffic. That's why I asked about HTTPS.
Replaced by whom? Yes, you are being paranoid. Is your provider blocking Steam? Do you have a real case here? Because so far, it looks like principles -only.
I haven't a real case for me and Steam, but there are cases for other resources and my country providers. So I wanted to.. oh, you know. Well, as we found out I'm being paranoid and you have no HTTPS page with the client download link, I think we are done with it here. Thank you:)
Last edited by Wolzette; Feb 24, 2017 @ 7:23am
Showing 1-10 of 10 comments
Per page: 1530 50

Date Posted: Feb 24, 2017 @ 6:45am
Posts: 10