3 ms·
At some point this is less of a steam issue and more of a Windows issue. An OS shouldn't allow applications to compromise eachother. Steam should maybe be liab
by tfha 7y ago
At some point this is less of a steam issue and more of a Windows issue. An OS shouldn't allow applications to compromise eachother.
Steam should maybe be liable if they are actively thwarting disclosure that would protect users but that's a tough thing to establish legally.
- yellowapple 7y agoIt's a Steam issue, given that background services don't have to run as SYSTEM, and yet Valve decided to have Steam's background service do precisely that. Thankfully, the Linux version doesn't seem to have this problem (AFAICT).
- e_proxus 7y agoI think it should become a Windows/Microsoft issue, to be honest. A good example is the recent Zoom vulnerability, the software made it possible to perform certain exploits on the user and operating system, so Apple stepped in and disabled the exploit. In this case, I think Microsoft should do the same in order to protect their users. My guess would be that the install base of Steam on Windows is as least on par with Zoom on macOS, if not many times larger. In the end, Microsoft will get bad reputation for having an insecure OS (not to even mention Valve here, and in the long run it will hurt them as same as it did Adobe with their Flash stubbornness).
- yellowapple 7y agoTrue; it'd be really nice if Microsoft started deprecating running non-essential things under the SYSTEM user. Windows could/should emulate the OpenBSD strategy of running services/daemons as unprivileged users dedicated to those services instead of as root. Windows does support this functionality, and ultimately Valve's to blame for not using it, but you're right that Microsoft should be more proactive in encouraging good design and discouraging bad design.