5 ms·
I built a separate Arch Linux box just for Steam gaming. I will never log into any of my sensitive accounts -- email, banking, etc. -- on that machine. It's a F
by steelframe 2y ago
I built a separate Arch Linux box just for Steam gaming. I will never log into any of my sensitive accounts -- email, banking, etc. -- on that machine. It's a Framework laptop so I can physically keep the camera and microphone disconnected. I basically treat it like a public terminal.
- j-bos 2y agoThis is the way.
- cascades42 2y agoYep, same here. I have a dedicated gaming machine because I’m afraid to expose my banking information.
- nathants 2y agodedicated hardware is a good idea, but too expensive for many. dedicated os is a good first step.
- Aeolun 2y agoDo you truly expect any steam games to have anything like a root kit that’d exfiltrate your credentials? I feel if this were the case literally anything I install on my PC would be suspect. Installing ssh would be a much more scary thing than a random steam game.
- wodenokoto 2y agoNo, he expects the root kit will open up his machine to automated worms.
- m463 2y agoI thought some games snooped through your system. Kerbal Space Program comes to mind, I recall it had adware that did this.
- Delk 2y agoUnity has some kind of data collection that can be used for analytics and advertising, so you might need to opt out of that in a Unity game. I think that came up in KSP as well. https://unity.com/legal/game-player-and-app-user-privacy-policy https://unity.com/legal/game-player-and-app-user-privacy-pol... https://unity.com/legal/game-player-and-app-user-privacy-faq https://unity.com/legal/game-player-and-app-user-privacy-faq
- westpfelia 2y agoThe concern is that malicious actors can take advantage of what is certainly a poorly written rootkit.
- gspetr 2y ago>Do you truly expect any steam games to have anything like a root kit that’d exfiltrate your credentials? https://www.bleepingcomputer.com/news/security/steam-game-mod-breached-to-push-password-stealing-malware/ https://www.bleepingcomputer.com/news/security/steam-game-mo... "Downfall, a fan expansion for the popular Slay the Spire indie strategy game, was breached on Christmas Day to push Epsilon information stealer malware using the Steam update system. Once installed on a compromised computer, the malware will collect cookies and saved passwords and credit cards from web browsers (Google Chrome, Yandex, Microsoft Edge, Mozilla Firefox, Brave, Vivaldi), as well as Steam and Discord info. It will also look for documents containing 'password' in the filenames and for more credentials, including the local Windows login and Telegram."
- maccard 2y agoThat's not a steam game, that's a user mod (read: random binary downloaded from the internet and executed). Also, it doesn't need kernel level access to do any of that stuff, it can get by just fine with normal application level permissions. This is no different to downloading a random binary off the internet and being surprised it's malicious.
- remnantdiving 2y agopatched: https://hackerone.com/reports/470520 https://hackerone.com/reports/470520 https://hackerone.com/reports/1070835 https://hackerone.com/reports/1070835 https://secret.club/2021/04/20/source-engine-rce-invite.html https://secret.club/2021/04/20/source-engine-rce-invite.html https://secret.club/2020/10/30/alien-swarm-rce.html https://secret.club/2020/10/30/alien-swarm-rce.html https://threatpost.com/dark-souls-servers-down-rce-bug/177896/ https://threatpost.com/dark-souls-servers-down-rce-bug/17789... https://blog.thalium.re/posts/achieving-remote-code-execution-in-steam-remote-play https://blog.thalium.re/posts/achieving-remote-code-executio... https://www.pcgamer.com/garrys-mod-cough-virus-is-cured-but-it-could-have-been-worse/ https://www.pcgamer.com/garrys-mod-cough-virus-is-cured-but-... you can buy these games in their unpatched state today, and download a poc for them from github too: https://nvd.nist.gov/vuln/detail/CVE-2018-10718 https://nvd.nist.gov/vuln/detail/CVE-2018-10718 https://nvd.nist.gov/vuln/detail/CVE-2018-20817 https://nvd.nist.gov/vuln/detail/CVE-2018-20817 frankly playing video games on a dedicated device and network is the reasonable response to reading this shit
- steelframe 2y ago> root kit that’d exfiltrate your credentials Yes. I truly believe some janky random anti-cheat kernel module could very well capture telemetry about my keystrokes to a log and then send that log off to a server. At the very least I don't trust that it's secure enough to be in the kernel of a machine for which I require any degree of trust in its integrity.
- LinXitoW 2y agoI don't expect that. I expect that publicly traded companies will cut corners in developing their kernel extension (like always), turning them into literal root kits waiting for anyone willing to exploit them. See: https://www.trendmicro.com/en_us/research/22/h/ransomware-actor-abuses-genshin-impact-anti-cheat-driver-to-kill-antivirus.html https://www.trendmicro.com/en_us/research/22/h/ransomware-ac...
- rldjbpin 2y agoat that rate why bother using arch for the box? unless you never touch online multiplayer games, i can understand that it probably works for you.
- gradientsrneat 2y agoI've heard good things about the Framework laptops from a modularity perspective, but how are the thermals? Can it have a dedicated GPU?