Skip to content

Reevaluate permission for external disks (huge security risk for backups) #1531

@gechoto

Description

@gechoto

UPDATE: see #1531 (comment) & #1531 (comment)


The steam flatpak added full read/write permission for secondary and external disks.

Having a steam library on external disks already worked before (without this permission).
I just tested it again by removing all filesystem permission and it still works.

I wonder what this is supposed to fix?
Can you explain in which cases this is really needed?

However it comes with a big downside:

It is somewhat common to use external disks for stuff like backups. Many users copy all their important stuff to backup media (including ssh keys and so on).

Now Steam sadly sometimes hosts malware.

This malware now has access to SSH keys and other private data.
It can infect other files with malware and when users try to run the programs from their backup drive it can easily infect the rest of the system.

This is a huge risk and helps malware a lot.

Please reevaluate or explain why this is really needed.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions