Valve removes free horror game from Steam after players discover it contains malware that steals your data
https://www.pcguide.com/news/valve-removes-free-horror-game-from-steam-after-players-discover-it-contains-malware-that-steals-your-data/
539 points · 62 comments · view on lemmy.world
62 Comments
gandalf_der_12te@discuss.tchncs.de · 135 pts · 74d
the simple solution would be to put every game into a sandbox by default
scholar@lemmy.world · 135 pts · 74d
Every program ideally should be in a sandbox and if it wants permission to access something it should have to ask for it.
defaultusername@lemmy.dbzer0.com · 62 pts · 74d
Kind of like Android or iOS.
Flatpak tries to accomplish this on Desktop, and it works, but isn't as comprehensive as something like Android or iOS.
On the extreme side, there is QubesOS, which runs every app in a dedicated virtual machine, including the networking stack.
LodeMike@lemmy.today · 8 pts · 74d
Flatpak also doesn't ask for permissions. If an app requires a new one does it just add it upon update?
defaultusername@lemmy.dbzer0.com · 2 pts · 74d
I believe so.
hirihit640@sh.itjust.works · 1 pts · 74d
I think either Bazaar or GNOME software center does tell you if an app asks for more permissions, I forgot which one though
LodeMike@lemmy.today · 1 pts · 74d
GNOME Software. That's not what I'm concerned about though.
elvith@feddit.org · 1 pts · 74d
IIRC Discover on KDE also tells you on the update list. But only somewhere in the list of updates - theres no explicit dialog warning you of changes/new permissions
BradleyUffner@lemmy.world · 3 pts · 74d
I've never seen a flatpak prompt me for permissions. If it needs something it didn't have it just silently fails for me and I have to guess what permission it needed manually using flatseal. Is that normal or am I setup wrong?
defaultusername@lemmy.dbzer0.com · 2 pts · 74d
That's normal.
Holytimes@sh.itjust.works · 1 pts · 72d
Its also the most annoying as fucking problem...
justlemmyin@lemmy.world · 2 pts · 74d
Is that what proton does on Linux?
elvith@feddit.org · 19 pts · 74d
No, that's just to make Windows programs/games run on Linux. But you can e.g. use the Flatpack version of Steam to Sandbox Steam and its games (https://docs.flatpak.org/en/latest/sandbox-permissions.html)
gandalf_der_12te@discuss.tchncs.de · 1 pts · 74d
thanks, i didn't know that! i'll keep it in mind.
elvith@feddit.org · 6 pts · 74d
Only downside: Initially the creator of a Flatpack defines how it is sandboxed. For Steam it's rather permissive. It's not like on mobile where you get asked for permission for everything potentially dangerous/privacy invading, but rather like the earlier days on mobile where you install a Flatpack and implicitly allow all permissions it wants.
An update might change the permissions or introduce new ones. You can use tools like Flatseal to change the permissions of installed Flatpack apps, but keep in mind that those changes will probably be gone after the next update and can introduce problems.
In the end, sandboxing something like Steam is hard, as you not only need to think about Steam's permissions, but also any game you might run from it...
gandalf_der_12te@discuss.tchncs.de · 2 pts · 74d
yeah personally i would be fine if it could access anything but my own personal files / the OS installation.
HertzDentalBar@lemmy.blahaj.zone · 10 pts · 74d
Those are my favourite type of game.
/s
DevoidWisdom@sh.itjust.works · 102 pts · 74d
HAL_9_TRILLION@lemmy.dbzer0.com · 54 pts · 74d
Joke's on them. I just put games in my library and never install them.
GutterRat42@lemmy.world · 50 pts · 74d
That's the horror part. It's part of the immersion.
BeUnique@lemmy.zip · 32 pts · 74d
Shouldn't Valve be scanning for these types of things!? The alarming part is that players had to find it
FireWire400@lemmy.world · 31 pts · 74d
There are so many games on Steam and every day a few hundred more are added. I assume there are automated checks and rudimentary malware scans in place but those aren't fault proof.
rob_t_firefly@lemmy.world · 12 pts · 74d
This appears to have originally been published as a totally different non-malware game. Either the original dev got their account taken over or turned heel, because the entire game was replaced with the malware game as an update to an existing game rather than a new published game.
I'm only speculating as I don't know much about the Steam publishing process, but I wonder if that helped the malware sneak past more rigorous checks which would happen on a totally-new upload.
bold_atlas@lemmy.world · 11 pts · 74d
Couldn't they just put the malware in encrypted compression files that the game unpacks on the client end?
Hudell@lemmy.dbzer0.com · 7 pts · 73d
When I first published a game on steam, valve kept blocking it because I had checked "controller support" and they tested it and said it didn't work with controllers. I tried to find any controller that didn't work, asked a lot of people to test it for me as well, no issues whatsoever. Gave up and unchecked that option. Game got approved. Players used controllers just fine, I went back and checked it and never heard anything from valve again.
BeUnique@lemmy.zip · 1 pts · 73d
Alright, setting you up for a shameless plug! What game did you make?
Hudell@lemmy.dbzer0.com · 4 pts · 73d
I'll let the opportunity pass, as the game is no longer mine and I'm not proud of how it ended up.
BeUnique@lemmy.zip · 2 pts · 73d
That sucks, sorry to hear. Hopefully you'll be able to create what you want someday.
BradleyUffner@lemmy.world · 5 pts · 74d
Scanners are only going to pick up known "off the shelf" malware. They are never going to pick up something bespoke that the developers wrote themselves.
TotallyWorthLife@lemmy.world · 1 pts · 74d
With the amount of games published every day, they can't. They should, but really can't. Either they keep it this way, or review each and every game under the Sun to find malware before they get published.
Hiro8811@lemmy.world · 0 pts · 74d
Maybe? Games are huge nowadays and looking through all of them will probably be impossible and not sure how well it'll prove? Google does that and there still are a lot of malware on play store.
teslekova@sh.itjust.works · 28 pts · 74d
Well, that's pretty horrifying.
osanna@lemmy.vg · 4 pts · 74d
dad, that you?
HugeNerd@lemmy.ca · 1 pts · 73d
Why, you wanna steal his joke?
tehn00bi@lemmy.world · 20 pts · 74d
When is valve removing windows 11?
Warl0k3@lemmy.world · 41 pts · 74d
Isn't that exactly what SteamOS is doing?
Kolanaki@pawb.social · 14 pts · 74d
When you buy a Steam Deck or Steam Machine.
Chais@sh.itjust.works · 9 pts · 74d
They can't. It's not sold through Steam.
Lost_My_Mind@lemmy.world · 16 pts · 74d
What? Why are they removing free games??? Oooooh, they must want you to pick the paid games....
Oh. Well that's a very good reason to remove it. Thanks Valve!
panda_abyss@lemmy.ca · 13 pts · 74d
Once wasm 64 bit deploys more, we should migrate as much as possible to it.
That at least will make it harder to access random files and keys from disk due to the sandboxing.
Sandbox escapes are still possible, but that’s an additional level of control we can enforce.
BoxOfFeet@lemmy.world · 9 pts · 74d
Nothing's free in Waterworld.
LapGoat@pawb.social · 7 pts · 74d
to be devils advocate, that is pretty scary.
TryingToBeGood@reddthat.com · 7 pts · 74d
Yikes!
Squatcher@piefed.social · 1 pts · 74d
But it was a "feature"
Gsus4@mander.xyz · 1 pts · 74d
They had to do one thing...
db2@lemmy.world · -26 pts · 74d
laughs in proton
Thaurin@lemmy.world · 73 pts · 74d
Proton does not protect you from harm. It’s not a sandbox.
WraithGear@lemmy.world · 1 pts · 74d
what about bazzite set to immutable?
nous@programming.dev · 25 pts · 74d
That does not stop things from stealing your data.
db2@lemmy.world · 0 pts · 74d
No but it also doesn't have windows on the other side, someone would have to target a proton setup to get much of anything.
DacoTaco@lemmy.world · 14 pts · 74d
Ye no. If i made malware for windows that goes over all reported drives wine will just happily translate that. Hell, by default wine will map root as z: so no, wine/proton will not help.
Even wannacry was able to cause some damage to linux if ran through wine
bryndos@fedia.io · 1 pts · 73d
Thanks! That's very useful to know - I'd have assumed it can only see it's own files within the wineprefix folder.
It looks like trying Steam within flatpak, and limiting the flatpak's access might offer some protection. Or maybe getting stem to run as a different user.
Thaurin@lemmy.world · 3 pts · 74d
Why wouldn’t they? Linux is gaining market share.
demonsword@lemmy.world · 3 pts · 74d
Yeah, it's slowly gaining market share, but it's still a minuscule size of the user base
alakey@piefed.social · 12 pts · 74d
Would that even help? Windows malware can run on Linux precisely thanks to Wine and Proton.
chloroken@lemmy.ml · -11 pts · 74d
You don't actually believe this, right?
altkey@lemmy.dbzer0.com · 4 pts · 74d
My uneducated guess is that it would run inside the prefix but would have troubles with basic Windows dependencies not availiable/running, prefix's folder structure being cut down to the most basic components and barebones, and that nothing actually runs like in Windows but is rather translated from Linux commands to Windows one and back? Meaning there's no processes or services like in a VM, no way to run cmd or powershell scripts, nothing to steal without leaving containment? Am I wrong somewhere?
I recall there was a wave of dread about Proton leaving host system easily accessible and not implementing any security measures as they are out of scope, but if we assume it's a virus targeting Windows, I'm half sure it would have troubles doing anything the usual way.
cmnybo@discuss.tchncs.de · 11 pts · 74d
The malware won't be able to do as much as it could on windows, but it can still access all of the files your user account has access to. It can steal, encrypt or delete all of your files. It can also access your microphone if you have one connected.
You can run Wine as a different user or run it with firejail to limit what it has access to.
altkey@lemmy.dbzer0.com · 1 pts · 74d
Is it applicable to Proton in some way? I'm guilty of using less popular and thus less veried cracked software with it so I'd like some level of protection. Can I separately write it in some config file?
cmnybo@discuss.tchncs.de · 3 pts · 74d
Proton is just Wine with some modifications. You can use the same sandboxing methods you would use with Wine.
wonderingwanderer@sopuli.xyz · 1 pts · 74d
Firejail runs apps in a sandbox.
And you can make a separate non-root desktop profile to run it in so even if it somehow escapes containment it can't run sudo commands or steal your main login's data.
alakey@piefed.social · 2 pts · 74d
https://www.youtube.com/watch?v=d3fSnHTJdR0
chloroken@lemmy.ml · -4 pts · 74d
Hey PieFed user, posting a 5-minute meme video where the guy struggles to make a custom virus do something through Proton isn't the own you think it is. It literally corroborates my point. Windows viruses and malware will not work through Proton.