The Jackbox Megapicker was corrupting SteamOS and forcing people to reinstall the entire OS. It’s been fixed with a hot fix for now, but probably safest to avoid it until they get this all sorted out.

  • inlandempire@jlai.lu
    link
    fedilink
    arrow-up
    18
    ·
    4 months ago

    What worries me is : can a bad actor reproduce whatever bug was corrupting SteamOS, and publish games on the storefront with the sole intent to mess with people?

    • deegeese@sopuli.xyz
      link
      fedilink
      arrow-up
      7
      ·
      4 months ago

      I hope it’s a case of the writer glossing over details, like it corrupts its own files in a way Steam can’t understand or recover.

      The implication that a malicious app can break the whole OS is scary.

    • rotopenguin@infosec.pub
      link
      fedilink
      English
      arrow-up
      3
      ·
      4 months ago

      The main thing that a bad actor would gain is “being kicked off of the steam store”. The bigger threat would be if Gabe figures out which is the bad actor’s main account. Losing all their games would be pretty big blowback for such an attacker.

      • CaptDust@sh.itjust.works
        link
        fedilink
        arrow-up
        2
        ·
        edit-2
        4 months ago

        Ah… so I guess the gamescope session would fail bc steam fails, and leave the user no way to change to desktop/plasma session. And yeah, steam configs would be accessible in user space as it’s not system level. Yikes all around.

    • rotopenguin@infosec.pub
      link
      fedilink
      English
      arrow-up
      5
      ·
      4 months ago

      The problem is that SteamOS doesn’t have a whole lot of boot options besides “start up directly into Game Mode successfully”. If Steam chokes while ingesting any of its config or any metadata in your library, that’s the end of it. You can hold a button to wipe everything (the Playstation solution), or you can figure out how to boot a live-iso and fix “the problem”. Not everybody has the skills to fix stuff in Linux, heck not everybody has the ability to “boot up from a usb stick and have a working keyboard, using only one USB hole”.

  • solberg
    link
    fedilink
    English
    arrow-up
    3
    ·
    4 months ago

    This is like crowdstrike all over again