Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.bugs.dist > #1231526
| From | Fabian Greffrath <fabian@greffrath.com> |
|---|---|
| Newsgroups | linux.debian.bugs.dist |
| Subject | Bug#1094998: steam-devices: should document the security trade-offs implied by installing this package |
| Date | 2025-02-03 08:50 +0100 |
| Message-ID | <KbZnr-e0TL-1@gated-at.bofh.it> (permalink) |
| References | <KbHgR-dOpg-11@gated-at.bofh.it> <KbHgR-dOpg-11@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
Hi Simon, Am 2025-02-02 13:23, schrieb Simon McVittie: > If packages outside the Valve/Steam ecosystem are going to install > steam-devices automatically (#1094936) or encourage it to be installed > (#1078751) then it should have documentation describing the trade-off > between functionality and security that it implies. > > I am "too close" to this package to write that documentation: I don't > know > where prospective users of this package would look for this information > (README.Debian? the Description? Appstream metadata, if added by > #1078751?) > and I don't know how to condense the details of its security tradeoffs > into > a short summary. > > Below is an attempt at the long version, with the benefits and risks of > each thing that it enables. I would appreciate it if someone else could > condense this into a summary. thank you very much for the elaboration, it was a fun read! I guess your expertice on this topic is unmatched by most other developers. I think the long version of the risk documentation that you provided below would fit perfectly into README.Debian, though I agree that a TL/DR version would be nice to have as well. This should be accompanied by a short reference in the package description such as "Installing this package may impose some security risks that are discussed in detail in /usr/share/doc/steam-devices/README.Debian." The downside of this approach is, of course, that the documentation will only be available once the package is already installed. But, to be honest, if you already share your computer hardware and access at the system console with a malicious user, there may be way more obvious ways to get attacked than through the steam-devices package, right? Cheers, - Fabian
Back to linux.debian.bugs.dist | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
Bug#1094998: steam-devices: should document the security trade-offs implied by installing this package Simon McVittie <smcv@debian.org> - 2025-02-02 13:30 +0100
Bug#1094998: steam-devices: should document the security trade-offs implied by installing this package Fabian Greffrath <fabian@greffrath.com> - 2025-02-03 08:50 +0100
Bug#1094998: steam-devices: should document the security trade-offs implied by installing this package Simon McVittie <smcv@debian.org> - 2025-02-03 12:00 +0100
Bug#1094998: steam-devices: should document the security trade-offs implied by installing this package Fabian Greffrath <fabian@greffrath.com> - 2025-02-03 12:10 +0100
csiph-web