I feel if this were the case literally anything I install on my PC would be suspect. Installing ssh would be a much more scary thing than a random steam game.
Kerbal Space Program comes to mind, I recall it had adware that did this.
https://unity.com/legal/game-player-and-app-user-privacy-pol...
https://unity.com/legal/game-player-and-app-user-privacy-faq
https://www.bleepingcomputer.com/news/security/steam-game-mo...
"Downfall, a fan expansion for the popular Slay the Spire indie strategy game, was breached on Christmas Day to push Epsilon information stealer malware using the Steam update system.
Once installed on a compromised computer, the malware will collect cookies and saved passwords and credit cards from web browsers (Google Chrome, Yandex, Microsoft Edge, Mozilla Firefox, Brave, Vivaldi), as well as Steam and Discord info.
It will also look for documents containing 'password' in the filenames and for more credentials, including the local Windows login and Telegram."
This is no different to downloading a random binary off the internet and being surprised it's malicious.
you can buy these games in their unpatched state today, and download a poc for them from github too: https://nvd.nist.gov/vuln/detail/CVE-2018-10718 https://nvd.nist.gov/vuln/detail/CVE-2018-20817
frankly playing video games on a dedicated device and network is the reasonable response to reading this shit
Then that has to be balanced against the freedom aspect where people want flexibility to build a workstation how they want and do what they want on it, and expecting it all to work (windows games being supported on non-windows is a more common issue now). PC casts the broadest net and catches a lot of different desires, similar with how high-end and low-end seem to be splitting over the past ~5 years rather than being a continuous spectrum I wonder if there will be distinct types of PC for gaming (eg set models like the old Commodore Amiga) or if trying to resist splits does more harm than good.
If I was really concerned about security I'd sooner dual boot into a second OS that had nothing on it, than buy a second box just to game on.
Yes. I truly believe some janky random anti-cheat kernel module could very well capture telemetry about my keystrokes to a log and then send that log off to a server.
At the very least I don't trust that it's secure enough to be in the kernel of a machine for which I require any degree of trust in its integrity.
See: https://www.trendmicro.com/en_us/research/22/h/ransomware-ac...