Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Not if they haven't granted access to the files to you. In fact by default the files in a user's home folder (including Documents, Videos etc.) are inaccessible to other (non-privileged) users on Windows.


If they have physical access, then they don't need to boot into Windows. They could boot from a flashdrive and access any files they want.


This is true, and also why I lock down my BIOSs and set the OS as the only boot device. TRK is a bootable portable linux specifically for resetting and unlocking local admin accounts.

Encryption, however, cannot be broken without your credentials. These can be obtained from default running instance of Windows with Mimikatz if the admin credentials are still in memory from an earlier session.


Yeah, there are definitely ways of securing versus someone with physical access, but I expect most machines with a non-sandboxed steam installed probably don't have them.

This privilege escalation attack is probably never going to be used if the attacker has physical access.


> In fact by default the files in a user's home folder (including Documents, Videos etc.) are inaccessible to other (non-privileged) users on Windows.

Sure that's certainly right but physical access doesn't force you to be "on Windows".

> This is true, and also why I lock down my BIOSs and set the OS as the only boot device.

I never talked about you specifically, you are a tiny tiny minority. Even then, that just block your computer. If you can't bypass that BIOS (seriously doubtful), the hard drive is still accessible.

> Encryption, however, cannot be broken without your credentials.

Is there an encryption on by default? That must be new because I'm pretty sure I never had trouble to access my user folders on some of my old Windows 7 installation (that's would be a good 20% of Steams users).

I can't find anything about this, if I have time tonight I'll try to see if I can access my user folder through another OS.


That won't help in the case of full-disk encryption.


And Windows has useful account-based file encryption too.


> And Windows has useful account-based file encryption too.

Is this on by default on Windows? I haven't needed to access my files from another Windows installation for a long time, but I'm pretty sure the last time I tried on my good old hard drive with Windows 7, they weren't encrypted and I had no trouble to access them.


No, but it only takes a minute to turn on if you're going to be sharing unsupervised access to a computer.


> No, but it only takes a minute to turn on if you're going to be sharing unsupervised access to a computer.

This is not something that 99.99% of Steam users would do though...

It would still be possible to retrieve the encryption keys too if the PC is still running (which is also the only ways to make Steam vulnerability viable) using a can of compressed air [1].

As I said, physical access to a computer is pretty much already game over... The Steam vulnerability is quite useful while being connected remotely though (which is really the most likely scenario either way).

[1] https://www.zdnet.com/article/cryogenically-frozen-ram-bypas...




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: