Not if they haven't granted access to the files to you. In fact by default the files in a user's home folder (including Documents, Videos etc.) are inaccessible to other (non-privileged) users on Windows.
This is true, and also why I lock down my BIOSs and set the OS as the only boot device. TRK is a bootable portable linux specifically for resetting and unlocking local admin accounts.
Encryption, however, cannot be broken without your credentials. These can be obtained from default running instance of Windows with Mimikatz if the admin credentials are still in memory from an earlier session.
Yeah, there are definitely ways of securing versus someone with physical access, but I expect most machines with a non-sandboxed steam installed probably don't have them.
This privilege escalation attack is probably never going to be used if the attacker has physical access.
> In fact by default the files in a user's home folder (including Documents, Videos etc.) are inaccessible to other (non-privileged) users on Windows.
Sure that's certainly right but physical access doesn't force you to be "on Windows".
> This is true, and also why I lock down my BIOSs and set the OS as the only boot device.
I never talked about you specifically, you are a tiny tiny minority. Even then, that just block your computer. If you can't bypass that BIOS (seriously doubtful), the hard drive is still accessible.
> Encryption, however, cannot be broken without your credentials.
Is there an encryption on by default? That must be new because I'm pretty sure I never had trouble to access my user folders on some of my old Windows 7 installation (that's would be a good 20% of Steams users).
I can't find anything about this, if I have time tonight I'll try to see if I can access my user folder through another OS.
> And Windows has useful account-based file encryption too.
Is this on by default on Windows? I haven't needed to access my files from another Windows installation for a long time, but I'm pretty sure the last time I tried on my good old hard drive with Windows 7, they weren't encrypted and I had no trouble to access them.
> No, but it only takes a minute to turn on if you're going to be sharing unsupervised access to a computer.
This is not something that 99.99% of Steam users would do though...
It would still be possible to retrieve the encryption keys too if the PC is still running (which is also the only ways to make Steam vulnerability viable) using a can of compressed air [1].
As I said, physical access to a computer is pretty much already game over... The Steam vulnerability is quite useful while being connected remotely though (which is really the most likely scenario either way).