ValveSoftware / steam-for-linux

Issue tracking for the Steam for Linux beta client

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

[Deck UI] Unlimited pin attempts without penalties

cchulo opened this issue · comments

Your system information

  • Steam client version (build number or date): 1716584667
  • Distribution (e.g. Ubuntu): Bazzite
  • Opted into Steam client beta?: [Yes/No] No
  • Have you checked for system updates?: [Yes/No] Yes
  • Steam Logs: N/A
  • GPU: AMD/Steam Deck

Please describe your issue in as much detail as possible:

When setting a pin to unlock the steam deck, I am allowed to input as many wrong pin entries without any consequence. I would expect a penalty of 10 minute timeout for every 3-10 incorrect guesses for example. It is unclear, after experimenting and reading patch notes regarding this feature, if there are any limiters to prevent something like a USB input attack where thousands of pin combinations can be made per second. Adding a timeout after a few incorrect guesses can help mitigate such a case.

Steps for reproducing this issue:

  1. On the steam deck, set a pin
  2. Upon pin prompt, enter as many incorrect pin entries in rapid succession, one thing you can do hold the joy stick in one direction, and watch it populate the password incorrectly, really fast.
  3. After a few minutes of incorrect pins, enter the correct one, you are now logged in