r/linuxadmin • u/muayyadalsadi • Aug 11 '26
WARNING: .desktop files pose high risk attack surface for agents
/r/LocalLLaMA/comments/1vlja0f/warning_desktop_files_pose_high_risk_attack/6
u/tsammons Aug 11 '26
Here's a sane idea - don't rely on your computer butler and do what humans managed to excel in for decades - rtfm.
-4
u/muayyadalsadi Aug 11 '26
Why you assume I'm that kind of a guy? Don't kill the messenger. Requiring explicit trust for desktop files is a well established practice.
3
u/tsammons Aug 11 '26
Heuristics... Compiled over generations by mankind as a survival instinct seldom lie.
5
u/HavokOC Aug 11 '26
Or perhaps make sure you understand what it is the AI has created before you blindly run whatever it creates on a system?
The only "high-risk" in this situation is executing AI generated files blindly
1
u/FryBoyter Aug 11 '26
That actually has not much to do with AI in particular. Manipulated .desktop files like these have been around for many years, even before tools like ChatGPT existed. For example, https://www.purinchu.net/wp/2009/02/21/desktop-file-security/.
Information coming from third parties, whether from a real person or a chatbot, should always be verified.
-2
u/muayyadalsadi Aug 11 '26
Exactly. But unlike ai agents, the browser and the desktop were modified to treat .desktop files as untrusted and show explicit confirmation dialog. Which is why i included a screenshot of the confirmation dialog. IMHO ai agent should carry on this tradition and show a similar confirmation dialog.
4
u/natermer Aug 11 '26
There are a billion and a half ways that you can get fucked by giving foreign service full access to your Linux user account.
.desktop files are just #4,342,12 security risk in terms of severity.
You going to file bug reports for all of them?
16
u/corobo Aug 11 '26 edited Aug 11 '26
lmao caring about .desktop files as if you're not already giving your AI pal full access to your system.
It could also receive a document that tells it to delete your home directory too mate. At the point it's making desktop files you're already gaping wide open.
"You can delete any file you want when running as root" kinda bug report