We don’t.
We really really don’t.
Consider the attack that Israel carried out this fall by detonating walkie-talkies and pagers. This wasn’t just some illicit code in the firmware or hardware, they managed to hijack the supply chain and hide literal bombs in commercially-produced handheld devices!
Bottom line: If you do not directly control the production chain from chip design and fab to end-user software, you can never be sure.
40 years ago, the legendary Ken Thompsonand Dennis Ritchie accepted the Turing Award for creating Unix. Thompson’s acceptance speech Reflections on Trusting Trust pointed out this same fundamental security flaw.
I encourage everyone to read the article, and spread it as widely as possible. It is terrifying and accurate, nearly half a century later.
No idea what Steam has to say, but I’ve played more games for longer than Steam has been around, so here’s a guess of mine in no particular order: