15 ms·
Hmm, In my experience, trying to stop a sufficiently motivated 'kid' is an exercise in futility. Here are some possible scenarios, in decreasing order of plausi
by 174SIGSEGV 5y ago
Hmm, In my experience, trying to stop a sufficiently motivated 'kid' is an exercise in futility. Here are some possible scenarios, in decreasing order of plausiblity:
1. At the surface level, you have to assume that the password mechanism is secure. I'm sure many of us remember the Windows 95 login, for instance.
2. But even making the assumption that the password is secure, social engineering will typically work against the parent.
3. Even if the parent is cautious, one can bypass Edge Kids Mode by simply not using Edge.
4. Even if no other browser is installed, this can be bypassed by copying a portable version from a friends.
5. Say the parent blacklists certain executables via GPedit. Typically, renaming the executable to a whitelisted one (e.g. calc.exe) will suffice.
6. Suppose the parent chooses to enable S mode, so that only Edge and UWP packages from the Microsoft Store can be enabled. The child creates a Linux live USB (at a friends house) and modifies the Windows filesystem directly (or ignores it entirely).
7. What if USB is disabled in BIOS, and the parent enables a BIOS password, and Windows has full disk encryption enabled? Disconnect the CMOS battery for a bit, I guess?
8. Say the parent gives up, welds the device shut, and cancels the internet service. Can't browse the Inter-webs without internet service, right? Wrong. Go to the friend's/neighbor's/public library and do it anyway.
In summary, Kids Mode is about as effective as transparent schoolbags or the Great Firewall. You are probably better of finding something interesting and productive for the kid to do (not to say learning to abuse poor infosec is a waste of time), so that they have better things to do than explore double-plus-ungood web sites.
- DoctorOW 5y agoDevil's advocate: It's still effective even if it's possible to bypass. I guarantee it's possible for someone with relatively easy to acquire tools and experience could pick a lock. But you still lock your doors at night. Having imperfect protections can, in the right situation, still work. My best guess is the situation in which one has to make a Linux drive without access to any of the distro websites is enough of a hurdle for your average nine year old.
- pcdoodle 5y agoBonus, your kid is now learning problem solving.
- hiimshort 5y agoThe first item in the list reminded me of an exploit on Windows 7 that allowed anyone to login and use the computer without an account. I don't believe it treated you as an administrator, but some other system user instead. The trick was: 1. On the login screen, press the shift key until the Sticky Keys window pops up. 2. Click the informational "learn more" link. That will open up a text file in Notepad. 3. In Notepad, select File > Open. 4. Navigate to system32 and rename the sticky keys executable to something else. Then, copy bat.exe and give the copy the name of the original sticky keys program. 5. Press shift multiple times like before, but this time a terminal will appear. 6. Run explorer.exe I was amazed that this not only worked, but wasn't patched in the years that I used Windows 7. It came in handy a few times, but I do hope they've fixed it by now. I know a lot of people still use Windows 7.