3 ms·
I’m the only local admin on my mother’s laptop, she’s never noticed and I’ve not logged in to do anything in over 2 years.
by tsujamin 2y ago
I’m the only local admin on my mother’s laptop, she’s never noticed and I’ve not logged in to do anything in over 2 years.
- dataflow 2y agoYeah, exactly. It really depends what you're doing. If you're doing software development as part of your job, that's obviously going to require admin privilege way more often than if you're answering emails.
- taberiand 2y agoEven doing extensive software development - including WSL, Docker, SQL Server, and other services needing low level access - Admin privileges usually only come up when installing, updating or uninstalling software.
- fireflash38 2y agoOnly problem is that certain things update constantly (VSCode)
- dataflow 2y ago> Only problem is that certain things update constantly (VSCode) Can't you just install it at the user level? https://code.visualstudio.com/docs/setup/windows#_user-setup-versus-system-setup https://code.visualstudio.com/docs/setup/windows#_user-setup...
- pdonis 2y ago> Can't you just install it at the user level? Sure, if you want your ordinary non-admin user to have write access to the executables, which makes it a lot easier for some malicious piece of software to hack them since it no longer needs to get root permissions.
- josephcsible 2y agoIf malware is already running as you with the ability to write to your files, what does it gain by Trojaning your VSCode to do bad stuff instead of just doing the bad stuff directly?
- pdonis 2y agoTrojaning your VSCode means trojaning the compiler that makes executables for you so what gets compiled is not just the source code you put in. And these are executables you might end up shipping somewhere. Is it really so hard to see why doing that might be something malware would want?
- dataflow 2y ago> Sure, if you want your ordinary non-admin user to have write access to the executables, which makes it a lot easier for some malicious piece of software to hack them since it no longer needs to get root permissions. As if non-admins have no way to create a new executable and run those instead? Windows has a million ways to run code, both visibly and invisibly. Why would malware prefer to trash an executable that the user relies on for daily work and risk revealing its presence so quickly?
- tsujamin 2y agoAgree, but also you don’t need the entire session running as admin. I usually leave a terminal and IDE running as an admin user with the rest of the session low-priv. Obviously some security weaknesses there but it’s better than having a whole admin session.