4 ms·
Physical access is god access. Admin/root is god access. Guard them both with your life. I fail to see how handing over control of your boot to some 3rd part
by _account 14y ago
Physical access is god access. Admin/root is god access.
Guard them both with your life.
I fail to see how handing over control of your boot to some 3rd party who clearly doesn't have the same interests that you do is anything but a horrible idea.
Just physically secure your boxes(or VDI them) and use permissions and ACLs to do what they were designed to do[control and delegate authority].
A good first step for Microsoft, if it cares so much about security, is to stop making its users automagically admin for fogging a mirror, during new PC setup.
- csense 14y ago> handing over control of your boot to some 3rd party...a horrible idea It's actually a good idea if you're the party who's getting authority over the world's computers handed over to it. > use permissions and ACL I still have no idea how these work in the Windows world [1]. There's nowhere obvious in the UI or the "dir" command that shows you what the ownership and permission is [2], unlike Linux's ls -al. My one experience with Windows permissions is, in the early '00s, I put an NTFS partition on an external drive because I wanted to put >4GB files on it. I copied them and got a bunch of permissions errors opening them on another computer. My impression of Windows access controls from this: They're invisible things the OS attaches to your files which will potentially make them unreadable later. [1] I understand there's something called ACL's in Linux too, but I never use them. [2] I don't have much experience with multi-user Windows systems, and Linux has been my main OS for 3-4 years so I don't have as much experience with post-XP OS's.