Re: Weird situation



Ertugrul Soeylemez wrote:
"Barton L. Phillips" <barton@xxxxxxxxxxxxxxxxxx> (06-12-16 06:09:22):

I have seen a lot of enterprise Windows shops and almost all of them
have a VERY restricted user policy. No casual user has "Administrator"
(root) privilege. These shops are just a locked down as any Unix shop
and in some cases more locked down as they also use policies to
restrict use of applications and ACL (access control lists) to
restrict privileges (something which Linux has only recently started
to support). These enterprise shops have a full time staff of IT
people that have been trained and get good pay. End users do NOT under
any circumstance get to install anything. It can be pretty draconian
but it works just like the Sun shops I worked in. If you need it done
you have to call the IT people who come and do it and leave.

Most people just don't have the understanding or patience for this at
home. Windows biggest problem, in my opinion, has been there is no
equivalent to su or sudo. Windows does have a "Run As" mechanism but
it is disabled by default and it is just too hard to make work, if
fact it is just plane broken. Linux distributions like Ubuntu make it
pretty easy for a person to keep from living as root. The sudo
mechanism works pretty well, though it is a problem if a person is too
uninitiated. It is also not a good distribution, in my opinion, for an
enterprise shop as it is too easy to be root and destroy everything.

I hope I don't get flamed for this. As I said it is just my opinion
and I could be wrong.

In some matters, yes. The problem of Windows is, that security means
restriction. To secure something up, you need to prohibit at least this
particular thing. For example, in Linux you can do almost anything as a
normal user, besides changing system-wide things.

In Windows, such a configuration is not possible. Some people might
consider this security by obscurity. Like I have to prohibit my
children from turning on the TV themselves, so I get control over which
programs they watch.


Regards,
E.S.
I certainly agree and don't get me wrong I HATE Windows. As far as I am concerned Windows is and has always been broken. Year after year Microsoft has added new features but has seldom really fixed any of the standing problems.

Having ranted the above, I have worked in environments where Windows has been made to work and is pretty darn secure. This has taken tremendous effort from the IT staff and an enlightened management but it was done. The poor IT guys had to come in in the middle of the night to do almost all upgrades and patches because every machine in the enterprise would have to be rebooted many times during the process. However, with dedication and a awful lot of very hard work Windows can be made usable and basically secure.

Why anyone would want to go through such pain is hard for me to understand, especially now with so many very good and usable alternatives. But then again what do I know?
.



Relevant Pages

  • Re: Weird situation
    ... restrict privileges (something which Linux has only recently started ... These enterprise shops have a full time staff of IT ... Windows biggest problem, in my opinion, has been there is no ... pretty easy for a person to keep from living as root. ...
    (comp.os.linux.security)
  • Re: How to block system copy commands at driver level
    ... about GUI level windows internals, but there are a number of tricks you ... Open Source&Dest/Read Source/Write Dest loop, and you're not going to be ... thats the reason our task is limited to restrict standerd copy/paste ... #3 + preventing someone opening the file in notepad, ...
    (microsoft.public.development.device.drivers)
  • Re: How to restrict program access in guest account?
    ... To enforce file and folder security, boot the computer in Safe Mode and log ... Explorer and locate the file/folder you wish to restrict. ... NoWindowsSetupPage - Disable Windows Components Wizard ... >I want to create an account for visitors to use that will allow then> internet, games, and Office programs and nothing else. ...
    (microsoft.public.windowsxp.customize)
  • Re: how to restrict log on hours for child user
    ... > I need a somewhat transparent way to restrict ... Unfortunately, in a workgroup environment or on a standalone system, Windows ... You would have to manually disable your son's account ... If you put a checkmark there and click OK, your son will not be able to log ...
    (microsoft.public.security)
  • Re: Restrict folder access
    ... Set, View, Change, or Remove Special Permissions for Files and Folders ... > To restrict access to Control Panel and other system tools, see www.dougknox.com, Win XP Utilities, Windows XP Security Console. ... >> How do you restrict or deny access to folders for a user? ...
    (microsoft.public.windowsxp.security_admin)