Jump to content

stylemessiah

Members
  • Posts

    36
  • Joined

  • Last visited

Everything posted by stylemessiah

  1. Sorry to go OT, but... Thats actually not the only way to do it. Thats what Microsoft SAY is th eonly way to do it properly.... See my posts here: http://www.edugeek.net/forums/windows/81112-mandatory-profile-group-policy-preferences-2.html#post938300 and here: http://www.edugeek.net/forums/windows-7/109909-prevention-file-creation-etc.html#post941148 Between those two are the methods and tools i used to set up my mandatory profile - kiosk/guest user standalone PC Its targeted at a non domain PC with roaming profile, my needs were quite specific, but its good info to have in case you go down this path someday I use DefProf from ForensiT Free Downloads to copy over the customised profile to default, this tool does it properly, unlike every other way suggested, and it avoids having to do the sysprep garbage I really need to combine those posts into one, if only for my own records ....
  2. As far as my own mandatory profile, albeit on a standalone PC, if i want to edit anything, i just rename the ntuser.man to ntuser.dat, log in as the user that the logon is assigned to, edit away. once done i just logout and rename the ntuser.dat to ntuser.man again. If however youre trying to edit things that may be disallowed via GPO and arent editable when logged in as that user (though you can temporarily disable GPO's), and it is a simple change/edit that can be made via regedit, i would try the aforementioned load the ntuser.man hive, assign it to a temporary key (i always use 11111111) in regedit and edit the necessary registry entries, then unload the hive and test.
  3. A day ago, an article appeared online on one of our major newspapers: Designing A GooD BYOD Policy | Mobility Policy Is All About The User I count this as one of the worst articles on the subject ever written.... Here was my response to the article (pending perusal by newspaper), and it may apply here: Completely missing the point is that in the workplace, workers are there to work, and they must abide by company policy. The article seems to pontificate that users be able to being along any device they see fit and put the onus back on the IT department to work FOR them to enable them to use devices that they also use in their personal lives. This equation is completely backwards. The company, which not only pays their salary, also puts in place policies to decide what devices can be used in the workplace and what security implications there are using such devices. The company should have zero interest in making ANY effort to enable users to enable their personal devices on a company network. Ive seen plenty of educational institutions and some companies start to and accomplish setting up BYOD (Bring Your Own Device) infrastructure and policies, and at their cost, and my response to this is "Are you mental?". Who in their right mind would spend capital expenditure to enable users to use whatever device they own in a company/educational institution environment. the side effects or loss of productivity, security and the time spent catering to some random persons one off device having issues is just a massive time vampire hovering over the whole idea. Certainly where i work, people go there TO work, get paid for doing that work. The company or institution is there to make money/teach, not subject itself to the whims and wants of a tablet/iphone carrying timewaster. Implying theres some sort of right for users to expect this is unprofessional, completely uninformed and goes against the core responsibility of the IT department has to its employer, to provide a functional and secure environment for the benefit of the company not the end user....
  4. I assume that Chrome OS runs the Chrome browser...so thats 30 + 291 = 321 How does that refute my argument? One would think it only serves to strengthen it. Again, as i posted earlier, for me its about mitigating security vulnerabilities, and i argued that when you install software (Chrome) that has far far more vulnerabilities than the equivalent software already present in the OS, youre going against best security practice. To further push the point i offered to let people add up the underlying Os vulnerabilities along with the IE ones and suggest that it came close to the number in chrome. Honestly, i am truly leaving this thread and unsubscribing from the thread to stop the email updates for good as this is just like shooting fish in a barrel. People keep making my point for me.
  5. Actually i think you will find it was about security, and mitigating security issues, of which Chrome had the highest of any software last year. But youve just confirmed youre nothign but a fanboy with that comment....wow, thanks for making my point for me.
  6. So youre advocating that admins take a reactive role to security, instead of the tried, true and prudent proactive one that has existed since the beginning of admin time? Hey everyone, lets all go around and uninstall antivirus and anti malware and any other security software on all our users desktops, and while we're at it, lets take down the firewall as well. We'll worry about the damage after its occurred...wait, that doesnt sound right..... Your comments re: Chrome just continue to paint you as a fanboy....and i loathe fanboys Oh, im confused, on one hand you want to let Chrome, java and flash to roam untamed, but now youre saying you do mitigate security issues with firewalls, AV and ACL's. Seems a little inconsistent with your earlier comment above....Im just saying.... But then youre back to reactive again talking about backups in case it all goes horribly wrong.... So i'll say what i said a dozen messages ago or so, why install a product with a demonstrated and known high number of security issues in the first place? Wouldnt that be best answer to both my proactive, and your reactive styles of admin? Again, the comment of a fanboy defending blindly his chosen company/software I wont be changing my name and fleeing to a country with no extradition with the US anytime soon. Its your right to side with someone else who wants to remain a fanboy and blind to reality and easily verifiable facts ive presented, ironically you can use Google search to do this. but no, you would rather stick with your limited views and argue rather than do some research. thats fine Where have i supported any one company. I think ive said i dont use IE, that Microsoft's security used to be a joke, but has gotten better. So yeah, im not a fanboy like you. If i support any company or software, and i havent in this entire thread, its based on actual facts and personal experience (usually over many years), not the wide eyed optimism (coupled with ironically complete blindness) of a fanboy. Dont you? Nope, my responsibility doesnt extend to personal devices. and youre being silly... No they can print, but its only going to be either things they create or have access to via a whitelist on the internet. Any sensitive material is logged as its being accessed or printed. Its called security. Actually youre wrong. You can mitigate almost any point youve raised pretty easily. ive explained how and why already. Im glad to hear you at least have a policy to require data leaving the site to be encrypted. its just a shame youre willing to open up the possibility of it leaking via insecure software, via the internet, which is a much more likely path in this day and age. Really am over this thread. Whoever ventures in here and agrees with the title "Chrome will bring about the ICT revolution in schools" is entering a fools paradise. Im out.
  7. Umm, if you read above, i have already stated i dont use IE...so no, im not against installing things not in the OS...cleared up. What im against is installing things which are full of exploits far far above what are present in those equivalents in the OS, in the case when specifically talking about Chrome and IE. Its utter madness to do so. no admin worth his left teste would do such a thing. Really, as you seem to love google, if i wanted to deal with fanboyism, i'd go over to Neowin....really really over blind faith fanboys....really Youre right its illegal for them to openly disclose any information they gather of a personal nature. But then its hard to sue a company who isnt doing it openly. Reminds me of the AT&T & Verizon personal disclosure terms and agreements, and how well they worked, right up until a whistleblower blew the lid on the FBI to a lesser extent, and the NSA a larger, having their own rooms at AT&T & Verizon where they spliced directly into trunk lines and had access to all users data, not just those who were subject to warrants. When the staffer blew the whistle the FBI pointed out that the companies (AT&T & Verizon) themselves were data mining their own customers and passing on their information to 3rd parties. And the story quickly died. And you dont think that Google, with its huge server farms, and whose entire business is based on user data, is doing anything but whats in its terms and conditions? Ummm, did someone call me naive earlier? Time for me to go to sleep....
  8. Nope, but they will love to have their names, any date information, any personal information to be able to identify and track that person in future. When you realise that employment agencies are already not only rejecting applicants by keywords and phrases in cover letters and resumes, but then submitting those on the short list to companies who do background checks using data that has already been mined, then you might take things a little more seriously.
  9. Yep, i am isolating Chrome and IE. For this simple reason, one comes as part of the OS, and one you have to manually install. And i believe thats its responsible to mitigate security issues, and by installing Chrome, as it currently stands, its counterproductive in my opinion. Why would any sane person install something thats less secure than a built in component of the OS. Lets be clear, Chrome uses WebKit, which has the most exploits of any browser engine. And its used in Safari and iTunes, so if you have a Mac and run all these then good luck to you. And of course the once popular Opera has announced its moving to WebKit...bad move....sure to make it even less relevant IE doesnt use WebKit, and while the underlying OS has had its share of exploits (more in the past than present), show me where the 291 exploits Chrome had last year match the 291 in Windows OS.......in fact in a sign of generosity, ill let you add the underlying OS exploits and the IE exploits together, and you'll still fall horribly a long long way short of 291 I started out in Unix, ah the old days when you had to write your own device drivers, have worked for HP, ISP's, turned down a job at Microsoft, Government and law enforcement agencies and several Universities and schools. My first interface to the net was gopher, so i was using the Net well before the WWW. So when i see that my digital footprint is nil after 20 odd years, yet people who have been on for like a week turn up in search results, then i kind of take a serious view of personal data security. So if you think its arrogant of me to mention my experience, then thats your interpretation, im just mentioning merely with the intent of using it as background for what i consider an important argument. See my earlier point about mitigating security issues by not installing a 3rd party application that has more vulnerabilities than the equivalent program already present in the OS. Some might see it as their right to be advised of such, i do. Its not your right to agree to submit their data on their behalf, without their knowledge. No im not, i havent said that Microsoft doesnt do it, i have said its not their main business, whereas Googles is. Thats right, they have an exchange account for school business, which is all they should be using during their school day for school related communications, for which they are paid. They are not blocked from receiving email of a personal nature form outside the domain of a personal nature. But they arent allowed to email information or upload documents which may contain confidential or student related information to any web based mail service. this is to protect confidential information, student data and to legally protect the school. Anyways time for me to head off, still alarmed.
  10. Nope, but the data stripped and mined from it will.
  11. Another bone to pick, the fascination and the folly of "The Cloud". so many people have bought into the idea of the cloud that those people who run the cloud services must be laughing at how easy it has been to convince you to give up your data security. And just because it may be an option to save Office docs to the cloud, doesnt mean you should use it. In fact for me that would constitute a security issue. Honestly the level of blind acceptance to Google stuff and The Cloud makes this about the most disturbing thread i have seen in a while.
  12. So are you going to make Little Jimmy fully aware that his data might be subject to collection by Google when you let him use their products or hand him a chromebook. I wonder if you might want think of the possible legal ramifications of acting so blaise about this. For the record, at the schools i admin, not even staff have access to webmail, because of the possible legal issues that they could expose the school to, and yet your attitude is a free for all and no questions asked.... And please tell me exactly how Microsoft have been data mining students data? Oh enough, honestly im tired of trying to highlight issues which i thin are valid to people who would rather bury their heads in sand.
  13. I think its hilarious that you think I'M naive Lets reconvene in say a decade and see who was right..... And i think it is relevant whether its their primary business, it couldnt be more central to the argument And ill take Microsoft security, which has improved from being a joke to improving no end especially since the release of Windows 7, over Googles anyday. Like i said, Chrome had 7 times the number of exploits compared to IE last year. If youre going to tell me that you would rather use Chrome or consider it equally secure to IE, then i hope youre not in charge of anything more than your home PC. Its not like my 3 decades of experience or managing 43 servers and about 2200 desktops currently mean anything.... If you want to just give away your data and live in some delusional world where the almighty google is a benevolent entity, then you go ahead. I can see im wasting my time here.
  14. Oh theyre quite welcome to use the words i type in the search box, and yes that is supposed to make it easier and quicker and more relevant for future searches. I consider that for want of a better term, part of the terms and conditions of use, and implied by hitting the search button..... What im talking about is the data mining they do of other data that you havent agreed to let them a) access or b) use Dont know how many times ive had to answer the same question from new users of gmail..."Why is google suggesting that i might like to add these people, some of whom i havent spoken to in over a decade to my contacts or chat or google+". Thats just the tip of the obtrusiveness....that comes from mining your data. Honestly nothing gives me the willies quite like things the Chromebook, its a recipe for surrendering your data security. I cant see why people are so willing to do so like its no big deal.
  15. Giggle you might, and i might also point out that Apple's & Microsoft's main product isnt a search engine, Google's is....in fact all Google's products rely on making use of and linking data together.... But if you want to give your data away free, well thats your mistake to make..... Also, recently the number of exploits in Chrome were like 7 times those of IE in the same period (and im not a fanboy of any particular company, or browser - i dont use IE myself), so not only is Google exploiting your data, they are leaving you open to having it exploited by 3rd parties, notably hackers... But like i said, its your mistake to make....
  16. Dont know if anyone has realised or mentioned that anything Google releases is just going to be a data mining tool, they are not doing anything for any other reason. As i keep telling people who use facebook/twitter or social media in general...youre giving your information away for free, why? And once its out there you cant get it back, and it can also be used against you. Chrome and Chromebook to me are two things i will stay away from and advising others to do the same Google just wants your information, if they have to lull you into giving it away, then a really cheap netbook is, for them, a laughably cheap option to do so, and to continue to exploit that information for the rest of your life.
  17. Be a bit of a dictator on this one, advise all users that flash files not generated as part of course work will constitute a breach of school policy and result in their account being filescreened for flash files. Thats a simple thing to do. Put the onus back on them, and take it off yourself Dont forget who sets the rules If they want to pass a course the balls in their court. I would probably make them save legitimate course related flash files in one shared folder (with subfolders per student) for their class. That way you would only have to monitor that shared folder. Then i would filescreen flash files out of existence within their home folders Thats just one way id probably go about it. You might also consider, if you havent done so already, removing executable permissions for removable drives (Removable Storage Access in Group Policy) We got sick of spending hours trying to work around students trying to work around us, and came to the realisation that if they were spending time trying to circumvent school policy, then they were not applying themselves to coursework anyways, and the best thing to do was to actually enforce school policy and if necessary lock their account down even further as well. Such students tend to play on the fact that any mitigation you attempt will have to apply to every one and think you will likely not do so as the effects on many would cause disruption. Switch the tables on this thinking and save yourself hours of frustration by punishing the particular user, and not everyone. Let them know who's in charge.
  18. Whats so great? Well you get to pay to upgrade to software thats unnecessary, and you get hours of fun watching productivity slide as you manhandle a touchscreen optimised (throw in your own cough here) GUI on a non touch desktop PC. Its cheap at twice the price. Oh wait, they halved to cost of Windows 8 in the UK recently because its been doing so well. Honestly, Office has no new features that justify an upgrade, and the who native PDF support will trash any document thats more elaborate than just plain text. Almost no review ive read suggests paying for it if you have 2007/2010 and are happy with it.
  19. Oracle, a company that likes to absorb software products (java and mysql amongst them) and watch them languish.
  20. Hehe knowing the users i deal with, they will be the type that run wizards Ive read that they are (slowly so far) converting to python. I'm sure im not he only person (and googling reveals so) that believes that java is a fundamental requirement of OO/LO Ill give it a go and see what happens...lol it might take some time to round up some MS Office licenses anyways
  21. From their Sys Reqs page: For certain features of the software - but not most - Java is required. Java is notably required for Base. Im not sure im going to sit there and try every function of every components by hand till i hit the ones that dont work. Be helpful if they listed those features which didnt require it, but they dont Update: Bit of googling reveals quite a bit of it still relies on java: https://wiki.documentfoundation.org/Development/Java
  22. Once a big believer in OpenOffice/LibreOffice, im now determined to move away onto MS Office so i can get rid of Java (the only reason its installed is for LibreOffice currently) as the rotating updates for it just realyl annoy me and give no one any confidence.
  23. Now that Firefox v19+ has PDF reading built in, im on the war path to get rid of the sceurity issue that is Adobe Reader, im on a warpath against Java as well, and plan to remove that as well. If only i could get rid of the last remaining glaring security hole that is Flash....
  24. Both Im becoming REALLY disillusioned by Microsoft, not only the pricing, but the overall direction their Desktop & Server have taken, Case in point, not happy with hampering productivity in Windows 8 with Modern GUI, they apply the same arsebackwards mentality to the server arm as well. Add to that the lack of ANY CALS with their server product.... Then factor in no SBS, and no Exchange in its replacement, Essentials...but at least they give you 25 user access in that.... With most places i deal with running on the smell of an oily rag, its increasingly hard to justify the purchase of MS products....let alone navigating the licensing quagmire. If Linux doesnt smell this and make more of an effort to capture what is becoming a rapidly disgruntled MS playground, then i'd be surprised.
  25. Always been a PIA I wish i could get rid of it, but we dont have licenses for MS Office, and instead use LibreOffice, which of course is java based. Just when things were looking up for being able to eliminate unsecure plugins/software - i.e. Firefox 19 has PDF abilities and i can ditch the unsecure Adobe Reader - the unsecure java train just rolls one.....a day or so after the last update from Oracle and another 2 bugs were discovered. Makes one think about what will happen with the most common apps that run on java, like LibreOffice and some educational apps/websites, are going to do when we all finally put our foot down and refuse to install java....
×
×
  • Create New...