E
E
Evdokim2019-01-10 13:08:05
linux
Evdokim, 2019-01-10 13:08:05

Does it make sense to install Linux if the local admin on Windows is easy to hack?

Earlier, I asked a question about whether it is easy to hack the local admin on Windows in a corporate environment. As far as I understand, this is easier to do than a steamed turnip .
Does it make sense to install Linux in this case? So that it is not so simple and not so easy to hack the local admin.
I just know that there are means by which you can unlock the admin via LiveCD (WinPE) if the account is disabled, and even set a new password.
Please help me to sort out this issue.
Then I want to enter a laptop with Linux into the ActiveDirectory domain

Answer the question

In order to leave comments, you need to log in

9 answer(s)
S
stratosmi, 2019-01-10
@stratosmi

Does it make sense to install Linux in this case? So that it is not so simple and not so easy to hack the local admin.

1) On Linux, the local admin is even easier to crack.
2) You have strange criteria. And what, the application software used (on Windows and Linux it is different) - does it matter? Are you running only one bare OS?

M
Melkij, 2019-01-10
@melkij

it is possible through LiveCD

If there is physical access, everything is elementary hacked.
For example, why hack at all if you can install your own system and copy the necessary data. Is the disk encrypted? So if you don't have a password, how did you work with the system before?

S
Saboteur, 2019-01-10
@saboteur_kiev

In Linux, hacking the local admin is even easier.
Understand. If you have physical access to the device - hacking local rights is not a problem.
The only thing is if you encrypt the entire partition with the operating system and data. But this complicates the solution of problems if something suddenly fails.

A
Alexander, 2019-01-10
@alexr64

Does it make sense to install Linux in this case? So that it is not so simple and not so easy to hack the local admin.

https://habr.com/post/104536/
Google for the phrase "Single User mode linux".
In general, if there is free access to the car: you can turn it in any direction. And don't really do anything. Look not for how to protect yourself, but how to eliminate workarounds: the inability to boot from removable media, over the network, from other disks. BIOS password + physical restriction of access to the machine, for example, a safe.

D
Danil, 2019-01-10
@Veneomin

To protect the local admin from hacking, you need to spend 50% of the time on protection and 50% on the suspicious activity monitoring system. Usually it is the second 50% that helps to find the grief of hackers on the very first attempts. Fortunately, now there is software that spies and monitors a wagon and a small cart out of the box, the only question is the price.

C
CityCat4, 2019-01-10
@CityCat4

If there is physical access to a piece of hardware or access to a virtual machine management environment for VMs, both Windows and Linux break more than once. The exception is encrypted media, which without a key looks like a disk full of garbage.
But in general, the meaning of the question is incomprehensible - linux software works on linux, on Windows - windows, there is little cross-platform software, as little pipets works in vine, and even less will start on virtual linux in Windows.
The axis is still the basis for the operation of application software :)

D
Dmitry Shitskov, 2019-01-10
@Zarom

Does it make sense to install Linux in this case? So that it is not so simple and not so easy to hack the local admin.

Oh, so there will be no need to soar turnips. Root mounted, changed the root password and that's it :)

S
Sergey, 2019-01-10
@edinorog

Hack what? If the axis is loaded over the network ... What is there to hack? And who said that hacking Windows is elementary?) I can complicate the task so much ... that it will be easier to reinstall it.

M
maniac_by, 2019-01-10
@maniac_by

Having local access to the admin's Linux machine, it's like hacking two fingers. Does it make sense to install Linux? However, on Windows it’s also simple, but at least you can write more steps to this in the manual. Just take modern security measures. Encrypt disks, duplicate information, write smart passwords, etc.
But what is paranoia? All security features are disabled on my phone, because no one needs me. What about the corporate segment? Then provide jobs on servers, and only thin clients for users. A server room with a three-key lock and there will be no problems

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question