Re: Local Remote Desktop, no Remote Web?

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance



I know how important passwords and such are - I was one of those bored
teenagers some years ago. I was only ever a novice at that time imo, but it
was all in good fun. I guess all I really can do is to convince them that
passwords are a good idea, though that was my first suggestion when I was
hired. They claim that it somehow worked before with the setup I described
of separate user accounts. Personally, I feel they were told that it worked
as said by some idiot, when in reality this has been the ultimate in
security vulnerability for some time.

"Lanwench [MVP - Exchange]"
<lanwench@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:elrbL$69HHA.3548@xxxxxxxxxxxxxxxxxxxxxxx
John Baumann <jbaumann@xxxxxxxxxxxxxxxxxxx> wrote:
Hi all, here is my situation:

At my workplace, our boss desires that we not have passwords for our
user accounts. We have a few employees who work remotely from home.
The approach I have been looking at is to create an account with a
password to connect to Remote Web Workplace, where they could connect
to their computer, and then login with their local cridentials. At
this time, I am unable to find a setup that will allow this. It seems
that if a user is not a member of the Remote Web Workplace Users
group, they are not able to use any remote features.

Right.

But if I make
users a member of that group, they are able to connect via the web
with no password.

Eh? Connect to what? Not a TS box, not Remote Desktop to a
workstation.....

IP filtering is not an option, because of users
with Dynamic IP connections at home.

To be blunt, this is an insane idea.

By default, you can't connect to any Windows box via Remote Desktop unless
you have a password...VPN won't help out at all there. This is a
built-inWindows restriction, and it's there for a very good reason.

If you have any inbound connectivity permitted to your network *at all*
you need a good password policy, and that includes a minimum pw length (I
recommend 8), and regular forced changes. It doesn't matter if everyone in
the company is sweetness and light personified, without a malicious bone
in his/her body. Explain this to your boss. What is the reason he doesn't
want passwords? Doesn't he care if someone opens his mailbox and starts
snooping around, deleting mail, sending mail out pretending to be him?
Remember, this doesn't have to be someone in your office! There are a lot
of bored teenagers out there on the internet.

Remember, passwords can be passphrases...and can have spaces in them to
make them easier to remember.

Sadistic network admin!

is a very good password, for example.




.



Relevant Pages

  • Re: Remote Desktop Connection on a LAN?
    ... I set up a user "Remote" on both machines. ... From PC-B I can RDC to PC-A and gain control of it. ... Both computers must have users with passwords, ...
    (microsoft.public.windowsxp.hardware)
  • Unable to successfully setu p and use .Remote Desktop Connection.
    ... I haveWinXP PRO and WinXP SE OS's with Remote desktop installed. ... to successfully log on to the RDC. ... Remote connections might not be enabled or the computer might be too busy to ... I went back and added passwords under users as administrator. ...
    (microsoft.public.windowsxp.help_and_support)
  • Re: Software for remote PC?
    ... Afterwards you will need to forward the remote desktop TCP/IP ... configured for use with Remote Desktop have STRONG passwords. ... You can use something like VNC with almost any operating system out ... There are a number of VNC servers to choose from, ...
    (alt.sys.pc-clone.dell)
  • Re: Local Remote Desktop, no Remote Web?
    ... our boss desires that we not have passwords for our ... It seems that if a user is not a member of the Remote ... Web Workplace Users group, they are not able to use any remote ... teenagers out there on the internet. ...
    (microsoft.public.windows.server.networking)
  • Re: Apple Safari on MacOSX may reveal users saved passwords
    ... passwords etc that I might use for online banking and which I don't ... I don't think that the Keychain bit is ... but logging in as *root* will. ... Sounds more like the cure is just to either disable root (and/or remote) ...
    (Bugtraq)