Windows Security Guidence

Oasisfactor

New member
Local time
8:36 AM
Messages
7
Greetings, I'm not sure where to ask this question, so if this is the wrong forum then please move it.

I started volunteering at a community center that teaches people the basics of computers. They use Windows 7 and Secure login (CTRL+ALT+DEL). They also printed and pasted the passwords to the machines on the case itself. I don't work there, but they thing is, this is bad security practice. I know they did this for convenience. I haven't used the machines yet, but I'm assuming they gave the users administrator accounts.

These computers can be used by ANYONE, meaning anyone can walk in plug a USB drive in, or download whatever they want, and run it in admin mode.

I'm thinking about talking to the manager about this, What is the best password practice when it comes to a public lab? Should I also recommend not using Admin accounts for standard users?
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
None
OS
Lubuntu 32 Bit
CPU
None
Motherboard
None
Memory
None
Graphics Card(s)
None
Hard Drives
None
Antivirus
None
Browser
None
Hi and welcome to SevenForums,
Not sure about crtl+alt+delete deal but I'd ask for more details and I would imagine the accounts are not admin but this would be my first inquiry ;)

Either way they might take care of some sure in the network firewall
And as people come and go they may maintain them other ways seeing as the passwords are printed on them
They might not even be connected to the internet ?
Cheers.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom assembled by me :}
OS
Win-7-Pro64bit 7-H-Prem-64bit
CPU
i7-5930K 2nd i9-9940x both water blocked VRM's too
Motherboard
ASUS SABERTOOTH X99 2nd ASUS x299 Apex
Memory
Trident-z 3200C14 2nd Trident-z 3600C16
Graphics Card(s)
EVGA 1080ti ftw3 2nd Titan Xp both water blocked
Sound Card
Built-in Realtek
Monitor(s) Displays
1-AOC G2460PG 24"G-Sync 144Hz/ 2nd 1-ASUS VG248QE 24" 144Hz
Screen Resolution
1920 x 1080 144Hz
Hard Drives
2-Samsung M.2 Evo & Evo Plus
2-Samsung 850 EVO 500GB SSD's/ 3-2.5 W.D. Black 1tb-&3-1tb/3-3.5 WD Black 1tb hdd's
PSU
EVGA SuperNOVA 1000-P2 2nd 1200-P2
Case
2-Corsair Obsidian Series 450D Black ATX Mid Tower
Cooling
Custom water loops
Keyboard
Logitech G710+/ 2nd Logitech G910
Mouse
2-RedDragon M901 Perdition 16400 dpi Gaming mouse = wired
Internet Speed
Comcast Ping 19ms 89.31mbps download speed 6.12mbps upload
Antivirus
Malwarebytes Pro/ Superantispyware Pro
Browser
FireFox & Pale moon
Other Info
2nd ASUS X299 Apex/Intel i9-9940x with Custom water loop/7H-Prem-x64/Corsair 450D case/Ram Trident-z 3600C16 4x8gb / Samsung970Evo plus 500gb SSD/Dual ssd EZ swap evo/PSU EVGA SuperNova 1200w-P2 80+Platinum/GPU Titan Xp /8-ML-140 on push-pull on 2-280GTX rads
They are connected to the internet. I have to teach people using these same computers how to create e-mail accounts, type documents, and use social media.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
None
OS
Lubuntu 32 Bit
CPU
None
Motherboard
None
Memory
None
Graphics Card(s)
None
Hard Drives
None
Antivirus
None
Browser
None
What are the exact things you want to protect against?
Preventing them messing with computers? Disallow everything but web browsing? Keeping privacy of the data stored there?
Which raises the questions, what activities do them need to support, how the admins will use them, and what data the users and the owners will store there, if any?
 

My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Toshiba Sattelite A665-S6092
OS
Windows 7 Ultimate x64
CPU
Intel Core i7-740QM
Memory
8 GB DDR3
Graphics Card(s)
NVIDIA GeForce 330GT
Screen Resolution
1366x768
Hard Drives
Samsung 840 SSD 500GB
1TB USB3 external HD
Cooling
Coolermaster Notepal U3 notebook cooling pad
Internet Speed
3mbps ASDL
Antivirus
ClamWin 0.98.7
Browser
Opera 12.17 x86 (main), Firefox 38 (sec), IE11 (last resort)
Don't like the idea of just anyone having admin accounts.



I'm teaching them how to use social media, and the basics of word, excel, etc... I might teach them how to use a password database such as KeePass, and how to store files on a USB. Under no circumstances will I allow them to store files on the computers.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
None
OS
Lubuntu 32 Bit
CPU
None
Motherboard
None
Memory
None
Graphics Card(s)
None
Hard Drives
None
Antivirus
None
Browser
None
Hi,
Saving files directly to flash drives can spread infections pretty easily what is your goal to infect other machines via plug and play ?

You need to save in the default areas = Downloads folder then scan with multiple utilities antivirus/ Malware would be the best two right there before transferring to flash media device
Otherwise you teach them the easiest way to carry portable corruption to other machines.
Cheers.

I'll add on any machine turn autoplay Off,
Once a flash drive is connected scan it immediately with the other systems security a-v and malware utilities.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom assembled by me :}
OS
Win-7-Pro64bit 7-H-Prem-64bit
CPU
i7-5930K 2nd i9-9940x both water blocked VRM's too
Motherboard
ASUS SABERTOOTH X99 2nd ASUS x299 Apex
Memory
Trident-z 3200C14 2nd Trident-z 3600C16
Graphics Card(s)
EVGA 1080ti ftw3 2nd Titan Xp both water blocked
Sound Card
Built-in Realtek
Monitor(s) Displays
1-AOC G2460PG 24"G-Sync 144Hz/ 2nd 1-ASUS VG248QE 24" 144Hz
Screen Resolution
1920 x 1080 144Hz
Hard Drives
2-Samsung M.2 Evo & Evo Plus
2-Samsung 850 EVO 500GB SSD's/ 3-2.5 W.D. Black 1tb-&3-1tb/3-3.5 WD Black 1tb hdd's
PSU
EVGA SuperNOVA 1000-P2 2nd 1200-P2
Case
2-Corsair Obsidian Series 450D Black ATX Mid Tower
Cooling
Custom water loops
Keyboard
Logitech G710+/ 2nd Logitech G910
Mouse
2-RedDragon M901 Perdition 16400 dpi Gaming mouse = wired
Internet Speed
Comcast Ping 19ms 89.31mbps download speed 6.12mbps upload
Antivirus
Malwarebytes Pro/ Superantispyware Pro
Browser
FireFox & Pale moon
Other Info
2nd ASUS X299 Apex/Intel i9-9940x with Custom water loop/7H-Prem-x64/Corsair 450D case/Ram Trident-z 3600C16 4x8gb / Samsung970Evo plus 500gb SSD/Dual ssd EZ swap evo/PSU EVGA SuperNova 1200w-P2 80+Platinum/GPU Titan Xp /8-ML-140 on push-pull on 2-280GTX rads
Hi,
Saving files directly to flash drives can spread infections pretty easily what is your goal to infect other machines via plug and play ?

You need to save in the default areas = Downloads folder then scan with multiple utilities antivirus/ Malware would be the best two right there before transferring to flash media device
Otherwise you teach them the easiest way to carry portable corruption to other machines.
Cheers.

I'll add on any machine turn autoplay Off,
Once a flash drive is connected scan it immediately with the other systems security a-v and malware utilities.

The issue is, showing them to scan might be too difficult, these people never seen a computer before, or rarely used one.

Do I need to worry about scanning if it's just saving files that they created ex. doc, xls .....?
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
None
OS
Lubuntu 32 Bit
CPU
None
Motherboard
None
Memory
None
Graphics Card(s)
None
Hard Drives
None
Antivirus
None
Browser
None
Hi,
Well safety and security is item one to learn about since these people can download anything and plug anything in and go.

Which in it's self is not a good idea or environment to plug in anything or create anything to take to another computer that might have more infections than the first :)

Then you can get into where everything is located programs..... and how to "save as" in doc formats picture formats... and of course where to save items so they can easily find them = making folders.....
Then be able to search and find those folders using save as = browse function.

Either way with an open admin rights users place like that you'd have to know how often these machines are wiped clean and what security suite they have installed = Norton/ ...... because you'd have to scan them every time someone logged in or the previous was logging out :/
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom assembled by me :}
OS
Win-7-Pro64bit 7-H-Prem-64bit
CPU
i7-5930K 2nd i9-9940x both water blocked VRM's too
Motherboard
ASUS SABERTOOTH X99 2nd ASUS x299 Apex
Memory
Trident-z 3200C14 2nd Trident-z 3600C16
Graphics Card(s)
EVGA 1080ti ftw3 2nd Titan Xp both water blocked
Sound Card
Built-in Realtek
Monitor(s) Displays
1-AOC G2460PG 24"G-Sync 144Hz/ 2nd 1-ASUS VG248QE 24" 144Hz
Screen Resolution
1920 x 1080 144Hz
Hard Drives
2-Samsung M.2 Evo & Evo Plus
2-Samsung 850 EVO 500GB SSD's/ 3-2.5 W.D. Black 1tb-&3-1tb/3-3.5 WD Black 1tb hdd's
PSU
EVGA SuperNOVA 1000-P2 2nd 1200-P2
Case
2-Corsair Obsidian Series 450D Black ATX Mid Tower
Cooling
Custom water loops
Keyboard
Logitech G710+/ 2nd Logitech G910
Mouse
2-RedDragon M901 Perdition 16400 dpi Gaming mouse = wired
Internet Speed
Comcast Ping 19ms 89.31mbps download speed 6.12mbps upload
Antivirus
Malwarebytes Pro/ Superantispyware Pro
Browser
FireFox & Pale moon
Other Info
2nd ASUS X299 Apex/Intel i9-9940x with Custom water loop/7H-Prem-x64/Corsair 450D case/Ram Trident-z 3600C16 4x8gb / Samsung970Evo plus 500gb SSD/Dual ssd EZ swap evo/PSU EVGA SuperNova 1200w-P2 80+Platinum/GPU Titan Xp /8-ML-140 on push-pull on 2-280GTX rads
Back
Top