Page 1 of 1

Interesting Security "Flaw" I Found...

Posted: Fri Oct 24, 2008 10:05 am
by Sovereign
The solution is as obvious as daylight, but here's what happens (at least for me on Windows Vista Business SP1): I was going to log onto my laptop this morning before I went to class, but I didn't. I did, however, type my password in its entirety. The computer was sitting at the logon screen because it had been restarted to install updates. I closed the lid, took the machine with me to class and opened it again. My password was still there, so anyone who had physical possession of the machine could have logged in without knowing my password had they pressed [ENTER].

Obviously, you shouldn't type your password and then not logon, but in the even that you do you could compromise your machine's security. I will bet money this screws over some stupid person either in corporate or government and results in a data breach.

Re: Interesting Security "Flaw" I Found...

Posted: Fri Oct 24, 2008 12:44 pm
by moon111
Users will always be the biggest security flaw.

Re: Interesting Security "Flaw" I Found...

Posted: Sat Oct 25, 2008 10:34 am
by Nobahar
moon111 wrote:Users will always be the biggest security flaw.
I agree, you shouldn't blame Microsoft for people's stupidity.