Prevent Offline Password and Registry Editing - TechRepublic
Question
June 23, 2008 at 02:33 PM
lilyofnod

Prevent Offline Password and Registry Editing

by lilyofnod . Updated 18 years, 1 month ago

I work at an organization that is federally regulated, this means that we are basically under constant audit. One of our audit issues, that seems to result in a write up every audit, is the vulnerability of our machines against someone using a password and/or registry editor loaded on boot from disk or similar option. A prime example of this is the Offline NT Password and Registry Editor that you can find all over the internet with extreme ease. I could put a lock on every case and a password on every BIOS but that is easily defeated, not to mention that all of our machines have the option to press F9 on boot for the Boot Menu. Now I should mention that, yes, I am aware that physical security is the first barrier against this sort of attack. However, when I mention this to our auditors their answer is always ?But what if they get past that?? Well, what if? What if they get past the doors that require you to swipe a badge and sit at a desk or and plop in their disk? What if no one notices a stranger in the building or just fails to report them? What if the attacker is an employee? Well my auditor friend, I hate to say this but, ?I don?t know?. I?ve posed this same question to vendors who?ve contacted us to use their security appliances and such. Some give the same answer I do; others say I should purchase a whole disk encryption product. I?m looking for suggestions (preferably not whole disk encryption) and I know this is one of the best places to get them.

This discussion is locked

All Comments