←back to thread

186 points rvnx | 2 comments | | HN request time: 0.461s | source
Show context
gdulli ◴[] No.45763751[source]
There used to be a much bigger scene around custom Windows installs and I hope it gets resurrected if/when the ability to create local accounts goes away. The desire for a tiny install is pretty niche at this point but I could see demand going up to preserve local accounts.

Or perhaps that won't be necessary because certain enterprise customers will insist on local accounts and it will be easier for pirates to just tap into that install path? One way or another, if/when local accounts go away I hope there's some option to work around it.

replies(5): >>45763978 #>>45764518 #>>45764551 #>>45765410 #>>45767862 #
ZiiS ◴[] No.45764551[source]
Do any enterprise use local accounts? I guess for airgapped?
replies(2): >>45765184 #>>45771967 #
gdulli ◴[] No.45765184[source]
I don't know, but I was thinking/hoping maybe the code for local accounts has to live on if at least any enterprise customers demand it.
replies(2): >>45766153 #>>45767464 #
1. wildzzz ◴[] No.45767464[source]
Likely the process is to provision the PC using an AD account, setup a local account, and then disconnect from the network forever. Microsoft isn't going to step on the toes of businesses that need local accounts but they really don't care about upsetting individuals

In reality, truly airgapped PCs are rare. They are usually just there to run some specific application that likely can't run on anything safe to connect to the network. Unless you're both the admin and the only user, an airgapped PC is disadvantageous for security reasons. There's no one monitoring what the users are doing with it, how do you know if anything malicious is running on it if the only reference you have is the PC itself? It's like owning a single clock and never checking to see if the time is actually correct. You're more likely to find airgapped networks that allow for monitoring of the hardware and what users are doing with it. Of course there will always be things like malware testing but with how smart malware is now, it's pretty good at detecting when it running airgapped and won't actually do anything until it knows it can phone home.

replies(1): >>45769842 #
2. hulitu ◴[] No.45769842[source]
> in reality, truly airgapped PCs are rare.

there is a lot of measuring equipment running Windows