Quantcast
Channel: Ctrl + Alt + Del prior to Windows 10 logon no longer needed? - Server Fault
Viewing all articles
Browse latest Browse all 3

Ctrl + Alt + Del prior to Windows 10 logon no longer needed?

$
0
0

I was running Windows 7 at work; power up the desktop pc and always had to hit Ctrl+Alt+Del before entering your username and password.

I am now running Windows 10 at work, Windows 10 Enterprise if I look on my PC. I no longer have to hit Ctrl+Alt+Del before logging in, and I am pretty sure it is not just me.

Is the existing link with rationale explained no longer relevant with Windows 10? What changed?

Is this no longer relevant? : How does CTRL-ALT-DEL to log in make Windows more secure?

Update:

From Interactive logon: Do not require CTRL+ALT+DEL:

Not having to press CTRL+ALT+DEL leaves users susceptible to attacks that attempt to intercept the users' passwords. Requiring CTRL+ALT+DEL before users log on ensures that users are communicating by means of a trusted path when entering their passwords... A malicious user might install malware that looks like the standard logon dialog box for the Windows operating system, and capture a user's password. The attacker can then log on to the compromised account with whatever level of user rights that user has.

I am having trouble understanding this rationale for Ctrl+Alt+Del I mean if a malicious user installs malware that looks like the standard logon screen shouldn't I first be worried about that having happened where malware got installed? Can someone at least provide examples of those attacks user's are left susceptible to?

For so long we've all be marching to the tune of must do Ctrl+Alt+Del prior to logon, and ironically it is worded "Interactive logon: Do not require CTRL+ALT+DEL = Disabled".

Recently NIST revised their password recommendations, I believe it's publication 800-63B. As such, you can read numerous articles and opinions on the subject. My favorite is Stack Overflow cofounder Jeff Atwood's rage: password rules are b.s.. I don't need to go much further than that title to summarize that topic, basically admission that some password rules were security theater. So now I am sort of questioning the credibility of Ctrl+Alt+Del, because (1) it seems it was suddenly dropped in Windows 10, and (2) to me the [official] wording from Microsoft is quite vague.

If you use any computer you are susceptible to attacks in a variety of ways, so I am looking for technical specifics that I can wrap my head around regarding Ctrl+Alt+Del providing value prior to logon.


Viewing all articles
Browse latest Browse all 3

Trending Articles





<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>