Solved

Why is allowing users to change/add wallpaper to their desktops a security issue.

Posted on 2008-06-26
11
198 Views
Last Modified: 2013-12-04
We are trying to apply standard desktops throughout our organization. However we ran into issues when we removed the users abliity to add/change the wallpaper on the desktops. People are not happy with this change, and my Manager cannot understand why we removed users ability to change their desktops. We need to show him proof that allowing users access to change their desktops is a securty risk.
Looking for a document that explains security issues involved with access to the desktop in simple easy to understand language ie non technical.
0
Comment
Question by:larrybac
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
11 Comments
 
LVL 4

Assisted Solution

by:dude02
dude02 earned 20 total points
ID: 21875838
The biggest thing that comes to mine is a virus, spyware, and/or adware.  Any one or more of these problematic issues can be attaching to a picture image.  I have seen my fare cases of when users go on the web and select a picture that they think would make a great background images causes them more problems than they ever image.  Then they call us and wonder why their computer is running so slow to find that they have adware all over their system registry.  
0
 

Author Comment

by:larrybac
ID: 21875888
Yes we agree and understand these issues. We are trying to show "proof" to our Management. We as IT professionals Understand the risks, but providing evidence to the managers is another matter.
0
 
LVL 23

Assisted Solution

by:Danny Child
Danny Child earned 20 total points
ID: 21876064
It can also be justified in applying a uniform Look and Feel across an office - so when visitors are there, it is obvious that a defined pc setup is in place.  

It also avoids more temptation where users prank each other by changing their wallpaper.  The next thing users will ask for is custom screensavers, mouse pointers, and other downloadable junk.  

Why don't you take a standard, clean, NON-secured pc, and hook it up to the internet.  Run a scan on it for nasties, and store the results.  Invite your 5 favourite users of wallpaper to browse around for an hour or two, looking for wallpaper, etc, that they'd like to download and use.  When they're all done, run the same scan again, and then you'll see all the malware, of course.  Show the results to your boss.

It's more a question of what is the business **benefit** of allowing this - all the time users are tweaking their pcs, they're not working, and they're generating trouble for later.  

hth, Danny
0
When ransomware hits your clients, what do you do?

MSPs: Endpoint security isn’t enough to prevent ransomware.
As the impact and severity of crypto ransomware attacks has grown, Webroot fought back, not just by building a next-gen endpoint solution capable of preventing ransomware attacks but also by being a thought leader.

 

Author Comment

by:larrybac
ID: 21876870
You can see my issue. We already have problems with people loading photos of the family and whatever, and personal screensavers, and the adware infections, and the viruses. But we cannot convience management that this is an issue. What we need is some resource that points out these risks to prove what we are trying to do with locking down the desktops.
0
 
LVL 6

Assisted Solution

by:hyphenpipe
hyphenpipe earned 20 total points
ID: 21876961
You could always just allow it, and when the crap hits the fan tell them 'I told you so' and then demand a raise.
0
 

Author Comment

by:larrybac
ID: 21878017
I guess what we need is a consensus from the professional IT community to demonstrate the importance for the standard desktop. Looks like we need to hire a consultant....
0
 
LVL 50

Assisted Solution

by:jcimarron
jcimarron earned 45 total points
ID: 21879167
0
 
LVL 31

Assisted Solution

by:James Murrell
James Murrell earned 20 total points
ID: 21883507
could you just say "An improperly configured machine can be an invitation for disaster." we did and the board signed off on desktop wallpapers
0
 
LVL 50

Accepted Solution

by:
jcimarron earned 45 total points
ID: 22098898
In the original post, larrybac asked "We need to show him proof that allowing users access to change their desktops is a securty risk.
Looking for a document that explains security issues involved with access to the desktop in simple easy to understand language ie non technical."
There were several good comments, but certainly the reference http://tech.yahoo.com/blogs/raskin/1515 
should satisfy the requested requirement.
0
 
LVL 27

Expert Comment

by:Tolomir
ID: 22098913
Well I see a big difference between a wallpaper and a screensaver.

Thus the link from yahoo didn't and doesn't convince me that changing wallpapers is bad.  

Tolomir
0

Featured Post

How our DevOps Teams Maximize Uptime

Our Dev teams are like yours. They’re continually cranking out code for new features/bugs fixes, testing, deploying, responding to production monitoring events and more. It’s complex. So, we thought you’d like to see what’s working for us. Read the use case whitepaper.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

SHARE your personal details only on a NEED to basis. Take CHARGE and SECURE your IDENTITY. How do I then PROTECT myself and stay in charge of my own Personal details (and) - MY own WAY...
A quick step-by-step overview of installing and configuring Carbonite Server Backup.
Two types of users will appreciate AOMEI Backupper Pro: 1 - Those with PCIe drives (and haven't found cloning software that works on them). 2 - Those who want a fast clone of their boot drive (no re-boots needed) and it can clone your drive wh…
There are cases when e.g. an IT administrator wants to have full access and view into selected mailboxes on Exchange server, directly from his own email account in Outlook or Outlook Web Access. This proves useful when for example administrator want…

707 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question