Solved

Why is allowing users to change/add wallpaper to their desktops a security issue.

Posted on 2008-06-26
11
197 Views
Last Modified: 2013-12-04
We are trying to apply standard desktops throughout our organization. However we ran into issues when we removed the users abliity to add/change the wallpaper on the desktops. People are not happy with this change, and my Manager cannot understand why we removed users ability to change their desktops. We need to show him proof that allowing users access to change their desktops is a securty risk.
Looking for a document that explains security issues involved with access to the desktop in simple easy to understand language ie non technical.
0
Comment
Question by:larrybac
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
11 Comments
 
LVL 4

Assisted Solution

by:dude02
dude02 earned 20 total points
ID: 21875838
The biggest thing that comes to mine is a virus, spyware, and/or adware.  Any one or more of these problematic issues can be attaching to a picture image.  I have seen my fare cases of when users go on the web and select a picture that they think would make a great background images causes them more problems than they ever image.  Then they call us and wonder why their computer is running so slow to find that they have adware all over their system registry.  
0
 

Author Comment

by:larrybac
ID: 21875888
Yes we agree and understand these issues. We are trying to show "proof" to our Management. We as IT professionals Understand the risks, but providing evidence to the managers is another matter.
0
 
LVL 23

Assisted Solution

by:Danny Child
Danny Child earned 20 total points
ID: 21876064
It can also be justified in applying a uniform Look and Feel across an office - so when visitors are there, it is obvious that a defined pc setup is in place.  

It also avoids more temptation where users prank each other by changing their wallpaper.  The next thing users will ask for is custom screensavers, mouse pointers, and other downloadable junk.  

Why don't you take a standard, clean, NON-secured pc, and hook it up to the internet.  Run a scan on it for nasties, and store the results.  Invite your 5 favourite users of wallpaper to browse around for an hour or two, looking for wallpaper, etc, that they'd like to download and use.  When they're all done, run the same scan again, and then you'll see all the malware, of course.  Show the results to your boss.

It's more a question of what is the business **benefit** of allowing this - all the time users are tweaking their pcs, they're not working, and they're generating trouble for later.  

hth, Danny
0
Threat Trends for MSPs to Watch

See the findings.
Despite its humble beginnings, phishing has come a long way since those first crudely constructed emails. Today, phishing sites can appear and disappear in the length of a coffee break, and it takes more than a little know-how to keep your clients secure.

 

Author Comment

by:larrybac
ID: 21876870
You can see my issue. We already have problems with people loading photos of the family and whatever, and personal screensavers, and the adware infections, and the viruses. But we cannot convience management that this is an issue. What we need is some resource that points out these risks to prove what we are trying to do with locking down the desktops.
0
 
LVL 6

Assisted Solution

by:hyphenpipe
hyphenpipe earned 20 total points
ID: 21876961
You could always just allow it, and when the crap hits the fan tell them 'I told you so' and then demand a raise.
0
 

Author Comment

by:larrybac
ID: 21878017
I guess what we need is a consensus from the professional IT community to demonstrate the importance for the standard desktop. Looks like we need to hire a consultant....
0
 
LVL 50

Assisted Solution

by:jcimarron
jcimarron earned 45 total points
ID: 21879167
0
 
LVL 31

Assisted Solution

by:James Murrell
James Murrell earned 20 total points
ID: 21883507
could you just say "An improperly configured machine can be an invitation for disaster." we did and the board signed off on desktop wallpapers
0
 
LVL 50

Accepted Solution

by:
jcimarron earned 45 total points
ID: 22098898
In the original post, larrybac asked "We need to show him proof that allowing users access to change their desktops is a securty risk.
Looking for a document that explains security issues involved with access to the desktop in simple easy to understand language ie non technical."
There were several good comments, but certainly the reference http://tech.yahoo.com/blogs/raskin/1515 
should satisfy the requested requirement.
0
 
LVL 27

Expert Comment

by:Tolomir
ID: 22098913
Well I see a big difference between a wallpaper and a screensaver.

Thus the link from yahoo didn't and doesn't convince me that changing wallpapers is bad.  

Tolomir
0

Featured Post

Put Machine Learning to Work--Protect Your Clients

Machine learning means Smarter Cybersecurity™ Solutions.
As technology continues to advance, managing and analyzing massive data sets just can’t be accomplished by humans alone. It requires huge amounts of memory and storage, as well as the high-speed power of the cloud.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Learn about cloud computing and its benefits for small business owners.
For both online and offline retail, the cross-channel business is the most recent pattern in the B2C trade space.
Two types of users will appreciate AOMEI Backupper Pro: 1 - Those with PCIe drives (and haven't found cloning software that works on them). 2 - Those who want a fast clone of their boot drive (no re-boots needed) and it can clone your drive wh…
This video shows how to use Hyena, from SystemTools Software, to update 100 user accounts from an external text file. View in 1080p for best video quality.

739 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question