xentr_theme_editor

  • Please do not post any links until you have 3 posts as they will automatically be rejected to prevent SPAM. Many words are also blocked due to being used in SPAM Messages. Thanks!

How to keep laptop screen on when Administrator has Power & Sleep settings locked to 10 minutes?

Just sayin, if they lack permissions to change the screen timeout, I'd be surprised if they had permissions to install any third-party applications.

And not devil's advocate at all I would say @Helzy . Good info. Managing security is a beast. And the OP should certainly consider the implications before implementing a "workaround" :)

I've just always found the screen timeout thing to be in the "illusion of security" category. Better to ideally have your people trained to lock the screen when they step away. If they leave the screen unlocked and walk away, an actor on site can do a lot damage and of course keep the screen from locking manually anyway.
 
I agree the timeout lock screen does seem somewhat illusory, that said, the lock mechanism makes sense, we do have quite a few units that are leveraged by public facing staff and it really does, aside from a short window, eliminate the potentiality of someone reaching for a keyboard and doing something nefarious.

Every year the requirements to maintain our policy increase, there is 0 relaxation. Also, there is numerous activities behind the scenes, staff awareness training, penetration testing that is audited by our insurance company. I am fully anticipating that next year we will be forced to turn off USB key access on our comps too, which will take care of the 'jigglers'.

We had staff order them (all IT procurement goes through me) anything to defeat the timeouts. yes they were denied. noty to say no one has purchased them though, my Force skills are strong, but not that strong.
 
Man!....I guess there's just no going back to the "good 'ol internet days"...Eh?
Pluggin' that comp directly into your ISP router woo! Mind, most of them, if not all have SPI at least nowadays but the idea of doing such sets off some Spidey Sense tingles. In the wrong places unfortunately...
 
xentr_thread_starter
Hi fellows,

I tried the Admins and the policy is 10 minute shutdown. Any suggestions on a USB jiggler would be appreciated :) First time I have heard about a USB jiggler!

How exactly does a USB jiggler work anyway?
 
Every year the requirements to maintain our policy increase, there is 0 relaxation. Also, there is numerous activities behind the scenes, staff awareness training, penetration testing that is audited by our insurance company. I am fully anticipating that next year we will be forced to turn off USB key access on our comps too, which will take care of the 'jigglers'.

So no external mice or keyboards? I don't see how that would work unless corporate boxes start coming with bios detection settings which look for a proprietary KB/Mouse ID to enable it.

This wouldn't be the same as locking out USB memory sticks, the jiggler dongles should be just seen as an external mouse. The fact that it moves every 5 minutes or so would be irrelevant to how it's seen to the PC.
 
So no external mice or keyboards? I don't see how that would work unless corporate boxes start coming with bios detection settings which look for a proprietary KB/Mouse ID to enable it.

This wouldn't be the same as locking out USB memory sticks, the jiggler dongles should be just seen as an external mouse. The fact that it moves every 5 minutes or so would be irrelevant to how it's seen to the PC.

Its been done in LOTS of places. USB keys are the worst for attacks on networks and its very easy through group policies to block USB keys but not keyboards/mice.

Any buying some weird ass mouse jiggler from Amazon to use in a USB port is a perfect example of why those policies exist.

Go look at powershell.. you'll find a lot of small scripts that do this very easily.
 

Latest posts

Back
Top