Dear,

Some links to topics on the board
http://kixtart.org/cgi-bin/ultimatebb.cgi?ubb=get_topic&f=1&t=001109 securing screensaver
http://kixtart.org/cgi-bin/ultimatebb.cgi?ubb=get_topic&f=1&t=002687 screen saver password
http://kixtart.org/cgi-bin/ultimatebb.cgi?ubb=get_topic&f=2&t=000880 screen saver by policies
Short reaction about catching users password:

  • on our office everybody was told don't give your password to anybody.
  • catching password in one or other way - in this case without the knowledge of user - decrease
    the responsibility for the user. in this case it is for a good goal, but another
    person can misuse it.
    Administrators of server never ask a password, but they only change it for their
    work when necesarry and they change it only with permission of the user. Normally
    a lot of sensitive information will open up after a successful logon session.
    Some super privileges are only for doing your job and not for spying around. Knowledge of
    not 'known' information can be very bad for your sleep.
  • we know that some internet applications store their secure information in the
    registry, which can catch easily and can misuse also easily. Most people doesn't
    know in which way and where sensitive information will be stored on your system.
    All kind of information which can damage your privacy.
    Mostly we advise to reenter the password to such programs all the time.

In some organizations we are working for we advise two policies about screen savers:

  • all users must have a screen saver which will be activated within an acceptable
    time f.e. 5 minutes.
  • special users must have a screen saver with a password f.e. employees of human
    resource and accounting department.

For systems like windows 9x we can always check the status of screen savers
and change them in a direction we wanted. The very special users can also
be checked for "screen saver with password" still active.
The result will generate the proper actions.
Greetings.
_________________________
email scripting@wanadoo.nl homepage scripting@wanadoo.nl | Links | Summary of Site Site KiXforms FAQ kixtart.org library collection mirror MCA | FAQ & UDF help file UDF kixtart.org library collection mirror MCA | mirror USA | mirror europe UDF scriptlogic library collection UDFs | mirror MCA