"Need local admin and have physical access? ..."
"Need local admin and have physical access? ..."
What is the point of downplaying local privilege escalation vulnerabilities just because it's a hard scenario to defend against?
In my experience, it is in fact pretty trivial.
I'm not saying it shouldn't be fixed, I'm saying it isn't nrealy as big a deal as people are making it out to be. The infosec community likes to latch on to any little vulnerability it can and act like the sky is falling even if, when taken in context, said vulnerability is only a problem in narrow use cases or requires the target to pretty much already be completely exploited.
That's because while a given potential exploit might not be a huge deal, a collection of exploits become greater than the sum of their parts, so if you're security-minded, then you want as few of those parts as possible.
If you are talking about scenarios where full disk encryption is not enabled, then that is irrelevant. You may as well say that privilege escalation is trivial because some users don't put passwords on their account. The user obviously needs to take care of the basic expectancies first before worrying about vulnerabilities.
That's fair, I was making that assumption because it is true in literally every case I've come across. But consider that if you have local access to a logged in account you've already got access to unencrypted files for that user anyway. You don't even need admin.
FDE is orthogonal to user accounts, but yes it would prevent the trivial local access methods of taking over the admin account.
Not that, you know, anything the user cares about requires an admin account to get at anyway, as ransomware has consistently proven.
at the end of the day, users are responsible for the software they run on their machine. but viruses/worms that run amok are largely over thanks to restraining userland permissions.
Your opinion is dangerous, professional negligence.