ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Looking for solutions to allow remote users access to their internal psychical computers

    IT Discussion
    13
    76
    3.0k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J
      JasGot @Grey
      last edited by

      @Grey said in Looking for solutions to allow remote users access to their internal psychical computers:

      @dave247 said in Looking for solutions to allow remote users access to their internal psychical computers:

      @scottalanmiller said in Looking for solutions to allow remote users access to their internal psychical computers:

      @dave247 said in Looking for solutions to allow remote users access to their internal psychical computers:

      @scottalanmiller said in Looking for solutions to allow remote users access to their internal psychical computers:

      @dave247 said in Looking for solutions to allow remote users access to their internal psychical computers:

      I wanted to figure out a solution for allowing the users to login to their company issued laptops and then click one or twice and get to their remote desktops as easily and as efficiently as possible.

      You CAN make all or most of the credentials between that laptop and the resulting device be cached or saved. So that it is a really quick and painless process.

      True but if a user's password expires or they change it, they may get themselves locked out. We try not to encourage saving passwords too much.

      For security reasons, we avoid expiring passwords. That's what makes users write them down and make them easy to guess. Non-expiring, or rarely expiring passwords, are shown to be far more secure and make things like this much easier.

      yeah I know its a balance. We have had a few trade offs between password length and expiration time

      https://cdnapisec.kaltura.com/index.php/extwidget/preview/partner_id/684682/uiconf_id/31013851/entry_id/0_svsg82xf/embed/dynamic

      NIST guidelines were updated in 2017. They mostly follow XKCD.

      7c05c4e1-5fc4-4449-9eab-b52103daab0d-image.png

      I've been using this infographic for years! I love it.

      Have you seen this: http://correcthorsebatterystaple.net/

      GreyG 1 Reply Last reply Reply Quote 0
      • GreyG
        Grey @JasGot
        last edited by

        @JasGot said in Looking for solutions to allow remote users access to their internal psychical computers:

        @Grey said in Looking for solutions to allow remote users access to their internal psychical computers:

        @dave247 said in Looking for solutions to allow remote users access to their internal psychical computers:

        @scottalanmiller said in Looking for solutions to allow remote users access to their internal psychical computers:

        @dave247 said in Looking for solutions to allow remote users access to their internal psychical computers:

        @scottalanmiller said in Looking for solutions to allow remote users access to their internal psychical computers:

        @dave247 said in Looking for solutions to allow remote users access to their internal psychical computers:

        I wanted to figure out a solution for allowing the users to login to their company issued laptops and then click one or twice and get to their remote desktops as easily and as efficiently as possible.

        You CAN make all or most of the credentials between that laptop and the resulting device be cached or saved. So that it is a really quick and painless process.

        True but if a user's password expires or they change it, they may get themselves locked out. We try not to encourage saving passwords too much.

        For security reasons, we avoid expiring passwords. That's what makes users write them down and make them easy to guess. Non-expiring, or rarely expiring passwords, are shown to be far more secure and make things like this much easier.

        yeah I know its a balance. We have had a few trade offs between password length and expiration time

        https://cdnapisec.kaltura.com/index.php/extwidget/preview/partner_id/684682/uiconf_id/31013851/entry_id/0_svsg82xf/embed/dynamic

        NIST guidelines were updated in 2017. They mostly follow XKCD.

        7c05c4e1-5fc4-4449-9eab-b52103daab0d-image.png

        I've been using this infographic for years! I love it.

        Have you seen this: http://correcthorsebatterystaple.net/

        Yes, but I like https://xkpasswd.net/s/ more.

        travisdh1T JaredBuschJ J 3 Replies Last reply Reply Quote 0
        • travisdh1T
          travisdh1 @Grey
          last edited by

          @Grey said in Looking for solutions to allow remote users access to their internal psychical computers:

          @JasGot said in Looking for solutions to allow remote users access to their internal psychical computers:

          @Grey said in Looking for solutions to allow remote users access to their internal psychical computers:

          @dave247 said in Looking for solutions to allow remote users access to their internal psychical computers:

          @scottalanmiller said in Looking for solutions to allow remote users access to their internal psychical computers:

          @dave247 said in Looking for solutions to allow remote users access to their internal psychical computers:

          @scottalanmiller said in Looking for solutions to allow remote users access to their internal psychical computers:

          @dave247 said in Looking for solutions to allow remote users access to their internal psychical computers:

          I wanted to figure out a solution for allowing the users to login to their company issued laptops and then click one or twice and get to their remote desktops as easily and as efficiently as possible.

          You CAN make all or most of the credentials between that laptop and the resulting device be cached or saved. So that it is a really quick and painless process.

          True but if a user's password expires or they change it, they may get themselves locked out. We try not to encourage saving passwords too much.

          For security reasons, we avoid expiring passwords. That's what makes users write them down and make them easy to guess. Non-expiring, or rarely expiring passwords, are shown to be far more secure and make things like this much easier.

          yeah I know its a balance. We have had a few trade offs between password length and expiration time

          https://cdnapisec.kaltura.com/index.php/extwidget/preview/partner_id/684682/uiconf_id/31013851/entry_id/0_svsg82xf/embed/dynamic

          NIST guidelines were updated in 2017. They mostly follow XKCD.

          7c05c4e1-5fc4-4449-9eab-b52103daab0d-image.png

          I've been using this infographic for years! I love it.

          Have you seen this: http://correcthorsebatterystaple.net/

          Yes, but I like https://xkpasswd.net/s/ more.

          At first glance, that's the best one yet.

          1 Reply Last reply Reply Quote 0
          • JaredBuschJ
            JaredBusch @Grey
            last edited by

            @Grey said in Looking for solutions to allow remote users access to their internal psychical computers:

            @JasGot said in Looking for solutions to allow remote users access to their internal psychical computers:

            @Grey said in Looking for solutions to allow remote users access to their internal psychical computers:

            @dave247 said in Looking for solutions to allow remote users access to their internal psychical computers:

            @scottalanmiller said in Looking for solutions to allow remote users access to their internal psychical computers:

            @dave247 said in Looking for solutions to allow remote users access to their internal psychical computers:

            @scottalanmiller said in Looking for solutions to allow remote users access to their internal psychical computers:

            @dave247 said in Looking for solutions to allow remote users access to their internal psychical computers:

            I wanted to figure out a solution for allowing the users to login to their company issued laptops and then click one or twice and get to their remote desktops as easily and as efficiently as possible.

            You CAN make all or most of the credentials between that laptop and the resulting device be cached or saved. So that it is a really quick and painless process.

            True but if a user's password expires or they change it, they may get themselves locked out. We try not to encourage saving passwords too much.

            For security reasons, we avoid expiring passwords. That's what makes users write them down and make them easy to guess. Non-expiring, or rarely expiring passwords, are shown to be far more secure and make things like this much easier.

            yeah I know its a balance. We have had a few trade offs between password length and expiration time

            https://cdnapisec.kaltura.com/index.php/extwidget/preview/partner_id/684682/uiconf_id/31013851/entry_id/0_svsg82xf/embed/dynamic

            NIST guidelines were updated in 2017. They mostly follow XKCD.

            7c05c4e1-5fc4-4449-9eab-b52103daab0d-image.png

            I've been using this infographic for years! I love it.

            Have you seen this: http://correcthorsebatterystaple.net/

            Yes, but I like https://xkpasswd.net/s/ more.

            That is horrible by default

            B90A42E2-5B19-4F27-9665-BB46AB5744C8.jpeg

            stacksofplatesS travisdh1T 2 Replies Last reply Reply Quote 0
            • stacksofplatesS
              stacksofplates @JaredBusch
              last edited by

              @JaredBusch said in Looking for solutions to allow remote users access to their internal psychical computers:

              @Grey said in Looking for solutions to allow remote users access to their internal psychical computers:

              @JasGot said in Looking for solutions to allow remote users access to their internal psychical computers:

              @Grey said in Looking for solutions to allow remote users access to their internal psychical computers:

              @dave247 said in Looking for solutions to allow remote users access to their internal psychical computers:

              @scottalanmiller said in Looking for solutions to allow remote users access to their internal psychical computers:

              @dave247 said in Looking for solutions to allow remote users access to their internal psychical computers:

              @scottalanmiller said in Looking for solutions to allow remote users access to their internal psychical computers:

              @dave247 said in Looking for solutions to allow remote users access to their internal psychical computers:

              I wanted to figure out a solution for allowing the users to login to their company issued laptops and then click one or twice and get to their remote desktops as easily and as efficiently as possible.

              You CAN make all or most of the credentials between that laptop and the resulting device be cached or saved. So that it is a really quick and painless process.

              True but if a user's password expires or they change it, they may get themselves locked out. We try not to encourage saving passwords too much.

              For security reasons, we avoid expiring passwords. That's what makes users write them down and make them easy to guess. Non-expiring, or rarely expiring passwords, are shown to be far more secure and make things like this much easier.

              yeah I know its a balance. We have had a few trade offs between password length and expiration time

              https://cdnapisec.kaltura.com/index.php/extwidget/preview/partner_id/684682/uiconf_id/31013851/entry_id/0_svsg82xf/embed/dynamic

              NIST guidelines were updated in 2017. They mostly follow XKCD.

              7c05c4e1-5fc4-4449-9eab-b52103daab0d-image.png

              I've been using this infographic for years! I love it.

              Have you seen this: http://correcthorsebatterystaple.net/

              Yes, but I like https://xkpasswd.net/s/ more.

              That is horrible by default

              B90A42E2-5B19-4F27-9665-BB46AB5744C8.jpeg

              ++74Why/do|YOU/say|ThAt|*11^

              GreyG 1 Reply Last reply Reply Quote 0
              • travisdh1T
                travisdh1 @JaredBusch
                last edited by

                @JaredBusch Yeah, you do have to click the XKCD button, and the site looks like I threw it up.

                1 Reply Last reply Reply Quote 0
                • J
                  JasGot @Grey
                  last edited by

                  @Grey said in Looking for solutions to allow remote users access to their internal psychical computers:

                  Yes, but I like https://xkpasswd.net/s/ more.

                  Thank you! I have a new favorite toy to play with!

                  1 Reply Last reply Reply Quote 0
                  • GreyG
                    Grey @stacksofplates
                    last edited by

                    @stacksofplates It's probably that @JaredBusch didn't see the section for presets. It's cool. Two out of three IT Pros liked it, and @JaredBusch is a Negative Nancy for many other things, so no surprise that he hated it.

                    1 Reply Last reply Reply Quote 0
                    • IRJI
                      IRJ
                      last edited by

                      I use Bitwarden's generator and just save my passwords. I dont really care about readability

                      DashrenderD stacksofplatesS 2 Replies Last reply Reply Quote 1
                      • DashrenderD
                        Dashrender @IRJ
                        last edited by

                        @IRJ said in Looking for solutions to allow remote users access to their internal psychical computers:

                        I use Bitwarden's generator and just save my passwords. I dont really care about readability

                        I do care about readability because I frequently find myself at company devices that don't have my password manager installed, so I end up typing it off my phone. That said - LP can make readable passwords.

                        IRJI 1 Reply Last reply Reply Quote 0
                        • IRJI
                          IRJ @Dashrender
                          last edited by

                          @Dashrender said in Looking for solutions to allow remote users access to their internal psychical computers:

                          @IRJ said in Looking for solutions to allow remote users access to their internal psychical computers:

                          I use Bitwarden's generator and just save my passwords. I dont really care about readability

                          I do care about readability because I frequently find myself at company devices that don't have my password manager installed, so I end up typing it off my phone. That said - LP can make readable passwords.

                          This is only an issue if you are accessing device physically.

                          DashrenderD 1 Reply Last reply Reply Quote 0
                          • DashrenderD
                            Dashrender @IRJ
                            last edited by

                            @IRJ said in Looking for solutions to allow remote users access to their internal psychical computers:

                            @Dashrender said in Looking for solutions to allow remote users access to their internal psychical computers:

                            @IRJ said in Looking for solutions to allow remote users access to their internal psychical computers:

                            I use Bitwarden's generator and just save my passwords. I dont really care about readability

                            I do care about readability because I frequently find myself at company devices that don't have my password manager installed, so I end up typing it off my phone. That said - LP can make readable passwords.

                            This is only an issue if you are accessing device physically.

                            True - which I do when I'm wondering around our clinical space fixing stupid.

                            Luckily, very little of that right now.

                            1 Reply Last reply Reply Quote 0
                            • stacksofplatesS
                              stacksofplates @IRJ
                              last edited by stacksofplates

                              @IRJ said in Looking for solutions to allow remote users access to their internal psychical computers:

                              I use Bitwarden's generator and just save my passwords. I dont really care about readability

                              Same here. I have it on my phones, my browsers and they even have a cli tool (I haven't used it though).

                              1 Reply Last reply Reply Quote 0
                              • K
                                krisleslie
                                last edited by

                                I used ZeroTier and RDP (without the flow rules) worked fine. If you have AD then yes you have more work to do! I never properly got it working with RDP+AD.

                                1 Reply Last reply Reply Quote 2
                                • K
                                  krisleslie @stacksofplates
                                  last edited by

                                  ZeroTier (with Flow rules) + RDP is how I solved this for my clients.
                                  Can you make a guide I'd be interested in that read.

                                  1 Reply Last reply Reply Quote 1
                                  • 1
                                  • 2
                                  • 3
                                  • 4
                                  • 4 / 4
                                  • First post
                                    Last post