![]() |
Patch reliability is unclear. Unless you have an immediate, pressing need to install a specific patch, don't do it. |
SIGN IN | Not a member? | REGISTER | PLUS MEMBERSHIP |
XP passwords rendered useless
In this issue
- TOP STORY: XP passwords rendered useless
- WACKY WEB WEEK: You thought privacy was bad - now the Web can read your mind
XP passwords rendered useless
By Brian Livingston
Windows XP, which has been marketed by Microsoft as “the most secure version ever,” has been found to have a flaw so bone-headed that it renders passwords ineffective as a means of keeping people out of your PC.
Reader Tony DeMartino alerted me to the problem, which all administrators of Windows XP machines should immediately take to heart:
- Anyone with a Windows 2000 CD can boot up a Windows XP box and start the Windows 2000 Recovery Console, a troubleshooting program.
- Windows XP then allows the visitor to operate as Administrator without a password, even if the Administrator account has a strong password.
- The visitor can also operate in any of the other user accounts that may be present on the XP machine, even if those accounts have passwords.
- Unbelievably, the visitor can copy files from the hard disk to a floppy disk or other removable media – something even an Administrator is normally prevented from doing when using the Recovery Console.
This problem is unrelated to a feature of XP that allows an Administrator to set up automatic logon when the Recovery Console is used. Even without the Registry entry that enables this, XP is vulnerable. (For info on that feature, see support.microsoft.com/?scid=kb;en-us;312149.)
Windows 2000, of course, doesn’t allow Recovery Console users to access a hard drive without a password, if one previously existed.
I notified four Microsoft executives of the XP flaw weeks ago, but haven’t yet received an official response. There’s no Knowledge Base article about it, and there may not even be a good solution to the problem.
When I’ve spoken with Microsoft security pros about similar problems in the past, they’ve referred me to a company policy that says, “If a bad guy has unrestricted physical access to your computer, it’s not your computer anymore.”
That’s all well and good – but the fact remains that Windows 2000 doesn’t allow anyone with an old CD to get password-free access, and Windows XP does.
My recommendation: If you use XP machines in open spaces, put the PCs behind a locked door or put a lock on the PCs themselves. The bad guys know about this flaw, and it’s just one more thing for the good guys to protect against.
To send me more information about this, or to send me a tip on any other subject, e-mail me at Brian@BriansBuzz.com
You thought privacy was bad - now the Web can read your mind
A simple layout masks a devilishly psychic power at The Flash Mind Reader page. You’re presented with a list of every two-digit number, from 00 to 99, and a set of corresponding symbols that represent each number. You choose a two-digit number, add the digits together, then subtract the result from your original number and concentrate – concentrate! – on the appropriate symbol.
When you click the magic crystal ball, the page reads your mind and displays the symbol you were thinking of. Awesome! You have to try this for yourself – but not in a dark room… The Flash Mind Reader
Publisher: AskWoody LLC (woody@askwoody.com); editor: Tracey Capen (editor@askwoody.com).
Trademarks: Microsoft and Windows are registered trademarks of Microsoft Corporation. AskWoody, Windows Secrets Newsletter, WindowsSecrets.com, WinFind, Windows Gizmos, Security Baseline, Perimeter Scan, Wacky Web Week, the Windows Secrets Logo Design (W, S or road, and Star), and the slogan Everything Microsoft Forgot to Mention all are trademarks and service marks of AskWoody LLC. All other marks are the trademarks or service marks of their respective owners.
Your email subscription:
- Subscription help: customersupport@askwoody.com
Copyright © 2025 AskWoody LLC, All rights reserved.

Plus Membership
Donations from Plus members keep this site going. You can identify the people who support AskWoody by the Plus badge on their avatars.
AskWoody Plus members not only get access to all of the contents of this site -- including Susan Bradley's frequently updated Patch Watch listing -- they also receive weekly AskWoody Plus Newsletters (formerly Windows Secrets Newsletter) and AskWoody Plus Alerts, emails when there are important breaking developments.
Get Plus!
Welcome to our unique respite from the madness.
It's easy to post questions about Windows 11, Windows 10, Win8.1, Win7, Surface, Office, or browse through our Forums. Post anonymously or register for greater privileges. Keep it civil, please: Decorous Lounge rules strictly enforced. Questions? Contact Customer Support.
Search Newsletters
Search Forums
View the Forum
Search for Topics
Recent Topics
-
Awoke to a rebooted Mac (crashed?)
by
rebop2020
1 hour, 4 minutes ago -
Office 2021 Perpetual for Mac
by
rebop2020
1 hour, 11 minutes ago -
Difface : Reconstruction of 3D Human Facial Images from DNA Sequence
by
Alex5723
4 hours, 43 minutes ago -
Seven things we learned from WhatsApp vs. NSO Group spyware lawsuit
by
Alex5723
5 hours, 5 minutes ago -
Outdated Laptop
by
jdamkeene
10 hours, 8 minutes ago -
Updating Keepass2Android
by
CBFPD-Chief115
15 hours, 33 minutes ago -
Another big Microsoft layoff
by
Charlie
15 hours, 13 minutes ago -
PowerShell to detect NPU – Testers Needed
by
RetiredGeek
6 hours, 11 minutes ago -
May 2025 updates are out
by
Susan Bradley
15 hours, 38 minutes ago -
Windows 11 Insider Preview build 26200.5600 released to DEV
by
joep517
21 hours, 17 minutes ago -
Windows 11 Insider Preview build 26120.3964 (24H2) released to BETA
by
joep517
21 hours, 19 minutes ago -
Drivers suggested via Windows Update
by
Tex265
21 hours, 10 minutes ago -
Thunderbird release notes for 128 esr have disappeared
by
EricB
18 hours, 54 minutes ago -
CISA mutes own website, shifts routine cyber alerts to X, RSS, email
by
Nibbled To Death By Ducks
1 day, 4 hours ago -
Apple releases 18.5
by
Susan Bradley
22 hours, 34 minutes ago -
Fedora Linux 40 will go end of life for updates and support on 2025-05-13.
by
Alex5723
1 day, 5 hours ago -
How a new type of AI is helping police skirt facial recognition bans
by
Alex5723
1 day, 6 hours ago -
Windows 7 ISO /Windows 10 ISO
by
ECWS
13 hours, 29 minutes ago -
No HP software folders
by
fpefpe
1 day, 13 hours ago -
Which antivirus apps and VPNs are the most secure in 2025?
by
B. Livingston
11 hours, 13 minutes ago -
Stay connected anywhere
by
Peter Deegan
1 day, 19 hours ago -
Copilot, under the table
by
Will Fastie
1 day, 10 hours ago -
The Windows experience
by
Will Fastie
2 days, 1 hour ago -
A tale of two operating systems
by
Susan Bradley
5 hours, 44 minutes ago -
Microsoft : Resolving Blue Screen errors in Windows
by
Alex5723
2 days, 6 hours ago -
Where’s the cache today?
by
Up2you2
2 days, 22 hours ago -
Ascension says recent data breach affects over 430,000 patients
by
Nibbled To Death By Ducks
2 days, 14 hours ago -
Nintendo Switch 2 has a remote killing switch
by
Alex5723
1 day, 15 hours ago -
Blocking Search (on task bar) from going to web
by
HenryW
17 hours, 31 minutes ago -
Windows 10: Microsoft 365 Apps will be supported up to Oct. 10 2028
by
Alex5723
3 days, 15 hours ago
Recent blog posts
Key Links
Want to Advertise in the free newsletter? How about a gift subscription in honor of a birthday? Send an email to sb@askwoody.com to ask how.
Mastodon profile for DefConPatch
Mastodon profile for AskWoody
Home • About • FAQ • Posts & Privacy • Forums • My Account
Register • Free Newsletter • Plus Membership • Gift Certificates • MS-DEFCON Alerts
Copyright ©2004-2025 by AskWoody Tech LLC. All Rights Reserved.