![]() |
Patch reliability is unclear. Unless you have an immediate, pressing need to install a specific patch, don't do it. |
SIGN IN | Not a member? | REGISTER | PLUS MEMBERSHIP |
XP passwords rendered useless
In this issue
- TOP STORY: XP passwords rendered useless
- WACKY WEB WEEK: You thought privacy was bad - now the Web can read your mind
XP passwords rendered useless
By Brian Livingston
Windows XP, which has been marketed by Microsoft as “the most secure version ever,” has been found to have a flaw so bone-headed that it renders passwords ineffective as a means of keeping people out of your PC.
Reader Tony DeMartino alerted me to the problem, which all administrators of Windows XP machines should immediately take to heart:
- Anyone with a Windows 2000 CD can boot up a Windows XP box and start the Windows 2000 Recovery Console, a troubleshooting program.
- Windows XP then allows the visitor to operate as Administrator without a password, even if the Administrator account has a strong password.
- The visitor can also operate in any of the other user accounts that may be present on the XP machine, even if those accounts have passwords.
- Unbelievably, the visitor can copy files from the hard disk to a floppy disk or other removable media – something even an Administrator is normally prevented from doing when using the Recovery Console.
This problem is unrelated to a feature of XP that allows an Administrator to set up automatic logon when the Recovery Console is used. Even without the Registry entry that enables this, XP is vulnerable. (For info on that feature, see support.microsoft.com/?scid=kb;en-us;312149.)
Windows 2000, of course, doesn’t allow Recovery Console users to access a hard drive without a password, if one previously existed.
I notified four Microsoft executives of the XP flaw weeks ago, but haven’t yet received an official response. There’s no Knowledge Base article about it, and there may not even be a good solution to the problem.
When I’ve spoken with Microsoft security pros about similar problems in the past, they’ve referred me to a company policy that says, “If a bad guy has unrestricted physical access to your computer, it’s not your computer anymore.”
That’s all well and good – but the fact remains that Windows 2000 doesn’t allow anyone with an old CD to get password-free access, and Windows XP does.
My recommendation: If you use XP machines in open spaces, put the PCs behind a locked door or put a lock on the PCs themselves. The bad guys know about this flaw, and it’s just one more thing for the good guys to protect against.
To send me more information about this, or to send me a tip on any other subject, e-mail me at Brian@BriansBuzz.com
You thought privacy was bad - now the Web can read your mind
A simple layout masks a devilishly psychic power at The Flash Mind Reader page. You’re presented with a list of every two-digit number, from 00 to 99, and a set of corresponding symbols that represent each number. You choose a two-digit number, add the digits together, then subtract the result from your original number and concentrate – concentrate! – on the appropriate symbol.
When you click the magic crystal ball, the page reads your mind and displays the symbol you were thinking of. Awesome! You have to try this for yourself – but not in a dark room… The Flash Mind Reader
Publisher: AskWoody LLC (woody@askwoody.com); editor: Tracey Capen (editor@askwoody.com).
Trademarks: Microsoft and Windows are registered trademarks of Microsoft Corporation. AskWoody, Windows Secrets Newsletter, WindowsSecrets.com, WinFind, Windows Gizmos, Security Baseline, Perimeter Scan, Wacky Web Week, the Windows Secrets Logo Design (W, S or road, and Star), and the slogan Everything Microsoft Forgot to Mention all are trademarks and service marks of AskWoody LLC. All other marks are the trademarks or service marks of their respective owners.
Your email subscription:
- Subscription help: customersupport@askwoody.com
Copyright © 2025 AskWoody LLC, All rights reserved.

Plus Membership
Donations from Plus members keep this site going. You can identify the people who support AskWoody by the Plus badge on their avatars.
AskWoody Plus members not only get access to all of the contents of this site -- including Susan Bradley's frequently updated Patch Watch listing -- they also receive weekly AskWoody Plus Newsletters (formerly Windows Secrets Newsletter) and AskWoody Plus Alerts, emails when there are important breaking developments.
Get Plus!
Welcome to our unique respite from the madness.
It's easy to post questions about Windows 11, Windows 10, Win8.1, Win7, Surface, Office, or browse through our Forums. Post anonymously or register for greater privileges. Keep it civil, please: Decorous Lounge rules strictly enforced. Questions? Contact Customer Support.
Search Newsletters
Search Forums
View the Forum
Search for Topics
Recent Topics
-
Latest Firefox requires Password on start up
by
Gordski
2 hours, 43 minutes ago -
Resolved : AutoCAD 2022 might not open after updating to 24H2
by
Alex5723
7 hours, 5 minutes ago -
Missing api-ms-win-core-libraryloader-11-2-1.dll
by
IreneLinda
2 hours, 56 minutes ago -
How Much Daylight have YOU Saved?
by
Nibbled To Death By Ducks
3 hours, 39 minutes ago -
A brief history of Windows Settings
by
Simon Bisson
2 hours, 36 minutes ago -
Thunderbolt is not just for monitors
by
Ben Myers
3 hours, 45 minutes ago -
Password Generators โ Your first line of defense
by
Deanna McElveen
2 hours, 57 minutes ago -
AskWoody at the computer museum
by
Will Fastie
3 hours, 18 minutes ago -
Planning for the unexpected
by
Susan Bradley
4 hours, 15 minutes ago -
Which printer type is the better one to buy?
by
Bob99
8 hours, 50 minutes ago -
Upgrading the web server
by
Susan Bradley
7 hours, 15 minutes ago -
New Windows 11 24H2 Setup – Initial Win Update prevention settings?
by
Tex265
1 day, 2 hours ago -
Creating a Google account
by
DavidofIN
1 day, 1 hour ago -
Undocumented “backdoor” found in Bluetooth chip used by a billion devices
by
Alex5723
1 day, 7 hours ago -
Microsoft Considering AI Models to Replace OpenAIโs in Copilot
by
Alex5723
1 day, 18 hours ago -
AI *emergent misalignment*
by
Alex5723
1 day, 19 hours ago -
Windows 11 Disk Encryption/ Bitlocker/ Recovery Key
by
Tex265
3 hours, 47 minutes ago -
Trouble signing out and restarting
by
Tech Hiker
20 hours, 23 minutes ago -
Windows 7 MSE Manual Updating
by
Microfix
2 days, 4 hours ago -
Problem running LMC 22 flash drive
by
Charlie
1 day, 2 hours ago -
Outlook Email Problem
by
Lil88reb
1 day, 3 hours ago -
“Microsoft 365 Office All-in-One For Dummies, 3rd Edition FREE
by
Alex5723
1 day, 10 hours ago -
Cant use Office 2013 – Getting error message about Office 2013
by
SAAR
2 days, 3 hours ago -
Nearly 1 million Windows devices targeted in advanced โmalvertisingโ spree
by
bbearren
2 days, 3 hours ago -
Windows 11 Insider Preview build 27808 released to Canary
by
joep517
3 days, 4 hours ago -
Windows 11 Insider Preview Build 22635.5025 (23H2) released to BETA
by
joep517
3 days, 4 hours ago -
Sysprep issue
by
Evit
3 days, 3 hours ago -
Android Security BulletinโMarch 2025
by
Alex5723
3 days, 6 hours ago -
23h2: PIN TO START randomly available on right-click
by
dataman1701
3 days, 6 hours ago -
Microsoft Defender
by
agoldhammer
3 days, 12 hours ago
Recent blog posts
Key Links
Want to Advertise in the free newsletter? How about a gift subscription in honor of a birthday? Send an email to sb@askwoody.com to ask how.
Mastodon profile for DefConPatch
Mastodon profile for AskWoody
Home • About • FAQ • Posts & Privacy • Forums • My Account
Register • Free Newsletter • Plus Membership • Gift Certificates • MS-DEFCON Alerts
Copyright ©2004-2025 by AskWoody Tech LLC. All Rights Reserved.