Win11 explorer bug?

Dec 09, 2024 Last reply: 1 year ago 46 Replies

I hate file drag and drop. I certainly wouldn't want to be able to destroy files that already exist in the destination folder. YMMV

I've turned that crap off.

Probably because it is *so* bug. (typo for big but Freudian slip seems OK)

There are devices that put the actual interface on the phone, via WiFi. The physical interface has a reduced set of features.

I'm thinking of a particular heating system with thermostat. You can program the times when the heating turns on automatically and the temps only via internet. On the thermostat on the wall there is only a manual control that sets the temp for "now", a knob.

Oh, and it comes with no manual, no docs.

Certainly. There is no other way unless ISPs provide IPv6 connectivity.

Well, it has economic advantages.

I really do *need* to handle the heating remotely.

Not a concern for me.

They save hardware and firmware, which was my point.

I hate this too. I'm resistant to cameras which bounce off the manufacturer's server, which could be anywhere.

That would be great. How do you do that?

Software Engineering is an oxymoron.

Apart from the obvious security and reliability worries, there is the issue that the *manufacturer* gets to decide when *your* device is obsolete.

The software industry invented that trick, but lots of other industries are catching on.

Jeroen Belleman

The device has a limited life expectancy, anyway. About 10 years. The boiler needs replacement of rubber gasket every year or two. There is a mandatory yearly maintenance visit. With the remote controller, maintenance visits are every two years, because the remote server monitors the parameters and decides when a visit is needed.

So, that convenience is decisive for me. Win win.

Inbound is problematic for various reasons. Do you want your cameras accepting inbound connections from anywhere in the world? Ok they don't have access credentials but there's still a risk of an 0-day in a camera system which isn't going to get any more firmware updates. I would do this myself because I can use a firewall to restrict inbound as necessary and I can quickly add any IP or network attempting brute force to a blacklist. But most people have no interest in that. Most people just want the pictures on their phone wherever they are and they may wrongly assume that it's impossible for the pictures to be viewed by anyone other than themselves.

One reason is that the packet filtering would have to be configured specifically for local requirements. This gets us back to the issue of most people not knowig a packet filter if they fell over it.

I don't permit outbound connections to a long list of countries. I can always whitelist if it does turn out that I need to connect to a server in one of those countries.

I don't see any additional value in this provided the file server is restricted to specific IP addresses or networks and the connection is secure.

A nearby store installed cameras not long ago. The number if cameras (or what looked like there were cameras inside them) made it easy to conclude that they were fake.

Engineers design giant systrems - cars, airplanes, bridges, buildings

- with lots of parts, and nobody understands all the parts. And they work first time.

Software is different, and it never works first time. Most programs don't even compile first try.

I could probably code a "Hello, world!" program that would run first try.

I insisted that our new cooktops have no electronics. Well, they have igniters but you can still light them with a match.

We have a dual oven that for some reason has one section with a classic pneumatic thermostat and the other with electronic controls. Guess which is broken.

A dodge occurs to me: Install a simple firewall between external Internet and internal network that hosts such things as cameras and furnaces. Set the firewall to accept only one of a small set of white listed sources, and otherwise not to reply.

White lists have the advantage of immunity to attempts from random places. The lack of response if not white listed will defeat most port IP address and scanners, even though the firewall most likely can be hacked if known.

Upgrade the firewall from time to time, to sorta keep up with the threats.

Joe Gwinn

AFAIK, I have the ISP installed router that has a firewall, and everything incoming is closed.

And this thing is installed on the guest LAN.

Over here, there is a safety "thing" (I don't know the name). When hot, it opens the gas valve, so that if the flame extinguishes, it goes cold, and closes the valve. It could be based on the Seebeck effect, so arguably electronics.

I believe it is mandatory.

We have the same thing, and yes it is mandatory.

The original ones were purely mechanical, or maybe electro-mechanical (uses a thermocouple stack to generate enough current to drive an actuator. These are still around, but things like oil burners also have photocells, to see if the sprayed oil is in fact burning, shutting the oil off if no light for maybe ten seconds.

Yeah.

Joe Gwinn

The host based filter is worthless if the user is administrator (like most Windows users are) because malware can configure/disable the firewall as it likes.

It does if you watch the logs for anything unusual. A connection to a neighbor IP address would be obvious to me and I'd likely block it to see if anything legitimate breaks. Just like I watch who goes in and out of my house and who I give keys to. Imagine owning a house where you can't tell who comes and goes or who has keys. That's how it is for most people online and they aren't interested in knowing more, except perhaps briefly after the ransomware cleanup.

Knowing that there's a house there is information. Or in the country I'm from, knowing that there's a castle there is information but if it's surrounded by a moat then good luck getting in unseen. Violation of the access protocol could get you an arrow or cannon ball up your somewhere in the past.

In many cases you can infer. 1.2.3.0/24 and if you know 1.2.3.20 is active then the rest are likely doing someting potentially interesting.

It must have been powered by something, even if everything else was wireless.

They tried to put me on lsn/cgnat. I was given a static IPv4 when I complained. Previously the IP had been sufficiently static but not totally static.

It's true that this is a situation you want to avoid but a properly designed internal network will not allow the malware free access to services it doesn't have access credentials for. And devices such as cameras can be on their own internal network separately packet filtered as necesary.

That still doesn't mean it has access credentials for anything it shouldn't have.

Automatic (python scripts in my case) examination of successful connections (ignoring anything blocked) takes a few seconds per day so that I can easily see anything out of the ordinary. Connection between anything on my network and another nearby IP on the same (or not far away) ISP would have been obvious.

See above.

See above. Security personnel are generally trained to watch for anything unusual. Knowing whether a complete stranger has entered your house is all that's needed. It is of course best that they stay locked out.

A better solution is not to get anything compromised.

I wouldn't want to use a laptop which wipes the OS each time I boot.

A camera system which requires me to go up a ladder to change the large battery and retrieve the footage doesn't sound like fun to me.

One reason might be because the organization does not employ anyone whose job it is to watch the firewall logs (using log analysis scripts as needed) in such a way that they can get familiar with what is usual and detect anything unusual. Let's take a hospital with myriad networked devices on various networks. Is anyone watching what goes in and out of the firewall like the security people are watching cameras and people activity? Or has the IT equipment and firewalls etc been installed and left to run without any monitoring?

So some of them are obviously doing much better than others.

I got an error (441 I think) trying to reply to your other 9:17 PM post so I'm going to leave it there.

>

So some of them are obviously doing much better than others.

I'm getting header line too long while replying to this and your other post at 9:17 so I'm going to leave it there.

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required