Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.


Ridiculousname

4 posts

Wannabe Geek


#293394 18-Jan-2022 12:28
Send private message

I would very much appreciate some advice please, in relation to my questions, as indicated, in relation to the following scenario:

 

 

 

Multiple users require unattended access to one remote PC.

 

All users work from home. Currently connect to remote PC with Teamviewer (ID and password).

 

Manager is concerned about security. Says remote PC is open to the entire internet.

 

Manager wants to implement Teamviewer's TFA-for-connections. Result: All devices on a list (in the remote PC's TeamViewer settings) receive a push notification to Deny or Allow each and every attempted connection.  

 

I've suggested, as an alternative solution, we add each user's computer to the Trusted Devices list on the Teamviewer Account to which the remote PC is assigned. Only trusted devices are allowed to connect. Authorisation of a trusted device is done via email. It's way less annoying. 

 

1) Does the alternative solution provide a similar level of authentication of connections to the remote PC?

 

 

 

If having the PC open to the internet is the primary concern, shouldn’t security and firewall policies of the remote PC be reviewed, rather than the authentication of connections made via one application?

 

2) Is this a fair statement?

 

 

 

Are there alternative solutions that don't require the purchase of additional software, aren't overly complicated to implement or to explain?

 

3) Is there a better way?

 

 

 

I realise the scenario described does not provide a lot of detail. If it's not mentioned, it's probably not happening 😩

 

 

 

Greatly appreciate all advice and suggested approaches.


Create new topic
timmmay
20578 posts

Uber Geek

Trusted
Lifetime subscriber

  #2852784 18-Jan-2022 12:31
Send private message

How about ensuring each person who wants to connect has a static IP, then whitelisting only those IPs in the computer inbound firewall? If it's behind a corporate firewall you can use that instead of the computer firewall. This isn't a full solution, it's a piece of defense in depth.




sparkz25
750 posts

Ultimate Geek
Inactive user


  #2852792 18-Jan-2022 12:42
Send private message

Firstly I would uninstall Team Viewer, it's pretty much a Disease in itself, it's painful to use and lacks a lot of functionality that we use daily. (personal preference is self Hosted Screen Connect),

 

You could purchase a screen connect license, but for what you're doing probably not worth it. 

 

I would suggest installing Zerotier on the machines and using just normal RDP to the Zt address of the said machine, you can auth and deauth users/machines in the ZT we console if needed.

 

As long as you are running AV of some sort and its up to date, you should be good!

 

Zerotier is free for up to 50 devices so if you are under 50 you should be good!

 

 


1101
3122 posts

Uber Geek


  #2852797 18-Jan-2022 12:54
Send private message

"Manager is concerned about security. Says remote PC is open to the entire internet."

 

Define remote PC : is it the work PC or the home PC ?

"concerned about security"
Then they need to supply a company laptop for ALL the remote users & lock that down.
There is no security if using a family PC from home for remote access, you have zero control over that home PC's use and could become riddled with malware .
At the very least, company should pay for good AV on the home PC/laptop & actively monitor the AV .

 

Whats the budget to setup secure remote access ?

 

BTW , teamveiwer will stop working once it detects commercial use . Ive seen that several times .
TV licensees are expensive

 

"concerned about security" sometimes becomes not so much an issue when $$$ are needed , in smallish companies.

 

I didnt think TV had the option for 2fa for remote access , only on the TV admin a/c ?




Ridiculousname

4 posts

Wannabe Geek


  #2852828 18-Jan-2022 13:49
Send private message

Thanks for the suggestions.

 

 

 

All computers are company issue.

 

Their concern is that anyone could potentially connect to the remote (work) PC. My argument is that if this is the primary concern, why is the focus only on setting up authentication of TV connections. 

 

TFA-for-connections is a feature of TV v15 onward.


evnafets
537 posts

Ultimate Geek

Lifetime subscriber

  #2852892 18-Jan-2022 14:38
Send private message

Add your manager's device as one of those that will get a push notification for 2FA every time somebody connects. 

 

See how fast he asks you to change it to some other solution. 

 

 


1cloud
164 posts

Master Geek


#2852943 18-Jan-2022 14:43
Send private message

evnafets:

 

Add your manager's device as one of those that will get a push notification for 2FA every time somebody connects. 

 

 

 

 

someone would be pissed 🤣


wellygary
8315 posts

Uber Geek


  #2852944 18-Jan-2022 14:43
Send private message

Manager is concerned about security. Says remote PC is open to the entire internet.

 

 

 

Sounds like all the other machines are equally as vulnerable ??? -

 

What protection is on them  and what do they connect to?


 
 
 
 

Shop now for Lenovo laptops and other devices (affiliate link).
sparkz25
750 posts

Ultimate Geek
Inactive user


  #2852950 18-Jan-2022 15:06
Send private message

wellygary:

 

Manager is concerned about security. Says remote PC is open to the entire internet.

 

 

 

Sounds like all the other machines are equally as vulnerable ??? -

 

What protection is on them  and what do they connect to?

 

 

 

 

I wonder if Port 3389 has been exposed to the internet?


1101
3122 posts

Uber Geek


  #2852961 18-Jan-2022 15:19
Send private message

Ridiculousname:

 

Their concern is that anyone could potentially connect to the remote (work) PC.

 

 

That supposedly happened many years back with TV ( a much older version) , hackers able to access TV enabled PC's , supposedly.
Enough claimed to have had it happen to make me wonder , TV denied any issues .

 

With any remote access , there is allways some risk .
The real risk is opening bogus emails on the work PC & letting hackers in that way .
I see more of that than hackers getting access some other way .


Varkk
643 posts

Ultimate Geek


  #2853168 19-Jan-2022 08:24
Send private message

1101:

 

Ridiculousname:

 

Their concern is that anyone could potentially connect to the remote (work) PC.

 

 

That supposedly happened many years back with TV ( a much older version) , hackers able to access TV enabled PC's , supposedly.
Enough claimed to have had it happen to make me wonder , TV denied any issues .

 

With any remote access , there is allways some risk .
The real risk is opening bogus emails on the work PC & letting hackers in that way .
I see more of that than hackers getting access some other way .

 

 

 

 

There was an issue where I think if you had set your own weak password there were some hackers gaining access to the PC. Teamviewer has changed the way passwords are handled in the client since then and beefed up the default auto-generated ones.


Create new topic





News and reviews »

Air New Zealand Starts AI adoption with OpenAI
Posted 24-Jul-2025 16:00


eero Pro 7 Review
Posted 23-Jul-2025 12:07


BeeStation Plus Review
Posted 21-Jul-2025 14:21


eero Unveils New Wi-Fi 7 Products in New Zealand
Posted 21-Jul-2025 00:01


WiZ Introduces HDMI Sync Box and other Light Devices
Posted 20-Jul-2025 17:32


RedShield Enhances DDoS and Bot Attack Protection
Posted 20-Jul-2025 17:26


Seagate Ships 30TB Drives
Posted 17-Jul-2025 11:24


Oclean AirPump A10 Water Flosser Review
Posted 13-Jul-2025 11:05


Samsung Galaxy Z Fold7: Raising the Bar for Smartphones
Posted 10-Jul-2025 02:01


Samsung Galaxy Z Flip7 Brings New Edge-To-Edge FlexWindow
Posted 10-Jul-2025 02:01


Epson Launches New AM-C550Z WorkForce Enterprise printer
Posted 9-Jul-2025 18:22


Samsung Releases Smart Monitor M9
Posted 9-Jul-2025 17:46


Nearly Half of Older Kiwis Still Write their Passwords on Paper
Posted 9-Jul-2025 08:42


D-Link 4G+ Cat6 Wi-Fi 6 DWR-933M Mobile Hotspot Review
Posted 1-Jul-2025 11:34


Oppo A5 Series Launches With New Levels of Durability
Posted 30-Jun-2025 10:15









Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.