If you plug a USB drive into Microsoft Windows, in many cases it will try to do things “for you” with the drive. Not a great idea. There could be malware lurking on that USB drive.

There are a couple of things you can do to help mitigate the issue. These tips assume Windows 11.

Turn off Autoplay

  • Open Settings. Press Windows + I to open the Settings app.
  • Go to Bluetooth & devices. In the left sidebar, click on “Bluetooth & devices.”
  • Select Autoplay. Scroll down and click on “Autoplay.”
  • Turn Off Autoplay. You’ll see a toggle switch labeled “Use Autoplay for all media and devices.” Turn this off.

This will turn it off completely. You can, if you want, make individual settings for different types of devices.

Deny Execute Access (Pro or Enterprise versions of Windows 11)

  • Open Group Policy Editor. Press Windows + R, type gpedit.msc, and press Enter.
  • Navigate to the Removable Storage Access Policies. Go to Computer Configuration > Administrative Templates > System > Removable Storage Access.
  • Modify Policies. You can enable the policy “Removable Disks: Deny execute access” to prevent execution from removable drives.
  • Apply and Reboot.

Note, there are some cases where you may want to execute scripts or programs from a removable drive. If that’s the case, you may not want to do this, or make a note of it so you can re-enable if needed.

  • merthyr1831@lemmy.ml
    link
    fedilink
    English
    arrow-up
    165
    arrow-down
    4
    ·
    1 month ago

    why the fuck did they re-enable autoplay? it was a terrible idea when they did it years ago and they quickly disabled it.

      • ImplyingImplications
        link
        fedilink
        arrow-up
        82
        ·
        1 month ago

        It’s honestly impressive how we went from “only nerds know tech” in gen x to “everyone knows tech” in millennials to “only nerds know tech” in gen z.

      • Bappity@lemmy.world
        link
        fedilink
        English
        arrow-up
        29
        arrow-down
        3
        ·
        1 month ago

        on this point…

        I heard from someone in my local area that it’s getting to the point where people don’t even know how to use a mouse and keyboard.

        this is the iPad generation…

        • SturgiesYrFase@lemmy.ml
          link
          fedilink
          arrow-up
          25
          ·
          1 month ago

          There’s been several articles in the past 10 years pointing out that kids going for IT and CompSci degrees in college/uni are often not aware of file structures. The thought is that they are so used to just saving something on a mobile device, and when they want to use/send/view it, the apps just comb the whole system and present files that fit the required extension formats.

          • rtxn@lemmy.world
            link
            fedilink
            English
            arrow-up
            18
            ·
            edit-2
            1 month ago

            I recently had to rescue the SSD of a data science PhD student. While dumping the files, I noticed that he had a dozen copies of identically named large CSV files (I mean 20+ gigabytes each). I compared their checksums - they were copies of the same raw data file, just sitting there in the downloads folder. When I asked, he said he’d made several backups of the project. Including the data.

            Unfortunately Windows somehow fucked up the partition table and took the “backups” with it.

            • TheImpressiveX@lemmy.ml
              link
              fedilink
              arrow-up
              17
              ·
              1 month ago

              He’s just following the 3-2-1 backup strategy - at least three copies of the data, two on different formats (.csv and .xls) and at least one copy in a different location (saved in the “Backup” folder instead of the “Documents” folder).

          • wizardbeard@lemmy.dbzer0.com
            link
            fedilink
            English
            arrow-up
            9
            ·
            1 month ago

            Was a Lab Assistant for the first Programming class for a Comp Sci degree, back in the very early 2010’s. Helping some of the students get set up with the IDE was… special.

      • Nemo Wuming@lemmy.world
        link
        fedilink
        arrow-up
        12
        arrow-down
        1
        ·
        1 month ago

        I just checked a freshly installed Windows 11 and the autoplay is off by default.

        So to follow up on the point you are trying to make: People are illiterate because they react loudly without checking what they react about. It’s enough for them to get a few online upvotes in a world where they don’t matter otherwise.

    • Nemo Wuming@lemmy.world
      link
      fedilink
      arrow-up
      23
      arrow-down
      1
      ·
      1 month ago

      I just checked a freshly installed Windows 11 and the autoplay is off by default.

      So to follow up on the value of your question: People react loudly without checking what they react about. It’s enough for them to get a few online upvotes in a world where they don’t matter otherwise.

    • snooggums@lemmy.world
      link
      fedilink
      English
      arrow-up
      8
      ·
      1 month ago

      Because people in general want things to be ‘easy’ far more than they they care about security risks they don’t understand. If they cared about security at all, they wouldn’t be plugging random USB sticks into their computers in the first place.

    • tomalley8342@lemmy.world
      link
      fedilink
      arrow-up
      3
      arrow-down
      1
      ·
      edit-2
      1 month ago

      You are remembering that the executable features of autorun.inf is disabled, which is still true. Autoplay (if enabled) as it exists currently only applies for discovered media file types and makes your default configured media player responsible for handling them. It would not be possible to execute arbitrary tasks unless you had an ACE exploit for the installed media player.

    • DarkCloud@lemmy.world
      link
      fedilink
      arrow-up
      3
      arrow-down
      5
      ·
      1 month ago

      Because people get all their music from MP3s downloaded via limewire, and store them on usb drives apparently.

      Such a modern operating system! Forward thinking Microsoft.

    • Boozilla@lemmy.worldOPM
      link
      fedilink
      English
      arrow-up
      21
      ·
      1 month ago

      Think of it as a seatbelt. You don’t plan on crashing your car, but shit happens. It’s even possible a brand new USB drive from a “reputable” company could have something on it.

    • Tujio@lemmy.world
      link
      fedilink
      arrow-up
      11
      ·
      1 month ago

      It’s surprising how many people will plug in a random USB drive that they find. Apparently that’s how the CIA got the Stuxnet virus into Iran’s system and nerfed their centrifuges back in the day.

  • deadbeef79000@lemmy.nz
    link
    fedilink
    arrow-up
    54
    ·
    1 month ago

    Why the fuck is the non execute setting, a principal safety feature, restricted to the pro and ent versions!?

    Fuck you Microsoft.

    • Boozilla@lemmy.worldOPM
      link
      fedilink
      English
      arrow-up
      8
      arrow-down
      1
      ·
      1 month ago

      There is also a registry hack for this but I have not looked into it or tested it. (And I agree with your sentiments re: Microsoft.)

      • JTskulk@lemmy.world
        link
        fedilink
        English
        arrow-up
        8
        arrow-down
        2
        ·
        1 month ago

        Registry changes are too confusing for normal computer users. The year of the Windows desktop is a pipe dream held dearly by the utterly deranged.

  • jet@hackertalks.com
    link
    fedilink
    English
    arrow-up
    49
    ·
    1 month ago

    It’s even worse than that. If you plug a USB device into a computer, it can pretend to be a keyboard and mouse, and do malicious things that way.

    Do not plug any random device into your hardware.

    • OutlierBlue
      link
      fedilink
      English
      arrow-up
      28
      ·
      1 month ago

      Yep, plug it into your coworker’s computer to test it first.

  • yesman@lemmy.world
    link
    fedilink
    arrow-up
    22
    ·
    1 month ago

    Some malicious USB drives have a capacitor that will discharge and fry your whole system. Unless you have an air-gap system that you don’t care about, unknown USB drives should be disposed of.

    Oh, and all this and more can be accomplished with a sneaky charging cable too. So you have to dial in your level of paranoia to suit your situation. The person most likely to tamper with your computer is a spouse. Search and chat histories as well as GPS devices are becoming common in divorce cases.

  • ohellidk@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    15
    arrow-down
    1
    ·
    1 month ago

    so one thing that has been driving me nuts is that windows is doing something to my external TB drive to where Ubuntu thinks its corrupt. (I have dual-boot) after googling it, windows sets the drive flag as a “dirty” NTFS system, and Linux no longer reads it afterwards. not sure if there’s any solution to fix that, but I’ll give these a shot.

    • tomkatt@lemmy.world
      link
      fedilink
      English
      arrow-up
      5
      ·
      edit-2
      1 month ago

      You can use ntfsfix on the drive to do a check and remove dirty bit. This isn’t a full check though, and could mask or hide actual issues with the drive if it’s failing.

      There’s also chkntfs which is more robust but I’m not sure if that’s open source and I’m not familiar with it.

      Using ntfsfix is a good quick fix in my experience, but at the end of the day, NTFS is a Microsoft exclusive format and shared disks should be mounted in a format that both OSes can use, like exFAT, or Btrfs with the WinBtrfs driver (the latter I’m not familiar with, I’ve always used exFAT for shared disks, but I don’t use Windows anymore).

    • Symen@lemmy.world
      link
      fedilink
      arrow-up
      1
      ·
      1 month ago

      Did you try to disable “Fast Startup” ?

      By default, Windows does not do a real shutdown anymore. It closes the user session and hibernates, to speed up the following start up. As a consequence, the Windows partition (and EFI partition ?) are not properly unmounted.

    • palordrolap@fedia.io
      link
      fedilink
      arrow-up
      1
      ·
      1 month ago

      If you have Windows, it might be worth getting it to run Scandisk - or whatever the current equivalent is - on that drive.

      That would at least give it less excuse to set problematic bits. In theory there’d be no harm doing this. In practice, well, make sure you have other copies of whatever is on that drive on the off-chance Windows constantly setting that bit is a sign of an underlying problem that Scandisk would make worse (or Windows/the disk decides to mangle files for some other reason.)

    • dual_sport_dork 🐧🗡️@lemmy.world
      link
      fedilink
      arrow-up
      12
      ·
      1 month ago

      95, and they disabled it circa Vista because it was obviously a stupid idea.

      Ironically, this was originally only for drives that reported themselves as optical media (CD/DVD), but now modern versions of Windows actually won’t autoplay an immutable commercially pressed CD, even if it has the correct autoplay.inf file on its root directory structure, but somehow it will autorun things on a flash drive which is a medium explicitly capable of being fucked with by a malicious actor.

      Because that makes sense.

      • LunchMoneyThief@links.hackliberty.org
        link
        fedilink
        English
        arrow-up
        5
        ·
        1 month ago

        It does make sense from the perspective of “destroy the public’s perception of ‘unsafe’ USB storage so that we can push them to use our ‘safe’ cloud storage (on our terms) instead”.

      • tomalley8342@lemmy.world
        link
        fedilink
        arrow-up
        2
        ·
        1 month ago

        That seems to be the opposite of what the others are saying: https://en.wikipedia.org/wiki/Autorun.inf#Inf_handling

        Windows 7, Windows 8, Windows 8.1, Windows 10

        For all drive types, except DRIVE_CDROM, the only keys available in the [autorun] section are label and icon. Any other keys in this section will be ignored. Thus only CD and DVD media types can specify an AutoRun task or affect double-click and right-click behaviour.[9][10]

        • dual_sport_dork 🐧🗡️@lemmy.world
          link
          fedilink
          arrow-up
          4
          ·
          1 month ago

          Malicious actors are getting USB drives to autorun somehow. If they’re not using built in Windows capabilities, they’re engaging in shenanigans emulating HID inputs over USB or something.

          All I know from personal experience is that modern Windows will not autorun a CD anymore, even though up until XP it would.

  • Nemo Wuming@lemmy.world
    link
    fedilink
    arrow-up
    5
    arrow-down
    5
    ·
    1 month ago

    I just checked a freshly installed Windows 11 and the autoplay is off by default.

    Were you trying to get upvotes just for the fun of it??

    • Boozilla@lemmy.worldOPM
      link
      fedilink
      English
      arrow-up
      3
      arrow-down
      4
      ·
      1 month ago

      First of all I believe you are incorrect.

      You’re doing a single anecdotal “test” from (I assume) one copy of the installation media. News flash, not all installation images of Windows 11 are the same.

      And I will answer your anecdotal evidence with some anecdotal evidence of my own: almost every friend and coworker I’ve asked about this says Autoplay is on. And when I check Google or ChatGPT, they confirm that a fresh install of Windows 11 will have it on by default. So…I guess everyone else is wrong about this but you’re right about every installation of Windows 11.

      Secondly, your question ignores the fact that people should probably check to see if it’s on. It can get turned on accidentally or even by an update. Microsoft is constantly messing arbitrarily with user preferences and settings with their weekly updates. You do know that, right?

      Finally, you posted some version of this same reply multiple times in this thread. Why? Are you just doing that to “get upvotes for fun”?

      BTW, there’s no karma on lemmy…upvotes don’t matter.

      It’s fine to correct someone, but first do a better job of checking your methodology, and second, don’t assume their motivations for trying to share helpful info.

      • Nemo Wuming@lemmy.world
        link
        fedilink
        arrow-up
        4
        arrow-down
        2
        ·
        1 month ago

        I checked two more computers after reading your reply (first time setups) and they all have autoplay off, so I remain skeptical of what you stated.

        There are so many trolls and misinformation floating around.

        As far as I have seen with those “fresh” installs, your information is not matching the reality here, so I’m moving on to other sources.

        • HatchetHaro@lemmy.blahaj.zone
          link
          fedilink
          arrow-up
          6
          ·
          1 month ago

          it could also be regional differences, since your checks are localized to your area, and OP’s his area. lots of software updates have incremental regional rollouts so i’m making a guess that that’s what’s happening, based on responses to this post.

          don’t automatically assume someone is “farming for points” when they post about something that doesn’t immediately apply to you. it may apply to you in the future.

          • Boozilla@lemmy.worldOPM
            link
            fedilink
            English
            arrow-up
            3
            ·
            1 month ago

            Thank you, this is the sort of thing I was trying to point out. And I love how he ignored all my other points just to focus on this one ISO or installer he’s using over and over again to “prove” that he’s right.

            Funny part is, I never said it was the default in the original post anyway. The whole point is, if it’s turned on, you may want to turn it off.

            • Nemo Wuming@lemmy.world
              link
              fedilink
              arrow-up
              1
              ·
              20 days ago

              Hello Boozilla, I had a couple weeks to reflect and I realize I overreacted . Sorry about that. Cheers to you.

        • Tenkard@lemmy.ml
          link
          fedilink
          arrow-up
          1
          ·
          1 month ago

          This was used as an attack vector more than 15 years ago,I can’t believe they re enabled it honestly. There was a virus on my school’s pcs which installed itself on the USB keys and people just went home and spread it everywhere without clicking on anything thanks to autoplay. Also “asked to chatgpt” lmao.