nether one of these are that big of a deal the attack vector
on both is local some one has to have physical access there is no way to lock down a computer from physical access
M$ has been trying to do this for 30+ years and has made a mess of there O\S in the effort
|