frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Ask HN: Running legacy IE/ActiveX clients without local admin rights?

1•Servant-of-Inos•1h ago
We are currently maintaining a very old client-server architecture. The server collects real-time data from a large number of sensors and controllers, transmitting it to a legacy database under continuous, massive load (writes every few seconds).

The problem is the client side. It’s ancient, strictly requires Internet Explorer, and heavily relies on ActiveX. If a standard domain user launches the browser, the data fails to load and the browser completely hangs. It only functions correctly if run with local administrator privileges.

Giving users local admin rights is a massive security risk we can't take. Currently, I have a workaround running in production using Task Scheduler to elevate just this specific application without giving the user the actual admin password. I documented the specific approach we are using here: https://www.hiddenobelisk.com/how-to-let-a-standard-domain-user-run-one-program-as-administrator-without-giving-admin-rights/#:~:text=least%20privilege.-,Approach%202%20%E2%80%94%20Running%20Applications%20with%20Administrative%20Privileges%20Using%20Task%20Scheduler,users%20can%20simply%20double%2Dclick%20the%20shortcut%20to%20launch%20the%20application.,-Changing%20the%20Shortcut

I recently started a thread over on r/sysadmin trying to find a cleaner solution: https://www.reddit.com/r/sysadmin/comments/1rm6uv4/how_do_you_let_a_standard_domain_user_run_one/

The general consensus there was to either buy an expensive enterprise PAM (Privileged Access Management) solution, or deep-dive with Procmon. I am currently analyzing the software with Procmon based on that advice, but so far, I haven't been able to make the client work without the Task Scheduler workaround.

My questions for the HN community:

1) Are there any reliable open-source PAM alternatives or privilege elevation tools for Windows that handle this "per-app" scenario effectively?

2) When dealing with hostile ActiveX components, are there specific legacy behaviors (beyond obvious file/registry Access Denied) I should be looking for in my Procmon captures?

3) How do you isolate this kind of hardcoded legacy requirement when there is zero budget for commercial enterprise tools?

Comments

stop50•26m ago
How much would it cost to rewrite the client tools as an intermediate solution and in the long term to replace the something that can withstand the load?

ULA again fails to launch a satellite; military transfers mission to SpaceX

https://arstechnica.com/space/2026/03/spacex-swipes-yet-another-military-contract-from-united-lau...
1•isaacfrond•1m ago•0 comments

Solving Impossible Problems for Fun and Profit – Dan Gelbart [video]

https://www.youtube.com/watch?v=UTgrWmOk4q8
1•nill0•1m ago•0 comments

Product Management on the AI Exponential

https://claude.com/blog/product-management-on-the-ai-exponential
2•tablet•6m ago•0 comments

Digs: Offline-first iOS app to browse your Discogs vinyl collection

https://lustin.fr/blog/building-digs/
2•rlustin•8m ago•0 comments

Dataframe 1.0.0.0

https://discourse.haskell.org/t/ann-dataframe-1-0-0-0/13834
1•internet_points•8m ago•0 comments

Ask HN: Are you using OpenClaw or similar agents? How?

2•nclin_•14m ago•1 comments

History of the Baumann Weltrecord

https://www.metmo.co.uk/pages/history-of-the-baumann-weltrecord
1•thunderbong•15m ago•0 comments

Ask HN: Growth for me,is realizing how much I didn't know 6 months ago. Yours?

1•kathir05•17m ago•0 comments

Pilot and co-pilot killed after Air Canada jet collision at LaGuardia New York

https://www.theguardian.com/us-news/2026/mar/23/air-canada-plane-collides-with-ground-vehicle-at-...
2•n1b0m•17m ago•0 comments

Police raid exposes YouTube "view farm" packed with phones

https://uk.news.yahoo.com/police-raid-exposes-secret-view-200051203.html
4•cft•22m ago•1 comments

MacBook Air M5 has newer wireless than the 14-inch MacBook Pro M5

https://www.apple.com/mac/compare/?modelList=MacBook-Air-M5,MacBook-Air-M5-15,MacBook-Pro-14-M5
2•dev_grex•23m ago•0 comments

A Geometric Solution for the Hubble Tension and Dark Matter(Open Source Physics)

https://github.com/robus4D/The-R4-Geometry-Manifest-The-Unity-of-Physics
1•Robus4D•24m ago•0 comments

BidWix – Fast fair way to agree on a price, from creator of myNoise.net

https://bidwix.com/
1•veltas•25m ago•1 comments

Cyber Security firm Cybereason open-sourced their Linux EDR agent

https://github.com/Cybereason-Public/owLSM
1•TheOpenSourcer•27m ago•1 comments

A Year of Multi-Model Assisted Development

https://fullhoffman.com/2026/03/22/on-a-year-of-multi-model-development/
1•adunk•28m ago•0 comments

Token Optimisation with LLMs

1•xoptions•28m ago•0 comments

Kardashev Scale

https://en.wikipedia.org/wiki/Kardashev_scale
1•tosh•32m ago•0 comments

A Tight Spot: Challenges Facing the Russian Oil Sector Through 2035

https://carnegieendowment.org/research/2026/03/russia-oil-situation-assessment
1•yread•34m ago•0 comments

Reddit considers Face ID to combat spam

https://www.engadget.com/social-media/reddit-is-weighing-identity-verification-methods-to-combat-...
1•smallnix•39m ago•1 comments

POSSE – Publish on your Own Site, Syndicate Elsewhere

https://indieweb.org/POSSE
45•tosh•40m ago•14 comments

Chopping my brain into bits – turning my brain into a 3D model on the web

https://srg.id.au/posts/brain/
2•lanakei•44m ago•0 comments

Show HN: The King Wen Permutation: [52, 10, 2]

https://gzw1987-bit.github.io/iching-math/
6•gezhengwen•48m ago•4 comments

Is possible a modern Linux without systemd? artix/dinit/labwc/noctalia

https://grigio.org/is-modern-linux-without-systemd-really-possible-artix-dinit-labwc-noctalia/
3•grigio•48m ago•1 comments

White-Collar AI Apocalypse Narrative Is Just Another Bullshit

https://martynasm.com/2026/03/22/white-collar-ai-apocalypse-narrative-is-just-another-bullshit/
9•mmiliauskas•53m ago•0 comments

VistAI–Save and Search AI Responses from ChatGPT, Claude, Gemini, and Perplexity

https://vistai.org
1•cbvinodvijay•59m ago•1 comments

Abstract Wikipedia

https://abstract.wikipedia.org/wiki/Abstract_Wikipedia:Main_page
3•abbe98•1h ago•0 comments

Random Numbers, Persian Code: A Mysterious Signal Transfixes Radio Sleuths

https://www.rferl.org/a/mystery-numbers-station-persian-signal-iran-war/33700659.html
2•austinallegro•1h ago•0 comments

AutoResearch by Karpathy and the Future of Autonomous AI Research

https://mljar.com/blog/autoresearch-karpathy-autonomous-ai-research/
1•pplonski86•1h ago•0 comments

Ask HN: How do you manage cloud access for your team without a VPN?

1•binoycyber•1h ago•1 comments

Airlines Are Preparing for an Oil Crisis

https://www.wired.com/story/united-airlines-jet-fuel-alarm-economy/
1•joozio•1h ago•0 comments