Question Don't entirely trust company that built my workstation. How can i be confident in security

May 12, 2023
19
8
15
Morning All.

I've had a company build a custom workstation for me and it should arrive with windows 11. It includes a "System Recovery Secure Drive Partition + Bootable USB Recovery". They haven't done anything specific to make me think they are malicious, but I believe one of the people building the machine has been convicted of mail fraud in the past. I don't have a lot of trust for him and I'm trying to approach this thoughtfully and responsibly.

Considering my limited knowledge in matters like this:

1) What steps would you recommend to ensure there isn't any keyloggers, or anything malicious embedded in the system? Do I need to consider a virus in the bios?

2) Will Malwarebytes and Windows Defender be sufficient?

Any input appreciated. Thank you!
 

kanewolf

Titan
Moderator
Morning All.

I've had a company build a custom workstation for me and it should arrive with windows 11. It includes a "System Recovery Secure Drive Partition + Bootable USB Recovery". They haven't done anything specific to make me think they are malicious, but I believe one of the people building the machine has been convicted of mail fraud in the past. I don't have a lot of trust for him and I'm trying to approach this thoughtfully and responsibly.

Considering my limited knowledge in matters like this:

1) What steps would you recommend to ensure there isn't any keyloggers, or anything malicious embedded in the system? Do I need to consider a virus in the bios?

2) Will Malwarebytes and Windows Defender be sufficient?

Any input appreciated. Thank you!
Bring this issue up with the owner of the company.
Cancel the order.
Download a copy of Windows installer from MS website and do a clean install.
 
May 12, 2023
19
8
15
Bring this issue up with the owner of the company.
Cancel the order.
Download a copy of Windows installer from MS website and do a clean install.
yeah, I've considered bringing up my concerns. I also do support people getting second chances, so I'm inclined to give him the benefit of the doubt. appreciate the input.
 
  • Like
Reactions: PEnns
Morning All.

I've had a company build a custom workstation for me and it should arrive with windows 11. It includes a "System Recovery Secure Drive Partition + Bootable USB Recovery". They haven't done anything specific to make me think they are malicious, but I believe one of the people building the machine has been convicted of mail fraud in the past. I don't have a lot of trust for him and I'm trying to approach this thoughtfully and responsibly.

Considering my limited knowledge in matters like this:

1) What steps would you recommend to ensure there isn't any keyloggers, or anything malicious embedded in the system? Do I need to consider a virus in the bios?

2) Will Malwarebytes and Windows Defender be sufficient?

Any input appreciated. Thank you!
If it's just one person who did mail fraud working at some independent computer outlet, then I wouldn't suspect they'd have the technical know-how to create a honeypot system.

And if I had a strong suspicion of them giving me a compromised system, I'd cancel the order or send it back. I can't assume the attacker if they really wanted to spend their time creating compromised systems would make said systems easy enough to clean.

So sure, while you can do a clean reinstall of Windows or update the BIOS with images from known good sources, that doesn't mean the system is clean.

But at the same time, anyone with that much technical skill and knowledge I don't think would be wasting time in a small volume outlet.