funsec mailing list archives

Windows 7's UAC is a broken mess; mend it or end it


From: Juha-Matti Laurio <juha-matti.laurio () netti fi>
Date: Sat, 7 Mar 2009 22:14:03 +0200 (EET)

"The changes Microsoft has made to Windows 7's UAC render it little more than a pesky annoyance.
If this is the path the company wishes to go down, it should stop doing things by halves and kill it off altogether.

By Peter Bright | Last updated March 4, 2009

I wrote a few weeks ago about changes Microsoft has made to Windows 7's User Account Control (UAC) that make the 
component less secure than it was in Vista.
Though the company has responded by saying it will change some of the problem behaviors,
yet more problems have emerged that indicate that a real fix will be harder than first expected.
But more than that, the flaws call into question the entire purpose of the Windows UAC feature,
at least in its commonplace "Admin Approval" mode."
--clip--

More at
http://arstechnica.com/microsoft/news/2009/03/opinion-ms-should-kill-win7-uac.ars

Juha-Matti
_______________________________________________
Fun and Misc security discussion for OT posts.
https://linuxbox.org/cgi-bin/mailman/listinfo/funsec
Note: funsec is a public and open mailing list.


Current thread: