Recommended Posts

Hello,

 

One concern I have not seen mentioned is how this would open up a new attack vector for Windows.  If Microsoft were to implement a "disable UAC on a per-program basis" type functionality in Microsoft Windows 8, it would mean that somewhere on the computer, the operating system would have to be storing what was allowed to bypass UAC in some kind of trusted application repository database.

 

Assuming such a database existed, it would rapidly become one of the most-studied entry points for malicious software authors, since finding a vulnerability in it would allow them to code exploits to bypassing your security.  Allowing programs to silently run with Administrator or SYSTEM privileges is not a good idea, and would set Windows security back by at least a decade.  The flip side to this is if the trusted application repository database was used to whitelist programs, why not also build in the functionality to blacklist them as well?  A malware author (or even just a disgruntled syadmin) might decide to use the database to block not just anti-malware software, but things like Windows updates, the base filtering engine, Windows firewall, and oter software that might be critical to securing your computer, or just run your business.

 

There are already technologies like AppLocker and Software Restriction Policies to control access to programs, and these work quite well, especially when combined with other tools like anti-malware software, EMET, encryption, software firewalls, and user account restrictions, to name a few.

 

On computers that I administer, I always turn up UAC to its highest level, not because it is a security boundary (it isn't) but because it alerts me when a program needs to perform operations that may affect the computer and its operating system, and I think that's something which is very important to know.  Of course, if you want to have a more insecure system, I don't judge, everyone has to make their own assessments of risk and trade-offs in security, but in this case, the idea of having a trusted application repository database on any system I am responsible for is something I would not want to see.

 

Regards,

 

Aryeh Goretsky

What a stupid thing to say. You can't defend your machine yourself!

 

What happens when you visit a website that has some drive-by malware which your anti-virus software doesn't pick up?

Perhaps you can't... but I certainly can, as witnessed by the fact that I have never had a virus... Please, do not assume that your level of competence is all there is.

Only tasks that require Administrator rights will trigger UAC. If is program triggering UAC prompt even when doing basic tasks there is some issue with the program.

 

Some older applications are a bit funny with UAC as well. The Steam edition of Mass Effect for example will crash if you're on a UAC enabled system and don't run Steam as an administrator the first time you launch Mass Effect.

Some older applications are a bit funny with UAC as well. The Steam edition of Mass Effect for example will crash if you're on a UAC enabled system and don't run Steam as an administrator the first time you launch Mass Effect.

 

Depends where Steam is installed, and thus where your games are.  If you're in program files.. then yes UAC comes into play - I have steam on it's own partition which isn't covered by UAC, so no prompts (aside from initial set-up for C drive stuff - e.g. run-times) when playing.  Regardless the fault there is mass effect for not being compliant (but then it's old).

 

Personally I agree with UAC - I'm a developer and I leave it on, all the time, on all my systems work and home.  I don't find it annoying since I understand it's purpose (despite the pain of making sure our own software was compliant with it when Vista arrived).    Nor do I think that just because I haven't been hit by a bus I never will (ze I must have ze control of all my funktions argument).  Weird thinking, but your choice(s).  OTOH I like having a method for elevation - and thus a way of being a 'non root' user when just doing my everyday work/play/surfing.  In truth i'm rarely prompted outside of installation.

 

I'm also really happy that my parents (once trained lol) actually think about that blacked out screen and UAC request rather than installing everything on God's own and killing their machine.  They'll click 'no' if unsure or if they can't ask me - instant 99% reduction in phone support.  Wicked.

This topic is now closed to further replies.
  • Posts

    • I have a couple to mention, and they still run great on Windows 11 Adobe Lightroom Version 2 Alcohol 120% CLZ Book, Comic, Game, Movie, & Music Collector (PC - No longer sold / Grandfathered in - now mobile apps/online only) DVDDecrypter ISO Buster Pro version 1.9.1 (Still supports HD-DVD too) Nero Burning Rom 8 (Only the burning software, no backup, media converter, etc)   OpenAL (Runtime) PowerDVD 12 Ultra SPTD (SCSI Pass through Direct Driver) UltraISO Windows Media Encoder 9 WinImage You can tell I still sport an optical drive    
    • Linux 7.1 arrives with an NTFS overhaul and major hardware performance boosts by Paul Hill The founder of the Linux kernel has just announced the availability of Linux 7.1. This is a stable version of the kernel that will now be tested by various Linux distributions before it is shipped to users through update managers. Some users, like those on Debian, for example, might not get it for a long time, if at all, while Fedora users can expect it in the near future. With Linux 7.1 out on time, the merge window for Linux 7.2 is now open, giving contributors the opportunity to send in major new features that have been waiting for the last two months. Torvalds warned that he is currently travelling and will be in another timezone, so timing for the merge window may be irregular due to timezone differences and limited internet access. Torvalds said that he has already fetched early pull requests to allow him to do some offline work, but the travel could still cause disruption. Right now, he is not planning to extend the release, but did consider it. He said he might later regret not extending, though. In terms of this last week of development for Linux 7.1, Torvalds said there were no major or alarming changes. This week consisted mostly of smaller driver updates to GPU, networking, and sound, networking fixes, trace tooling fixes, and misc minor fixes. The shortlog this week lists fixes for driver bugs, memory leaks, I/O and USB fixes, networking and RDMA fixes, DRM/graphics fixes, and tooling and verification improvements. Specific fixes include USB series heap-overflow and buffer overflow fixes, and multiple use-after-free, memory-leak, and refcount corrections across subsystems such as i2c, zram, gpio, and net. There are fixes for graphics drivers, including amdgpu, i915, and virtio, as well as hypervisor and virtualization tweaks affecting mshv, vmbus, and hyperv. According to Phoronix, anyone running Linux 7.1 should look out for the new NTFS driver, Intel FRED for improved performance on Panther Lake and future CPUs, faster graphics with Intel Arc Battlemage, and improvements for older AMD Radeon GPUs. If you are running Linux on your computer and everything is fine, then you don’t need to worry about updating to Linux 7.1 as a priority; just wait for it to be pushed to you. If you have tried Linux on hardware but it didn’t work properly, trying again with a distro that uses Linux 7.1 could cause Linux to work on your machine, thanks to the new hardware support.
    • you can also do this with this tool: PowerSettingsExplorer made by mbk1969 at 3dguru forum.. I found it by accident researching on modern standby and annoying quirks of it in 2022
    • AB Download Manager 1.9.1 by Razvan Serea AB Download Manager is an open-source, feature-rich download manager designed to accelerate downloads, organize files efficiently, and provide seamless control over downloads. With support for multiple connections, resume capability, and an intuitive interface, it enhances the downloading experience for users seeking speed and reliability. The software integrates with various browsers, enabling quick link grabbing and batch downloading. It supports HTTP, HTTPS, and FTP protocols, ensuring broad compatibility with different file sources. Users can schedule downloads, set speed limits, and categorize files automatically for better organization. AB Download Manager is lightweight yet powerful, making it a great alternative to proprietary download managers. Its open-source nature allows developers to contribute, customize, and improve the software as needed. Whether you're downloading large files, managing multiple downloads at once, or seeking an ad-free experience, this tool offers a practical and efficient solution. Key features of AB Download Manager: Multi-Connection Support – Accelerates downloads by splitting files into multiple segments. Resume Capability – Allows paused or interrupted downloads to be resumed without starting over. Batch Downloading – Supports downloading multiple files at once for improved efficiency. Browser Integration – Captures download links directly from browsers for seamless operation. HTTP, HTTPS, and FTP Support – Ensures compatibility with a wide range of file sources. Download Scheduling – Enables users to automate downloads at specific times. Speed Limiting – Lets users control bandwidth usage for optimized performance. File Categorization – Automatically organizes downloaded files into designated folders. User-Friendly Interface – Simple and intuitive design for easy navigation. Cross-Platform Compatibility – Works on multiple operating systems. Ad-Free Experience – No intrusive ads or tracking for a clean user experience. AB Download Manager 1.9.1 changelog: Added An option to customize notification sounds (#1259) Fixed Ongoing notification was laggy on Samsung One UI devices (#1269) Improved Updated Translations Minor UI/UX improvements Download: AB Download Manager 1.9.1 | Portable | ~80.0 MB (Open Source) Download: ARM64 | Portable ARM64 | Android Links: AB Download Manager Website | Github Page | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • watching him because of the Mr Klinton cat
  • Recent Achievements

    • Week One Done
      rolfus earned a badge
      Week One Done
    • One Month Later
      Leroy Jethro Gibbs earned a badge
      One Month Later
    • Conversation Starter
      flexorcist earned a badge
      Conversation Starter
    • One Month Later
      AndreaB earned a badge
      One Month Later
    • One Month Later
      agatameier earned a badge
      One Month Later
  • Popular Contributors

    1. 1
      +primortal
      507
    2. 2
      +Edouard
      196
    3. 3
      PsYcHoKiLLa
      139
    4. 4
      ATLien_0
      90
    5. 5
      Steven P.
      81
  • Tell a friend

    Love Neowin? Tell a friend!