The Great UAC Debate!


UAC  

1412 members have voted

  1. 1. Do You Use UAC?

    • Yes
      477
    • Yes, On "Silent Mode"
      91
    • No (I use an Admin Account)
      496
    • No (I use a Standard Account)
      39
    • I don't use Windows Vista
      118
  2. 2. Have You Ever Been Saved By UAC?

    • Yes
      226
    • No
      932
    • I don't use Windows Vista
      106


Recommended Posts

It's pretty frustrating when people like you advise others to disable UAC when you don't even understand how it works, or what it's for.

I understand the frustration but I don't want a security advisor asking me what to do. When I give my computer orders, it is to obey them without questions. For example if I want Word on my screen, I want it on my screen, no questions asked.

UAC will not protect 100% because many people are known to be "trigger" happy and will click Yes to every box they get. This will become very common. I know because you remember the IE security warning dialog boxes? Yeah UAC is like that but systemwide. I remember many computers was ridden with spyware and viruses becuse people click Yes to all Security Warning dialogs that disguse the real purpose (to install spyware and viruses disgused as addons or updates).

It's user common sense that play a large role in protecting the computer system from threats.

I understand the frustration but I don't want a security advisor asking me what to do. When I give my computer orders, it is to obey them without questions. For example if I want Word on my screen, I want it on my screen, no questions asked.

UAC will not protect 100% because many people are known to be "trigger" happy and will click Yes to every box they get. This will become very common. I know because you remember the IE security warning dialog boxes? Yeah UAC is like that but systemwide. I remember many computers was ridden with spyware and viruses becuse people click Yes to all Security Warning dialogs that disguse the real purpose (to install spyware and viruses disgused as addons or updates).

It's user common sense that play a large role in protecting the computer system from threats.

Sigh.

UAC can protect you without showing you a single prompt. In fact, that's actually when it's protecting you.

Let's say you launch Word. It is never going to launch itself with Administrative privileges, so it will always be running without access to any element of your filesystem that requires "Administrator" access. Let's say you got an email from a friend, but unbeknownst to you, a crafty little bit of malformed data managed to slip into that document, allowing for arbitrary code execution. Because Word does not have Administrative access to your PC, the amount of damage it can do it very limitted compared to if you had UAC turned off.

Or let's say it's some 0-day exploit in Firefox's JPEG image handler, and you're browsing neowin. The exact same thing as the Word scenario I posed above can happen.

Or even better, let's say you're using IE7. Because the IE process runs with a Low IL, it can't even touch your documents, put a file on your desktop, drop a link in your user startup folder. It just can't do it because the IE process has virtually no real access to your computer. It only can write to the LocalLow folder, where your temporary internet files folder is, and that's going to generally be useless for any exploit's purposes.

UAC is not about second guessing what you're trying to do. What it will do, however, is prevent the machine from automatically allowing a process to spawn another process with greater access to the machine than the original process had. It's simply a tool for controlling how much access to your machine a given process gets when it's launched.

Want a real world example? The ANI exploit was stopped in it's tracks by UAC in many cases.

And that's not even all that UAC does. It also allows for virtualization of the filesystem and registry, to help legacy apps work, and further protect the system by on occasion tricking apps into believing they successfully made changes to areas of the system that they did not have access to, but in actuality storing those changes to an area that only these apps can see.

Edited by MioTheGreat

There's only one reason why I have to turn off UAC, and that is fact that all of the software I develop requires admin permissions, so they bring up a UAC dialog.

- InfoBar freezes without admin permissions due to the possibility that one of it's modules cannot function without them.

- NeoCleaner obviously needs admin privs because it searches for, and deletes, files anywhere on any hard drive that meet certain criteria.

The one thing I really, really, really wish was implemented was a way to check a box and say "Run this application every time with admin privileges." That way apps will run at startup and when I manually start them, without UAC prompts. I think it would be a feature that would make people that turn UAC off happy.

Everywhere here I see people saying that UAC is "great", there is "no reason" to turn it off. Personally I would never use it, but I leave this on for my brother. He always agree with anything that comes up, so there is no point anyway. I guess his antivirus keep he save, so - again - there is no point to UAC.

Has you ever been saved by it? Ever saw the confirmation dialog when you wasn't expecting and actually clicked "cancel"?

No. The information given for some installers is just cryptic and doesn't reflect what the program is, meaning that I often have to allow it even if I'm unsure of the application. That means I could be accepting some random installer that is piggybacking off another application. I like the idea but it becomes so common you don't even look at what is says.

Having said that I haven't disabled it at the moment. I might do at a later stage.

Here is what I think about UAC...

In Vista, when I am doing a fresh, clean install of Vista, I will disable UAC so I can go on installing all my software. Afterwards, I will then turn on UAC for security reasons, and security reasons only.

Here's a little tip: you can try executing your installers from an elevated command prompt window, so you don't actually have to turn it off.

UAC is about as useful as **** on a pump handle

but some people really need this when their mommy and daddy isn't around to ask them if they really 'want to do something'

:wacko:

That's not at all why we have UAC, and it's really terrible to post that kind of stuff, since it's flat out wrong, and people who don't know any better actually come here for advice.

You're at the 'just enough knowledge to be dangerous' level, I believe. You understand how to turn UAC off, and since you don't understand its purpose, you're going to go ahead and do it, because you don't know any better.

Here's why what you just said about hand holding is flat out wrong:

https://www.neowin.net/forum/index.php?show...amp;p=589146941

Edited by Frank
:wacko:

That's not at all why we have UAC, and it's really terrible to post that kind of stuff, since it's flat out wrong, and people who don't know any better actually come here for advice.

You're at the 'just enough knowledge to be dangerous' level, I believe. You understand how to turn UAC off, and since you don't understand its purpose, you're going to go ahead and do it, because you don't know any better.

Here's why what you just said about hand holding is flat out wrong:

https://www.neowin.net/forum/index.php?show...amp;p=589146941

QFT.

UAC doesn't come up very often after the initial installing of software on a fresh install anyway. I have had no problems with it.

Mine is on and it is useful... especially when visiting pron sites :p. I would be browsing a site and UAC would randomly come on asking if this program can be installed. Its obvious that its spyware/worm/virus therefore I cancel.

it is a very nice feature ... but with my PC it's off because some old game can't run with it ^^; ... full screen issues ... but I really like the UAC and I plan to turn it on again :)

but for my family's PCs ... it is a MUST :) ... really saved me from a lot of pain :) ...

i have mine on,if the prompts bother me i use tweakuac to keep it on while having the prompts off,uac is really useful as it helps to protect ie even if you dont use it now thats what i call real immunization.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • YouTube has finally brought back its DMs feature, but only in these countries by David Uzondu Late last year, YouTube started testing a "new" way to share videos directly with friends, without having to leave the app. Now, the video giant has announced that is now rolling out a revamped direct messaging inbox, which lets you share videos, Shorts, and live streams and have conversations about them, directly on YouTube. The platform limits this feature to 18+ users who are signed in to a verified channel and use the latest mobile app version. Direct messaging on YouTube first became a thing back in 2017 inside the mobile app (later renamed to "Messages"), where users could chat one-on-one and share clips directly, but all that came to an end on September 18, 2019, when Google decided to shut it down after giving users a month to download a .zip file archive of their past chats. No one really knows why YouTube killed the feature, but users were encouraged to migrate to the public Comments section, on Community tab posts, and via YouTube Stories. The previous incarnation suffered from moderation challenges, prompting Google to implement stricter safety guidelines and age verifications for this new iteration. Here's a list of the countries where the re-launched feature is currently available, though note that Brand Accounts do not have access to it, at least for now: Countries American Samoa Austria Belgium Brazil Bulgaria Croatia Cyprus Czech Republic Denmark Estonia Finland France Germany Greece Guam Hungary Iceland Ireland Italy Latvia Liechtenstein Lithuania Luxembourg Malta Netherlands Northern Mariana Islands Norway Poland Portugal Puerto Rico Romania Singapore Slovakia Slovenia Spain Sweden Switzerland U.S. Virgin Islands United Kingdom United States Before you can use the feature, you first have to send an invite link to your contact. Invite links expire exactly seven days after you create them. If the person on the other end accepts the invite, you can exchange videos directly and text back and forth inside the app. To delete a message, just long-press on the message and tap unsend to remove it for both users. You can also delete entire conversations by long-pressing the thread and selecting delete, but the other person will continue to see the chat history on their end. To make sure everything remains safe, YouTube monitors these messages to ensure they follow Community Guidelines.
    • The problem of course is simply that government does not always know best. My point is that agency is taken away from the EU consumer in these cases. I'm sorry, but I do not believe that governments (politicians) are inherently good, and "looking out for me." Primarily they look to themselves and their own personal desires first, foremost, and always. When the EU or the DOJ fines these companies, claiming to "represent the welfare of the consumer," how much of these billion-dollar judgments are handed to the consumers they claim to represent? Not even a dollar, as I've seen. Yet the EUC lawyers who are paid to sit around and dream up these suits make huge commissions on the fines the EUC adjudicates, which is an ironclad fact I hope everyone is aware of. It's also rank corruption, of course, but that's another topic. Last, when the EU inflicts these judgments, or the DOJ, take your pick, the costs are bundled right along in the cost of the goods and services these companies provide the consumers they are "looking out for." If you are someone who believes his government is his savior then you have my condolences. I think Apple is right here, because the whole scheme of consumer choice is that consumers pick and choose among the products companies offer. Microsoft Windows is more compatible with third party software and hardware than any desktop OS on Earth, which is my sole reason for choosing it. Just because the EUC forces companies do certain things it knows the companies do not want to do, "or else", has no bearing on consumer benefit. This Siri thing is almost idiotic it's so infantile. But this is what the EUC does when the EU in Brussels becomes cash-strapped and needs a big infusion of cash. Some people get upset by "big companies" but it's the opposite when governments dwarf the size and scope of these companies, which is so obvious it hurts.... I mean you can't honestly believe that forcing Apple to do things with Siri it has its own reasons to decline is something that "opens up" Apple, do you? Say it aint' so...
    • Looks like many years since the request was made, a directory tree view finally may be added. https://github.com/files-community/Files/pull/18537
    • Is it still super slow or has it improved on that area?
    • There's this from last year https://gist.github.com/threat...364659a8887841aa43deca4efd9 but nothing about a buffer overflow that MS somehow can't code against. No matter what, it makes sense to take a "protected by default" approach.
  • Recent Achievements

    • One Month Later
      sjbousquet earned a badge
      One Month Later
    • Week One Done
      sjbousquet earned a badge
      Week One Done
    • First Post
      DragonOfMercy earned a badge
      First Post
    • First Post
      bella52 earned a badge
      First Post
    • Reacting Well
      Techinmay earned a badge
      Reacting Well
  • Popular Contributors

    1. 1
      +primortal
      501
    2. 2
      PsYcHoKiLLa
      214
    3. 3
      +Edouard
      156
    4. 4
      Steven P.
      84
    5. 5
      FloatingFatMan
      73
  • Tell a friend

    Love Neowin? Tell a friend!