The Great UAC Debate!


UAC  

1412 members have voted

  1. 1. Do You Use UAC?

    • Yes
      477
    • Yes, On "Silent Mode"
      91
    • No (I use an Admin Account)
      496
    • No (I use a Standard Account)
      39
    • I don't use Windows Vista
      118
  2. 2. Have You Ever Been Saved By UAC?

    • Yes
      226
    • No
      932
    • I don't use Windows Vista
      106


Recommended Posts

  • 1 month later...

UAC is the first thing i disable on every Vista system i setup... UAC is a royal pain in the *SS, and most of my clients absolutely hate UAC, because it constantly nags/annoys the user about the most trivial activities. UAC just gets in the way of getting real work done.

UAC is not a feature, it's a bug, and if microsoft was serious about securing the OS, then they would never have hacked together a crappy/half-assed/stop-gap measure like UAC.

UAC is the first thing i disable on every Vista system i setup... UAC is a royal pain in the *SS, and most of my clients absolutely hate UAC, because it constantly nags/annoys the user about the most trivial activities. UAC just gets in the way of getting real work done.

UAC is not a feature, it's a bug, and if microsoft was serious about securing the OS, then they would never have hacked together a crappy/half-assed/stop-gap measure like UAC.

Wow, I seriously pity any client you have, if that's the best you can come up with. Do us a favor and get out of the field before you do any more damage.

Ok, I'm not claiming to be an expert.

But let us say i follow the turn UAC off camp,

What's the worst that could happen considering the arguments for and against, i end up giving malware admin access that wasn't intended as mentioned above.

Now considering I don't turn it off,

I'm annoyed daily when I'm renaming files editing ini files in program files(which i now know i can find in the virtual store thanks topic :D).

considering the two worst scenario outcomes I can tell you I personally would rather be "Protected" and annoyed.

Edit: Wow 26 pages, I think this thread has gotten way too big, and i only read until page 9, and even rorm the first 3 pages just saw people repeating themselves, reckon the facts from this topic just need to be pinned, and then locked,

but its not my place to back seat mod....

Edited by ryan_the_leach

UAC in Vista was horrible, but since I moved to Windows 7, i have it turned on default settings - I only see it when a program needs to elevate itself, which hardly ever happens - and it saved my ass a couple of times too, the icon overlay usually gives you a heads up, when an app is not supposed to make use of the administrator privileges. A great thing!

  • 1 month later...

I like UAC. I run as a standard user and my Admin account has a password. Despite all of that you never know when something might get through, so UAC is turned on, just in case. It is slightly annoying but not nearly as annoying as many make it out to be.

As I stated in another thread I need an AV because all the systems at one of my client's office are infected and I have to connect my USB drive there to exchange data, I also bring back viruses/malware from there and for me the combination of Norton AV 2009 and UAC is golden.. no infections so far since I started using these 2.. UAC doesn't let the exe files run without consent and NAV cleans them off. I feel almost nothing can sneak through and infect me system (Y)

Sigh... when will that crap die.

It's a non-issue. UAC in Win7 works as intended and should be left at the default setting for most users (the UAC settings dialog explains which option you should use based on your usage habits).

Is it better to run as a standard user and elevate as necessary? I'll be reinstalling 7 when the final comes out so I'll switch to doing that if there is a genuine benefit over running as admin at max UAC settings.

The most secure thing you can do is to run as a standard user, and use Fast User Switching to switch to an administrator account for admin tasks.

A step down from that is to use OTS (Over The Shoulder) elevation, where you run as a standard user but run admin tools as an Administrator on the same desktop. To make this safer you'll want to turn on the option that requires a Ctrl+Alt+Del press before elevating, since you'll have to type a password, and you want to make sure the dialog isn't being spoofed. However, this is not a security boundary because non-admin and admin apps are sharing the same desktop.

A step down from that is UAC at the maximum setting. This is much easier to live with because you don't need to enter a password (and don't need the C+A+D press to protect from spoofing) and the apps still run with your user profile and such. Again this is not considered a security boundary because non-admin and admin apps share the same desktop.

-- The above two options are safest at times when there are no admin apps are running --

A small step down from that is the default Win7 configuration where you aren't prompted for changes to Windows settings. This reduces the barrier between non-admin and admin applications, but maintains the same barrier between protected applications (like the IE Protected Mode and Chrome sandboxes) and normal applications.

There's another notch below that where the secure desktop switch is not enabled, opening up the possibility that someone could tamper with the consent dialog.

Below that is disabling UAC entirely. This is a very bad idea because it removes the "low integrity" option used for things like IE's Protected Mode and Chrome's sandbox. That is a very important and useful security feature for mitigating the impact of exploits against the most common attack surfaces.

Across these options you have trade-offs between safety and useability. The default option is meant to provide the best balance for most users.

A step down from that is UAC at the maximum setting. This is much easier to live with because you don't need to enter a password (and don't need the C+A+D press to protect from spoofing) and the apps still run with your user profile and such.

that's right and this way it was done in Vista.

Again this is not considered a security boundary because non-admin and admin apps share the same desktop.

Yes it it. The IL levels prevent you from attacking an admin app from a non-admin app.

Across these options you have trade-offs between safety and useability. The default option is meant to provide the best balance for most users.

no, it only opens a security whole which can be used very easy run apps with admin rights without accepting the UAC prompt. If Average Joe got a mail with a link to get a free cool game and the chance to win a few bucks he will download the tool and try to run it. Under Vista UAC prompt was shown and this unsettles him and de doesn't accept it. With Win7 the apps can use the Explorer, DWM or several other MS apps to bypass the UAC prompt and still get admin rights.

And this is WRONG!

The IL levels prevent you from attacking an admin app from a non-admin app.

No, this is not the purpose of IL levels (in every Windows NT version any admin app can't be attacked by a non-admin app). The purpose of IL levels is preventing an app1 to attack another app2 which runs with the same privileges of app1 i.e. app1 and app2 are running with the same privileges but different integrity levels.

Edited by jamesVault
  • 2 months later...
I'm hoping future versions will not have an option to disable UAC, any insider info on that possibility?

That should NOT happen. People should have the ability to customize they're computer, I personally don't like **** popping up whenever I click to run programs, it happens everytime firefox starts up, some java **** or something.

That should NOT happen. People should have the ability to customize they're computer, I personally don't like **** popping up whenever I click to run programs, it happens everytime firefox starts up, some java **** or something.

It should have happened in Windows 7. Microsoft should have hard coded UAC at default with NO way to change it period. I have never ever had a UAC prompt for Firefox ever if you are getting them you have something on your end.

  • 6 months later...
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • If it ain't broke, don't fix it. One Commander Free also available in the Store has been my goto Files Manager for years. It does what I need at a more than reasonable speed. I do occasionally use Files Explorer just because it is there and does what I need without any problems when I use it.
    • I think you missed his point. He wasn't saying that cloud storage isn't possible on GNU/Linux, clearly it is. He was pointing out that you are commenting about your dislike of Windows on an article about OneDrive (not Windows) for Mac (also not Windows). Its about as off topic as coming to an article about Sony improving something on the PlayStation and saying that you hate Sony TVs and prefer LG.
    • Nvidia's GeForce NOW summer sale drops prices for Ultimate and Premium memberships by Pulasthi Ariyasinghe Nvidia has a fresh update for GeForce NOW subscribers today, bringing in more games to add to its ever-growing supported titles list. At the same time, the company announced the kick-off for its summer sale for the streaming subscription service, dropping the prices for both its premium packages for anyone looking to upgrade or join. The offer is for the 12-month membership options that the company offers. This drops the 12-month Performance membership from $99.99 to $64.99, saving members $35. Next, the 12-month Ultimate membership is currently going for $129.99, dropping prices by $70 from the original $199.99. "The Performance membership delivers smooth, high-quality cloud gaming across devices, with streaming up to 1080p at 60 frames per second (fps) and access to RTX-powered servers for supported games," says Nvidia, describing its tiers. "The Ultimate membership steps things up with RTX 4080‑ or 5080‑class performance in the cloud, supporting up to 4K and beyond on ultrawide displays, up to 120 fps, and advanced features like ray tracing, NVIDIA DLSS and NVIDIA Reflex for a more responsive, visually rich experience." With the sales out of the way, here are the games joining GeForce NOW's supported list this week: NBA THE RUN (New release on Steam, available on June 9) Witchspire (New release on Steam, available on June 10) SpaceCraft (New release on Steam, available on June 11) Duet Night Abyss (Launcher) DOOM Eternal (Epic Games Store) The Elder Scrolls Online (Xbox, available on Game Pass) Farever (Steam) World of Tanks: HEAT (Wargaming) Nvidia plans to add support for a bunch of more games during the rest of June. Find the full announcement from last week over here. Keep in mind that, unlike subscription services like Game Pass or EA Play, a copy of a game must be owned by the GeForce NOW member (or at least have a license via PC Game Pass) to start playing via Nvidia's cloud servers. There is also a limit to how many hours subscribers can use the service per month.
    • It's actually shocking how logs filling disks has been a constant issue going back for decades, yet we see very little improvement over the years. Even in the server world, its actually shockingly common for a server to either go totally down, or have a critical alert raised due to logs filling disks.
    • YouTube has finally brought back its DMs feature, but only in these countries by David Uzondu Late last year, YouTube started testing a "new" way to share videos directly with friends, without having to leave the app. Now, the video giant has announced that is now rolling out a revamped direct messaging inbox, which lets you share videos, Shorts, and live streams and have conversations about them, directly on YouTube. The platform limits this feature to 18+ users who are signed in to a verified channel and use the latest mobile app version. Direct messaging on YouTube first became a thing back in 2017 inside the mobile app (later renamed to "Messages"), where users could chat one-on-one and share clips directly, but all that came to an end on September 18, 2019, when Google decided to shut it down after giving users a month to download a .zip file archive of their past chats. No one really knows why YouTube killed the feature, but users were encouraged to migrate to the public Comments section, on Community tab posts, and via YouTube Stories. The previous incarnation suffered from moderation challenges, prompting Google to implement stricter safety guidelines and age verifications for this new iteration. Here's a list of the countries where the re-launched feature is currently available, though note that Brand Accounts do not have access to it, at least for now: Countries American Samoa Austria Belgium Brazil Bulgaria Croatia Cyprus Czech Republic Denmark Estonia Finland France Germany Greece Guam Hungary Iceland Ireland Italy Latvia Liechtenstein Lithuania Luxembourg Malta Netherlands Northern Mariana Islands Norway Poland Portugal Puerto Rico Romania Singapore Slovakia Slovenia Spain Sweden Switzerland U.S. Virgin Islands United Kingdom United States Before you can use the feature, you first have to send an invite link to your contact. Invite links expire exactly seven days after you create them. If the person on the other end accepts the invite, you can exchange videos directly and text back and forth inside the app. To delete a message, just long-press on the message and tap unsend to remove it for both users. You can also delete entire conversations by long-pressing the thread and selecting delete, but the other person will continue to see the chat history on their end. To make sure everything remains safe, YouTube monitors these messages to ensure they follow Community Guidelines.
  • Recent Achievements

    • One Month Later
      Tommi118 earned a badge
      One Month Later
    • One Month Later
      sjbousquet earned a badge
      One Month Later
    • Week One Done
      sjbousquet earned a badge
      Week One Done
    • First Post
      DragonOfMercy earned a badge
      First Post
    • First Post
      bella52 earned a badge
      First Post
  • Popular Contributors

    1. 1
      +primortal
      501
    2. 2
      PsYcHoKiLLa
      208
    3. 3
      +Edouard
      155
    4. 4
      Steven P.
      83
    5. 5
      FloatingFatMan
      73
  • Tell a friend

    Love Neowin? Tell a friend!