I will not buy Windows 7 unless it has ... *Feature*


Recommended Posts

That would be a horrible idea.

How so?

I mean, a higher percentage of users have as their main OS WinXP. Are people really that stupid that they're going to buy a new OS based on a product they didn't like?

Is like trying to build a brand new car based on the Gremlin (I'm exagerating but it makes my point a lot easier to see ;))

As far as I know, VSC only does byte level changes of the original? How would that fare as a real backup solution if the original drive/file fails or gets corrupted? How does one set an interval for backing up?

Other things I'm not sure about? Does VSC work through actual applications rather than just Explorer for restoring mail, contacts, or photos? (Live Mail, Windows Contacts, Photo Gallery)

VSC does only record byte level backups, and only on the same volume, as far as i know. However, Vista (don't remember which editions but im assuming at least all of them that ship with VSC) also ships with the backup and restore center which allows you to backup to external HDs, etc which does what you are asking.

VSC also can be accessed through other programs. WPG/WLPG uses it to track changes you make to photos, for example.

How so?

I mean, a higher percentage of users have as their main OS WinXP. Are people really that stupid that they're going to buy a new OS based on a product they didn't like?

Is like trying to build a brand new car based on the Gremlin (I'm exagerating but it makes my point a lot easier to see ;))

Because Vista is, architecturally, much more stable and secure than XP could ever hope to be.

Vista is a significantly greater stepping stone for a future OS than XP. It doesn't matter what people do or do not like, the fact is that XP is a last generation operating system, and between the massive driver model, security, etc. changes to Windows, it'd be too much work to make a modern OS out of XP (And you'd just end up with Vista, anyway.)

Also, given that everything in Vista has had time to mature (WDDM, for instance), 7 should be great.

How so?

I mean, a higher percentage of users have as their main OS WinXP. Are people really that stupid that they're going to buy a new OS based on a product they didn't like?

Is like trying to build a brand new car based on the Gremlin (I'm exagerating but it makes my point a lot easier to see ;))

The reason it doesn't make any sense is that the possible thousands of people that complain about Vista in no way equal the millions that are using it without complaint. :)

How so?

I mean, a higher percentage of users have as their main OS WinXP. Are people really that stupid that they're going to buy a new OS based on a product they didn't like?

Is like trying to build a brand new car based on the Gremlin (I'm exagerating but it makes my point a lot easier to see ;) )

It's a horrible idea because Vista is built on Windows Server 2003, a much different and better kernel than Windows XP, which was built mainly from Windows 2000. "Vista" is largely just a GUI built on top of Windows Server 2003, and therefore, Windows 7 could theoretically look exactly like Windows XP, and yet still have the better kernel. And this is why basing anything on WinXP is a horrible idea. Because any new product will continue to suffer from the major security exploits and instability that plagues Windows XP even with SP3.

And as stated above, millions use Vista with no complaints. It's only a very small minority that complains on the Internet, and more often than that, the complainers have no clue what they're talking about. Microsoft bashing has become a big trend in the past couple years.

That is what Linux does, too. Ubuntu, anyhow, the existing screen is "frozen" as it transitions and asserts a separate prompt screen that uses the previous image as a background. It isn't unique to Vista.

I have, on many occasions, commended Microsoft on the security work they have put into Vista. The only "shame" of it that I have pointed out is that it should have been done in XP. At least they are finally treating security seriously.

There's two implementations I see in Ubuntu. gksudo (full screen blackout) and the OS X-style dialog with the 'unlock' button. The latter may be capable of keystroke hijacking.

Also I recall seeing video playback in the background through the gksudo dialog's black background, at least if compiz is on.

i really don't get why all these anti trust things are out there.. i would love to be able to install windows of a disk and have it have everything that i would ever need. i am sure anyone would do the same... if microsoft bundled it's office with windows i am sure no one would say anything... but if it's internet explorer there is hell to be raised... wtf... just put everything in one place and of course give us the option to install it or not.

VSC does only record byte level backups, and only on the same volume, as far as i know. However, Vista (don't remember which editions but im assuming at least all of them that ship with VSC) also ships with the backup and restore center which allows you to backup to external HDs, etc which does what you are asking.

VSC also can be accessed through other programs. WPG/WLPG uses it to track changes you make to photos, for example.

You can think of Time Machine as a combination of the Backup and Restore Center backup with VSC functionality.

I'm reading more up on Vista's backup and some things have caught my eye.

Instead of backing up based on file types, they should be based on directories or files. I can have thousands of different pictures or zips/rars scattered around my hdd--I don't want them all backed up. For example, let me schedule automated backup for just my Home folder. Or say just my Documents, Pictures, and preferences. :

5-BackupFiles.JPG

This is basically how I have my backup set up in Time Machine. By default, TM will backup your entire volume [like Vista Complete PC Backup] but I've set it to exclude everything, save my Home folder which contains all my documents, pictures, files, preferences, etc. It first copies files exactly and then resorts to only incremental backups for files that have changed since the last backup. I can set the backup intervals to hourly, daily, weekly, or monthly. [extra options with TimeMachineEditor]

Picture%201.png

Exactly. If your drive fails or shadow copy backup gets corrupted, you'd be sol. This is basically where Time Machine differs--it's not really a comparable service to VSC even though it offers the same functionality of restoring from previous versions.

Wait what? They're exactly the same as far as I know. I'm pretty sure they both store entire backups of the files.

There's two implementations I see in Ubuntu. gksudo (full screen blackout) and the OS X-style dialog with the 'unlock' button. The latter may be capable of keystroke hijacking.

Also I recall seeing video playback in the background through the gksudo dialog's black background, at least if compiz is on.

As far as I know, Ubuntu's default only dims the screen and makes the prompt modal. It doesn't actually live in a different user session like Secure Desktop. Does Ubuntu even support a "Continue/Cancel" consent model instead of password entry? If you require the user to type a password then there's no reason for anything like Secure Desktop. Instead you get to worry about spoofing.

Wait what? They're exactly the same. They both store entire backups of the files.

I was told that Volume Shadow Copy stores the files on the same hard disk and only makes a snapshot once a day?

(But if you can use VSC on an external drive, what good would it be if it can't restore files or your system fully in the case of a hard drive failure because it only stores byte level changes in the snapshots? I assume this is why they implemented the Backup and Restore Center additionally.)

As far as I know, Ubuntu's default only dims the screen and makes the prompt modal. It doesn't actually live in a different user session like Secure Desktop. Does Ubuntu even support a "Continue/Cancel" consent model instead of password entry? If you require the user to type a password then there's no reason for anything like Secure Desktop. Instead you get to worry about spoofing.

There is the standard "password" dialog box (I can get this when accessing the user settings "control panel" ), which is like a standard dialog. I can still use other windows without addressing this.

There is the dialog that forbids interaction with the background (you are shown a static shot of when the prompt appears). I just tried it, and even the X manipulations to switch sessions (Linux has several user sessions, most TTY, but can have multiple X sessions running simultaneously) are locked out. This would appear to me to also lock out any other session from interacting with the prompt.

If you are interested in "continue/cancel" type authorization (which is nonsense in my book), it can be done by using a blank password for user/root - and this is prevented by default (one would have to alter Ubuntu a bit to allow a null password). Are you promoting "cancel/allow" as a security improvement in some way I don't see? :unsure:

There is the dialog that forbids interaction with the background (you are shown a static shot of when the prompt appears). I just tried it, and even the X manipulations to switch sessions (Linux has several user sessions, most TTY, but can have multiple X sessions running simultaneously) are locked out. This would appear to me to also lock out any other session from interacting with the prompt.

But what is the reason for this? If it's not a consent (continue/cancel prompt) this just seems like it would be a nuisance.

If you are interested in "continue/cancel" type authorization (which is nonsense in my book), it can be done by using a blank password for user/root - and this is prevented by default (one would have to alter Ubuntu a bit to allow a null password). Are you promoting "cancel/allow" as a security improvement in some way I don't see? :unsure:

Consent vs credentials each have their advantages. Obviously consent tends to be easier for users.

If you're authenticating the same user, then consent prompts can be more secure as they cannot be the target of spoofing attacks. With a credential prompt my code can create a replica that you type your password into, and now I own your machine AND actually know your password (something even your OS probably doesn't know), which you probably use elsewhere.

Credential prompts can also be targetted for keystroke recording, if you don't take measures like require a Ctrl+Alt+Del press before entering it.

But what is the reason for this? If it's not a consent (continue/cancel prompt) this just seems like it would be a nuisance.

Consent vs credentials each have their advantages. Obviously consent tends to be easier for users.

If you're authenticating the same user, then consent prompts can be more secure as they cannot be the target of spoofing attacks. With a credential prompt my code can create a replica that you type your password into, and now I own your machine AND actually know your password (something even your OS probably doesn't know), which you probably use elsewhere.

Credential prompts can also be targetted for keystroke recording, if you don't take measures like require a Ctrl+Alt+Del press before entering it.

You have to be kidding to think that un-credentialled authorizations are more secure than credentialed. :blink:

You have to be kidding to think that un-credentialled authorizations are more secure than credentialed. :blink:

I think what Brandon's getting at is for Windows, assuming you keep Secure Desktop on (personal note: now I do, I used to shut it off) it's guaranteed 99% of the time* only the user has full control over giving consent to a secured dialog not requiring credentials, as opposed to providing credentials to a dialog potentially open for exploitation. He's suggesting that there's the possibility a rogue *nix process can track keystrokes used to authenticate sudo prompts, and then hijack the next sudo prompt to carry out its dirty business. Whether such proof of concept exists, I don't know. If it does exist, Ubuntu distros and Mac OS X would be in trouble.

What I'm still sketchy on for, say Ubuntu and similar distro's implementation of these consent dialogs, is the grace period given after authenticating a gksudo prompt. I'm not entirely sure if the OS can distinguish between a user-initiated action and one done by a program automatically - on the Windows side at least, it can't, so it opts to prompt everytime just to be on the safe side.

Of course, Vista users who are extremely paranoid about security can choose to enable credentialled UAC dialog boxes even for administrators with a simple setting change in Local Security Policy.

*let's leave 1% in case someone discovers a flaw in UAC

You have to be kidding to think that un-credentialled authorizations are more secure than credentialed. :blink:

Absolutely. You're very naive if you think otherwise. Remember, we're talking about a situation where the user has already been authenticated with an account that has administrator privileges.

Do you disagree that virtually any credential prompt can be easily spoofed? Or that software keyloggers are a valid concern?

It is possible to take steps to prevent spoofing and keylogging (a verification image / phrase, Ctrl+Alt+Del press, etc) - but it's very difficult to take steps like that during a user session, for every administrative action. And those steps don't completely eliminate the concern.

He's suggesting that there's the possibility a rogue *nix process can track keystrokes used to authenticate sudo prompts, and then hijack the next sudo prompt to carry out its dirty business. Whether such proof of concept exists, I don't know. If it does exist, Ubuntu distros and Mac OS X would be in trouble.

More importantly, my rogue application can display a prompt that looks exactly like the gksudo prompt, so you type in your password and now I know something that even your OS doesn't know. Now for many people I likely have your bank account, e-mail, or paypal password.

Absolutely. You're very naive if you think otherwise. Remember, we're talking about a situation where the user has already been authenticated with an account that has administrator privileges.

...

No. The login gives the user his "user" permissions.

An attempt to do an "admin" task gets a password prompt with gksudo. And a "Click here" prompt with UAC.

The "click here" is less secure.

I think there is a little confusion here.

The idea is, a typed prompt, if it manages to look like a real prompt, allows a program to steal your password. At this point, you've already lost a lot of your security - and not only for the OS - for whatever else you might use that password for.

With a Click here, there's no password to steal. You've entered the password at login. The average Vista user is an "admin" (essentially), and it's based around that being the norm (a lesson learnt from XP, since everyone just set their accounts as admin). This may not be the case with Linux, which makes some comparisons difficult.

Yes, a password is more secure in terms of user initiation than a button - but that is not what is being protected against. It's versus malicious programs.

No. The login gives the user his "user" permissions.

An attempt to do an "admin" task gets a password prompt with gksudo. And a "Click here" prompt with UAC.

The "click here" is less secure.

Did you even read my post? It is not less secure! There is no fathomable way in which it is less secure, in the context of an authenticated admin user (the most common scenario). If you're talking about an over-the-shoulder elevation, then obviously that's not possible with a consent prompt - but that scenario doesn't even apply here.

Please give me one conceivable way in which credential prompting is more secure than consent prompting. I've given you the counter example.

You are talking about an admin user? Right there it is insecure. Adding "are you sure?" prompts are pointless.

If you want me to give "one conceivable way in which credential prompting is more secure than consent prompting", then let me do so just to stop this silly line of reasoning.

I, as an admin user on a secure Vista box, leave my PC for a second. My 7 year old comes in and tries to delete a system file. He gets a UAC prompt asking to continue. He does. It is gone. Buh-bye.

If prompted for a password credential, the little snot-nosed brat would have been stopped, and saved himself an hour in time-out. :p

There. Does that show you "one conceivable way"?

I would love it if Microsoft would shrink the size of the OS by doing like Apple not support all old app's and drivers. It's time for Microsoft to say if want to run an application that is ten years old then use a virtual machine with Windows XX on it so can make there OS smaller and faster. I would like Microsoft to rethink the registry and come up with no registry or something better.

that's my two cents

You are talking about an admin user? Right there it is insecure. Adding "are you sure?" prompts are pointless.

This is a naive statement. There is no "are you sure" prompt involved with UAC. There is only the "Do you want to allow this program to run with administrator privileges" dialog. This has nothing to do with certainty. It's there to inform you that an application wants to run with admin privileges, and to give you the opportunity to stop that from happening.

They are far from pointless. They provide a better user experience and increased security over credential prompts like those in OSX (that ask you to verify the current users's password).

If you want me to give "one conceivable way in which credential prompting is more secure than consent prompting", then let me do so just to stop this silly line of reasoning.

I, as an admin user on a secure Vista box, leave my PC for a second. My 7 year old comes in and tries to delete a system file. He gets a UAC prompt asking to continue. He does. It is gone. Buh-bye.

If prompted for a password credential, the little snot-nosed brat would have been stopped, and saved himself an hour in time-out. :p

There. Does that show you "one conceivable way"?

That's a multi-user scenario, I was referring to the common single-user admin scenario. In your case, you should lock your machine.

So it *is* a "conceivable way, then?

Unless you are adding in constraints? I thought that the situation I described is realistic, and I bet it happens an awful lot.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Ocenaudio 3.19.3 by Razvan Serea  Ocenaudio is a full featured, fast and easy to use audio and music editor. It is the ideal software for people who need to edit and analyze audio files without complications. Ocenaudio also has powerful features that will please more advanced users. To assist ocenaudio development, a powerful toolset of audio editing, analysis and manipulation called Ocen Framework was created. ocenaudio is also based on Qt framework, a well known library for cross-platform development. Cross-platform support ocenaudio is available for all major operating systems: Microsoft Windows, Mac OS X and Linux. Native applications are generated for each platform from a common source, in order to achieve excelent performance and seamless integration with the operating system. All versions of ocenaudio have a uniform set of features and the same graphical interface, so the skills you learn in one platform can be used in the others. VST plugins support Ocenaudio supports VST (Virtual Studio Technology) plugins, giving its users access to numerous effects. Like the native effects, VST effects can use real-time preview to aide configuration. Real-time preview of effects Applying effects such as EQ, gain and filtering is an important part of audio editing. However, it is very tricky to get the desired result by adjusting the controls configuration alone: you must listen the processed audio. To ease the configuration of audio effects, ocenaudio has a real time preview feature: you hear the processed signal while adjusting the controls. The effect configuration window also includes a miniature view of the selected audio signal. You can navigate on this miniature view in the same way as you do on the main interface, selecting parts that interest you and listening to the effect result in real time. Multiselection for delicate editions To speed up complex audio files editing, ocenaudio includes multi-selection. With this amazing tool, you can simultaneously select different portions of an audio file and listen, edit or even apply an effect to them. For example, if you want to normalize only the excerpts of an interview where the interviewee is talking, just select them and apply the effect. Eficient edition of large files With ocenaudio, there is no limit to the length or the quantity of the audio files you can edit. Using an advanced memory management system, the application keeps your files open without wasting any of your computer's memory. Even in files several hours long, common editing operations such as copy, cut or paste happen almost instantly. Fully featured spectrogram Besides offering an incredible waveform view of your audio files, ocenaudio has a powerful and complete spectrogram view. In this view, you can analyze the spectral content of your audio signal with maximum clarity. Advanced users will be surprised to find that the spectrogram settings are applied in real time. The display is updated immediately when altering features such as the number of frequency bands, window type and size and dynamic range of the display. Ocenaudio 3.19.3 changelog: Fixes issues with MP4 files with more than 8 channels Fixes incorrect VBR detection for some CBR MP3 files Other bug fixes and improvements Download: Ocenaudio 64-bit | Portable | ~40.0 MB (Freeware) Download: Ocenaudio for Linux and Mac OS View: Ocenaudio Homepage | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • DiskGenius 6.2.0.1829 - All Versions: Free, Lite & Portable by Razvan Serea DiskGenius is a full-featured partition manager, which is designed to optimize disk usage for Windows users. It will efficiently help you recover lost data, resize/split partition, backup files, edit hex data, check bad sectors, manage virtual disks, erase data, etc.. Create a system image backup for current Windows with simple clicks to keep the operating system under protection. DiskGenius key features: Partition Management - It can create format, resize, extend, backup, split, hide and clone partition, both MBR and GPT are supported. Disk and partition conversion - Convert dynamic disk to basic, convert virtual disk format and convert MBR to GPT, convert primary partition to logical. File recovery - It can recover files deleted or emptied form recycle bin, recover files from damaged partition or disk and recover files by file type and supports file preview and file filter. Partition recovery - It is the best partition recovery program in that it can recover files from damaged, corrupted and RAW partitions, search for lost partition and recover files from it, besides, it can fix partition table. RAID recovery - It can reconstruct Virtual RAID and recover files from it, and all RAID types are supported. Sector Editor - A Hex editor is embedded to help users edit raw hex data and recover data manually. Backup and Restore - It can backup and restore partition including system partition, hard disk and partition table. Bad Tracks - It can check and repair bad sectors for all storage devices; check hard disk S.M.A.R.T. information. Delete files permanently - It can delete files permanently so that they can't be recovered by any data recovery software. Virtual Disk - It supports virtual disks, including VMware, Virtual PC and Virtual Box. Create WinPE bootable disk and you can manage disk partition when system crashes or there is no operating system on your computer. Support FAT12/FAT16/FAt32/exFAT/NTFS/EXT2/EXT3/EXT4 file system format. DiskGenius 6.2.0.1829 changelog: Add the "Disk Speed Test" feature. Add the "Windows Boot Repair and Conversion" feature. Add the BMB21-2019 erase standard to the "Erase Sectors" feature. Add support for restoring an individual partition from a PMFX disk image file. Enhanced The "Verify Or Repair Bad Sectors/Blocks" feature displays disk read speed in the detection window during scanning. The "Quick Partition" dialog box allows users to quickly select the number of partitions by pressing the numeric keys 1, 2, 7, 8, or 9. The "Set Volume Name" dialog box supports selecting preset volume labels provided by the software. The "Copy Sectors" feature supports resuming copy tasks after modifying the number of skipped bad sectors. Add the "TRIM Optimization" option to the format dialog box. The "Clone Partition" and "Clone Disk" features perform TRIM optimization on target partitions or disks before cloning. Add support for Not Equal To search conditions (prefixed with "!") when searching hexadecimal data in the sector editor. Optimize the display of capacity values in the program interface to show two decimal places. Add a minimize button to dialogs that may require long processing time. Enhance support for the ReFS file system. Enhance support for newer HIF and MP4 formats when recovering files by type. Enhance support for the EXT4 file system. Enhance compatibility of the "File Recovery" feature with special data structures. Fixed Fixed the issue that the selected file system type automatically reverted to NTFS after changing it to exFAT or EXT4 in the "Quick Partition" dialog box. Fixed inaccurate Unicode string search results in the "Sector Editor" feature. Fixed the issue that exceptions might occur when adding multiple disks in the "Erase Sectors" feature. Fixed the issue that insufficient target disk space was incorrectly reported in some cases when cloning, backing up, or restoring disks. Fixed the issue that folder modification timestamps were not preserved when copying files from ReFS partitions. Fixed the issue that Excel-format reports generated by features such as file copying or bad sector checking could not be opened when the report contained more than one million rows. Fixed the issue that folders were not displayed in the exclude-folder dialog box when backing up partitions to image files. Fixed the issue that the "Erase Sectors" feature could not be executed in some cases. Download: DiskGenius 6.2.0.1829 | 63.9 MB (Freeware, paid upgrade available) Download: DiskGenius Portable 64-bit | 40.0 MB Download: DiskGenius Portable 32-bit | 36.0 MB Download: DiskGenius Lite 64-bit | 13.4 MB Download: DiskGenius Lite 32-bit | 11.6 MB View: DiskGenius Home Page | DiskGenius Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • Really? Use a better search engine https://www.google.com/search?...ourceid=chrome&ie=UTF-8
  • Recent Achievements

    • Week One Done
      agatameier earned a badge
      Week One Done
    • One Month Later
      agatameier earned a badge
      One Month Later
    • Week One Done
      ssd21345 earned a badge
      Week One Done
    • Contributor
      MarkHughes4096 went up a rank
      Contributor
    • Dedicated
      jordanspringer earned a badge
      Dedicated
  • Popular Contributors

    1. 1
      +primortal
      513
    2. 2
      +Edouard
      184
    3. 3
      PsYcHoKiLLa
      144
    4. 4
      ATLien_0
      95
    5. 5
      Steven P.
      75
  • Tell a friend

    Love Neowin? Tell a friend!