90 percent of Windows 7 flaws fixed by removing admin rights


Recommended Posts

there is a psychological difference between typing a password or clicking a button.

My thought process

Which means you don't need to change anything unless you just want that extra step for typing in credentials.

I do want that step. She is the type of person to need to look them up each time. This creates a barrier that will ultimately defend her.

Works like that even if she is an admin. :p Which means you don't need to change anything unless you just want that extra step for typing in credentials.

You could also make a case that malware could emulate the look of this window and get her admin credentials (albeit probably without the driver disabling/screen dimming). Either way, giving something administrative privileges really doesn't mean anything. Any range of malware can run and do harm without them.

sure, i'm not refuting that :). The user will always be the weakest link.

I do want that step. She is the type of person to need to look them up each time. This creates a barrier that will ultimately defend her.

It's also somewhat of a false sense of security. The reason is that (as Elliott says) malware can in fact clone the credential dialog, complete with simulated dimming and all. If you enter your credentials into the malware's dialog, it now owns the system. The regular UAC dialog, on the other hand, can't be cloned because simply having you push a button is of little value to the malware.

The biggest issue, though, is that this ignores the fact that everything of interest on the machine is available without admin access. There are also other issues with UAC, such as the fact that there is a window of opportunity between the time your download of an executable finishes and the time you run it. In this time, malware running as standard user can modify the executable (provided it isn't signed, of course) or add a DLL that will automatically load when it's executed. The result is that the malware will ride the elevation of what you think is legitimate software.

Now, most malware won't work without admin rights, and doesn't do clever things like what I've described, so in that sense it does offer a safer experience. The point I'm really making though, is that we wouldn't really be much safer in a world where people didn't blindly run things as admin.

So how much money did they get paid to come up with that foolish report..... How about you don't turn on your machine then 100% of the security holes are fixed.... Can I have ?500 for that please.

What a bizarre complaint. Do you actually have an issue with their report, or are you just looking for things to whine about?

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Tixati 3.44 is out.
    • Speccy 1.34.084 by Razvan Serea Speccy will give you detailed statistics on every piece of hardware in your computer. Including CPU, Motherboard, RAM, Graphics Cards, Hard Disks, Optical Drives, Audio support. Additionally Speccy adds the temperatures of your different components, so you can easily see if there's a problem! Processor brand and model Hard drive size and speed Amount of memory (RAM) Graphics card Operating system At first glance, Speccy may seem like an application for system administrators and power users. It certainly is, but Speccy can also help normal users, in everyday computing life. If you need to add more memory to your system, for example, you can check how many memory slots your computer has and what memory's already installed. Then you can go out and buy the right type of memory to add on or replace what you've already got. Download: Speccy 1.34.084 | 20.5 MB (Freeware) View: Speccy Website | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • ImgDrive 2.2.7 by Razvan Serea ImgDrive is a CD/DVD/BD emulator - a tool that allows you to mount optical disc images by simply clicking on them in Windows Explorer. If you have downloaded an ISO image and want to use it without burning it to a blank disc, ImgDrive is the easiest way to do it. ImgDrive features: One-click mounting of iso, cue, nrg, mds/mdf, ccd, isz images Runs on 32-bit and 64-bit Windows versions Mount ape, flac, m4a, wav, wavpack, tta file as AUDIO CD (16-bit/44.1kHz) Mount a folder as DVD/BD Mount images in command line Does not require rebooting after installation Support up to 7 virtual drives at the same time Support multi session disc image (ccd/mds/nrg) A special portable version is available Translated to more than 10 languages Support File Type: .ccd - CloneCD image files .cue - Cue sheets files of ape/flac/m4a/tta/wav/wv/bin .iso - Standard ISO image files .isz - Compressed ISO image files .nrg - Nero image files .mds - Media descriptor image files ImgDrive 2.2.7 changelog: Added command line parameter to set number of drives Added AACS-Auth support for HD DVD Bumped kernel driver version to 2.2.7 Download: ImgDrive 2.2.7 | 692 KB (Freeware, paid upgrade available) Download: ImgDrive Portable 535 KB View: ImgDrive Home Page | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • AnyDesk 9.7.7 by Razvan Serea AnyDesk is a fast remote desktop system and enables users to access their data, images, videos and applications from anywhere and at any time, and also to share it with others. AnyDesk is the first remote desktop software that doesn't require you to think about what you can do. CAD, video editing or simply working comfortably with an office suite for hours are just a few examples. AnyDesk is designed for modern multi-core CPUs. Most of AnyDesk's image processing is done con­currently. This way, AnyDesk can utilize up to 90% of modern CPUs. AnyDesk works across multiple platforms and operating systems: Windows, Linux, Free BSD, Mac OS, iOS and Android. Just 7 megabytes - downloaded in a glimpse, sent via email, or fired up from your USB drive, AnyDesk will turn any desktop into your desktop in se­conds. No administrative privileges or installation needed. AnyDesk 9.7.7 fixes: Fixed an issue that prevented users from creating meetings without an active license Download: AnyDesk 9.7.7 | 8.0 MB (Free for private use, paid upgrade available) Links: AnyDesk Home Page | Other platforms | Release History | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • I used a Pixel 10 Pro XL when it first came out for about 8 months. When I first got it, it was using Google assistant and that was fast, when asking it to call somone etc. Then it automatically switched with some update to Gemini. Doing even the simplist of things like asking it to call someone in my contacts was soooooo slow compared to Google assistant. I guess it had to go out to the cloud to do that? Back on iPhone and while Siri is dumb right now, it does do those simple things, like call someone, set a timer, star the stop watch etc, really fast. That an while I like Google Material Design 3 over iOS 26, they Pixel 10 Pro XL was so slow in comparison to the iPhone 17 Pro I am using.
  • Recent Achievements

    • Dedicated
      tuben earned a badge
      Dedicated
    • Week One Done
      mnsgroup earned a badge
      Week One Done
    • Conversation Starter
      sumytbe earned a badge
      Conversation Starter
    • One Year In
      B4dM1k3 earned a badge
      One Year In
    • One Year In
      DarkWun earned a badge
      One Year In
  • Popular Contributors

    1. 1
      +primortal
      524
    2. 2
      +Edouard
      199
    3. 3
      PsYcHoKiLLa
      94
    4. 4
      Michael Scrip
      82
    5. 5
      Steven P.
      67
  • Tell a friend

    Love Neowin? Tell a friend!