90 percent of Windows 7 flaws fixed by removing admin rights


Recommended Posts

there is a psychological difference between typing a password or clicking a button.

My thought process

Which means you don't need to change anything unless you just want that extra step for typing in credentials.

I do want that step. She is the type of person to need to look them up each time. This creates a barrier that will ultimately defend her.

Works like that even if she is an admin. :p Which means you don't need to change anything unless you just want that extra step for typing in credentials.

You could also make a case that malware could emulate the look of this window and get her admin credentials (albeit probably without the driver disabling/screen dimming). Either way, giving something administrative privileges really doesn't mean anything. Any range of malware can run and do harm without them.

sure, i'm not refuting that :). The user will always be the weakest link.

I do want that step. She is the type of person to need to look them up each time. This creates a barrier that will ultimately defend her.

It's also somewhat of a false sense of security. The reason is that (as Elliott says) malware can in fact clone the credential dialog, complete with simulated dimming and all. If you enter your credentials into the malware's dialog, it now owns the system. The regular UAC dialog, on the other hand, can't be cloned because simply having you push a button is of little value to the malware.

The biggest issue, though, is that this ignores the fact that everything of interest on the machine is available without admin access. There are also other issues with UAC, such as the fact that there is a window of opportunity between the time your download of an executable finishes and the time you run it. In this time, malware running as standard user can modify the executable (provided it isn't signed, of course) or add a DLL that will automatically load when it's executed. The result is that the malware will ride the elevation of what you think is legitimate software.

Now, most malware won't work without admin rights, and doesn't do clever things like what I've described, so in that sense it does offer a safer experience. The point I'm really making though, is that we wouldn't really be much safer in a world where people didn't blindly run things as admin.

So how much money did they get paid to come up with that foolish report..... How about you don't turn on your machine then 100% of the security holes are fixed.... Can I have ?500 for that please.

What a bizarre complaint. Do you actually have an issue with their report, or are you just looking for things to whine about?

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Samsung Galaxy XR arrives in the UK with new AI and enterprise features by Fiza Ali Samsung is bringing its Galaxy XR headset to the UK several months after the device made its debut as the first headset built on Google's Android XR platform. The headset was first teased in late 2024 alongside Google's introduction of Android XR before making its commercial debut in 2025. Developed in collaboration with Google and Qualcomm, Galaxy XR combines mixed reality experiences with Gemini-powered AI features, allowing users to interact with digital content using voice, gestures, and visual inputs. While the hardware itself remains largely unchanged from the version Samsung unveiled last year, the company is using the UK launch to spotlight several software enhancements that have arrived through recent updates. Among the most notable additions is deeper integration with Google's ecosystem. Galaxy XR users can explore destinations through Google Maps' Immersive View, receiving AI-powered recommendations and contextual information from Gemini while navigating virtual environments. Furthermore, entertainment experiences have also expanded; users can watch 180-degree and 360-degree videos on YouTube, browse spatial content converted into 3D, and ask Gemini questions about on-screen content without interrupting playback. Samsung is also highlighting mixed-reality features such as Circle to Search, which allows users to identify real-world objects through hand gestures while using the headset's video pass-through mode. Another feature automatically converts photos and videos into spatial 3D experiences. Moreover, the headset now also supports Android Enterprise, allowing organisations to manage deployments using existing Android management tools. Annika Bizon, Vice President, Product and Marketing, Mobile Experience, Samsung UK & Ireland, talked about the device, stating: The headset is powered by Qualcomm's Snapdragon XR2+ Gen 2 platform and features dual 4K Micro-OLED displays. The tech giant says that users can expect up to 2.5 hours of battery life. Samsung also confirmed that Galaxy XR will continue receiving software and security updates as the company works alongside Google and Qualcomm to expand the Android XR ecosystem. Galaxy XR is now available for pre-order and will go on sale on 8 July. Customers interested in trying the headset before launch can visit Samsung KX in London and selected Samsung Experience Stores from 17 June. Finally, the company will also host a livestream on 19 June showcasing the headset's capabilities and answering questions from prospective customers.
    • Cowork is so broken. it will keep just not responding while trying to do a task. Then you have to work to get it to REstart the task.
  • Recent Achievements

    • First Post
      Jocimo earned a badge
      First Post
    • Week One Done
      suprememobiles48 earned a badge
      Week One Done
    • One Month Later
      Windows Guy earned a badge
      One Month Later
    • One Month Later
      Prasann earned a badge
      One Month Later
    • Week One Done
      Prasann earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      521
    2. 2
      +Edouard
      174
    3. 3
      PsYcHoKiLLa
      95
    4. 4
      Steven P.
      84
    5. 5
      ATLien_0
      70
  • Tell a friend

    Love Neowin? Tell a friend!