Discussion on:

8
Comments

Join the conversation!

Follow via:
RSS
Email Alert
What are your impressions of UAC? Does it look like a genuine security enhancement or do you think it's too easily circumvented?
0 Votes
+ -
Net Positive
gsquared 4th Dec 2006
I find it a net positive. It's kind of annoying to have to click to authorize certain programs, but it does increase the security of the system. I'll trade an extra click or two for a more secure system.
0 Votes
+ -
I use unattended.txt to relocate and rename Windows, Program Files, Documents and Settings. Moving profiles to another volume helps manage disk space. Renaming folders is another layer in the security onion to keep out simpler scripts. Will UAC concept of Secure Locations go along?
0 Votes
+ -
Very Informative
jpr75 1st Dec 2006
Lots of good info nicely summarized. Thank-you.
0 Votes
+ -
I found the info on the Secure Desktop misleading, and likely to influence people to make a bad decision. The Secure Desktop in which UAC prompts are displayed by default serves a very important purpose and should not be disabled.

It ensures that UAC prompts cannot easily be spoofed by trojan horse programs or manipulated by keystroke-sending programs. It hardens the UAC prompt against a class of security exploits known as the "Shatter" attack, in which untrusted code can manipulate programs running with higher privileges.

(It does so by presenting UAC prompts in a seperate 'Windows Station'. Programs cannot send messages to programs running in a different Windows Station, so cannot query or maniplutate them.)
0 Votes
+ -
What happens if
bbri14 8th Dec 2006
What happens if malware constantly tries to install itself (like every 5 seconds) - will the UAC prompt the user every 5 seconds? Or is it a one time thing until you reboot? This would get annoying in a hurry if that is an issue.
Great article, very helpful. Thank you!
I beleive remote users in Vista have a low privilege and would like to know if there is any remote applications can get elevated privilege.
Keyboard Shortcuts:
Prev
Next
Toggle
Join the conversation
Formatting +
BB Codes - Note: HTML is not supported in forums
  • [b] Bold [/b]
  • [i] Italic [/i]
  • [u] Underline [/u]
  • [s] Strikethrough [/s]
  • [q] "Quote" [/q]
  • [ol][*] 1. Ordered List [/ol]
  • [ul][*] · Unordered List [/ul]
  • [pre] Preformat [/pre]
  • [quote] "Blockquote" [/quote]

Join the TechRepublic Community and join the conversation! Signing-up is free and quick, Do it now, we want to hear your opinion.