KezNews.com
DownloadsOther NewsForumBlogsWallpapersJokewareSearch

News letter:


Enter Your E-mail:

Windows 7 RTM 7600.16385.090713-1255 HERE !

How to activate Windows 7 RC build 7600, 7264, 7231 and olders


Analyst: Vista's UAC Will Reform Developers

section: windows, for your questions: KezNews forum, 8.6.2007

    Tip: Click here to update all your PC's outdated drivers

When it comes to the new security functions in Windows Vista, User Account Control is the one people tend to scratch their heads over, Gartner Analyst Neil MacDonald said during his presentation on implementing Vista security at Gartner's IT Security Summit here on June 4.




"It's one that has plenty of people confused regarding what, exactly, it is," MacDonald said.

In fact, UAC isn't one capability; rather, it's a set of Vista capabilities that collectively help to limit the ability of applications and users to make unsanctioned system changes—whether the user is running as an administrator or as a standard user.

"The idea is that when a piece of software is asking for user credentials … you shouldn't just hand them over," MacDonald said.

UAC's raison d'ętre is basically to cure the new operating system of a legacy of bad applications that freely granted administrator rights—a tendency that has eased malware writers' jobs. "Malicious code would be far less effective if users ran without administrative privileges," MacDonald said.

Microsoft initially promoted UAC as a signifier of a new, more secure era for Windows. The security function's reputation was tarnished, however, when security researchers pointed out that UAC is vulnerable to social engineering attacks.

Microsoft confirmed that vulnerability, and defended UAC by describing it as a security feature rather than a hard security boundary such as a firewall.

The idea behind UAC is to limit user privileges as much as possible for most of a user's interaction with the desktop. User rights are elevated only when necessary for administrative tasks, at which point a dialog box prompts the user to OK the escalation. Limiting normal permissions is a good thing, given that it limits the operating system surface an attacker can latch onto.

source: eweek.com

  >> Click Here to Run a Free Scan for PC Errors <<

send email Send link 2 friend  |  Permalink
<< previouse article
Vista License and Product Key Terminology Part 3
next article >>
Windows Home Server, RC Next week?

MORE RELATED ARTICLES:
Replace Windows Vista UAC with Smart UAC Replacement || Analyst sees Windows 7 done by summer || Windows 7 UAC has a second flaw || Microsoft neuters UAC in Windows 7 || Microsoft backpedals on UAC flaw

Comments(0)


No new comments are allowed for this article.

For your questions use our KezNews Forum