Re: Anybody Have any Problems With AceUpdater for Addons and Vista?



"Ronny" <ronny@xxxxxxxxxxxxx> writes:
UAC has been developed by Microsoft to make windows more like Linux, OSX etc
In short terms what it does is remove the ability of the user to run
everything as an administrator, now in Linux this is fine as everyone knows
you should never run programs in root, but in MS os's we have always been
admin of our own machine and all programs have been run as administrator.

Actually, UAC is simply a lame attempt to let the user AVOID proper access
controls. In most situations the user is still admin - all UAC does is spam
a password window at them.

If programmers didn't hate UAC so much they might program the apps with UAC
switched on, in fact they are all turning it off so in effect turning their
Vista pc into a winXP machine <security wise>

You are correct that a windows app can be written to properly interact with
UAC (so that there's only one entry required, and only when needed). But
coding one that way can actually reduce the security of the app, because
windows believes the app when it says it only needs security at those
points. It's a big mess.

So MS either need to make UAC compulsory or remove it totally, as windows xp
doesn't use it and games/apps manufacturers have to write software to run
with both OS's I would say it's best to keep it switched off.

Windows needs to come up with a proper security model that makes it
feasible to run the machine in end-user mode. WAY, way too much stuff runs
in admin mode and thus has the run of the machine. *
--
* PV something like badgers--something like lizards--and something
like corkscrews.
.



Relevant Pages

  • Re: Sygate Free PFW
    ... security holes won't be fixed. ... switch to the windows XP SP2 firewall? ... Windows firewall does not inform user when an apps tries to connect ... This arrives, of course, when app is installed in a session where user has ...
    (comp.security.firewalls)
  • [Full-disclosure] "run as" local denial-of-service enables administrative account proces
    ... Windows XP Professional with SP2 ... While a user, at any security membership ... A contributing factor to the success of the attack ... Log in to the computer as a local administrator. ...
    (Full-Disclosure)
  • "run as" local denial-of-service enables administrative account processes to be killed
    ... Windows XP Professional with SP2 ... While a user, at any security membership ... A contributing factor to the success of the attack ... Log in to the computer as a local administrator. ...
    (Bugtraq)
  • RE: how to change security settings
    ... Administrator account Windows XP is Administrator. ... security model to bypass, disable, or reset the password. ...
    (microsoft.public.windowsxp.security_admin)
  • Re: domain/password
    ... | Organization: DragonByte Computing ... | Simply use the built-in Administrator account to log in locally. ... Karl Levinson's Microsoft Security FAQ ... Windows XP Security Homepage: ...
    (microsoft.public.windowsxp.security_admin)