OWASP Navigation

UAC not a security feature

I guess it is official now :Microsoft: UAC not a security feature  (http://www.computerpartner.nl/article.php?news=int&id=4742)

I had some friends in Seattle that had told me that ‘UAC is NOT a security feature!!!!!!’ b, ut until now most Microsoft’s writings still talked up UAC’s security capabilities

Here is Mark’s Post: http://blogs.technet.com/markrussinovich/archive/2007/02/12/638372.aspx

And from Mark’s Comment “Vista makes tradeoffs between security and convenience, and both UAC and Protected Mode IE have design choices that required paths to be opened in the IL wall for application compatibility and ease of use.  ” what  I like to know is what paths are these? (or will Microsoft wait for public disclosure before documenting them?

other interresting posts:

  • http://en.wikipedia.org/wiki/Security_and_safety_features_new_to_Windows_Vista#User_Account_Control
  • http://www2.csoonline.com/blog_view.html?CID=28516
  • http://windowsvistablog.com/blogs/windowsvista/archive/2007/01/23/security-features-vs-convenience.aspx

One Response to “UAC not a security feature”

  1. diniscruz Says:

    More here:
    * Microsoft backpedals on Vista security : http://www.heise-security.co.uk/news/85360
    * Running Vista Every Day! http://theinvisiblethings.blogspot.com/2007/02/running-vista-every-day.html
    * Vista Security Model – A Big Joke? http://theinvisiblethings.blogspot.com/2007/02/vista-security-model-big-joke.html

    ahh, how I wished I had more time to spend in this type of research…

Leave a Reply

You must be logged in to post a comment.