also @ TechSpot: Next iPad rumored to be 33% lighter and thinner thanks to new touchscreen tech

Microsoft agrees to change UAC in Windows 7

By

On February 6, 2009, 1:48 PM

Microsoft is doing some backtracking today. After initially downplaying the risks and defending its choices around the User Account Control feature in Windows 7, the company has now bowed to pressure and said it will make some modifications to the upcoming release candidate in response to the outcry.


For those who haven’t been following this story, the problem stems from a more permissive UAC default setting in Windows 7 compared to Vista, which has been blasted by users as being too intrusive regarding these security measures. The change resulted in a by far less annoying Windows 7, but it also introduced a gaping security hole in which the feature could easily be turned off altogether, using pre-approved Microsoft applications to fool Windows 7 into granting malicious code full access rights.

Microsoft refused to acknowledge this as a flaw but rather claimed it constituted a feature created “by design.” However, in a reassuring sign that the Windows beta process isn’t just for show, the company has now vowed to make some seemingly straightforward changes in the upcoming release candidate to address this concern. Namely that changing the level of the UAC will prompt for confirmation.

No tags on this story

User Comments: 28

Got something to say? Post a comment
  1. Wow, thank you MichaelLSSo you are able to use google and find out my entire work experienceGood for you, I hope you also found out that I have gone a 2 year IT Technician school, where I learned much of what I know todayAnd FYI the direction I took was not Microsofts Active Directory but Novell's NDS, with some Linux knowledge (but this was only a small course of it, the main was NDS)I guess it also showed the place I did my practice at, the Goverment for Gnosjö Municipal in Sweden, and I suppose you called them and they informed you what a poor job I did at it?And when I wrote that Windows is flawed by design and can't be fixed I guess I am also a " fanatical hobbyist Micro$oft"Thank you very much for those nice wordsAlso I have to admit that I only post pictures etc of my main rig, I usually don't post pictures of computers at work etc that I build or maintainAnd I also have to admit to using a US Robotics Courier V Everything Modem, this due to the fact that broadband was not available at my home 5 or so years ago (I do not remember the exact date I am sorry)And because I sometime mixup sudo and su, and left and right and two towns I live near I of course "have no real experience at all."For this I am very sorry, I will straight away try to better myself, I also have trouble remembering peoples names, this I also apologize forAnd I am so so sorry that the naming of the axis on two machines, in the direction Up and Down, is on one of them named Z- for down, and on the other Y+ for down (i.e. the same direction)I don't know how to respond to this, but as you say I obviously must have no idea at all, you can call Adige Italy because I just finnished the acceptance setup procedure with them, so they can inform you that the controls "obviously completely eludes you"EDIT; Sorry for this late addition, but I thought a link to this site I am also a member of (sadly more active at than this site, sorry Julio ) might be of interest to you;[url]http://www.badcaps.net/forum/showthread.php?t=5974&
    ighlight=Dell[/url][Edited by Per Hansson on 2009-02-12 12:48:25]
  2. Kage Goomba;I am so sorry that I am not allowed to mix up two so totally different words as sudo and su, yes I agree, there really is no reason for thisThey are so different, almost like left and right"To entertain the crowd..... lets say your saying SU is the same function as UAC.... well... so what your telling me is every time UAC comes up it's switching into the admin account?"Yes, that is actually exactly what it does (which of course also means that if you disable UAC everything is run as Admin, just like if you are always logged in as root on a Linux system"Still not prompting for a password! SU demands a password...whether there is one or not!"That is correct"Each movement is logged... something that UAC never does unless its some hidden dark abysmal function that can be changed."No, as far as I know nothing is logged with UAC, you are correct"SU is a quick and dirty way of logging in into an another account until you "Exit" or close down the terminal."Yes, I agree, this is how I use it too"Speaking of which... it completely leaves your previous state behind in a suspended state until you return... what you do in SU is unique to the session in which you started it in"Yes I know, this is by it's design"In fact people who do SU all the time should be advised its really foolish and stupid as you could be leaving yourself open to attack or a mistype keystroke which could destroy your system."Yes I agree, it's just the same thing as always being logged in as rootOr in Windows to do the comparsion to always be logged in as Admin (as was default up to Vista) or as with Vista to disable UAC so everything is run as AdminVery easy for a virus or trojan to kill the system then as you no doubt have witnessed in the Windows world"SUDO... if you bothered to read the bloodly manual... as clearly stated on that site and in the MAN page i told you to read.... is completely different."Yes, I agree to all your comments on SUDO, I know what it is and how it works, I rarley use it tho, but I did mix up it's name with su as I told you"SUDO... if you bothered to read the bloodly manual... as clearly stated on that site and in the MAN page i told you to read.... is completely different."Yes, I agree to all your comments on SUDO, I know what it is and how it works, I rarley use it tho, but I did mix up it's name with su as I told you"SUDO by its default configuraiton isn't exactly polite and takes a bit of time and effort to refine.... some people get lazy and ignore it and just SU into ROOT. SysAdmins however do not... and they make sure its propperly configured."I am guilty of this, however the systems I setup are mostly webservers etc where no "normal" users ever need to use the system, so sudo is not needed for that reason, that is why I pretty much never configure it up, because for the system I setup it's not requested or needed"But you really don't care do you.... your too busy defending your lack of knowledge on the matter and comparing a completely different system to UAC."How the system in Linux to gain root access and the system in Windows to gain Admin access can not be related I do not understand, so obviously my lack of experience shows now... (so this is why I don't answer your next two paragraphs)"Mixing 2 very powerful tools that are totally different is not what I call a excusable thing. Try explaining that to your boss if your in charge of an enterprise network. Some how I don't think he/she will be so forgiving"I never do, if I am uncertain I check first what the command does by typing --h or whatever is appropriate for the command in question (obviously this is not possible to do for a linux command in Windows so there I would need to ask google and I do admit I was too lazy to do that in this case r.e. sudo vs su)"I live in the real world where security is critical... and maintaining enterprise systems are important. Yes I'm very serious.... should show in my attitude here."Yes it does show."I take my work seriously.... very seriously."I take your word for it, I also take my work very seriously"Leave the world of linux and UNIX to the people who know what they are doing thank you very much."I am sorry but this I can not do, you could for example ask Julio in this case to stop me being the system administrator for this site, Techspot.comBut untill you do I am afraid I will need to maintain this system, plus others for relatives and friends and some companies"I'm done here... its obvious the people who run this dog and pony show don't know there stuff..... and just play around. "Who are the others, other than me?"So yes.. rejoice... the angry mushroom is leaving."Why would I rejoice? Communication is how humans learn things, I can appreciate that"Not that it will matter in the end... ban me... block me."No, I will not ban you, I only ban people that do not follow the T.O.S for Techspot (why would I want to ban you?)"Won't change the facts. If I need advise on fixing something to do with mechanics ill ask you.... but forgive me if I refuse to send people to you or respect your so called opinion on the subject of computers."Sure, that is no problem, I have all the work I need as it is, and you are of course free to contract whoever you want"Yes I respect the fact your a hobbyist... but that doesn't give you the right to spout off things just because you "Dabbled""Sorry, what does the word "Dabbled" mean? (yea, I am to lazy to google it) anyway, I think both Sweden and the US still honors free speech? If not then yes, you are right..."I eat breath sleep this stuff for a living...." "You obviously don't..."I also earn my living off this"Farewell.. and good luck on your UNIX endeavors... you'll be happier in Windows 7 for sure."I prefer Windows 2000 actually, it's much cleaner than XP and Vista, it should show in these articles;[url]http://www.techspot.com/vb/topic85224.html[/ur
    ][url]http://www.techspot.com/vb/topic90831.html[/url]I recently upgraded to XP x64 however, as you can see here;[url]http://www.techspot.com/blog/224/slow-system-perfo
    mance-when-copying-large-files-in-xp-x64-server-2003-x64/[
    url]As for my opinion yes, Windows7 is much better than Vista, I think I voiced this already howeverIt is also interesting how we agree on pretty much everythingIt is just that you are trying to very hard hate me for some reasonOf course this is a free site so you are free to do soAs long as you give me the liberty to defend myselfI will end this with a link to a LASER video of a machine I previously operated, note the marks for axis directions written with a black pencil, that was by me [url]http://www.techspot.com/files/Pers_Stuff/3DCutting55deg
    =5mm.divx.avi[/url]You can find some more info and pics here;[url]http://www.badcaps.net/forum/showthread.php?t=1956
    /url][Edited by Per Hansson on 2009-02-12 12:13:51][Edited by Per Hansson on 2009-02-12 12:23:48]
  3. Thanks for confirming all that we learned about you.Now, again, I suggest you stop deceiving people by talking as though you know these topics. Knock it off!Two years in a little known IT Technician school. Give me a break. You are barely trained in IT - let alone - some OS expert.Nice stack of books. Too bad you never retained what is written within.When you have worked in this industry for 35 years or more then we might respect what you have to say here. Until then, Fan Boy, do everyone a favor and stick to playing FPS games on your home built computer.

Recently commented stories

Post a new comment

Social Login & Guest Posting TechSpot Members
Login here or sign up for free,
it takes about a minute.
Get complete access to the TechSpot community. Join thousands of technology enthusiasts that contribute and share knowledge in our forum. Get a private inbox, upload your own photo gallery and more.
TechSpot on:

Subscribe to TechSpot

Get free exclusive content, learn about new features and breaking tech news.