Esato

Forum > General discussions > Non mobile discussion > Vista feature designed to 'annoy users'

Author Vista feature designed to 'annoy users'
paul101
G502
Joined: Mar 26, 2007
Posts: > 500
From: first to last
PM, WWW
Posted: 2008-04-12 22:27
Reply with quoteEdit/Delete This PostPrint this post
SAN FRANCISCO--A Microsoft manager has said that one of the security features in Vista was deliberately designed to "annoy users" to put pressure on third-party software makers to make their applications more secure.

David Cross, a product unit manager at Microsoft, was the group program manager in charge of designing User Account Control (UAC), which, when activated, requires people to run Vista in standard user mode rather than having administrator privileges, and offers a prompt if they try to install a program.

"The reason we put UAC into the (Vista) platform was to annoy users--I'm serious," said Cross, speaking at the RSA Conference here Thursday. "Most users had administrator privileges on previous Windows systems and most applications needed administrator privileges to install or run."

Cross claimed that annoying users had been part of a Microsoft strategy to force independent software vendors (ISVs) to make their code more secure, as insecure code would trigger a prompt, discouraging users from executing the code.

"We needed to change the ecosystem," said Cross. "UAC is changing the ISV ecosystem; applications are getting more secure. This was our target--to change the ecosystem. The fact is that there are fewer applications causing prompts. Eighty percent of the prompts were caused by 10 apps, some from ISVs and some from Microsoft. Sixty-six percent of sessions now have no prompts," said Cross.

Cross claimed it is a myth that users just turn UAC off, saying that Microsoft had collected opt-in information from users that showed that 88 percent were running UAC. Cross said it was also a myth that users blindly accept prompts without reading them.

"It's a myth that users click 'yes,' 'yes,' 'yes,' 'yes,'" said Cross. "Seven percent of all prompts are canceled. Users are not just saying 'yes.'"

Security company Kaspersky has severely criticized UAC, claiming in March last year that it would make Vista less secure than Windows XP.

At this year's RSA Conference, however, the security specialist seemed to have changed its tune. With Windows, "there is a large attack surface with a number of entry points," said Jeff Aliber, Kaspersky's U.S. senior director of product marketing. "Anyone trying to shrink that attack surface and promote secure apps development has to be a good thing."

Prior to the launch of Vista, Kaspersky issued a report in January 2007 that said UAC would be ineffectual. The company claimed that many applications perform harmless actions that, in a security context, can appear to be malicious. As UAC flashes up a warning every time such an action is performed, Kaspersky said that users would be forced to either blindly ignore the warning and allow the action to be performed or disable the feature to stop themselves from going "crazy."


SOURCE
I don't wanna sleep
I don't wanna dream
'cause my dreams don't comfort me
QVGA
Nokia Lumia 1020
Joined: May 23, 2006
Posts: > 500
From: Pakistan
PM, WWW
Posted: 2008-04-13 08:28
Reply with quoteEdit/Delete This PostPrint this post
It takes 10 seconds to turn UAC off. People who moan about this should first learn how to do the basics,
thomas93
W810 black
Joined: Sep 28, 2007
Posts: 444
PM
Posted: 2008-04-13 11:16
Reply with quoteEdit/Delete This PostPrint this post
QVGA but then I get constant security alerts.

UAC is not on, may I ate some more RAM now??
Cycovision
P990
Joined: Nov 30, 2003
Posts: > 500
From: England
PM, WWW
Posted: 2008-04-13 13:20
Reply with quoteEdit/Delete This PostPrint this post
Or it takes 1 second to read the message box and click 'allow'...

It's not very often that I agree with M$ but they're right. As long as the software is written correctly, you shouldn't get UAC messages very often. I had my first Trojan the other day and UAC stopped it at exactly the same time as my antivirus popped up an alert. Two lines of defence are better than one, so I'm leaving my UAC switched on for now!
paul101
G502
Joined: Mar 26, 2007
Posts: > 500
From: first to last
PM, WWW
Posted: 2008-04-13 14:08
Reply with quoteEdit/Delete This PostPrint this post
chief security adviser? He must have used Linux, even briefly, at some time, right? This is a feature that Linux has had since the beginning, in the form of 'su' and 'sudo'. before you think otherwise, no, Windows vista was not even the first OS to bring it to the desktop! Here is a screenshot of Ubuntu!!:



Microsoft have publicly said how great UAC in Vista is... (i'm contradicting myself here ) (though it hasn't stopped Apple making fun of it! ). In fact they recommend that other operating systems should support it too!




_________________
It's Raining, It's Pouring...
Oh sh1t, it's Global Warming.


[ This Message was edited by: paul101 on 2008-04-13 13:13 ]
thomas93
W810 black
Joined: Sep 28, 2007
Posts: 444
PM
Posted: 2008-04-13 15:17
Reply with quoteEdit/Delete This PostPrint this post
Paul look @ this

http://uk.youtube.com/watch?v=8HhncO6w4Pc&NR=1
QVGA
Nokia Lumia 1020
Joined: May 23, 2006
Posts: > 500
From: Pakistan
PM, WWW
Posted: 2008-04-13 15:52
Reply with quoteEdit/Delete This PostPrint this post

On 2008-04-13 11:16:35, thomas93 wrote:
QVGA but then I get constant security alerts.

UAC is not on, may I ate some more RAM now??

i dont. i disabled UAC and now i dont get any such stuff.
Access the forum with a mobile phone via esato.mobi