Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Subscribe
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Subscribe
    Home Cybersecurity
    • Cybersecurity

    Can Microsoft Make Vista Less Annoying?

    Written by

    Ryan Naraine
    Published June 5, 2006
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      Microsoft plans to make several significant tweaks to the next beta of Windows Vista to make a key security feature less annoying to users.

      In response to widespread criticisms that the implementation of the UAC (User Account Control) feature triggers too many privilege elevation prompt pop-ups, the software maker will make changes in Windows Vista RC1 (Release Candidate 1).

      By default, current versions of Windows configure most user accounts as a member of the administrator group, giving users all system privileges and capabilities. This allows users to install and configure applications and make system changes, but it presents a serious security risk because malware writers could take complete control of an exploited system.

      With the UAC feature, formerly known as LUA (Limited User Account), Vista separates standard user privileges and activities from those that require administrator access, reducing vulnerability to hacker attacks.

      However, in its current form, the feature requires that users click on multiple security prompts before carrying out some basic computer tasks.

      “There are simply too many elevations,” said Steve Hiskey, lead program manager for User Account Control in Microsofts Windows Security Core group, in a blog entry announcing the plans.

      In Windows Vista RC1, Hiskey said, Microsoft will make changes in the operating system to create safe scenarios for the Standard User account to accomplish tasks that used to require a privilege elevation prompt. It will also apply application compatibility fixes, called “shims,” for applications that need help running as Standard User.

      Hiskey said Microsoft will also work with ISVs to update the applications that cant be shimmed and to design the future applications so that the next generation of apps run well under Standard User privileges.

      /zimages/4/28571.gifClick here to read more about Microsofts rationale for reducing user privileges.

      One specific change outlined by Hiskey will allow a Standard User to “go get and install all critical updates” without being prompted to elevate privileges.

      “The Admin and the Standard User could install updates and shutdown in Beta 2, but they were not allowed to get them now without an elevation prompt. We didnt open up the Windows Update Service to be generically driven by a Standard User application to do this. For example, there will still be an elevation dialog to remove an update or to take update #1 and #3, but not update #2,” Hiskey said.

      “We are also going through the OS and modifying functionality to take a non-elevating default. For example, in the case of the Public vs. Private network choice, the default choice will become Public to save an elevation,” he said.

      “In Windows Vista RC1, Microsoft is going through the operating system point by point on each elevation to make a determination if the elevation is a bad elevation where we think the Standard User can safely accomplish the task. You should see significant improvement in RC1 in the number of elevations that you see,” Hiskey said.

      /zimages/4/28571.gifClick here to read about the addition of Address Space Layout Randomization in Windows Vista Beta 2.

      In the end, Microsoft wants Vista users to “rarely see an elevation prompt,” or at least to fully understand why a privilege elevation prompt was triggered, he said, and after the initial setup, home users ” should only see OS elevation prompts when they do something that changes the system,” Hiskey said.

      Based on beta testing feedback, Microsoft also expects to remove the consent prompt for administrators when deleting icons on the public desktop, he said.

      The changes follow a scathing report from Yankee Group analyst Andrew Jaquith that the Vista UAC implementation will be “particularly problematic” for users.

      “[Early] independent reports and notes from the blogosphere suggest that Microsofts own Money program—as well as the anti-virus packages from Symantec and McAfee—are incompatible with UAC and will need to be rewritten,” Jaquith said.

      “[My] testing of the December Community Technology Preview (CTP) build of Vista revealed that although the new security system shows promise, it is far too chatty and annoying for everyday use,” he added, noting that UAC blocks ordinary users from running the SafeDocs backup program that ships with Vista.

      “Even simple tasks such as opening Control Panel applets required administrator credentials or consent,” Jaquith said, citing a complaint from a beta tester that UAC was “probably the most annoying thing ever invented…”

      In short, Microsofts mission is to use UAC to make user accounts with admin privileges safer by limiting access to sensitive system resources and functions by default, and by prompting for approval when performing admin tasks that require greater privileges. Now, it must get the balance between annoyance and security just right.

      /zimages/4/28571.gifCheck out eWEEK.coms for the latest security news, reviews and analysis. And for insights on security coverage around the Web, take a look at eWEEK.com Security Center Editor Larry Seltzers Weblog.

      Ryan Naraine
      Ryan Naraine

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.