Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Subscribe
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Subscribe
    Home Cybersecurity
    • Cybersecurity

    Least Privilege Can Be the Best

    Written by

    David Coursey
    Published March 3, 2005
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      Want fewer security hassles? Demote yourself!

      Want to do something right now that can help protect you from malware? Then stop being an administrator. No, I am not suggesting a career change, though I suppose that would have much the same effect. Rather, I hope youll consider using your desktops administrator account only when absolutely necessary and creating a user account for general computing.

      Why am I making this suggestion? Because too many people do all their computing as administrators—even those whose user name is something besides “Administrator.”

      This opens their machines to all the malware the Internet has to offer. Reducing your privileges can stop malware that requires administrator privileges to create its mayhem, making this perhaps the easiest way to improve system security.

      Advocates call this “least privilege” computing because everyone operates with as few privileges as are necessary to get their work done. In his blog, Microsofts Aaron Margosis says this decreases a users exposure to Internet threats.

      As to why this is important, Margosis slides into some metaphors I hadnt thought of:

      “Well, if you were a surgeon, would you always want to hold an unsheathed scalpel in your hand? Or would you prefer to keep it in a safe place until you actually need it? Does that metaphor work? How about running with sharp scissors?”

      In his blog, Margosis explains specifically how malware can exploit administrative rights to harm your machine and discusses why developers shouldnt do programming as administrators. He also takes his Microsoft colleagues to task for not always setting the best example.

      /zimages/6/28571.gifRead Larry Seltzers opinion here about Microsofts participation in the malware removal market.

      All this sounds pretty good so far, but weve learned that behind every silver lining lies a big dark cloud, which in this case is the “gotcha” of least-privilege computing: Some apps dont run unless they have admin rights. If you change your user properties from administrator to “standard,” some of your applications might stop working. Become a “restricted user” and even more software may break.

      My friend, Susan Bradley, discovered this when she tried to secure her own desktop at the accounting firm where she works. She grabbed some screen shots of apps that failed.

      (If you want to try this, open the User Accounts control panel in Windows XP and create a new account with reduced privileges. I dont actually recommend changing your current account, which you will still want to use at least occasionally.)

      Why does least-privilege computing break applications? Because of programmers who write everyday applications that require them. Why do they do this? Because using admin rights made it easier to write certain programs. It also didnt used to be a big deal. This type of development, however, encouraged all user accounts to be set up with admin privileges by default, opening the door for some of the malicious code were fighting today.

      (It should be mentioned that Mac OS X and other Unix-based operating systems assume users run in a restricted mode and thus avoid these sorts of problems.)

      /zimages/6/28571.gifClick here to read more about new least privilege-based anti-malware software from Hewlett-Packard Labs.

      I am aware of no “complete” list of apps that break when a non-administrator tries to run them. But I can point you to a couple of sites that encourage programmers to write better code and that include some examples of programs that dont work.

      Keith Brown has gone so far as to create a “Hall of Shame” of applications that require admin mode to run. Susan Bradley has a site, Threatcode.com, which also lists applications and provides links to resources.

      With 20/20 hindsight, its now easy to criticize developers for overstepping the bounds of good programming practice. Some vendors are offering fixes that allow their apps to run in a reduced privilege environment. Users can also use an admin log-on when they run specific programs and a standard or restricted log-on the rest of the time.

      I hope you will experiment with this, as I have been. Reducing privileges may be the easiest thing we can do to protect systems from the malware invasion.

      /zimages/6/28571.gifCheck out eWEEK.coms for the latest security news, reviews and analysis. And for insights on security coverage around the Web, take a look at eWEEK.com Security Center Editor Larry Seltzers Weblog.

      David Coursey
      David Coursey
      One of technology's most recognized bylines, David Coursey is Special Correspondent for eWeek.com, where he writes a daily Blog (blog.ziffdavis.com/coursey) and twice-weekly column. He is also Editor/Publisher of the Technology Insights newsletter and President of DCC, Inc., a professional services and consulting firm.Former Executive Editor of ZDNet AnchorDesk, Coursey has also been Executive Producer of a number of industry conferences, including DEMO, Showcase, and Digital Living Room. Coursey's columns have been quoted by both Bill Gates and Steve Jobs and he has appeared on ABC News Nightline, CNN, CBS News, and other broadcasts as an expert on computing and the Internet. He has also written for InfoWorld, USA Today, PC World, Computerworld, and a number of other publications. His Web site is www.coursey.com.

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.