UAC . . What is it good for?

Another developers take on UAC

I ran across a cool little app the other day.  It's nothing fancy but it is useful.  It lets you reboot into a specific OS on shutdown.  Easy-peasy.  Except that Vista UAC hated it.  Wouldn't let it run.

The developers made it work though. They split it into an admin service and an app that calls the service to execute the goal. (Which is how MS intended apps to work so that malicious code can't be executed.) Apparently it was a pain in the ass though.

Having read a number of posts about how other companies have had to fight with Vista security I thought it interesting enough to share.

"Perhaps most importantly though, is the fact that Windows Vista's newly-implemented security limitations are artificial at best, easy to code around, and only there to give the impression of security. Any program that UAC blocks from starting up "for good security reasons" can be coded to work around these limitations with (relative) ease. The "architectural redesign" of Vista's security framework isn't so much a rebuilt system as much as it is a makeover, intended to give the false impression of a more secure OS.

With the current Windows Vista security models, Microsoft can claim that Vista blocks system-modification tools from running at startup; but the truth is, there are still many ways to get them to run. At the end of day, our experience with iReboot and Vista's security implementations brings us to the sad conclusion that with Windows Vista, Microsoft has made ISVs' jobs more complicated without actually providing any any further protection for end users from malware authors - which certainly isn't the best way of going about this task."

I wonder if other companies, working within the system designed by MS, are "punished" for doing so.

The rest of the post is an interesting read (as are the comments of course)  and the apps pretty cool too.
454 views 2 replies
Reply #1 Top
Thanks Zu. I may need this soon.  :D 
Reply #2 Top
I wonder if other companies, working within the system designed by MS, are "punished" for doing so.
End of quote


"YES" it all depends on what has been truely done with what. I'm sure MS is looking at this stuff.

SGT :)