Gizmodo

  • Gizmodo
  • bestmodo
  • lifehacker
  • kotaku
Profile logout login
Uncle Joel's Guide to Giving Gadgets on Valentine's Day (or, Relationship Advice from a Man Who Drinks Alone)

Uncle Joel's Guide to Giving Gadgets on Valentine's Day (or, Relationship Advice from a Man Who Drinks Alone) #giftguide #valentinesday

25 New Ads to Introduce Xfinity to the Masses

25 New Ads to Introduce Xfinity to the Masses #photoshopcontest #photoshop

What Is Google Buzz?

What Is Google Buzz? #google #googlebuzz

74 Phenomenal Panoramic Planets

74 Phenomenal Panoramic Planets #photography #shootingchallenge

Apple iPad: Everything You Need to Know

Apple iPad: Everything You Need to Know #apple #appleipad

Canon Rebel T2i DSLR: 18MP and Legit 1080p Video for $899

Canon Rebel T2i DSLR: 18MP and Legit 1080p Video for $899 #digitalcameras #canonrebelt2i

Super Bowl Ads 2010: Lots of Chips and Beer, Light On Gadgets

Super Bowl Ads 2010: Lots of Chips and Beer, Light On Gadgets #superbowl #superbowlads

Gizmodo

FAQ. Include # before tag:
#tips, #whitenoise, #broken, #lifechanger, etc.

New York, 5:15 AM
Wed Feb 10
59 posts in the last 24 hours

FR | IT | DE | SP | JP | AU | BR

GIZMODO TEAM

Tip Your Editors:


Editorial Director:
Brian Lam | | Twitter

Editor:
Jason Chen
| AIM | Twitter

Features Editor:
Wilson Rothman
| Twitter

Senior Contributing Editors:
Jesus Diaz
| AIM | Twitter
Mark Wilson, Reviews
| AIM | Twitter

Contributing Editors:
Matt Buchanan
| AIM | Twitter
Adam Frucci
| Twitter
Sean Fallon
| Twitter
Jack Loftus
| Twitter
John Herrman
| Twitter
Dan Nosowitz

Chris Mascari

Kat Hannaford
| Twitter
Rosa Golijan
| Twitter
Chris Jacob


Columnist:
Brendan I. Koerner

Interns:
Don Nguyen

Kyle VanHemert


Heroes and Friends

Comment Account Questions:

SUBSCRIBE TO GIZMODO RSS

New: Breaking news and daily top stories via email
9515 Subscribers


Please confirm your birth date:

Please enter a valid date
Please enter your full birth year
This content is restricted.

Microsoft On Windows 7 UAC Security Hole: "This is Not a Vulnerability"

Even though the gaping breach in Windows 7's User Account Control feature seems, to all eyes, like a pretty easy fix, Microsoft appears to be in denial mode with MS expert Mary Jo Foley.

As we've reported, various Windows security hounds have found that the new, less-naggy User Account Control (which doesn't bug you as often when potentially malicious apps get their fingers in your system) can be easily exploited to bring the nastiness to your PC. Many of said hounds have concluded that, with the UAC hole, Windows 7 is significantly less secure than Vista.

But for some reason, Microsoft won't fess up. When Mary Jo pressed them on the issue, they came back with this statement, which seems to contradict many of the observations of those publicizing the exploit:

* “This is not a vulnerability. The intent of the default configuration of UAC is that users don’t get prompted when making changes to Windows settings. This includes changing the UAC prompting level.
* Microsoft has received a great deal of usability feedback on UAC prompting behavior in UAC, and has made changes in accordance with user feedback.
* UAC is a feature designed to enable users to run software at user (non-admin) rights, something we refer to as Standard User. Running software as standard user improves security reduces TCO.
* The only way this could be changed without the user’s knowledge is by malicious code already running on the box.
* In order for malicious code to have gotten on to the box, something else has already been breached (or the user has explicitly consented)”

Windows 7 is, of course, still in beta, but the tone of denial here is troubling. Hopefully a change of tune is in order, as it would be a shame to see security be the downfall of an otherwise fantastic improvement over Vista. For more analysis check out Mary Jo Foley's blog: [All About Microsoft]


Contact information for this author is not available.


Upload an image | Add an image URL ×
×
×
Choose a file to upload:
×
Dsmvwl  Admin  Promote to frontpage Approve user Ban user ×
Loading comments ... -/|\
Earlier discussions Paging in progress... | Other discussions | Show all discussions | Show featured discussions only | Expand all threads Collapse all threads
Start a new discussion
By John Mahoney
Feb 4, 2009 10:00 AM 9,561 91
Edit » Set to Draft » Invite » Syndicate »

Syndicate this post


Site:
Mode:

sending request
cancel
more about #windows7securityhole
read more: #windows7, #windows7securityhole, #uac, #useraccountcontrol, #windows, #security, #windows7beta, #vista, #windowsvista
 
  • Archives
  • About
  • Advertising
  • Legal
  • Help
  • Report a Bug
  • FAQ
Original material is licensed under a Creative Commons License permitting non-commercial sharing with attribution.

Login

Enter your username and password.

Please enter a username.
Please enter your password.
logging in
Login via Facebook | Sign Up | Forgot Password?

Reset Password

Please enter your email address to have your password reset.

Please enter your email address.
Please enter a valid email address.
requesting password reset

Register

Registering will give you a user profile and the ability to add other users as friends. To become a commenter, however, you need to audition.

Want to know more? Consult the Comment FAQ and legal terms.

Please enter a username.
Please enter a password.
Please confirm your password.
Passwords are not identical.
Please enter a valid email address.
registration sent, waiting for reply

Submit Your Comment

You don't need to login to comment. Just enter your email address below.

See how your address will be displayed in the Comment FAQ.

Please enter a valid email address.
Please enter a valid email address.
logging in

Login with your Facebook or Gizmodo account.

Sign up here.



Send An Invitation

To invite commenters to this page, paste in a list of comma-separated email addresses, and then select send invites.

Please enter at least one email address.
Please use valid email addresses.
Please use unique email addresses.
Please enter fewer addresses.
requesting invites

Send a link

Send a link to this post 'Microsoft On Windows 7 UAC Security Hole: "This is Not a Vulnerability"' via email:

Please enter your name.
Please enter your email address.
Please enter a valid email address.
Please enter your recipient's email address.
Please enter a valid email address.
Please enter your message.
Sending message