ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Desktop platforms Toolkit in association with http://ad.doubleclick.net/clk;205413468;14699245;m?http://adfarm.mediaplex.com/ad/ck/2397-58840-22058-14

Microsoft: Vista UAC designed to 'annoy users'

Tom Espiner ZDNet.co.uk

Published: 11 Apr 2008 11:52 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A Microsoft manager has said one of the security features in Vista was deliberately designed to "annoy users" in order to put pressure on third-party software makers to make their applications more secure.

David Cross, a product unit manager at Microsoft, was the group program manager in charge of designing User Account Control (UAC), which, when activated, requires people to run Vista in standard user mode rather than having administrator privileges, and offers a prompt if they try to install a program.

"The reason we put UAC into the [Vista] platform was to annoy users — I'm serious," said Cross, speaking at the RSA Conference in San Francisco on Thursday. "Most users had administrator privileges on previous Windows systems and most applications needed administrator privileges to install or run."

Cross claimed that annoying users had been part of a Microsoft strategy to force independent software vendors (ISVs) to make their code more secure, as insecure code would trigger a prompt, discouraging users from executing the code.

"We needed to change the ecosystem," said Cross. "UAC is changing the ISV ecosystem; applications are getting more secure. This was our target — to change the ecosystem. The fact is that there are fewer applications causing prompts. Eighty percent of the prompts were caused by 10 apps, some from ISVs and some from Microsoft. Sixty-six percent of sessions now have no prompts," said Cross.

Cross claimed it is a myth that users just turn UAC off, saying that Microsoft had collected opt-in information from users which showed that 88 percent were running UAC. Cross said it was also a myth that users blindly accept prompts without reading them.

"It's a myth that users click 'yes', 'yes', 'yes', 'yes'," said Cross. "Seven percent of all prompts are cancelled. Users are not just saying 'yes'."

Security company Kaspersky has in the past severely criticised UAC, claiming in March last year that it would make Vista less secure than XP.

At this year's RSA Conference, however, the security specialist seemed to have changed its tune. Jeff Aliber, Kaspersky's US senior director of product marketing, said: "[With Windows], there is a large attack surface with a number of entry points," said Aliber. "Anyone trying to shrink that attack surface and promote secure apps development has to be a good thing."

Prior to the launch of Vista, Kaspersky issued a report in January 2007 which said UAC would be ineffectual. The company claimed that many applications perform harmless actions that, in a security context, can appear to be malicious. As UAC flashes up a warning every time such an action is performed, Kaspersky said that users would be forced to either blindly ignore the warning and allow the action to be performed or disable the feature to stop themselves going "crazy".

"If the user were to be notified about every one of these actions with a request for confirmation or a request to enter a password, the user will either go crazy or disable the security feature," said Kaspersky.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
11 out of 13 people found this useful


Company/Topic Alerts

Create a new alert from the list below:






Related Jobs

3rd line/Network Administrator-W\'dows,AD,Exchange 2003,Vmware,MCSE VCP

3rd line/ Network Administrator Windows/Linux, AD,Exchange 2003,Vmware,VDI ,Citrix, Presentation server 4.0, Networking, Firewalls, Banking ...

Helpdesk Support Analyst (1st/2nd Line Support)

You will be required to log all incidents from City of London Police customers received from all sources (including telephone, emails request forms ...

Unix / Linux Redhat Systems Administrator- Market Leaders- London

This is a great opportunity for the right candidate to be part of a team where their actions and decisions will help move technology and the business ...

Featured Talkback

So if you upgrade to XP SP3 you can't uninstall Internet Explorer, I'm quite sure I'm having a Deja-vu feeling about MS preventing people from uninstalling Internet Explorer in other Windows products.

By: TheKLF99

Read full story:
Upgraders to XP SP3 warned over IE downgrades

Desktop Management Benchmarking

Test Your Desktop Management Systems

How good are your company's desktop management solutions? How do they compare with those of your peers?

Take two minutes to complete our new Desktop Management and Energy Consumption benchmark, and find out what issues your business needs to focus on.