Windows IT Pro is the authoritative and independent resource for windows nt, windows 2000, windows 2003, windows xp. Features a collection of resources and magazines for windows IT professionals.
  
  
  Advanced Search 


August 30, 2006

Vista 2007's User Account Control Examined

RSS
Subscribe to Windows IT Pro | See More Windows OSs Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!

Only last January, before Beta 2 arrived and nearly a year before it'll finally be released, I started spending a serious amount of time with Microsoft's upcoming desktop OS, Windows Vista 2007. I don't usually make predictions about the final look of an OS so early in the beta process, as doing so is typically a fool's errand, but back then I'd have said that I could state one thing for certain about the final version of Vista: "That irritating User Account Control [UAC] thing has got to go."

As I said, I'd have been a fool to write the UAC comment, because I now see it as a useful tool. But not everyone--ahem--sees my point of view. So this month, let me take up the cause of what may well be Vista's most-hated feature. UAC, formerly called Limited User Access and then User Account Protection by Microsoft--and called a whole lot of things that we can't print by others--is an intrinsic piece of Vista intended to, among other tasks, reduce users' chances of inadvertently installing malware on their systems. I'm simplifying here, but basically UAC attacks malware by preventing malware's most common means of installation: deceiving a user into approving the malware installation. As anyone who's helped spyware victims knows, many users don't realize that running seemingly innocuous programs or clicking on hyperlinks might do more than let them play some fun game or see pictures of naked people; instead, the program or hyperlink is probably trying to fool those folks into lending that program or hyperlink their administrative permissions and privileges so that the malware

But how does UAC prevent users from installing malware? Again I'm simplifying, but basically anytime you do something that would require administrative powers, from installing a piece of software to changing your system time, UAC opens a dialog box that essentially says, "Hey, you seem to want to do something that's reserved for administrators; did you mean to do that?" That's why many Vista beta testers hate UAC. It's irritating. When I first saw the UAC prompts, I thought, "I'm sitting at MY computer, doing things that I want to do, and this blasted thing is raising my blood pressure by insulting me by questioning my intelligence. Off with its head!" So I shut it off, and told anyone who'd listen that they should do it, too. But then I had a revelation back in early June, when I was helping what seemed like the millionth person to remove 10 different pieces of spyware from her computer. Here's an intelligent person. Someone who works in a technical field other than computers, and yet she'd not only opened Pandora's box, she'd put an addition on the house to make the box's former occupants feel right at home.

Here's why we need UAC: Lots of computer users don't understand which actions can endanger their privacy and property, not to mention which actions might turn their systems into worm farms that slow the Internet to a crawl. Ignorance is a serious problem, and it needs serious medicine. I would guess that nearly everyone reading this has at least one spyware-removal story. The state of malware nowadays is easy to summarize: We're at war, and we're losing. Yes, UAC has annoyed me, although I got used to it. But heck, I find seat belts irritating--probably because I've been fortunate to not need them; had a seatbelt allowed me to walk away from a should-have-been-fatal crash, I suspect I'd feel differently. In the same way, I don't THINK I could be duped into installing malware on my system, but I could be wrong. UAC tapping me on the shoulder now and then to remind me that I'm doing something potentially dangerous might be as welcome one day.

Let me close with a few suggestions to the UAC haters among the Vista beta testers out there. First, I highly recommend that you give it a try; it really does become innocuous after a while. Second, remember that by beta testing software, you get a chance to influence the software's final look, so do that. Watch how UAC works and offer suggestions as to how it could look and perform better. I've run all of the betas and interim builds since the beginning of the year and have noticed significant decrease in UAC's intrusiveness. Offer Microsoft feedback on UAC now; after Vista ships, 90 percent of the Vista programmers will become Server 2007 programmers, and almost no one will be around to listen to what people don't like about UAC. Third, leaven any suggestions about how UAC could be better with your knowledge of how malware works: Malware is darned smart these days, and creating a UAC that catches only 80 percent of the common types of malware would be the worst of all things-- something that annoys us but that does not protect us. (Remember, only the airport security people get to do that kind of security and get paid for it.) And finally, remember if you truly can't live with UAC, you can always turn it off, either from the GUI or via Group Policy. But by making UAC the default behavior, Microsoft might save one of your friends or family members a heap of trouble!

End of Article



Reader Comments

You must log on before posting a comment.

If you don't have a username & password, please register now.




Top Viewed ArticlesView all articles
Friday at PASS Europe 2006

Kevin talks about the closing day of the event and shares a funny Microsoft film. ...

The Memory-Optimization Hoax

Don't believe the hype. At best, RAM optimizers have no effect. At worst, they seriously degrade performance. ...

VMware and the Future of Virtualization

What's next for virtualization and business IT? Windows IT Pro senior editor Jeff James speaks with VMware President and CEO Diane Greene on the future of virtualization technology. ...


Windows OSs Whitepapers Why SaaS is the Right Solution for Log Management

Are You Satisfied?

A Preliminary Look at Deployment Plans for Microsoft Windows Vista

Related Events Check out our list of Free Email Newsletters!

Windows OSs eBooks Understanding and Leveraging Code Signing Technologies

A Guide to Windows Certification and Public Keys

SQL Server Administration for Oracle DBAs

Related Windows OSs Resources Become a VIP member of the Windows IT Pro community!
Get it all with the VIP CD and VIP access. A $500+ value for only $279!

Subscribe to Windows IT Pro!
Solve your toughest technical problems with our experts and access 10,000 + articles online. 30% off

Monthly Online Pass - Only $5.95!
Get instant access to 10,000+ articles from Windows IT Pro Magazine!

TechNet Virtual Labs
Evaluate and test Microsoft's newest products.

Job Openings in IT


ADS BY GOOGLE SPONSORED LINKS FEATURED LINKS

IT Connections
Dive into the new Microsoft platforms and products you implement and support with the experts from Microsoft, TechNet Magazine, Windows ITPro and industry gurus. There are 70+ sessions and interactive panels with networking opportunities.

Attention User Group Leaders...
Announcing the eNews Generator—a FREE HTML e-newsletter builder for user group leaders. Build your HTML and text e-newsletters in minutes and add Windows IT Pro & SQL Server Mag articles alongside your own message!.

Master SharePoint with 3 eLearning Seminars
Learn how to build a better SharePoint infrastructure and enable powerful collaboration with MVPs Dan Holme and Michael Noel. Register today!

Get SQL Server 2008 at WinConnections
Don’t miss Microsoft Exchange and Windows Connections conferences, the premier events for Microsoft IT Professionals in Las Vegas, November 10-13. Every attendee will receive a copy of SQL Server 2008 Standard Edition with one CAL.



Interested in Email Encryption?
Read about the advantages of identity-based encryption in this free report.

Order Your SQL Fundamentals CD Today!
Learn how to use SQL Server, understand Office integration techniques and dive into the essentials of SQL Express and Visual Basic with this free SQL Fundamentals CD.

Virtualization Congress Oct. 14-16 in London
Don't miss Virtualization Congress, the premiere EMEA conference dedicated to hardware, OS and application virtualization. Oct. 14-16.
Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro Windows Dev Pro IT Job Hound ITTV
IT Library Technical Resources Directory Connected Home Windows Excavator Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 Copyright © 2008 Penton Media, Inc., All rights reserved. Terms and Use | Privacy Statement | Reprints and Licensing