I have been appalled at what has taken place over the last week. And now that it is over, I want to talk
I have been appalled at what has taken place over the last week. And now that it is over, I want to talk
If you weren't at the TED conference this week, you might've missed Bill Gates' mosquito stunt as noted
The problem is, with the current settings the UAC prompts for third-party apps are security theater that only punish well-behaved software.
Anything that wants to can bypass UAC completely, as I've shown here:
http://leo.lss.com.au/W7E_VID_INT/W7E_VID_INT.htm
http://leo.lss.com.au/W7E_VID_DRA/W7E_VID_DRA.htm
Those videos made late night show an updated of my earlier proof-of-concept code-injection technique. It doesn't use RunDll32 or SendKeys. It can hijack any "blessed" Microsoft executable running at medium integrity (i.e. normal, elevated), including Explorer.exe, Calc.exe, Notepad.exe, MSPaint.exe... (Why on earth have you given all of those apps the ability to bypass UAC when creating COM objects? Why extend the attack surface to Calc.exe etc.?)
Given that any process can use this fairly simple technique to elevate anything it wants, the UAC prompts in Windows 7 with default settings offer virtually no protection.
Thus you should either remove them from *all* apps (i.e. the "elevate without prompting" option which was already in Vista's UAC) or you should make them secure again by default.
I don't really care which you do so long as I can turn on "always prompt" but what you're doing right now is a) Security theater, since it offers only the illusion of protection which can be bypassed trivially; and b) Anti-competitive, since people who compete with your bundled administrative and/or file management software are forced to either show UAC prompts or use dodgy workarounds.
And going back to it, there really is no excuse for apps like Calc, Notepad and Paint to have access to full UAC elevation without prompting.
when ever i try to use google chrome user account dialog box appears asking for a permission.....can u tell me how to remove this!!!!
hope u will reply soon......