3 ms·
Have they changed their policy on UAC not being considered security barrier on administrator accounts since W10? Windows was screwed for a long time[1], in prac
by RaleyField 8y ago
Have they changed their policy on UAC not being considered security barrier on administrator accounts since W10? Windows was screwed for a long time[1], in practice not much better than running in SYSTEM all the time like in Windows 95 days.
[1] http://www.istartedsomething.com/20090611/uac-in-windows-7-still-broken-microsoft-wont-fix-code-injection-vulnerability/ http://www.istartedsomething.com/20090611/uac-in-windows-7-s...
- temac 8y agoI'm not sure even sure they will ever change it. It was designed for Vista using a security model that now corresponds to the "always ask" setting, and hastily changed to propose the two other settings for Windows 7 because users were thinking it asked too often. But the other settings do not even correspond to a sound security model, so there are hundreds or maybe thousands of bypass in Windows if using those, which include the setting by default. That's why MS simply declared that it is not a security boundary, because they had no sound model to make it work against. It's a "best effort" casual mitigation.