3 ms·
I’ve really come to the conclusion that OS users are merely policy barriers and not security barriers (or at least, not strong barriers). This seems to be the
by invokestatic 5y ago
I’ve really come to the conclusion that OS users are merely policy barriers and not security barriers (or at least, not strong barriers). This seems to be the position of Microsoft as well, given their stance on UAC and privilege escalation exploits in general.
I think it’s akin to real-life locks. Keeps good guys out, but not a determined attacker.
- hsbauauvhabzb 5y agoI mostly agree but it’s also pretty hard to LPE on modern hardened windows or Linux. Not impossible, but enough that low tier attackers can’t do it.
- eternityforest 5y agoYou don't need to though. Most desktops only have one user, and you can do plenty of bad stuff without root.