3 ms·
I largely concur with Raymond Chen's reasoning on the subject. However, there are two distinct factors Microsoft does not seem to realize as problems: 1. There
by Genbox 4y ago
I largely concur with Raymond Chen's reasoning on the subject. However, there are two distinct factors Microsoft does not seem to realize as problems:
1. There has been a precedent in Windows to run everything as local administrator. Linux has always had the user vs. root paradigm, but Windows - at least in the client versions - has always just defaulted to administrative accounts.
2. Features designed to provide more fine-grained control of token privileges, such as UAC, process integrity, and virtualization, have been excluded from security bug bounties as being "not a real security boundary". This stance is somewhat counterintuitive and quite dangerous.
Combine those two with the fact that Microsoft never provided sane secure defaults for any of their software; it just goes to show that Microsoft is not concerned nor bothered with securing their software.
That shifts the issue of "don't run as admin, stupid" responsibility from the user to Microsoft to a large extent.
- ocdtrekkie 4y agoI think the core issue is Windows has always prioritized consumer usability, and that often, yes, means worse security defaults. I only finally stopped being an admin on my personal PC's main account a couple months ago, and I consider myself a security person. ;)