4 ms·
> That's why the Windows security model is so silly. An administrator is not allowed to 'su' to another user without the user's password but any reasonable subs
by wfunction 11y ago
> That's why the Windows security model is so silly. An administrator is not allowed to 'su' to another user without the user's password but any reasonable subset of the administrator's privileges can be used to silently cause any user to execute arbitrary code
That's like saying kernel memory protection is silly when the user is an admin because he could just as well load a driver into the system to wreak whatever havoc he wants.
Yes, he could. No, it's not silly.
- AnthonyMouse 11y agoMemory protection is not silly. Not being able to bypass memory protection (and therefore prohibiting all manner of debugging tools) is silly, and that is the appropriate analogy. If a user correctly has permission to do a thing via a series of ugly hacks then there is no reason not to just let the user do the thing directly.