Microsoft will change Windows 7 UAC

Reacting to intense criticism of an important security feature in Windows 7, Microsoft Corp. today said it will change the behavior of User Account Control (UAC) in Windows 7's release candidate.

"We are going to deliver two changes to the Release Candidate that we'll all see," said John DeVaan and Steven Sinofsky, two Microsoft executives responsible for Windows' development.

"First, the UAC control panel will run in a high integrity process, which requires elevation," said DeVaan and Sinofsky. "Second, changing the level of the UAC will also prompt for confirmation."

The changes, they said, were prompted by feedback from users, including comments appended to an earlier post Thursday by DeVaan in which he defended the modifications Microsoft made to UAC in Windows 7.

"Our dialog is at that point where many do not feel listened to and also many feel various viewpoints are not well-informed," DeVaan and Sinofsky said in the later blog post. "That's not the dialog we set out to have and we're going to do our best to improve."

The UAC feature, which debuted in 2007 as part of Windows Vista but was altered to reduce the number of prompts in Windows 7, has been under fire since last week, when two Windows bloggers, Rafael Rivera and Long Zheng, first reported that it could easily be disabled by attackers.

Yesterday, they followed up with more information about how hackers could piggyback on UAC-approved applications to fool Windows 7 into giving a malicious payload full administrative rights.

"This is definitely the result we've been looking for," Long said in an e-mail late Thursday. "[But] I'm a little bit shocked at just how quickly Microsoft has turned around, considering they made a post not 12 hours earlier stating that they would not change their position."

Rivera, Long and others urged Microsoft to reconsider the default setting of UAC in Windows 7. That default, which DeVaan said Microsoft had selected because people running Windows balked at dealing with more than two security prompts per day, was to "Notify me only when programs try to make changes to my computer."

Microsoft, however, won't be taking that tack. Instead, the next public version of Windows 7 -- dubbed RC, for release candidate -- will prompt the user before allowing any changes to UAC settings. "The way we're going to think about this [is] that the UAC setting is something like a password, and to change your password you need to enter your old password," DeVaan and Sinofsky said today.

Microsoft has not spelled out a Windows 7 RC timetable, but Sinofsky reiterated last week that the development process was moving straight from the public beta, which was launched Jan. 10, to the release candidate. In the past, the company has delivered multiple betas before moving to the RC milestone.

The other change to be implemented in Windows 7 RC will effectively render moot the proof-of-concept attack that Rivera and Long published last week, which silently disables UAC. "That was already in the works before this discussion and doing this prevents all the mechanics around SendKeys and the like from working," DeVaan and Sinofsky said.

They didn't issue an apology for the dust-up, but said Microsoft had erred when deciding how to implement UAC in Windows 7. "We said we thought we were bound to make a mistake in the process of designing and blogging about Windows 7."

"We want to continue the dialog and hopefully everyone recognizes that engineering, perhaps especially engineering Windows 7, is sometimes going to be a lively discussion with a broad spectrum of viewpoints," they said.

One security professional praised Microsoft's move. "This goes back to what beta programs are supposed to provide: feedback from a real audience," said Andrew Storms, director of security operations at nCircle Network Security Inc.

"This was an obvious design flaw, and for them to say they simply weren't going to fix it, that was the real problem," Storms said. "I think they realized that they needed to do something, more over the concern about their reaction than to the vulnerability itself."

Source : www.computerworld.com

19 comments:

Unknown said...

Security has never been Microsoft's strength. Useful info !!

Stephen said...

Microsoft offers no security in fact. :D

-http://bigcashmaker.blogspot.com

Anonymous said...

I hope they optimize the UAC feature, on windows vista I had to turn off this feature because it is too often ask for confirmation.

Islamist writer, Mohammad Yousuf mlaifi said...

thank you very much

websites directory said...

thanks for the nice Blog :)

new websites said...

Thank you very much

web search said...

Thank you for your wonderful efforts

Alex said...

<a href="http://www.thelaptopcentral.info> Click Here</a> For great deals on PCs and other computer accessories.

sites like service said...

Thank you very much for your wonderful

whois domain find said...

Your article more than wonderful ... Good luck

kayan Association said...

Thank you for this wonderful blog

how to do it easy said...

Thank you very much for your wonderful

Francis Bonto said...

Its good to know about that but i think it need high performance hardware like a high operating processor to meet its features..

runtime error 429 windows 7 said...

Hi,

very useful information you are mentioned in your post.there is no security system in Microsoft.
Thanks

video streaming said...

Great Post having useful information.....

streaming video said...

Good Article it is...i realy like it

Stop 0x00000124 said...

hi...
wonderful blog.its very informative.Very good effort.
thanks.

real estate said...

hi...
very informative blog.great to learn the post
.its a very good effort,keep it up.
thank u so much
thanks.

error 1310 windows 7 said...

Its good news to hear, their are a lot of security issues with Microsoft.

Recent Comments

Partner Site :

Critics, Comments, Suggestion, Concerns

Computers Science Desktop PCs Laptops / Notebooks Network Internet Maintenance and Troubleshooting Cool Windows Guide, Tips and Tricks PC Games
Add to Technorati Favorites Top Blogs blogarama - the blog directory Computers Computers blogs Hardware Blogs - Blog Catalog Blog Directory
Search Engine Optimization and SEO Tools
Template by KangNoval & Abdul Munir | blog Blogger Templates