<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: UAC in 7: Silent Attack Vector Multiplier (redux)</title>
	<atom:link href="http://winjade.net/2009/06/uac-in-7-exponential-silent-attack-vector-multiplier-redux/feed/" rel="self" type="application/rss+xml" />
	<link>http://winjade.net/2009/06/uac-in-7-exponential-silent-attack-vector-multiplier-redux/</link>
	<description>Just another WordPress weblog</description>
	<lastBuildDate>Fri, 20 Nov 2009 03:01:11 -0500</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: AeroXperience &#187; Blog Archive &#187; Microsoft lists UAC hack as malware, kinda</title>
		<link>http://winjade.net/2009/06/uac-in-7-exponential-silent-attack-vector-multiplier-redux/comment-page-1/#comment-973</link>
		<dc:creator>AeroXperience &#187; Blog Archive &#187; Microsoft lists UAC hack as malware, kinda</dc:creator>
		<pubDate>Thu, 30 Jul 2009 19:26:24 +0000</pubDate>
		<guid isPermaLink="false">http://www.aeroxp.org/2009/06/uac-in-7-exponential-silent-attack-vector-multiplier-redux/#comment-973</guid>
		<description>[...] those involved in the Windows 7 community may know, Microsoft has failed to fix a crucial flaw in the User Account Control feature of the operating system which allows a specific whitelist of [...]</description>
		<content:encoded><![CDATA[<p>[...] those involved in the Windows 7 community may know, Microsoft has failed to fix a crucial flaw in the User Account Control feature of the operating system which allows a specific whitelist of [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: SolidJediKnight</title>
		<link>http://winjade.net/2009/06/uac-in-7-exponential-silent-attack-vector-multiplier-redux/comment-page-1/#comment-969</link>
		<dc:creator>SolidJediKnight</dc:creator>
		<pubDate>Fri, 19 Jun 2009 10:31:38 +0000</pubDate>
		<guid isPermaLink="false">http://www.aeroxp.org/2009/06/uac-in-7-exponential-silent-attack-vector-multiplier-redux/#comment-969</guid>
		<description>This is the one issue where Microsoft is definitely stuck between a rock and the hard place. A too aggressive UAC like in Vista is highly unpopular. However, to us enthusiasts/techno saavy crowd, a towned down UAC isn&#039;t secure enough. Do you please the masses or do you &quot;dumb it down to double your dollars&quot; as rapper Jay Z once rhymed. In many cases, if you want success, the original intention is going to get toned down. That has been and always will be the price for success. Essentially and just on principle, I agree with you guys that a strong UAC should be win Windows 7, I completely understand why Microsoft HAS no choice but to dumb it down. It gives way too much ammunition for the anti-Microsoft/hard core Mac fans/hard core Linux fan crowd to bash away and let it stick.

I think Microsoft&#039;s counter attack should be working with other background and otherwise silent defenses within Windows. If the internal defense, stronger firewalls, whitelist/blacklist defense, and other methods should be part of the solution, the hardware layers of security also have to be strengthened too. Microsoft has to keep attacking security in ways that are invisible but still very relevant to protecting users from themselves. Howerver, a lot of the reason why Windows has so many problems is that the vast majority of the userbase is very ignorant in how PC&#039;s work and how to browse safely. Many of Windows issues wouldn&#039;t be as much of an issue if PC fundamentals, PC ethics, intermediate PC education, and advanced PC skills were taught to our children in Elementary, Middle School, and High School as part of the mandatory curriculum.

However, there are some people saying that the x64 version of Windows 7, that this RCE doesn&#039;t even work. That this might be limited to just 32 bit versions of Windows 7. While I do appreciate the war being waged, this is a very fine line we have to walk here.</description>
		<content:encoded><![CDATA[<p>This is the one issue where Microsoft is definitely stuck between a rock and the hard place. A too aggressive UAC like in Vista is highly unpopular. However, to us enthusiasts/techno saavy crowd, a towned down UAC isn&#8217;t secure enough. Do you please the masses or do you &#8220;dumb it down to double your dollars&#8221; as rapper Jay Z once rhymed. In many cases, if you want success, the original intention is going to get toned down. That has been and always will be the price for success. Essentially and just on principle, I agree with you guys that a strong UAC should be win Windows 7, I completely understand why Microsoft HAS no choice but to dumb it down. It gives way too much ammunition for the anti-Microsoft/hard core Mac fans/hard core Linux fan crowd to bash away and let it stick.</p>
<p>I think Microsoft&#8217;s counter attack should be working with other background and otherwise silent defenses within Windows. If the internal defense, stronger firewalls, whitelist/blacklist defense, and other methods should be part of the solution, the hardware layers of security also have to be strengthened too. Microsoft has to keep attacking security in ways that are invisible but still very relevant to protecting users from themselves. Howerver, a lot of the reason why Windows has so many problems is that the vast majority of the userbase is very ignorant in how PC&#8217;s work and how to browse safely. Many of Windows issues wouldn&#8217;t be as much of an issue if PC fundamentals, PC ethics, intermediate PC education, and advanced PC skills were taught to our children in Elementary, Middle School, and High School as part of the mandatory curriculum.</p>
<p>However, there are some people saying that the x64 version of Windows 7, that this RCE doesn&#8217;t even work. That this might be limited to just 32 bit versions of Windows 7. While I do appreciate the war being waged, this is a very fine line we have to walk here.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jug</title>
		<link>http://winjade.net/2009/06/uac-in-7-exponential-silent-attack-vector-multiplier-redux/comment-page-1/#comment-972</link>
		<dc:creator>Jug</dc:creator>
		<pubDate>Mon, 15 Jun 2009 07:44:40 +0000</pubDate>
		<guid isPermaLink="false">http://www.aeroxp.org/2009/06/uac-in-7-exponential-silent-attack-vector-multiplier-redux/#comment-972</guid>
		<description>I don&#039;t think Microsoft will try to deny anything that they&#039;ve said, they just won&#039;t comment on it. Inofficially, I suppose they&#039;re simply changing why UAC is there, as I fail to believe they have already forgot why they added UAC...</description>
		<content:encoded><![CDATA[<p>I don&#8217;t think Microsoft will try to deny anything that they&#8217;ve said, they just won&#8217;t comment on it. Inofficially, I suppose they&#8217;re simply changing why UAC is there, as I fail to believe they have already forgot why they added UAC&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: VeraBlue</title>
		<link>http://winjade.net/2009/06/uac-in-7-exponential-silent-attack-vector-multiplier-redux/comment-page-1/#comment-971</link>
		<dc:creator>VeraBlue</dc:creator>
		<pubDate>Sat, 13 Jun 2009 04:17:51 +0000</pubDate>
		<guid isPermaLink="false">http://www.aeroxp.org/2009/06/uac-in-7-exponential-silent-attack-vector-multiplier-redux/#comment-971</guid>
		<description>Since day one, when I first touched build 6801, I always set UAC to the &quot;always notify&quot; setting... my reasons for doing so should be apparent.  Through what is basically a marketing gimmick, Windows 7 is less secure than Vista.  MSFT should of have left the settings as they were in Vista, set to &quot;always notify&quot;.  Under normal circumstances, when set to the highest level the UAC dialogue rarely pops up.</description>
		<content:encoded><![CDATA[<p>Since day one, when I first touched build 6801, I always set UAC to the &#8220;always notify&#8221; setting&#8230; my reasons for doing so should be apparent.  Through what is basically a marketing gimmick, Windows 7 is less secure than Vista.  MSFT should of have left the settings as they were in Vista, set to &#8220;always notify&#8221;.  Under normal circumstances, when set to the highest level the UAC dialogue rarely pops up.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sam Johnson</title>
		<link>http://winjade.net/2009/06/uac-in-7-exponential-silent-attack-vector-multiplier-redux/comment-page-1/#comment-967</link>
		<dc:creator>Sam Johnson</dc:creator>
		<pubDate>Fri, 12 Jun 2009 20:03:33 +0000</pubDate>
		<guid isPermaLink="false">http://www.aeroxp.org/2009/06/uac-in-7-exponential-silent-attack-vector-multiplier-redux/#comment-967</guid>
		<description>So much for &#039;less annoying to be secure&#039; as a selling point.  This is definitely not okay and I cannot believe Microsoft will not change it; they did well fixing the other issue earlier this year.</description>
		<content:encoded><![CDATA[<p>So much for &#8216;less annoying to be secure&#8217; as a selling point.  This is definitely not okay and I cannot believe Microsoft will not change it; they did well fixing the other issue earlier this year.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Bryant</title>
		<link>http://winjade.net/2009/06/uac-in-7-exponential-silent-attack-vector-multiplier-redux/comment-page-1/#comment-970</link>
		<dc:creator>Bryant</dc:creator>
		<pubDate>Fri, 12 Jun 2009 19:20:16 +0000</pubDate>
		<guid isPermaLink="false">http://www.aeroxp.org/2009/06/uac-in-7-exponential-silent-attack-vector-multiplier-redux/#comment-970</guid>
		<description>Crap. Good point about robots.txt. /saves page</description>
		<content:encoded><![CDATA[<p>Crap. Good point about robots.txt. /saves page</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Yert</title>
		<link>http://winjade.net/2009/06/uac-in-7-exponential-silent-attack-vector-multiplier-redux/comment-page-1/#comment-968</link>
		<dc:creator>Yert</dc:creator>
		<pubDate>Fri, 12 Jun 2009 18:56:05 +0000</pubDate>
		<guid isPermaLink="false">http://www.aeroxp.org/2009/06/uac-in-7-exponential-silent-attack-vector-multiplier-redux/#comment-968</guid>
		<description>You forget that they can change their robot.txt file to have the Internet Archive delete the archived pages. Keep a local copy. :P

And I find it interesting that Russinovich won&#039;t even call it a security feature. Elevation is first and foremost about security, and users who were actually concerned about the concept of LUA, not having to go with XP&#039;s Run As when on a Limited Account was a godsend. Thankfully you can still turn on UAC if you want the security; the issue now is that the default is branded as safe when perhaps it should not be.</description>
		<content:encoded><![CDATA[<p>You forget that they can change their robot.txt file to have the Internet Archive delete the archived pages. Keep a local copy. <img src='http://winjade.net/wp-includes/images/smilies/icon_razz.gif' alt=':P' class='wp-smiley' /> </p>
<p>And I find it interesting that Russinovich won&#8217;t even call it a security feature. Elevation is first and foremost about security, and users who were actually concerned about the concept of LUA, not having to go with XP&#8217;s Run As when on a Limited Account was a godsend. Thankfully you can still turn on UAC if you want the security; the issue now is that the default is branded as safe when perhaps it should not be.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
