Free Republic 3rd Qtr 2025 Fundraising Target: $81,000 Receipts & Pledges to-date: $2,910
3%  
Woo hoo!! 3rd Qtr 2025 FReepathon is now underway!!

Keyword: defectivebydesgn

Brevity: Headers | « Text »
  • Hacker, Microsoft duke it out over Vista design flaw (UAC broken by design)

    02/13/2007 10:59:28 PM PST · by Spktyr · 60 replies · 1,665+ views
    ZDNet ^ | 13 Feb 07 | Ryan Naraine
    Joanna Rutkowska has always been a big supporter of the Windows Vista security model. Until she stumbled upon a "very severe hole" in the design of UAC (User Account Control) and found out — from Microsoft officials — that the default no-admin setting isn't even a security mechanism anymore. Joanna Rutkowska Rutkowska, a hacker with a track record of defeating Vista's security mechanisms, believes UAC has a major flaw in the way it automatically assumes that all setup programs (application installers) should be run with administrator privileges. "[When] you try to run such a program, you get a UAC prompt...