Latest Entries

UAC isnt a security feature, really?

Thursday, February 22nd, 2007

The press has been having a field day with headlines like this one due to a recent post by Mark Russinovich which explains how UAC Windows Vista 031.jpgand its integrity levels (user rights separation) work, among other things. The part of the post that people grabbed onto was his statement that ‘It should be clear then, that neither UAC elevations nor Protected Mode IE define new Windows security boundaries." he goes on to say "Because elevations and ILs don’t define a security boundary, potential avenues of attack , regardless of ease or scope, are not security bugs."

What does all this mean? Well it can be really confusing to be honest. Mark has a wonderfully detailed post that, well, you can get lost in the details of. Microsoft press materials don’t really make this any clearer as they can refer to it as increasing security or helping with trust…. So lets take this down a notch to better understand it. Josh’s Windows Weblog : UAC isn’t a security feature, really?

Popular Posts

Comments are closed.


Please read our Disclaimer