Posted By: vesuvius | Jun 18th @ 12:19 PM
page 1 of 1
Comments: 7 | Views: 652
vesuvius
vesuvius
Das Glasperlenspiel

Mark Russinovitch constructs a disquisition. I know people have been complaining about how out of date information is, this is hot off the press.

CannotResolveSymbol
CannotResolveSymbol
{insert caption here}

You do realize that's the article that started this most recent bit of controversy, right?

stevo_
stevo_
Human after all

I don't think it specifically was, the uac thing started from a guy who posted a proof of concept.. which has been more pimped by that 'long .. (sorry, cant remember)' guy..

The final result comes down to being attack by either downloading a malicious program, or because a vulnerability in an app you use.. in which case in vista this would be a uac confirm dialog, and in 7 wouldn't (it would just run)..

In the event you just downloaded an ran a program, you are of course going to just hit accept on the uac confirmation dialog.. why wouldn't you- you just downloaded it, it was your intent to run it..

In the case of a vulnerable app, the uac confirm dialog would appear to come from the app you trust- and you will probably again trust it..

Theres a certain few more expert users who would perhaps not accept the exploited app vector, but those are the few- and the people who would know about how 7 works, and potentially adjust UAC anyway..

 

I've always thought this exploit was a complete non-issue.. however the media is going to run with this, so why wouldn't you fix it.. the E7 blog has already talked about making a change not because it was a flaw, but because of user perception (can't remember what it was).. so clearly MS understands the reasoning behind doing the change.. clearly the problem is that they CANT fix it..

Which makes me conclude.. why the f-- are we still going on about it then? wheres the accomplishment, MS probably agrees on some level they should fix this, but CANT, and thats not a big deal.

(although they may find a way, and change behavior in a service pack- who knows).

page 1 of 1
Comments: 7 | Views: 652
Microsoft Communities