internet.com
You are in the: Small Business Computing Channelarrow
Small Business Technology
» ECommerce-Guide | Small Business Computing | Webopedia | WinPlanet

WinPlanet Software Downloads and Reviews for Small Businesses
Search
Power Search | Tips
-
Navigate WinPlanet
WinPlanet Home Page

Software
Download Index
In-Depth Reviews
Tips & Tutorials
Updates
News

Software Categories
Browsers
Chat / Conferencing
Desktop Utilities
Development
Internet Apps
Multimedia
OS Service Packs
Productivity Tools

Software Glossary

WinPlanet Newsletter

internet.commerce
Partners & Affiliates













Small Business Computing
Small Business Computing
Ecommerce Guide
Webopedia
WinPlanet

WinPlanet / News

Download of the day
Adobe Flash Player

Most Popular Software Downloads
Windows Vista Service Pack 2 (Vista SP2)
Mozilla Firefox 3
QuickTime for Windows
Adobe Flash Player
Windows 7
Norton Internet Security 2010
Internet Explorer 8
CCleaner (Crap Cleaner)
Winamp
Skype

Most Popular Software Articles
Windows Vista Tips: Home Networking Setup Tutorial
10 Must-Have Apps: The Free Windows Networking Toolkit
How to Make Your Internet Connection Faster, Better


Software Reviews

Microsoft Caves In to Users on Windows 7 Security
Windows 7's Vaunted Security Is Flawed
Stuart J. Johnston

Windows 7's vaunted security is flawed. The good news is that, despite initial responses denying it, Microsoft announced today that it plans to deliver a comprehensive fix soon.

After a week of denying that the default setting for Windows 7's User Account Control (UAC) is too easy to compromise and could lead to malware disabling the very mechanism that's meant to keep users safe from attacks, Microsoft Thursday caved in to users' demands.

If not fixed, many observers had said in their harangues, the issue could turn out to be Windows 7's Achilles' heel. In fact, Microsoft claimed as recently as early in the day on Thursday that Windows 7's UAC default settings are not flawed at all, but rather constitute a feature created "by design."

Further, the company argued, an attack program would already have to be installed on the user's PC in order to exploit the two holes in UAC found by third-party developers, a Microsoft executive insists. For that to happen, Microsoft asserts, the user would need to click to allow a malware download to the user's PC in the first place.

A few hours later, things changed. "We are going to deliver two changes to the [Windows 7] Release Candidate that we'll all see. First, the UAC control panel will run in a high integrity process, which requires elevation … Second, changing the level of the UAC will also prompt for confirmation," said a joint posting on the Engineering Windows 7 blog Thursday afternoon.

The post was co-signed by Steven Sinofsky, senior vice president of Windows and Windows Live Engineering, and Jon DeVaan, senior vice president of the Windows Core Operating System Division.

Windows 7 is currently in beta test and is in the hands of literally millions of users. The system has largely gotten rave reviews, including one group of hardcore fans that have started an online petition demanding the beta be terminated now and the software released immediately.

Microsoft continues to maintain Windows 7 will ship in the first quarter of 2010. In actuality, however, Windows 7 is expected to reach the release candidate stage of testing — the last testing step before commercial release — by the end of April. That's when the changes to UAC will be added.

Observers still differ on their bets as to when Windows 7 will actually be released — with estimates running from early June to late summer — but it will most certainly be available for the Christmas sales season, barring any showstopper bugs turning up between now and then.

A Familiar Headache

UAC is not new. It debuted with Windows Vista as a way to doublecheck that changes to the operating system — such as installing new programs — are done under the auspices of high-quality security, including passwords that must be keyed in before such an installation proceeds.

While Vista's UAC got high marks for security, it was too disruptive for many users. In fact, many users became so frustrated with the constant dialog boxes and prompts popping up, asking for a password before continuing, that they simply disabled UAC altogether, thus defeating UAC's purpose.

With Windows 7, Microsoft changed the defaults for UAC at what it insists was users' request. The current default in Windows 7 is to notify the user and ask for permission to download a file or install a program only if that action is triggered by a script, but not if the user is clearly interacting with Windows 7 him or herself. This lessens the number of prompts that the user needs to respond to, but makes a tradeoff on the quality of Windows 7's security.

However, what if an attacker could write a script that did a good job of pretending to be a human keying in changes — such as turning off UAC or elevating the script's user rights? That's the rub.

The problems were initially publicized late last week by several blogger developers, including Rafael Rivera and Long Zheng. The second problem, the ability for a script to upgrade its user rights to a higher administrative level, surfaced earlier this week.

"A change to User Account Control (UAC) in Windows 7 (beta) to make it 'less annoying' inadvertently clears the path for a simple but ingenious override that renders UAC disabled without user interaction," said a post on Zheng's blog.

Microsoft officials, meanwhile, insisted that the problems were overblown. "Microsoft's position that the reports about UAC do not constitute a vulnerability is because the reports have not shown a way for malware to get onto the machine in the first place without express consent [of the user]," said a blog post by DeVaan earlier Thursday [February 5].

A lot can change in just a few hours, though, as the later joint posting reveals.

"The feedback is that UAC is special, because it can be used to disable silently future warnings if that change is not elevated and so to change the UAC setting an elevation will be required," reads the late afternoon joint post.

Just Dump Administrator Access?

Of course, one thing to do is to take advantage of other Windows security features to mitigate the problems. For instance, security management firm BeyondTrust published a report on Tuesday stating that its research shows that 92 percent of "critical Microsoft vulnerabilities" can be ameliorated by simply eliminating administrators' rights from users' systems.

That could be annoying for both corporate and consumer users, however, and defeats one of UAC's goals, which is to reduce demands on administrators' time and enable users to perform some of their own security tasks. For consumers, it means logging off their user accounts, logging into separate administrator's accounts and performing the needed tasks, then logging back in as users.

One leading security expert says that he thinks Microsoft's heart is in the right spot.

"What they're trying to do is improve the usability of UAC," Johannes Ulrich, chief research officer for the SANS Internet Storm Center, told InternetNews.com. "If it frustrates the users, they'll just turn it off."

Perhaps one thing that got Microsoft executives' attention was the fact that Long Zheng and Rivera, as well as others, posted proof-of-concept code to disable UAC in Windows 7. Additionally, they also posted a homegrown fix for both holes.

The Internet Storm Center's Ulrich says there will always be tradeoffs between protecting users and allowing them to have more control of their systems.

" What it would really take is a completely new operating system, but for Windows 7 this is the best you can expect," Ulrich added.

News courtesy of internetnews.com

February 6, 2009

Download Windows 7 Now!Download

Download Windows Vista SP2 Now!Download

View All Microsoft Software

Contents:
1. Windows 7's Vaunted Security Is Flawed


Additional Articles:

  • 2010 for Next Big Windows Release?
  • Microsoft's 'Windows 7' Gets Antitrust Checkup
  • Gates Provides More Windows 7 Details
  • No New Kernel on Tap for Windows 7
  • Windows 7 to Feature Multi-Touch
  • Three Things You Need to Know About Windows 7
  • More IT Shops Plan to Wait for Windows 7
  • Microsoft Opens Windows to Version 7 with Blog
  • Windows 7 Looking Like a June 2009 Delivery
  • It's Official: Windows 7 at PDC, WinHEC
  • Is Windows 7 Really Mojave?
  • Windows 7: It's Not Just a Codename Anymore
  • PDC Is Not Just the Windows 7 Show
  • What to Expect from Windows 7
  • Windows 7 Gets Its Coming-Out Party
  • Windows 7 May Trigger 64-bit OS Adoption
  • Windows 7 Build Already Leaked on Torrent Sites
  • Windows 7 Drivers to Get a Makeover
  • Microsoft Plans Windows 7 Beta for Mid-January
  • Pirates Snag Latest Windows 7 Build
  • Official Windows 7 Beta Build Leaks to BitTorrent
  • Windows 7 Beta On Tap for Ballmer's CES Keynote
  • Ballmer to CES: Windows 7 Beta Off and Running
  • New Signs Point to Summer Ship for Windows 7
  • Windows 7 Demand Clogs Beta Download Servers
  • UI Reporting Bug Causes Windows 7 Crashes
  • Does Windows 7 Threaten Mac OS and Linux?
  • Clock's Ticking on Windows 7 Public Beta
  • Is a Windows 7 'Release Candidate' Near?
  • Windows 7 Packaging Includes XP Upgrades
  • Windows 7's Worst-Kept Secret? Its Release Date
  • Will Windows 7 Be a PC Mover?
  • Windows 7 Inches Ahead Amid Leaks on Ship Date
  • Leaked Windows 7 Build Lets Users Turn Off IE8
  • Windows 7 Early Looks: First Impressions and Future Possibilities
  • Windows 7 Set to Get Compatibility Tester
  • Another Windows 7 'Release Candidate' Leaks
  • Windows 7 Gets More Cosmetic Tweaks
  • Gartner: Don't Wait for Windows 7 SP1
  • Has Windows 7's Release Candidate Slipped?
  • Survey: 83% of IT Shops Will Skip Vista
  • Windows 7 RC Goes to Partners
  • Microsoft Bets on Low-End Windows 7 for Netbooks
  • Is Microsoft Readying 'XP Mode' for Windows 7?
  • Windows 7 'Release Candidate' Due Next Week
  • Windows 7 'Release Candidate' Debuts for Some
  • Get Ready for Windows 7 'Release Candidate'
  • Is Windows 7 Really Mojave? (Part II)
  • Windows 7 Virtualization Leaves Some CPUs Out
  • After the Wait, Windows 7 Is Almost Here
  • Microsoft: Windows 7 in Time for the Holidays
  • Windows 7: Three Months Until 'RTM?'
  • Gartner: 'Deployed Vista? No? Skip to Windows 7'
  • Windows 7 Starter Edition App Limits Lifted
  • It's a Date: Windows 7 Available on October 22
  • Best Buy Memo Hints at Windows 7 Pricing
  • Microsoft to Ship Windows 7 in Europe Without IE
  • Counting Down to Windows 7 Free Upgrades
  • Most Windows 7 Prices Same as Vista, Others Fall
  • Analyst Criticizes Windows 7 Upgrade Limit
  • Windows 7 Beta Users: Welcome to Shutdown Hell
  • Is Windows 7 Release to Manufacturing Imminent?
  • Most Enterprises May Avoid Windows 7: Study
  • Windows 7 Early Looks: Why I Like Windows 7
  • Windows 7 Almost 'Released to Manufacturing?'
  • Write a Win7 App, Win $17,777
  • Lots of Users Will Get Windows 7 Early
  • Windows 7 Released to Manufacturing
  • Microsoft: Rival Browsers May Ship in Windows 7
  • Hasta la Vista, Baby. Hello Windows 7
  • Microsoft's Details Windows 7 Family Pack Deal
  • Windows 7 to Get Internet Explorer in Europe
  • Windows 7 'XP Mode' Nears Release
  • Will a 'Bug' Derail Windows 7 Launch?
  • TechNet and MSDN Subscribers Download Windows 7
  • Last Chance to Try Windows 7 'Release Candidate'
  • Bad Marks for Windows 7 on Netbook Battery Life
  • Free Software Group Lobbies Against Windows 7
  • It's Unofficial: Windows 7 Gala Slated for NYC
  • Microsoft Delivers Windows 7 Embedded 'Preview'
  • Microsoft Offers Free Trial for Windows 7
  • Is Windows 7 on Patch Tuesday Agenda?
  • Hold a Launch Party, Earn Windows 7 Ultimate
  • Did Windows 7 Get Its First Zero-Day Exploit?
  • Microsoft Takes to the Airwaves for Windows 7
  • Windows 7 Install May Take an Hour or a Day
  • Students Get a Deal on Windows 7
  • Windows 7-Compatible Products Surpass 6,000
  • 'XP Mode' Ready by Windows 7 Consumer Rollout
  • Windows 7 Already Stealing Market Share from Vista
  • Windows 7 May Trigger IT Upgrade Cycle After All
  • All Quiet on the Windows Front
  • Reports Find IT Poised to Adopt Windows 7 Soon
  • Windows 7 Early Looks: Improvements May Finally Satisfy SMBs
  • Countdown to Windows 7
  • Windows 7 Tips & Tricks: Tips for Upgrading from XP to Windows 7
  • Windows 7: It's Here
  • Windows 7 Launch: Microsoft's Big Bet on a New OS
  • Windows 7 Launch Hits Some Snags
  • Windows 7 Tips & Tricks: Five Tips for Getting Started with Windows 7
  • Libraries Give Vista Apps a Windows 7 Look
  • Windows 7 'Full Upgrade' Hack Is Illegal
  • Windows 7 Tips & Tricks: Surviving a Windows 7 Upgrade
  • Windows 7 Shows Signs of Early Gains
  • Windows 7 Drives a 49% Spike in PC Sales
  • Netbook Buyers Don't Want Windows 7 'Starter'
  • Windows 7 Gets Its First 'Zero Day'
  • Windows 7 Sales 'Fantastic,' Ballmer Says
  • Windows 7: From Beta to Final Code in One Year
  • Microsoft: No 'Back Door' in Windows 7


  • internet.commediabistro.comJusttechjobs.comGraphics.com

    Search:

    WebMediaBrands Corporate Info

    Legal Notices, Licensing, Permissions, Privacy Policy.
    Advertise | Newsletters | Shopping | E-mail Offers | Freelance Jobs