Microsoft Apologises; To Fix Win 7 UAC Flaw
Earlier this week, Tom's Hardware reported that there was an inherent security flaw in the newly renovated User Account Control (UAC) built into the current Windows 7 beta build 7000. Microsoft has listened to the critics and has released details of their fix to address the problem.
At first Microsoft brushed off the issue as "by design," that is, it won't prompt users as much as in Vista which is what it was aiming for. But because the default UAC setting prevents changes to UAC from causing a secure desktop prompt, malicious code can alter the settings and even disable UAC without the user knowing it. Viruses and other malware can then run wild on the system with full administrative rights.
Who makes changes to UAC so often that they will be constantly pummelled with prompts? It wouldn't damage Microsoft's quieter UAC policy too badly to make an exception to the rule in this case for the sake of security. Fortunately, that is what it has now decided to do.
After a negative outcry from the community on their blog post defending the "problem", Microsoft's Jon DeVaan and Steven Sinofsky followed up with another post responding to community feedback.
“Our dialog is at that point where many do not feel listened to and also many feel various viewpoints are not well-informed. That’s not the dialog we set out to have and we’re going to do our best to improve,” they said.
According to the blog post, two changes will be made to the Release Candidate regarding UAC. Firstly, the UAC control panel will run in a "high integrity" process that requires permissions elevation. The blog states that this first change was already being worked on before this issue came to light. The second change will force prompts for confirmation to changes to UAC settings, which is the "simple" fix that Long Zheng mentioned in his blog when the problem was first publicised.
While it may take a fair amount of persuasion, it's good to see that Microsoft responds to user feedback positively.
- Insiders Say Intel to Build PlayStation 4 GPU
- RIM Chief Steps Down Amidst Stock Penalty
- Apple Stores Blocking Facebook
- Vuze calls FCC to Probe Cox's Net Traffic Wrangling
- Palm Pre Targeted to Hit Sprint Inventory March 15
- Ubuntu Gaining Popularity For Businesses
- Sega Vision Emerges With TV Tuner, MP3 Playback
- Intel Now Shipping Upgraded Atom and HD Video Chipset
- More Dell Mini 10 Details Trickle Out
- Forget the Remote, Make Gestures at Your TV
- Eight out of 10 Households Ready for DTV
- Psion Claims "netBook" Trademark; Google Abides
- PC Gaming Roundup - February 9, 2009
- GeForce GTX260 with New PCB Design
- Plausible: Nvidia Working on x86 CPU
- German Mac Cloner Skirts Around OS X EULA
- CyberPower Unleashes the 'Gamer Dragon'
- Tom's Hardware X58 Contest Winner





Read all about it.
Beta version changed due to tester feedback!
waxdart is tuesday's comedian!
Cant wait til they integrate UAC fully to the net:
Are you sure you wanted to load Internet Explorer?
Are you sure you wanted to go to this website?
Are you sure you wanted to read this article?
Are you sure you wanted to read the next article?
Are you sure you wanted to close this article?
Are you sure you wanted to close Internet Explorer?
Are you sure you want to live?