BetaONE will rise again!


 
Prev Previous Post   Next Post Next
  #1  
Old 14th Feb 07, 11:24 PM
Alpine's Avatar
Alpine Alpine is offline
Retired Crew
 
Join Date: Feb 2002
Location: Run Forest, RUN!!
Posts: 3,601
Alpine is on a distinguished road
Send a message via ICQ to Alpine Send a message via AIM to Alpine
M$ Vista has enormous gaping hole
Security blown out of the water

A CHIP COMPANY called Microsoft said its "highly secure" Vista operating system has a whopping great security hole in its User Account Control.


According to the hackette who found it, Joanna Rutkowska, the hole means that the legendary default no-admin setting isn't a security mechanism any more. Got that?

Rutkowska told ZD Net that the UAC automatically assumes that all setup programs should be run with administrator privileges.

When you run such a program, you get a UAC prompt and you can either to agree to run this application as administrator or to disallow running it. Still awake?

So if "punters" download the Tetris "game", they would have the choice of giving the program total rights to their file system, registry and kernel drivers or not run it. At no point did Vole wonder why a Tetris installer be allowed to load kernel drivers.

In her bog 'Invisible Things', Rutkowska said that she should be offered a choice whether to fully trust the software or add a folder in C:Program Files and some keys under HKLMSoftware and do nothing more. This much better security option was possible under XP but has been dropped from Vista.

A Security Vole has dismissed the hole, claiming that the way Vista allowed access to different bits of the operating system was not that easy. He admitted that it was a weakness, but that was really a "design choice".

Rutkowska told ZD Net that she wasn't happy with Vole's flippant attitude to the potential risk by declaring that that all *implementation* bugs in UAC are not to be considered as security bugs. More here and also here. Is that clear now?

The REGister
Reply With Quote
 


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is On
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
M$ Vista is still a mess Alpine BetaONE News 0 11th Sep 06 02:06 PM
Microsoft: Push the Windows Vista date back NewsBot NeoWin News 0 4th Aug 06 08:00 PM
Microsoft Plans Six Core Windows Vista Versions Alpine BetaONE News 0 20th Feb 06 10:37 PM
Microsoft Plans Six Core Windows Vista Versions NewsBot ieXbeta News 0 20th Feb 06 05:00 AM
Vista graphics drivers to be more stable than XP drivers, ATI says Alpine BetaONE News 0 24th Sep 05 05:38 PM


All times are GMT +1. The time now is 08:01 PM.


Design by Vjacheslav Trushkin for phpBBStyles.com.
Powered by vBulletin® Version 3.6.5
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.