Join CNET.com.au: Receive free newsletters, post to forums and win prizes. Sign up now!

Microsoft: Vista UAC designed to 'annoy users'

By Tom Espiner on 14 April 2008

Tags: actions | apps | attack | cross | uac | kaspersky | prompt | user | yes

A Microsoft manager has said one of the security features in Vista was deliberately designed to "annoy users" in order to put pressure on third-party software makers to make their applications more secure.

David Cross, a product unit manager at Microsoft, was the group program manager in charge of designing User Account Control (UAC), which, when activated, requires people to run Vista in standard user mode rather than having administrator privileges, and offers a prompt if they try to install a program.

"The reason we put UAC into the [Vista] platform was to annoy users — I'm serious," said Cross, speaking at the RSA Conference in San Francisco on Thursday. "Most users had administrator privileges on previous Windows systems and most applications needed administrator privileges to install or run."

Cross claimed that annoying users had been part of a Microsoft strategy to force independent software vendors (ISVs) to make their code more secure, as insecure code would trigger a prompt, discouraging users from executing the code.

"We needed to change the ecosystem," said Cross. "UAC is changing the ISV ecosystem; applications are getting more secure. This was our target — to change the ecosystem. The fact is that there are fewer applications causing prompts. Eighty percent of the prompts were caused by 10 apps, some from ISVs and some from Microsoft. Sixty-six percent of sessions now have no prompts," said Cross.

Cross claimed it is a myth that users just turn UAC off, saying that Microsoft had collected opt-in information from users which showed that 88 percent were running UAC. Cross said it was also a myth that users blindly accept prompts without reading them.

"It's a myth that users click 'yes', 'yes', 'yes', 'yes'," said Cross. "Seven percent of all prompts are cancelled. Users are not just saying 'yes'."

Security company Kaspersky has in the past severely criticised UAC, claiming in March last year that it would make Vista less secure than XP.

At this year's RSA Conference, however, the security specialist seemed to have changed its tune. Jeff Aliber, Kaspersky's US senior director of product marketing, said: "[With Windows], there is a large attack surface with a number of entry points," said Aliber. "Anyone trying to shrink that attack surface and promote secure apps development has to be a good thing."

Prior to the launch of Vista, Kaspersky issued a report in January 2007 which said UAC would be ineffectual. The company claimed that many applications perform harmless actions that, in a security context, can appear to be malicious. As UAC flashes up a warning every time such an action is performed, Kaspersky said that users would be forced to either blindly ignore the warning and allow the action to be performed or disable the feature to stop themselves going "crazy".

"If the user were to be notified about every one of these actions with a request for confirmation or a request to enter a password, the user will either go crazy or disable the security feature," said Kaspersky.

Paul
14/04/2008 02:39 PM

"Cross claimed it is a myth that users just turn UAC off, saying that Microsoft had collected opt-in information from users which showed that 88 percent were running UAC. Cross said it was also a myth that users blindly accept prompts without reading them." Isn't it likely that those users who "opt in" are also the more likely type of user to leave UAC on? I don't think that these two are independent variables, so this quoted figure is a useless statistic.

Report offensive content

ripntime
24/04/2008 06:34 PM

I agree with Paul, their reasoning, excuses explanations,etc are all complely usless and flawed, Like Vista is. simply mouth fodder.

Report offensive content

ripntime
24/04/2008 06:46 PM

I agree with Paul, their reasoning, excuses explanations,etc are all complely usless and flawed, Like Vista is. simply mouth fodder.

Report offensive content

  • Leave a comment

All fields marked with * are required

What do you think

Your e-mail will not be displayed

You must read and type the 6 chars within 0..9 and A..F

You must read and type the 6 chars.


  • News

  • Features

  • Oi!

  • Must read

  • Free Speed: Make your Mac faster

  • Apple putting Snow Leopard on crash diet?

  • Apple previews OS X 10.6: Snow Leopard

  • XP on your desktop till 2010, if it's cheap

  • Apple releases Mac OS X 10.5.3

  • Microsoft makes Yahoo a new offer

  • Microsoft: Try Vista, it's not as bad you think

  • Microsoft pulls Windows XP and Vista service packs from Windows Update

  • Windows XP SP3: A quick, painless upgrade

More news »

Find the right software

Brand
  • Multiple options can be selected

    The Explain Series

    • Microsoft Windows Vista SP1

      Microsoft Windows Vista SP1

      Microsoft pushes its first service pack for Vista out the door. Is it a salvation, a non-event or a flop?

    • Mac OS X 10.5 Leopard

      Mac OS X 10.5 Leopard

      The grace of Leopard's interface enhancements makes productivity more pleasurable with a Mac, as more than 300 functional and fun features top off this update.

    • Ubuntu 7.04

      Ubuntu 7.04

      Ubuntu is very user-friendly but not right for everyone. Oddly, both casual and advanced users will find this operating system wonderful, while day-to-day users may rail against Ubuntu's incompatibility with certain popular software applications.

    • Windows Mobile 6

      Windows Mobile 6

      Though it doesn't offer earth-shattering new features and interface issues remain, Windows Mobile 6 brings a collection of noteworthy improvements that makes its mobile devices easier to use and equips mobile professionals with more robust productivity tools.

    • Microsoft Vista Home Basic

      Microsoft Vista Home Basic

      If you're currently happy with Windows XP SP2, it is not worth rushing out to purchase Vista Home Basic. On the other hand, if you need a new computer right now, Windows Vista is stable enough for everyday use.

    More reviews »

    Membership benefits

    Create a personalised homepage

    Create a personalised homepage

    Choose your interests from our 16 categories and only see articles relevant to you. Sign up for a free CNET.com.au membership now!