Hacker, Microsoft Duke it Out Over Vista Design Flaw

Joanna Rutkowska has always been a big supporter of the Windows Vista security model. Until she stumbled upon a ‘very severe hole’ in the design of UAC and found out – from Microsoft officials – that the default no-admin setting isn’t even a security mechanism anymore. Rutkowska believes UAC has a major flaw in the way it automatically assumes that all setup programs (application installers) should be run with administrator privileges.

22 Comments

  1. 2007-02-14 8:05 pm
    • 2007-02-14 8:28 pm
  2. 2007-02-14 8:09 pm
    • 2007-02-14 8:29 pm
      • 2007-02-14 8:38 pm
        • 2007-02-14 8:48 pm
          • 2007-02-14 9:21 pm
          • 2007-02-14 10:01 pm
          • 2007-02-14 10:28 pm
        • 2007-02-14 10:28 pm
          • 2007-02-14 10:30 pm
    • 2007-02-14 10:20 pm
    • 2007-02-14 10:49 pm
  3. 2007-02-14 8:21 pm
  4. 2007-02-14 9:29 pm
  5. 2007-02-14 9:32 pm
    • 2007-02-14 10:03 pm
  6. 2007-02-15 1:31 am
  7. 2007-02-15 1:55 am
    • 2007-02-15 9:43 am
      • 2007-02-15 2:12 pm
  8. 2007-02-15 7:39 am