Frogboy Frogboy

Should Stardock fix Microsoft's UAC?

Should Stardock fix Microsoft's UAC?

User Account Control on Vista discussion

In a new Macintosh advertisement, the PC has what looks like a body guard who keeps interupting the conversation with the Mac in the name of  "security".  The feature Apple is making fun of is called the User Account Control.

The idea behind UAC is to protect users from malicious software and other content that could affect the stability and integrity of the user's computer.  But many users have expressed utter disdain for it. As a result, UAC ends up being disabled by users much to the chagrin of Microsoft.

But what if there was a different solution? What if third-parties were able to modify how UAC worked?

For example, imagine the UAC remembering what users had given it permission to previously? Right now, every time I open up Stardock Central, I'm prompted by UAC. Very annoying.  What if after I selected "continue" it saved Stardock Central and its checksum such that it wouldn't come up again for that program as long as it was unchanged?

Another example would be after I select continue on the UAC, the account remains in an elevated state for say 5 minutes (or some user-defined time) so that anything else that needs UAC would automatically be passed.

I think just these two changes would significantly improve the usability of UAC to the point where most of the complaints would go away.

And I think these kinds of changes are absolutely necessary because, right now, users are just turning it off completely which is definitely not a good thing. You should definitely not turn off UAC but it is very understandable how annoying its current implementation can tend to be.

Microsoft has stated that any attempt to alter the functionality of UAC would be considered a security violation that would be dealt with accordingly. It's scary sounding stuff.  But if the alternative is that millions simply turn off this functionality or the bad reputation of UAC slows migration to Windows Vista then what's the best path? 

Which brings us back, should third-parties like Stardock step in and fix UAC on their own?  Or should the user base wait and hope that Microsoft enhances the UAC experience?

 

44,229 views 92 replies
Reply #51 Top
You assume that UAC is broken ? - UAC may be an annoyance to many but broken it most definitely it is NOT.A simple reg tweak is all it takes to turn on or off as many already know.

If it's not broken, then why would you turn it off?
Reply #52 Top
I hate UAC!!

It not needed really, most unexperienced users would probably click continue even if it was a virus or something trying to damage the pc.
Reply #53 Top
Brad your intensions are good to such a great work. But they fully at MS intend to protect their software at any cost. For the time being I would just give instruction before installing any software via Stardock Central or even Stardock Central progam itself. That the user turn the UAC off! {If he has not already done so.}

The next best thing would be to offer such a design to Technet and see what happens to the design. With good intensions I believe the Techs would get approval to add your design to a new update for Vista OS and all would be well with things. This would also put the hammer down on other programs working along the same line. Such as Mcafee's SiteAdvisor and this could also startup some new ideas for them too.

I think you are on the right track and should follow through at whatever cost it maybe. It maybe that Stardock has an idea to venture into security for windows and espically it's own programs. This to gain a new name for Stardock with being safe and a excellent product to consider.

These people that say leave it to MS to fix have no idea what they are saying. UAC was designed around other software that is presently on the market today to make internet surfing safer for all. Thus it was the full intensions of MS to do this for Vista. But Vista is still a babe and it will go places here in the next few years too. So will Stardock as well espically.

The next best thing is to get in on the goings on at MS via a conference and let them know where you stand on the idea. A good start would be to attend the next conference here...

http://www.microsoft.com/events/mix/default.mspx

With that in mind and plenty of ammo for the right stuff. The work in progress for Stardock will take a major leap forward!Good luck and I hope that this all is helpful. You are on the right track Brad and your people there are to be congradulated on such great work for all the new Vista software they have done so well on.

SGT  
Reply #54 Top
Stop trying to fix the world...


I hate myself for acknowledging your existance but... you have actually outdumbed yourself. That is the most absurd thing I have seen on the internet to date.

Your animosity towards Stardock is transparent, biased,predictable and boring. You have silenced your own opinions. Deleting yourself right now would be a step towards fixing the world.   
Reply #55 Top
I vote against such practices.
This is nothing different as the super user account in a NIX environment.
Every program that has acces to system files and has the intention to change something, like the majority of Stardock programs, should first ask permission from the user.
I turned this back on, and unless you want to change something on the system, this UAC thing does not pop-up : it does not pop up when performing work (Word, Excel, ...), it does not pop up when accessing the internet, unless you download and install something (works as designed), it does not pop up when playing games, it does not pop up while chatting, it does not pop up when watching movies or listening to music ...
In short, it does not bug me while using the pc, only when I want to make changes.
And if you are really in a spring clean mood, you can always temporary turn UAC off until you are finished (but do not forget to turn it back on afterwards).
BTW, I don't see how it can block the communications with a MAC ?
Messenger, Skype, Googletalk and GMAIL conversations all work flawlessly on my PC, with UAC enabled.
And do not forget the warning of MS if you try to change it : they will sue you. It is written clearly in the EULA.
Jan
Reply #56 Top
Hey guys... Just so you know, there already is a better version of UAC. It is called third party anti-virus software.


It's frightening if you think you're a "power user" and yet you make comments that are that painfully inaccurate. Get a clue, read some information, then make uninformed comments afterwards because right now you just look stupid.

UAC is just microsoft's way of passing the responsibility for security on to the customer so they dont have to deal with it in the OS.

Disabled it as soon as that first box came up. Useless


Wow just wow. You obviously have no idea what UAC is/for then.
Reply #57 Top
Just go for it
Reply #58 Top
Something to add... it's 2/22/07 (A week+ further then when SD was going to release WB5.5). Maybe they can finish that project first before they try fixing someone else's software. How about that idea?... does that work for you?

Also, the whole "a regular user needs admin access to do things" is the real problem here. The problem stems from the fact that Windows natively is misdesigned. The failure in the design is around the fact that it has a registry and shared locations for system dependant items from programs such as dlls. This is where all the problems are comming from. If Windows would work much like other OSs work in terms of installing apps in their own directory and drop no other info anywhere else during install then you wouldn't need an admin account to function. The layout design of Windows is it's downfall. There's far too much crap getting dropped everywhere each time you install something, I think we can all agree on this. Imagine how much cleaner everything would be if you could install a program into it's own directory and the uninstall process was simply a delete of that directory and it's icon shortcut... there would be no hidden entries in the registry for registered portions of the program... it would be a simple layout much like Linux is... not to mention a cleaner layout in terms of admin work needed to maintain the systems. Until MS fixes this with a complete rewrite of the code from scratch there's always going to be some need for admin access to the end user. Users like to do stuff and cannot be locked down from this with a UAC or account restrictions. Account restrictions on a system at the moment is the only way to keep a user from "accidentatly" messing something up with an install or settings change. Until MS can find a way to split Kernel level control from User level control in Windows there will always be a weakness.
Reply #59 Top
yes yes yes yes yes yes yes yes yes

I desperately want to turn UAC back on but I do NOT want a warning to stop my whole system just because I go into display settings. I dont know my microsoft did not add a "dont prompt me for this again" option....even if only for administrator accounts.
Reply #60 Top
Believe it or not the first thing I did was look for a way to turn that piece of cr^p OFF...
If MS has no issue with Stardock modifying it then go for it!

The intentions were probably great, but for a power user it is the most ANNOYING thing that can happen..
Perhaps it could be implimented a bit differently?
perhaps for users with diffeent levels of experience..
Say a 7 year old gets on the machine to play games.. Novice Setting
The teenager gets on it to do research for homework.. Intermediate
A Master Skinner gets on it to create a WB ... Advanced

Of course the advanced setting would be much less annoying, yet the UAC would still be active..

As it is right now..I will never turn that thing on again..LoL
Reply #61 Top
Heck yes! is what i say.

Or at least make it remember stuff..

I dont mind the 1st time it asks, but even before getting to the UAC you have to hit ok 1-3 times (do you weant to install #1 ok, vistablabla has to get permission from the UAC agreed? #2 ok, and then the UAC itself.. #3 ok.) and a night of using my puter leaves me realy realy annoyed because of the constant holding my hand...

I friggin hate the uac

Reply #62 Top
As the developer of Winstep Xtreme, I feel for Stardock as their pains with the UAC are my pains as well (and, without a doubt, the pains of many thousands of other developers out there).

The UAC, in it's currently implementation, is simply brain damaged. It doesn't work, and it's forcing us, developers, to go to unbelievable extends to change software that worked perfectly in previous Windows versions. It's incredible frustrating, specially given the current lack of information provided by Microsoft. As for software that is NOT run-of-the-mill and is no longer in active development, tough luck - it simply won't work properly, or at all, in Vista.

As stated by many, it's still up to the user to allow an elevation of privilege or not. With the UAC crying wolf all the time (way too many things in Vista require an elevation of privilege), this is no different than before: it is still the user's responsibility to take care of their systems by clicking Yes or No!

As a responsible user, I only EVER caught a computer virus once, and that was in the first 3 months of buying my first PC, many, many, eons ago. I learned my lesson then. Like with a car, what people need are safety systems, not something that only lets you drive at 10 MPH because you might kill yourself in an accident otherwise. What you need are good Anti-Virus and Anti-Spyware tools (never understood why these two are not merged together in a single application as they should) and a proper Firewall. Add to that common sense, the same common sense that keeps most (sigh!) people from driving at 100 MPH on a wet road on a rainy day.

The current UAC implementation works by denying functionality, i.e.; it won't let virus do things that might damage your system, but it will also block other programs that might have VERY good and legit reasons to do the same thing. That is absolutely insane, and, since it's still up to the user to allow or deny a specific action, it changes almost NOTHING in terms of security while BREAKING thousands of applications.

For anyone interested, you can view a more detailed discussion about UAC problems from a developer's perspective in the Winstep Forums and in the MSDN Security Forums.
Reply #63 Top
Fix the broken piece of crap!
Reply #64 Top
While I found the UAC to be so annoying that I had to turn it off, I am having second thoughts about this.

This article in particular http://www.jimmah.com/vista/security/uac.aspx
had some great information.

I have been approaching UAC concerned only about how inconvenient I found it. I realize that most PC users do not do the things I do with my computer. I realize that frequently computers have more than one user, or are being used in a corporate environment. Indeed, it would seem that the vast majority of PC users will only infrequently see the UAC prompt.

Just because I like to install and try out several programs a week. Just because I like to access WMI from sidebar gadgets. Just because I use many older applications which silently fail with UAC enabled--all that does not mean that UAC is not a godsend for the more typical user.

Also, I need, as a person who like to make apps and widgets, to learn to live with UAC. I don't really want my apps to be another UAC annoyance when with a little forethought and planning I could design them to work alongside UAC. That is going to be my responsibility as a "developer", and it would be immature and shortsighted for me to ask users to circumvent their security just because I didn't want to take the time to do things right.

The article I linked above not only has great information on what UAC is and is not, but also has some helpful hints (which I will have to reboot to test, but..) about working with UAC. For example I found UAC particularly annoying when I was exploring the various control panels and changing settings. Turns out I probably could have just run "control.exe" as an administrator, and would have been able to make all the changes I wanted without being asked for confirmation at every step.

I'm not exactly happy about having to keep track myself which programs need a Run as Administrator shortcut (or right-click) and which can operate without this access. But I think that as developers adapt and update their products for this new system, that the annoyances will diminish.

Perfect, UAC is not. UAC can be more annoying than useful to a particular sort of power user. In particular I think the notifications should specifically state why the task needs elevated access--that is, what is it trying to do that is cause for concern. But I am going to give it another chance because I do believe in it in concept. If it interferes with my workflow significantly I may disable it entirely again, but I think I am going to give it a much closer look before making that decision.
Reply #65 Top
Rabidrobot,
thanks for this instructive article.
Unix users are for years used to the Administrator (or Super User) concept.
People have been bashing Microsoft because Windows was so vulnerable to viruses and, more important, users. Finally they come up with something that has been proved in the industry times and times again, and they get accused of delivering a broken piece of software ?
I really don't get it.
As you stated, most users will only rarely be confronted with this screen. Most of the time when they try to do something that was not intended for a normal user.
I consider myself a power user, even if I am not an experienced programmer. First thing I did was turning UAC off. Second thing I did was forcing not supported drivers to the system (heck, I picked all the parts myself, I know what I am doing!). Third thing I did was a complete clean install because my USB storage was not recognized anymore.
Would UAC have saved me ? No, because I am a power user, and know how to counter it.
But it would (and will) block a lot of people from doing stupid things.
Brad, Stardock, I strongly advice against adapting the security rules to your needs.
Instead, try to play the game. I granted Administrator rights to Stardock Central, and it asks me only once for confirmation.
So the feature most asked, memorize the granted acces for a period of time, is already build in. Only you need to be Administrator to activate it .
It is a new concept to Windows, and we will need to learn to work with it, but in the long run, we will all win, because viruses and trojans etc will have less opportunities to make havoc.
If one company starts to change the rules, others will follow, and we are back to zero.
Imagine a virus that makes use of Stardocks code to alter the security rules to its benefit.
How do you think Stardock will come out of that ?
Please read the mentioned article if you did not do it yet :
http://www.jimmah.com/vista/security/uac.aspx
Jan
Reply #66 Top

Microsoft had a perfectly good model upon which to base UAC, had they been able to get over their "not invented here" mentality--the way that Linux does it. When you install most Linux distros, you have to set up a ROOT password, in addition to the password for each user account. Users don't run as ROOT; they run as USERS. When something needs to be done that requires ROOT access, you get a pop-up that prompts you for the ROOT password. This does not lock up the rest of the system the way that UAC nag-boxes do, and if you're so inclined, you can go and do something else before responding.

I hate UAC, and think that MSFT must have been smoking some bad weed when they designed it and its in-your-face obnoxiousness. The Linux approach is much simpler, and doesn't have the stench of the sorta-kinda "administrator" account that Vista puts into place.

I _know_ there are plenty of smart people working for Microsoft; why do some of their latest creations seem to have been put together after a weekend-long binge?
Reply #67 Top
Microsoft had a perfectly good model upon which to base UAC, had they been able to get over their "not invented here" mentality--the way that Linux does it. When you install most Linux distros, you have to set up a ROOT password, in addition to the password for each user account. Users don't run as ROOT; they run as USERS. When something needs to be done that requires ROOT access, you get a pop-up that prompts you for the ROOT password. This does not lock up the rest of the system the way that UAC nag-boxes do, and if you're so inclined, you can go and do something else before responding.


Yes!!! I have to say that I'm not a big Linux user simply because I think I just can't do in Linux what I can do in Windows. Windows runs everything that I use from games to apps to whatever... it just works because "it's the most popular OS in the world", not because it's good. With that said, I would have LOVED Vista if it came with a UAC that acted like Linux's does. When I played arround with Mandrake I loved that feature... you'd try and do something and it would prompt for the password. People knew that you're going into a special mode for that one process... it took a little thinking and realization from the user. I don't know what they didn't do it this way. The damn thing should prompt when something is trying to install or when something is trying to make system or registry changes or run a process that's not considered "normal". Why the f*** does it have to prompt me when I go into display properties? I know why I'm going in there... I freaking asked it to. Have any of you ever seen any spyware that changes your resolution on the fly? I sure haven't, so there's no need to ass-pucker the display properties with UAC. Network settings... yes, maybe, if it's advanced settings.

In the end, a lof of us will note one thing. We're all getting a lot of UAC prompts because we're trying to do things in Vista in "The old Windows way". They have changed a lot of the layout of the system and where stuff is and you'll notice that if you actually do things the "Vista Way" you will not get any UAC prompts unless you're really digging through stuff. I think MS must have hired some Mac people to design the visual layout of Office 2007 and Vista because when I sit in front of a Vista/Office 2007 system right now I feel about as visually dumb as when I sit in front of a Mac.

I think we all have to kind of forget how we do things in previous versions of Windows in order to feel "more at home" with Vista.
Reply #68 Top
I'm joining this late but, my fear with UAC is that it builds on top of something windows does not need made any worse:

Too many options.

UAC in its present form is indeed very annoying. I have several apps that require admin privileges and i'd like to be able to elevate them once, and have UAC remember that setting. I also disabled the secure desktop because it lags every time something is elevated; i prefer to simply click 'allow' once.

But even if stardock's- or somebody elses' - tweak app could allow you to adjust UAC to work better for you, it becomes just another setting in an endless sea of settings that require adjustment when you set up windows. Most of us don't mind going in to the registry or opening services to tweak something. But when my mother says "How can i make it stop?" and i start opening control panels and adjusting things for her, it hurts to see her eyes roll. It shouldn't have to be messed with.

I'm happy that windows allows for UAC to be tweaked at the service level by an expert. But it is unnecessary to have to be done. They should have just gotten it right. Prompts to install programs, prompts to change a system file. That's it. Lock up the windows folder and organize the OS better. Build your protocols differently so that changes CAN only be made from the control panel by the present user, instead of relying on a prompt that comes up every time that service is accesses by anybody.

That i have to confirm 3 times ( and frequently still be denied ) deleting a file is ridiculous. The OS should be smart enough to know that i initiated that command and not someone else, instead of me having to tell it over and over again.
Reply #69 Top
"Why the f*** does it have to prompt me when I go into display properties?"

I just checked it for you, it does not prompt me. Right clicked on the desktop, and went right in. No UAC bugging me. I double checked, yes I have UAC activated.
So I made a second, standard user to be sure. Only got prompted when I wanted to check if UAC was activated - while logged in as this new user- to enter my password. Which is expected, because I could deactivate UAC from here.

I really don't understand what the fuss is. I only get prompted when I want to change something, like installing a new program, change system settings and so on.
And for code not being compatible with Vista due to this ? I found out that if I run the program as Administrator, it does always what it is supposed to do, just the way it did under XP.

Now I can understand that a programmer has more problems with this concept, as he has to think how his code will be influenced by UAC. But a normal user that is working with his PC (going to the internet, write a letter, play a game, chat, ...) would not be bothered often.

I work with Linuw and Unix systems every day. This is just the same principle as root acces in Unix systems.

Jan
Reply #70 Top
I just checked it for you, it does not prompt me. Right clicked on the desktop, and went right in. No UAC bugging me. I double checked, yes I have UAC activated.


Go in and change the resolution. Or better yet, click on advanced in that screen and go to where you can create a system restore point. You will get a prompt.
Reply #71 Top
YES...the UAC is getting to annoy me and I may turn it off soon!
Reply #72 Top
"Right now, every time I open up Stardock Central, I'm prompted by UAC".

Then, fix your own software first! There should be no reason for an application that checks for updates to require admin rights. Only installing an update should require those rights.
Reply #73 Top
if the UAC is as annoying as service pack 2 was with its informmation bar and outright refusal to allow for the remembering of certain things (dealing with website development), then I am quite glad I switched to the Apple.
Reply #74 Top

"Right now, every time I open up Stardock Central, I'm prompted by UAC".

Then, fix your own software first! There should be no reason for an application that checks for updates to require admin rights. Only installing an update should require those rights.

We agree. A program that simply does updates shouldn't get prompted. So how is this our fault?

Reply #75 Top
I found out that if I run the program as Administrator, it does always what it is supposed to do, just the way it did under XP.

Actually there are CRUCIAL differences. For instance: applications running at a higher privilege level (i.e.; as the Administrator) cannot accept files dragged & dropped from applications running at lower privilege levels. In fact, they ignore ALL messages sent to them by lower privilege applications.

For instance, if you decide to run ObjectDock as the Admin, then you will find yourself unable to drag files from Explorer and drop them into it because Explorer is running with a normal privilege level. If you don't run ObjectDock as the Admin, then, for instance, time synchronizing docklets (which run at the same privilege level as ObjectDock) will fail to set the system time, because - and that is ANOTHER example of the problem with the UAC - far too many things in Windows require Admin rights, like setting the system time.

You see, it makes sense, from a Corporation point of view, for things like setting the system time, changing display resolution, and LOTS and LOTS of other small things like that to require Admin privileges. For the Home user, however, it makes no sense at all!

Another problem is that there is no mechanism for applications to LOWER their privilege level (why the hell not? How would this break security?!). A real life example for this is application A that is launched from the installer (you know, when you install an application and the Setup program has a small checkbox that says 'Launch Application A' at the end): because the Setup program runs with a high privilege level, so will application A. Because application A cannot lower its privilege level, it will then be unable to, say, accept files dragged & dropped from Explorer. To the user, it will look like application A is broken. So what is the solution? Never to give the user the convenience to launch an application right after Setup? Blah!

And yet another problem: under Vista, applications running at normal privilege levels do not have write access to folders under c:\Program Files\, and this includes their own folder. Since a lot of applications save configuration data (INI files, for instance) in their own folder, this alone is going to be the source of many problems (Microsoft did come up with a mechanism to work around it, though, but it has its own problems). The solution is to start saving configuration files and the like in the My Documents or Application Data folders. But where to save themes and skins, then? If you save them to the 'My Documents' folder, the downloaded themes will then only be available to that user (since the My Documents folder is a per User folder), if you save them to 'Application Data', then the user will have a hard time navigating to this folder because it is hidden by default!

The problem with the UAC is not that it's a bad thing per se, just that the details and problems were not ironed out first in Microsoft's hurry to get Vista out the door. As it is, application developers have to go to great pains to change their applications to run properly on Vista, only to (probably) see all those efforts go to waste when Vista SP1 comes out and most of the problems get ironed out.