Frogboy Frogboy

Should Stardock fix Microsoft's UAC?

Should Stardock fix Microsoft's UAC?

User Account Control on Vista discussion

In a new Macintosh advertisement, the PC has what looks like a body guard who keeps interupting the conversation with the Mac in the name of  "security".  The feature Apple is making fun of is called the User Account Control.

The idea behind UAC is to protect users from malicious software and other content that could affect the stability and integrity of the user's computer.  But many users have expressed utter disdain for it. As a result, UAC ends up being disabled by users much to the chagrin of Microsoft.

But what if there was a different solution? What if third-parties were able to modify how UAC worked?

For example, imagine the UAC remembering what users had given it permission to previously? Right now, every time I open up Stardock Central, I'm prompted by UAC. Very annoying.  What if after I selected "continue" it saved Stardock Central and its checksum such that it wouldn't come up again for that program as long as it was unchanged?

Another example would be after I select continue on the UAC, the account remains in an elevated state for say 5 minutes (or some user-defined time) so that anything else that needs UAC would automatically be passed.

I think just these two changes would significantly improve the usability of UAC to the point where most of the complaints would go away.

And I think these kinds of changes are absolutely necessary because, right now, users are just turning it off completely which is definitely not a good thing. You should definitely not turn off UAC but it is very understandable how annoying its current implementation can tend to be.

Microsoft has stated that any attempt to alter the functionality of UAC would be considered a security violation that would be dealt with accordingly. It's scary sounding stuff.  But if the alternative is that millions simply turn off this functionality or the bad reputation of UAC slows migration to Windows Vista then what's the best path? 

Which brings us back, should third-parties like Stardock step in and fix UAC on their own?  Or should the user base wait and hope that Microsoft enhances the UAC experience?

 

44,236 views 92 replies
Reply #76 Top
If you think that's bad check this problem out that I had. So I installed Synaptics's touchpad drivers for Vista on my test setup of Vista Ultimate. (Keep in mind that these drivers/touchpad app was written for Vista.) Well, on EVERY startup of Windows I get a prompt to allow syntpenh.exe to run. It's part of the driver that runs at startup in a registry entry under run. Anyway, I though it was a little anoying (It wasn't a UAC prompt, but rather one of those "This application comes from another computer and cannot be trusted) so I decided to take a look at the file properties. Sure enough, it was not MS Certified, but it did have the normal place in file properties at the bottom where you can "unlock" the file so that Windows will not think it's "unsafe and from the internet". So I made the change and restarted... got no errors when I made the change mind you. I restart and get the same prompt... I'm like WTF? So I check the file properties again and it's back to locked. I open explorer on that directory (Yep, it's in Program Files) and run Explorer as administrator this time thinking it may have been rights that wouldn't allow me to change the file properties (but then agian, I never got the permission denied error). So I change the file properties again and recheck them after changing them. It's changed... I reboot and the prompt comes back on. I check the file properties and it's back to blocked. That's about the time I decided to put my other drive back in with XP on it after emailing Synaptics about the problem.

Now excuse me while I go to Best Buy and yell at the idiots selling Vista Home Basic/Premium to business users that need to have access to a domain server (with full login support).
Reply #77 Top
We agree. A program that simply does updates shouldn't get prompted. So how is this our fault?


That's not what I said; A program doing updates SHOULD prompt. A program showing updates shouldn't.

Doing an update is something only admins are allowed to do, since it touches application files.
Showing updates (depending on if the regular user should be allowed to view them at all), should be something that could be done without requiring elevated rights.

In short, decouple the viewer from the updater; When a user selects an update to be installed, launch a seperate out-of-process thing, which in turn can be elevated.

Good security practice is to not want/get/give more rights than needed; only request more rights when needed and lose those elevated rights as soon as possible.
Reply #78 Top
What you are saying is make the UAC like Windows Firewall right? I think it is the dumbest thing ever invented.

People don't need UAC if the firewall and Windows spyware/malware tool is not good enough then screw it. UAC is total useless. Suppose to stop viruses but it really just pissed off people.

Microsoft UAC is just another thing to tick off users like downloading a WGA update every time you need to download software from Microsoft isn't enough!
Reply #79 Top

UAC is just microsoft's way of passing the responsibility for security on to the customer so they dont have to deal with it in the OS.

Exactly.

By inserting user responsibility for potentially damaging actions into the equation MS can be removed from total/sole culpability if/when something goes belly-up.

Think response...."You idiot...you disabled the inherent protection/advice?"

It's intended to REMIND the casual user that what he says 'yes' to is potentially damaging....and to self-educate.

"Power Users" may simply consider their expertise to not warrant such reminders....in which case, as with any OS modification tool there's absolutely no drama associated with their use....provided [again] suitable warnings pop up....the last UAC one being...."are you sure you want to modify/remove the functionality of this OS 'protection' tool?".

I see no problems there...

 

Re other comments here....Stardock has close connections with MS so any such 'tool' for Modding the OS would quite likely have in-house feedback and 'tacit' endorsement...

Yes, SD makes games but they also make programs with close integration with the MS OS so UAC modding would be a romp in the park....

Reply #80 Top
That's not what I said; A program doing updates SHOULD prompt. A program showing updates shouldn't.


THAT I have to agree with.

And, concerning the original topic, I really don't think Stardock should mess with the UAC - that is Microsoft's business. What I think Stardock should do, however, since it appears to have some 'weight' with Microsoft, is to pressure them into fixing, as fast as possible, all that is wrong with the current UAC implementation.
Reply #81 Top

What you are saying is make the UAC like Windows Firewall right? I think it is the dumbest thing ever invented.

People don't need UAC if the firewall and Windows spyware/malware tool is not good enough then screw it. UAC is total useless. Suppose to stop viruses but it really just pissed off people.

Microsoft UAC is just another thing to tick off users like downloading a WGA update every time you need to download software from Microsoft isn't enough!


No, UAC is nothing like Windows Firewall, it's not an antivirus tool and it's got nothing to do with anti-piracy efforts.

You need to do a little more research before commenting publicly.
Reply #82 Top


By inserting user responsibility for potentially damaging actions into the equation MS can be removed from total/sole culpability if/when something goes belly-up.

Think response...."You idiot...you disabled the inherent protection/advice?"

It's intended to REMIND the casual user that what he says 'yes' to is potentially damaging....and to self-educate.



So why do you need to fix it ??

I see it like this ..

frogboy dislikes the UAC alarm when opening SD Central , AHH !! we'll fix UAC so our program doesn't raise the alarm .
Maybe your programming needs to be looked and not the UAC

Nice One
Reply #83 Top

What I don't like is constantly having to hit Continue when doing things on my computer.

If the bloody thing just remembered programs (store a checksum to be safe) that the user had already said "continue" I'd be happy.

But there are plenty of utilities and applications I run that keep seeming to bring it up.

frogboy dislikes the UAC alarm when opening SD Central , AHH !! we'll fix UAC so our program doesn't raise the alarm .
Maybe your programming needs to be looked and not the UAC

Right. Yes. It's us and half the other programs I'm running. It can't be that Microsoft's implementation of UAC is at fault.

Here's a reality check to the people who want to just pretend that everything is fine: People are turning it off. Look around. Look at the posts. People are turning it off. And the casual users who aren't? They're just learning to click continue without even thinking about it.

In short, UAC is worthless right now.

I'd prefer Microsoft to fix it, but if they don't fix it soon, someone else will OR people will just learn to turn it off.

Reply #84 Top

People need to get their heads out of the sand. UAC is useless. It does work - of course it works, but it works in such a way as to make even normal daily functions almost impossible.

Unless or until Microsoft (or someone else) makes UAC useable mine will be staying permanently off.

Reply #85 Top
Again and again and again.

Please define normal daily functions ?
For me that means : surfing the web, do some office work, play a game, chat, ... .
Modding Windows is not part of my list "normal daily functions".
Installing programs is not part if this list neither, as it can be dangerous (virusses, trojan horses, ...).

Stardock Central is designed to change programs and settings on my hard drive. Windows by no means can know who initiated those requests (it can even be someone who should not have acces to your computer, for example your youngest sister ).
Each and every time UAC comes up on my screen, it is expected, what means I am changing something outside my personal space.

If you are the only one that has acces to your pc, and you have proper firewall and antivirus, and you feel you are bugged by UAC, by all means, turn it off.
(But I wished I could turn it on on my fathers XP machine . Every family visit I end up cleaning out the mess he made).

I DO agree that this means developers need to change their habits and need to re-educate themselves, and that this is a big burden on them.
So Brad should take a closer look for why each time we try to use Stardock Central, it wakes up UAC, and change it. It is not Microsofts task. Microsoft however should give better information what rules to follow to 3rd party developers like Stardock ... .
Before Vista, EVERY program (including viruses) and every user had full administrative rights on the PC. This has changed. And as with any change, people are not happy.
But this is nothing new, Unix systems are doing it for years.

Microsoft could refine it, for example explain a little bit more in detail what the program in question is trying to do, for example a box telling :
this program is trying to install itself,
or
this program is trying to adjust your modem dial out number,
that is a change that would be helpful and make it more acceptable for most.
Reply #87 Top
If your app doesn't work under a normal user account (not one with admin rights!), UAC will nag you if launch it under a UAC'd admin account. Make your apps work under normal user accounts and your set to go.
Reply #88 Top
Frogboy:
If the bloody thing just remembered programs (store a checksum to be safe) that the user had already said "continue" I'd be happy.


Microsoft's reasoning for not doing this is that if this was possible (and lets call it 'blessing an application') and the user blessed, say, the Command Prompt, then a malware application could in theory launch the Command Prompt (which would then run with admin privileges WITHOUT displaying a UAC prompt) and use it to lauch a copy of itself. Because privilege is inherited, the malware launched by the 'blessed' Command Prompt would in turn run with admin privileges and have full access to the whole system.

Even if I do understand the reasoning behind this, there are two things I would like to point out: first, how would the malware know which applications have been 'blessed' and which not, so it knows which ones to 'abuse'? Second, it's still the user's responsability to reply Yes or No to an UAC prompt. Why trust the user for this and not for 'blessing' applications, then?! Doesn't make sense to me.

Here's a reality check to the people who want to just pretend that everything is fine: People are turning it off. Look around. Look at the posts. People are turning it off.


Unfortunately we, software developers, still have to change our applications so they work with the minority(?) that doesn't turn the UAC off. No less burden there for us.

Jan71:
Please define normal daily functions ? For me that means : surfing the web, do some office work, play a game, chat, ...


How about drag & dropping stuff from one window to another? Would you not think of this as 'normal daily function'? It so happens that, as I previously stated, a by-product of the UAC is that you are NOT able to do this if the target application is running with higher privileges than the source application. And I could give you a hundred different examples of little things that are not working properly, or at all, because of the current UAC implementation.

Also, you are here because you like to play with customization software. Customization software is NOT a 'spreadsheet' or 'word processor' type of application. For customization software to work properly, it needs to do things that normal applications do not. So, how would you like if, in the name of security, suddenly all you would be able to run were 'word processing' type of applications?

Microsoft however should give better information what rules to follow to 3rd party developers like Stardock


Agreed 100%. The current lack of information on the part of Microsoft on how to get around these limitations is appalling!

Microsoft could refine it, for example explain a little bit more in detail what the program in question is trying to do, for example a box telling : this program is trying to install itself, or this program is trying to adjust your modem dial out number, that is a change that would be helpful and make it more acceptable for most.


Altough apparently a good idea, because it is up to the application itself to request an elevation of privilege (unless it has 'setup', 'install', etc..., in the filename, in which case Windows will automatically assume it needs admin privileges to install *something*), Windows has no way of knowing what an application requiring admin privileges wants them for. If an application does not explicitily request an elevation of privilege via its manifest, then no UAC prompt will be displayed, the application will run with normal privileges and any function it calls that requires admin privileges will fail. It would thus be up to the applications themselves to give Windows the reason WHY they need to be elevated, not to the OS itself.
Reply #89 Top
For those of us who are power users & have no one else using our systems.....we really don't need it turned on. I would turn mine on if Stardock stepped in and fixed it. Now can someone do something about the security alert telling me I've turned it off without me turning off my security alerts all together lol. Also the Mac commercial is pretty funny.
Reply #90 Top
Maybe Microsoft can copy the way ZoneAlarm did with their OS Firewall function in ZoneAlarm Internet Security Suite. It remembers your choice. Furthermore, if some software really require bypass, you can set it to ignore that particular application - kind of give it a superuser privilige. If you are not sure, then it can also check with some kind of online database for some default options. Really cool. I allow all those that need privilege and still get informed when some malicious stuff try to write to the OS.
I think it's just better if MS buys off ZoneAlarm, and integrate the whole stuff: you get good firewall, good 'UAC' like implementation, plus spyware defence and some basic antivirus. If you can't integrate the code, at least integrate the design.
I turned off UAC and now wait for maybe ZoneAlarm to update for Vista.
Reply #91 Top
The things is.. this UAC actually copies the way Ubuntu implements it... or maybe Ubuntu copied the idea.. I'm not sure. But it does reminds me of my Ubuntu desktop..
Reply #92 Top

If your app doesn't work under a normal user account (not one with admin rights!), UAC will nag you if launch it under a UAC'd admin account. Make your apps work under normal user accounts and your set to go.

Not if Microsoft has hard-coded into the UAC that SDCentral.exe is an installer and should be flagged. There's nothing we can do on our end to make UAC not come up.  Is that intelligent behavior on Microsoft's part?