Wednesday | 9 July, 2008
Computerworld

Vista's UAC security is hopeless, says Symantec
Customers find the User Account Control so "chatty", that it is a burden on users, says Symantec
Matthew Broersma (Techworld.com) 18/01/2007 10:10:48

Computerworld Buyer's Guide - Vendors Matched to this Article
Related Features
  • +

    Your World. . . Hacked 02/10/2007 10:51:23

    As your business becomes more collaborative and global, the risks to your company’s trade secrets rise proportionally. Fortunately, there are new strategies to protect the data that allows you to compete
    The call to Bob Bailey, an IT executive with a major US government contractor, came on an otherwise ordinary day in October 2003. "Why are you attacking us?" demanded the caller, an IT leader with a Silicon Valley manufacturer. He wanted to know why Bailey's company had launched a denial-of-service attack against his network
  • +

    Beyond Vista 22/01/2007 12:19:24

    Inside Microsoft's plan to dominate the Web 2.0 enterprise
    Every decade or so, a new platform emerges that reduces the cost of running an IT department to such an extent that vendors have no choice but to embrace it or die. In the 1990s, PCs with powerful operating systems spelled the end of mainframe development and ushered in the client/server era. Today, cheap servers and high-speed Internet connections are triggering a move away from traditional desktop PC software and to software as a service, hosted by a third party and delivered over the Internet.
  • +

    When Egos Dare 05/06/2007 10:17:02

    For some observers and practitioners, the federated model brings the best elements of centralization and decentralization to the IT table. Others aren’t so sure . . .
    The monarch was dead. Demoralized and shaken, the organization spent time mourning for a popular and high-profile CIO who had reigned for many years. Then, with time starting to dull the pain, the young princes began sharpening their knives, sensing their best opportunity in years to seize power
  • +

    Getting Clueful: Five Things CIOs Should Know About Software Requirements 03/04/2007 12:37:05

    Software requirements documentation was supposed to itemize everything that the application required. But the project was late, the users were unhappy, and the budget spun out of control. Why? Just ask the developers
    Some days, you wish you had telepathy. You just know that your development staff is holding back in some way, but you don't know how to get them to communicate. Is the project in trouble, but they're afraid to tell you?
Additional Resources
Executive Guides
Whitepapers
Zones
Zone logoZones provide focussed content from Computerworld and leading technology partners.

Newsletter Subscription

Sign up for our Computerworld newsletters!
Computerworld's twice-daily news service keeps you in touch with the latest, most important headlines from Australia and around the world.
Keep up with the latest virtualization technologies, products, news and features.
RSS Feeds

A key security feature of Windows Vista, User Account Control (UAC) is still nearly unusable, Symantec has said.

At a press presentation last week, Symantec vice president of engineering Rowan Trollope said Symantec's customers had found the feature so "chatty", that it was a burden on users, potentially creating new help-desk calls.

He said that personally he had found the feature so distracting he had finally turned it off -- not a good sign for companies intending to use UAC to protect systems.

UAC allows administrators to create user accounts that have limited privileges, correcting what security experts perceive as a major weakness in previous versions of Windows. Previously, all Windows users were administrators, something nearly unheard of in the Linux/Unix world.

The change is designed to limit the damage malicious attacks can cause, and to put a damper on attacks that take over large numbers of systems. But it can only be effective if UAC is enabled on a large proportion of Windows systems.

The feature attracted criticism during the beta-testing process, from respected analysts among others, and Microsoft said it fine-tuned UAC.

Symantec does have a vested interest here -- the company plans to sell products that smooth out UAC's alleged faults -- but the company's findings could be evidence of spell additional headaches for system administrators considering Vista.

Symantec's idea is somewhat different; Trollope said the company is proposing to add an extra layer of "intelligence" on top of UAC which would make it easier to use. Such a plan will involve Microsoft's cooperation, Symantec acknowledged, but Microsoft security executives said the company was not yet aware of what Symantec has in mind.

Following Symantec's comments, Microsoft stood by its work. "If the user decides they do not want to run UAC and they would rather run a third-party solution that provides similar functionality, they do have the choice to disable it," Microsoft said in a statement.

Over recent months Microsoft has been moving toward bringing many basic security features under its own roof, providing its own firewall, antivirus and anti-spyware software, for example.

Symantec said users shouldn't get the idea that Vista no longer needs third-party security products -- which, it admitted, would be a disaster for Symantec's own business.

So far, however, industry analysts have largely agreed with Symantec, saying Microsoft has yet to prove itself as a security provider, particularly at the enterprise level.

Computerworld Buyer's Guide - Vendors Matched to this Article
More about Symantec, Microsoft
Market Place

Computerworld Member Login


 

Beyond Virtualisation - The Roadmap to 2012

CIO Breakfast Briefing
8:30am - 10:30am

Brisbane | 22 July | Sofitel Brisbane
Sydney | 23 July | Four Seasons Hotel
Canberra | 24 July | The Hyatt

Attend and discover:

  • What happens after virtualisation
  • The benefits automation drives
  • When automated infrastructures will emerge
  • What the roadmap to 2012 looks like
  • How to deliver an automated architecture
  • How to maximise your investment in virtualisation
Whitepaper

Application Modernization: Preserving Your Organization’s DNA

Modernization has once again attained buzz-word status. But like any other term with billions of dollars swimming around it, modernization has taken on some unexpected connotations. Read on to discover how to embrace modernization in your organization successfully.

Enterprise IT Buyer's Guide
Find Technology Vendors Fast
 
Find vendors by name | Find by category
Sponsored Links