NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home / News / Microsoft

Microsoft


Windows Vista Security Model - A Big Joke

Microsoft's flagship security technology (UAC) is in fact… not a security technology?

By Marius Oiaga, Technology News Editor

16th of February 2007, 10:47 GMT

Adjust text size:


The question whether the Windows Vista security model is a big joke was put forward by Joanna Rutkowska, a computer security researcher that has performed a malware code injection with the
Blue Pill rootkit in 64-bit Windows Vista after bypassing PatchGuard. Rutkowska has recently published an extended analysis of the User Account Control in Windows Vista.

Her analysis revealed that the Windows Vista UAC implementation contains bugs that allow for a low integrity process to hijack a high integrity level command prompt, rendering the UAC useless. Mark Russinovich, a Technical Fellow in Microsoft's Platform and Services Division, in an attempt to clarify the issue, said that the bug is not a security vulnerability.

"Because elevations and Integrity Levels don't define a security boundary, potential avenues of attack, regardless of ease or scope, are not security bugs. So if you aren't guaranteed that your elevated processes aren't susceptible to compromise by those running at a lower IL, why did Windows Vista go to the trouble of introducing elevations and ILs? To get us to a world where everyone runs as standard user by default and all software is written with that assumption," Russinovich explained.

Rutkowska then replied: "Is this supposed be a joke? We all remember all those Microsoft's statements about how serious Microsoft is about security in Vista and how all those new cool security features like UAC or Protected Mode IE will improve the world's security. And now we hear what? That this flagship security technology (UAC) is in fact… not a security technology!"

Rutkowska emphasized the UAC design which assumes that all executables should be run elevated and the bugs inherent to the UAC implementation, that are in fact security flaws.
Read by 2,056 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
Good (3.6/5) 10 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2009 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


Vista Windows.old

Is Microsoft Sending the Right Signals for XP Users with Vista?

Microsoft Patches Critical Vulnerability In Windows Vista

Vista vs. XP - Feature Comparison

Windows Ultimate Extra DreamScene Available

Windows Vista Causes Confusion Between "Secure" and "Security"

Windows Vista Kills Networks

Automatic KMS Activation Crack for Windows Vista

Want Lack of Choice? Buy a Mac

Windows Vista Ultimate KMS & Frankenbuild Crack

Microsoft Gags the Next Version of Windows

Microsoft Confirms Vista Follow-Up for 2009

The Best Place to Search for Windows Vista Cracks

Symantec Security for the Impenetrable Vista

Windows Vista Has Issues Handling Photo Metadata

The Windows Vista Aurora Borealis

Messenger Plus Live for Windows Vista

Windows Vista DVD Cubes

Microsoft Is Excluding Users from Vista Security Features

Windows Vista "Companion" Migration Tool

Microsoft Offers Proof of Windows 7 - Next Windows

Crack Available to Install Windows Vista with Only 256MB RAM

Microsoft Acknowledges Vista RAW Image Support Issues

Insight into Windows Vista User Account Control

PC Sales Skyrocket Following the Release of Windows Vista

The $500 Million Windows Vista "Wow"

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM