<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://community.winsupersite.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Norton Takes on Vista's User Account Control</title><link>http://community.winsupersite.com/blogs/paul/archive/2008/10/10/norton-takes-on-vista-s-user-account-control.aspx</link><description>So this is interesting . I can’t stand Norton, for whatever that’s worth, but they’ve shipped a User Account Control tool that seeks to replace the one that’s in Windows Vista (!). Yikes. User Account Control (UAC) is a new security feature in Microsoft</description><dc:language>en</dc:language><generator>CommunityServer 2007 SP2 (Build: 20611.960)</generator><item><title>re: Norton Takes on Vista's User Account Control</title><link>http://community.winsupersite.com/blogs/paul/archive/2008/10/10/norton-takes-on-vista-s-user-account-control.aspx#79087</link><pubDate>Sat, 11 Oct 2008 13:46:44 GMT</pubDate><guid isPermaLink="false">a5a28da7-a54a-49cb-8e3d-fb9e7f7597ae:79087</guid><dc:creator>mikegalos@msn.com</dc:creator><description>&lt;p&gt;PatriotB6007&lt;/p&gt;
&lt;p&gt;It's actually even worse than that. In the example, if app XYZ is Internet aware as most apps are these days then you don't need a vulnerability in both the browser and XYZ. &lt;/p&gt;
&lt;p&gt;You could have the case where XYZ phones home for an update and the XYZCorp update server has been spoofed (say a man in the middle attack). The XYZ app updates itself with the exploit with no prompt (the goal of the Symantec app) and now runs the exploit code.&lt;/p&gt;
&lt;p&gt;So far, this wouldn't be something that UAC would have saved you from since you were expecting the update so you'd have said OK anyway. The problem, though, is that now the pwned XYZ is running the exploit with Admin privs and is able to do lots of evil nasty stuff with no UAC prompts to let you know that the app has been hijacked. This is where UAC would normally prevent damage but the &amp;quot;don't show again&amp;quot; neutered UAC happily lets the pwned app destroy your system without warning.&lt;/p&gt;
&lt;img src="http://community.winsupersite.com/aggbug.aspx?PostID=79087" width="1" height="1"&gt;</description></item><item><title>re: Norton Takes on Vista's User Account Control</title><link>http://community.winsupersite.com/blogs/paul/archive/2008/10/10/norton-takes-on-vista-s-user-account-control.aspx#79086</link><pubDate>Sat, 11 Oct 2008 13:33:36 GMT</pubDate><guid isPermaLink="false">a5a28da7-a54a-49cb-8e3d-fb9e7f7597ae:79086</guid><dc:creator>mikegalos@msn.com</dc:creator><description>&lt;p&gt;PatriotB6007&lt;/p&gt;
&lt;p&gt;Exactly right.&lt;/p&gt;
&lt;p&gt;It isn't as though the people at Microsoft didn't think about &amp;quot;mark this as safe&amp;quot;. It's an obvious optimization. The problem is that it's also an insecure optimization.&lt;/p&gt;
&lt;p&gt;Maybe Symantec has some really neat trick behind the covers that solves the problem.&lt;/p&gt;
&lt;p&gt;Maybe.&lt;/p&gt;
&lt;p&gt;But, nothing on their site suggests that they have. And that makes this tool potentially a serious security hole.&lt;/p&gt;
&lt;img src="http://community.winsupersite.com/aggbug.aspx?PostID=79086" width="1" height="1"&gt;</description></item><item><title>re: Norton Takes on Vista's User Account Control</title><link>http://community.winsupersite.com/blogs/paul/archive/2008/10/10/norton-takes-on-vista-s-user-account-control.aspx#79084</link><pubDate>Sat, 11 Oct 2008 13:15:28 GMT</pubDate><guid isPermaLink="false">a5a28da7-a54a-49cb-8e3d-fb9e7f7597ae:79084</guid><dc:creator>gorath</dc:creator><description>&lt;p&gt;How insane are Symantec?&lt;/p&gt;
&lt;p&gt;Weren't they one of the loudest voices moaning about Vista's locked down kernel as well? And, therefore one of the main reasons why Vista x86 DOESN'T have a locked down kernel?&lt;/p&gt;
&lt;p&gt;And people still trust these morons with their PC's security?&lt;/p&gt;
&lt;img src="http://community.winsupersite.com/aggbug.aspx?PostID=79084" width="1" height="1"&gt;</description></item><item><title>re: Norton Takes on Vista's User Account Control</title><link>http://community.winsupersite.com/blogs/paul/archive/2008/10/10/norton-takes-on-vista-s-user-account-control.aspx#79077</link><pubDate>Sat, 11 Oct 2008 09:10:16 GMT</pubDate><guid isPermaLink="false">a5a28da7-a54a-49cb-8e3d-fb9e7f7597ae:79077</guid><dc:creator>PatriotB6007</dc:creator><description>&lt;p&gt;&amp;quot;Don't ask me again&amp;quot; is a very dangerous feature which leaves your system wide open for elevation of privelege attacks. &amp;nbsp;As I commented on a ZDNet blog yesterday:&lt;/p&gt;
&lt;p&gt;&amp;gt;&amp;gt;&amp;gt;&lt;/p&gt;
&lt;p&gt;The problem with &amp;quot;don't ask me again&amp;quot; is that the system has to know that *you* specifically are the one taking the action requesting the prompt. I'm curious if these Symantec prompts make any attempt to determine this, otherwise it's a giant elevation of privelege hole.&lt;/p&gt;
&lt;p&gt;Let's say there's an unpatched code execution vulnerability in my web browser and I go to a site that tries to exploit it. My browser runs at low integrity (IE) or regular/medium integrity (Firefox), and so I know that any exploit can't do anything administrative without my permission because a UAC prompt would need to appear first.&lt;/p&gt;
&lt;p&gt;However, what if they try to launch something that I'd already said &amp;quot;don't ask me again&amp;quot; for? Is Symantec smart enough to know that the request didn't really come from me? It's really, really hard to determine the difference between the exploit case and a legitimate case.&lt;/p&gt;
&lt;p&gt;&lt;a rel="nofollow" target="_new" href="http://talkback.zdnet.com/5208-12554-0.html?forumID=1&amp;amp;threadID=52936&amp;amp;messageID=998877&amp;amp;start=0"&gt;talkback.zdnet.com/5208-12554-0.html&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&amp;lt;&amp;lt;&amp;lt;&lt;/p&gt;
&lt;p&gt;A reply from &amp;quot;davewood [MS]&amp;quot; (Microsoft employee it would seem) agreed, and mentioned that this also opens the door for application installers to pre-mark the apps they install in the &amp;quot;don't ask&amp;quot; category.&lt;/p&gt;
&lt;p&gt;This enables the following elevation of privelege attack:&lt;/p&gt;
&lt;p&gt;1. I run the installer for app XYZ.&lt;/p&gt;
&lt;p&gt;2. The installer marks XYZ as &amp;quot;don't ask&amp;quot;.&lt;/p&gt;
&lt;p&gt;3. An attacker discovers upon two exploits, one in my web browser and one in XYZ.&lt;/p&gt;
&lt;p&gt;4. I stumble upon a malicious site which uses the browser exploit to cause my browser (which is NOT running as admin) to launch XYZ.exe, feeding it specifically-formed data e.g. via a command line parameter of a file or URL to open.&lt;/p&gt;
&lt;p&gt;5. XYZ silently elevates to Administrator, and the malicious data hits the vulnerability in XYZ and causes the attacker's code to run, with full administrative privileges. &amp;nbsp;Pwned.&lt;/p&gt;
&lt;img src="http://community.winsupersite.com/aggbug.aspx?PostID=79077" width="1" height="1"&gt;</description></item><item><title>re: Norton Takes on Vista's User Account Control</title><link>http://community.winsupersite.com/blogs/paul/archive/2008/10/10/norton-takes-on-vista-s-user-account-control.aspx#79076</link><pubDate>Sat, 11 Oct 2008 08:02:35 GMT</pubDate><guid isPermaLink="false">a5a28da7-a54a-49cb-8e3d-fb9e7f7597ae:79076</guid><dc:creator>lilserenity</dc:creator><description>&lt;p&gt;I haven't switched off UAC and don't understand why it's regarded as annoying. Granted I have only used Vista on my main desktop PC since SP1, but I have found it no more 'annoying' than Mac OS X or Linux systems I also use. It pops up in about the same places, when you install something, or when you want to change a sensitive control panel setting.&lt;/p&gt;
&lt;p&gt;That's been it. It certainly hasn't popped up in places where I wouldn't expect it. All in all, I can only imagine the people with the most problem with it are those who have run 2000/XP boxes with Administrator accounts (which is a heck of a lot) but to my mind, I have no reason to disable UAC.&lt;/p&gt;
&lt;p&gt;I guess I am used to this kind of prompting.&lt;/p&gt;
&lt;img src="http://community.winsupersite.com/aggbug.aspx?PostID=79076" width="1" height="1"&gt;</description></item><item><title>re: Norton Takes on Vista's User Account Control</title><link>http://community.winsupersite.com/blogs/paul/archive/2008/10/10/norton-takes-on-vista-s-user-account-control.aspx#79073</link><pubDate>Sat, 11 Oct 2008 05:32:46 GMT</pubDate><guid isPermaLink="false">a5a28da7-a54a-49cb-8e3d-fb9e7f7597ae:79073</guid><dc:creator>animositysomina</dc:creator><description>&lt;p&gt;Are you guys sure the screenshots we've already seen for Windows 7 UAC settings will make this utility moot? I don't think so because I haven't seen any Win 7 screenshots showing options like &amp;quot;don't display this UAC prompt for this application again&amp;quot; and this is what Norton's UAC utility is trying to achieve. Which may make it extremely useful utility for Win 7 despite what Sir_Timbit says&lt;/p&gt;
&lt;img src="http://community.winsupersite.com/aggbug.aspx?PostID=79073" width="1" height="1"&gt;</description></item><item><title>re: Norton Takes on Vista's User Account Control</title><link>http://community.winsupersite.com/blogs/paul/archive/2008/10/10/norton-takes-on-vista-s-user-account-control.aspx#79072</link><pubDate>Sat, 11 Oct 2008 05:15:37 GMT</pubDate><guid isPermaLink="false">a5a28da7-a54a-49cb-8e3d-fb9e7f7597ae:79072</guid><dc:creator>whiplash55</dc:creator><description>&lt;p&gt;I guess I have give them credit when credit is due. The latest Symantec Antivirus 2009 does not slow down my computer any more than AVG 8.0. I think they're starting to get it.&lt;/p&gt;
&lt;img src="http://community.winsupersite.com/aggbug.aspx?PostID=79072" width="1" height="1"&gt;</description></item><item><title>re: Norton Takes on Vista's User Account Control</title><link>http://community.winsupersite.com/blogs/paul/archive/2008/10/10/norton-takes-on-vista-s-user-account-control.aspx#79068</link><pubDate>Sat, 11 Oct 2008 03:16:14 GMT</pubDate><guid isPermaLink="false">a5a28da7-a54a-49cb-8e3d-fb9e7f7597ae:79068</guid><dc:creator>subzerohitman721</dc:creator><description>&lt;p&gt;I switched off Symantec in 2003, and this is just another reason to boycott Symantec.&lt;/p&gt;
&lt;p&gt;And turning off the UAC? How foolish can you be? It also deactivates several other safety features within Vista, leaving you more vulnerable. How in the hell can you make an argument about Vista and the UAC, when today's 50 additional patches to Leopard brings this year's grand total of OS-X patches to over 250! (Since Symantec also deals with Mac security, it makes it a very relevant discussion point.) Yet we have these morons running around saying to switch off of Vista? Don't make me laugh.&lt;/p&gt;
&lt;p&gt;If anything Symantec needs to know its role and fix its junky anti-virus solutions. Thats why people would rather use AVG or One Care Live, because it doesn't bring your computer down to limping with an injury speeds. With so many free solutions that run better, Symantec doing this crap just makes it more and more irrelevant.&lt;/p&gt;
&lt;p&gt;Paul, I'd do this little Symantec tool in virtualization with a virtualized Vista. I wouldn't want Symantec running in any decent system.&lt;/p&gt;
&lt;img src="http://community.winsupersite.com/aggbug.aspx?PostID=79068" width="1" height="1"&gt;</description></item><item><title>re: Norton Takes on Vista's User Account Control</title><link>http://community.winsupersite.com/blogs/paul/archive/2008/10/10/norton-takes-on-vista-s-user-account-control.aspx#79066</link><pubDate>Sat, 11 Oct 2008 00:40:20 GMT</pubDate><guid isPermaLink="false">a5a28da7-a54a-49cb-8e3d-fb9e7f7597ae:79066</guid><dc:creator>Sir_Timbit</dc:creator><description>&lt;p&gt;Really, just how useful is this product? I've been wary of Symantec stuff for a couple of years now, if only because they need to offer standalone uninstallers because their built-in ones can't do the job. And the screenshots we've already seen for Windows 7 UAC settings will make this utility moot.&lt;/p&gt;
&lt;img src="http://community.winsupersite.com/aggbug.aspx?PostID=79066" width="1" height="1"&gt;</description></item><item><title>re: Norton Takes on Vista's User Account Control</title><link>http://community.winsupersite.com/blogs/paul/archive/2008/10/10/norton-takes-on-vista-s-user-account-control.aspx#79064</link><pubDate>Fri, 10 Oct 2008 22:23:33 GMT</pubDate><guid isPermaLink="false">a5a28da7-a54a-49cb-8e3d-fb9e7f7597ae:79064</guid><dc:creator>mikegalos@msn.com</dc:creator><description>&lt;p&gt;RunTimeError&lt;/p&gt;
&lt;p&gt;I don't think in terms of &amp;quot;one of my own&amp;quot;&lt;/p&gt;
&lt;p&gt;I think of it as the equivalent of somebody in the auto industry saying, &amp;quot;I do not use seat belts for my cars. I am quite capable of making informed decisions about how I drive without some idiotic, poorly designed tool getting in my face and disrupting my driving all too often. &amp;quot;&lt;/p&gt;
&lt;p&gt;Encouraging people to turn off safety features for no better reason than bravado is irresponsible. (And, in this case, shows a lack of understanding about both how UAC works and the things it does besides the security prompts)&lt;/p&gt;
&lt;img src="http://community.winsupersite.com/aggbug.aspx?PostID=79064" width="1" height="1"&gt;</description></item><item><title>re: Norton Takes on Vista's User Account Control</title><link>http://community.winsupersite.com/blogs/paul/archive/2008/10/10/norton-takes-on-vista-s-user-account-control.aspx#79060</link><pubDate>Fri, 10 Oct 2008 21:57:08 GMT</pubDate><guid isPermaLink="false">a5a28da7-a54a-49cb-8e3d-fb9e7f7597ae:79060</guid><dc:creator>yert</dc:creator><description>&lt;p&gt;What’s more, because the UAC may give a false sense of security since other processes can still access the desktop, it actually raises security concerns.&lt;/p&gt;
&lt;p&gt;This is a straight out lie. UAC runs on a Secure Desktop by default. Microsoft should sue Norton for this false advertising that could damage their brand. &lt;/p&gt;
&lt;p&gt;And if Norton can't understand UAC, what makes you think they could do one better? &lt;/p&gt;
&lt;img src="http://community.winsupersite.com/aggbug.aspx?PostID=79060" width="1" height="1"&gt;</description></item><item><title>Najlepsze Programy, Recenzje, Informacje.  &amp;raquo; Blog Archive   &amp;raquo; Norton Takes on Vista&amp;#39;s User Account Control</title><link>http://community.winsupersite.com/blogs/paul/archive/2008/10/10/norton-takes-on-vista-s-user-account-control.aspx#79059</link><pubDate>Fri, 10 Oct 2008 21:52:51 GMT</pubDate><guid isPermaLink="false">a5a28da7-a54a-49cb-8e3d-fb9e7f7597ae:79059</guid><dc:creator>Najlepsze Programy, Recenzje, Informacje.  » Blog Archive   » Norton Takes on Vista's User Account Control</dc:creator><description>&lt;p&gt;Pingback from &amp;nbsp;Najlepsze Programy, Recenzje, Informacje. &amp;nbsp;&amp;amp;raquo; Blog Archive &amp;nbsp; &amp;amp;raquo; Norton Takes on Vista&amp;amp;#39;s User Account Control&lt;/p&gt;
&lt;img src="http://community.winsupersite.com/aggbug.aspx?PostID=79059" width="1" height="1"&gt;</description></item><item><title>Norton Takes on Vista&amp;#39;s User Account Control</title><link>http://community.winsupersite.com/blogs/paul/archive/2008/10/10/norton-takes-on-vista-s-user-account-control.aspx#79058</link><pubDate>Fri, 10 Oct 2008 21:43:16 GMT</pubDate><guid isPermaLink="false">a5a28da7-a54a-49cb-8e3d-fb9e7f7597ae:79058</guid><dc:creator>Norton Takes on Vista's User Account Control</dc:creator><description>&lt;p&gt;Pingback from &amp;nbsp;Norton Takes on Vista&amp;amp;#39;s User Account Control&lt;/p&gt;
&lt;img src="http://community.winsupersite.com/aggbug.aspx?PostID=79058" width="1" height="1"&gt;</description></item><item><title>re: Norton Takes on Vista's User Account Control</title><link>http://community.winsupersite.com/blogs/paul/archive/2008/10/10/norton-takes-on-vista-s-user-account-control.aspx#79053</link><pubDate>Fri, 10 Oct 2008 20:57:33 GMT</pubDate><guid isPermaLink="false">a5a28da7-a54a-49cb-8e3d-fb9e7f7597ae:79053</guid><dc:creator>lotsamystuff</dc:creator><description>&lt;p&gt;&amp;quot;You even beat down on your own.&amp;quot;&lt;/p&gt;
&lt;p&gt;I'm sure Waethorn does. Regularly.&lt;/p&gt;
&lt;p&gt;(I know. Childish. But really, that was just too easy.)&lt;/p&gt;
&lt;img src="http://community.winsupersite.com/aggbug.aspx?PostID=79053" width="1" height="1"&gt;</description></item><item><title>re: Norton Takes on Vista's User Account Control</title><link>http://community.winsupersite.com/blogs/paul/archive/2008/10/10/norton-takes-on-vista-s-user-account-control.aspx#79048</link><pubDate>Fri, 10 Oct 2008 19:41:29 GMT</pubDate><guid isPermaLink="false">a5a28da7-a54a-49cb-8e3d-fb9e7f7597ae:79048</guid><dc:creator>RunTimeError</dc:creator><description>&lt;p&gt;Mike and Weathorn.&lt;/p&gt;
&lt;p&gt;Sheesh. You just just can't stop can you. You even beat down on your own.&lt;/p&gt;
&lt;img src="http://community.winsupersite.com/aggbug.aspx?PostID=79048" width="1" height="1"&gt;</description></item></channel></rss>