On TV.com: Super Bowl Fun: DAVE + JAY + OPRAH
BNET Business Network:
BNET
TechRepublic
ZDNet

By
Posted on ZDNet News: Apr 11, 2008 6:38:00 PM

SAN FRANCISCO--A Microsoft manager has said that one of the security features in Vista was deliberately designed to "annoy users" to put pressure on third-party software makers to make their applications more secure.

David Cross, a product unit manager at Microsoft, was the group program manager in charge of designing User Account Control (UAC), which, when activated, requires people to run Vista in standard user mode rather than having administrator privileges, and offers a prompt if they try to install a program.

"The reason we put UAC into the (Vista) platform was to annoy users--I'm serious," said Cross, speaking at the RSA Conference here Thursday. "Most users had administrator privileges on previous Windows systems and most applications needed administrator privileges to install or run."

Cross claimed that annoying users had been part of a Microsoft strategy to force independent software vendors (ISVs) to make their code more secure, as insecure code would trigger a prompt, discouraging users from executing the code.

"We needed to change the ecosystem," said Cross. "UAC is changing the ISV ecosystem; applications are getting more secure. This was our target--to change the ecosystem. The fact is that there are fewer applications causing prompts. Eighty percent of the prompts were caused by 10 apps, some from ISVs and some from Microsoft. Sixty-six percent of sessions now have no prompts," said Cross.

Cross claimed it is a myth that users just turn UAC off, saying that Microsoft had collected opt-in information from users that showed that 88 percent were running UAC. Cross said it was also a myth that users blindly accept prompts without reading them.

"It's a myth that users click 'yes,' 'yes,' 'yes,' 'yes,'" said Cross. "Seven percent of all prompts are canceled. Users are not just saying 'yes.'"

Security company Kaspersky has severely criticized UAC, claiming in March last year that it would make Vista less secure than Windows XP.

At this year's RSA Conference, however, the security specialist seemed to have changed its tune. With Windows, "there is a large attack surface with a number of entry points," said Jeff Aliber, Kaspersky's U.S. senior director of product marketing. "Anyone trying to shrink that attack surface and promote secure apps development has to be a good thing."

Prior to the launch of Vista, Kaspersky issued a report in January 2007 that said UAC would be ineffectual. The company claimed that many applications perform harmless actions that, in a security context, can appear to be malicious. As UAC flashes up a warning every time such an action is performed, Kaspersky said that users would be forced to either blindly ignore the warning and allow the action to be performed or disable the feature to stop themselves from going "crazy."

Tom Espiner of ZDNet UK reported from San Francisco.

Click here for more stories on RSA 2008.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 89 Talkback(s)
RE: Microsoft: Vista feature designed to 'annoy users'
Can someone tell me how to configure my Linux machine so I can watch TV on it and use my TV with Linux on it? Can this be done without M$ software? I also have some great pictures of my recent trip ... (Read the rest)
Posted by: johnemartin25@... Posted on: 07/10/08 You are currently: a Guest | | Terms of Use
Statistics...  Solid Water | 04/11/08
New machines full of 'crapware' ...  mwagner@... | 06/05/08
Cross misspeakes...badly  Cayble | 07/10/08
The common solution for all bullies  Ole Man | 04/11/08
Do you post anything  mdemuth | 04/11/08
Yes the do...  cashaww | 04/13/08
Does a cognizant thought  Ole Man | 04/14/08
Thing is...  TtfnJohn | 04/14/08
Another uninformed MS basher  garry_k@... | 06/05/08
It is obvious who is uninformed, and who is not  Ole Man | 06/05/08
to annoy away their customers  djgvjh | 04/11/08
UAC is the No.1 reason users should upgrade  pa2004 | 04/11/08
Previous versions of Windows benefit too.  ye | 04/12/08
Just to clarify...  heres_johnny | 04/14/08
What iTunes does  A.Sinic | 06/05/08
A lot has to do with WHERE the code ...  mwagner@... | 06/05/08
And who is responsible for that?  Ole Man | 06/05/08
True, it's better for XP stability too  PhilippeV | 04/14/08
UAC is the No.1 reason users should upgrade  tracy anne | 04/15/08
More idiot dialog boxes  hasta la Vista, bah-bie | 04/15/08
Bull  Dr_Zinj | 05/08/08
UAC Is The ONLY Reason To Upgrade To Vista  chessmen | 05/08/08
RE: Microsoft: Vista feature designed to 'annoy users'  slikbrit | 04/12/08
Blow Thru?  zenwalker | 04/12/08
Why? Because you said so?  ye | 04/12/08
Re: Why? Because you said so?  none none | 04/13/08
The point is that under Vista ...  mwagner@... | 06/05/08
The point is..........  Ole Man | 06/05/08
More important is UAC scares users from installing  LittleGuy | 04/12/08
This is different than OS X of Linux how? (nt)  ye | 04/12/08
Are you trying to say?  Ole Man | 05/08/08
There are a lot of villians  T1Oracle | 04/12/08
Of course.  Dr_Zinj | 05/08/08
For years, MS has offered ISVs ...  mwagner@... | 06/05/08
"They kept breaking the rules"  Ole Man | 06/05/08
Only ONE MS Vista feature designed to annoy users?  JLMcC | 04/12/08
Curious  A.Sinic | 06/05/08
vista's dreaded BLUE SCREEN OF DEATH!  gleone | 06/05/08
The Best Feature in Vista  T1Oracle | 04/12/08
Well, they succeded.  BitTwiddler | 04/12/08
You're not alone  friedtoast@... | 04/14/08
RE: Microsoft: Vista feature designed to 'annoy users'  admin@... | 04/12/08
RE: Microsoft: Vista feature designed to 'annoy users'  thetwonkey | 04/12/08
Blaming 3rd Parties?  Uber Dweeb | 04/13/08
RE: Microsoft: Vista feature designed to 'annoy users'  chaimss | 04/13/08
RE: Microsoft: Vista feature designed to 'annoy users'  Vadim P. | 04/13/08
Vista superbly and thoroughly annoying  w_c_mead | 04/14/08
I'm used to it.... :P  angelo_elibz24@... | 04/14/08
Your are not alone  Domdomz | 05/08/08
RE: Microsoft: Vista feature designed to 'annoy users'  nwoodson@... | 04/14/08
RE: Microsoft: Vista feature designed to 'annoy users'  DailyWTF | 04/14/08
Annoy away M$....  Dave32265 | 04/14/08
RE: Microsoft: Vista feature designed to 'annoy users'  mhowe0422@... | 04/14/08
RE: Microsoft: Vista feature designed to 'annoy users'  eye4bear | 04/14/08
I am sticking with XP to annoy M$  erm@... | 04/14/08
That doesn't explain...  Demzon | 04/14/08
Why does MS's own Utilities trigger UAC  dbaechtel | 04/14/08
To Teach that UAC means ADMIN  cgarrett@... | 05/08/08
It worked - I WAS annoyed  Keeping Current | 04/14/08
so was I  bluescreen_z | 04/14/08
RE: Microsoft: Vista feature designed to 'annoy users'  dsturg63@... | 04/14/08
MS Annoys Users!!!!!  roog | 04/14/08
Did you miss something?  tracy anne | 04/15/08
RE: Microsoft: Vista feature designed to 'annoy users'  robe@... | 05/08/08
RE: Microsoft: Vista feature designed to 'annoy users'  jaqpc1@... | 05/08/08
This guy is serious????  bobd08 | 05/08/08
RE: Microsoft: Vista feature designed to 'annoy users'  rickhal | 05/08/08
vendors' fault ???  dgrainge | 05/08/08
crazy stuff  billw1234 | 05/10/08
All figured out, without a clue  Ole Man | 05/10/08
consumers to blame too  billw1234 | 05/10/08
One dog food for all, eh?  Ole Man | 05/10/08
Pride Cometh Before the Fall  Cardhu | 06/04/08
RE: Microsoft: Vista feature designed to 'annoy users'  dukebof69@... | 06/05/08
RE: Microsoft: Vista feature designed to 'annoy users'  radioeng | 06/05/08
RE: Microsoft: Vista feature designed to 'annoy users'  mwagner@... | 06/05/08
Finally I can agree with you  Ole Man | 06/05/08
RE: Microsoft: Vista feature designed to 'annoy users'  Daiv_Skinner | 06/05/08
I agree with MS  garry_k@... | 06/05/08
So you don't think  Ole Man | 06/05/08
you don't think you're a customer, do you?  springerj | 06/05/08
That's why I had "customers" in parenthesis  Ole Man | 06/07/08
RE: Microsoft: Vista feature designed to 'annoy users'  Schweigenthaler | 06/06/08
RE: Microsoft: Vista feature designed to 'annoy users'  alxnsc@... | 06/24/08
RE: Microsoft: Vista feature designed to 'annoy users'  rdhalsteatzd | 07/10/08
RE: Microsoft: Vista and Smokey the Bear  ghosko7772 | 07/10/08
Vista annoyed me into LINUX  rdhalsteatzd | 07/10/08
RE: Microsoft: Vista feature designed to 'annoy users'  kentech50 | 07/10/08
RE: Microsoft: Vista feature designed to 'annoy users'  johnemartin25@... | 07/10/08

What do you think?

advertisement
advertisement
Click Here

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here