<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: You are disabling UAC.  Cancel or Allow?</title>
	<atom:link href="http://www.securitycurve.com/wordpress/archives/500/feed" rel="self" type="application/rss+xml" />
	<link>http://www.securitycurve.com/wordpress/archives/500?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=you-are-disabling-uac-cancel-or-allow</link>
	<description></description>
	<lastBuildDate>Mon, 06 Sep 2010 07:38:49 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
	<item>
		<title>By: Dave H</title>
		<link>http://www.securitycurve.com/wordpress/archives/500/comment-page-1#comment-162</link>
		<dc:creator>Dave H</dc:creator>
		<pubDate>Thu, 29 Mar 2007 17:18:12 +0000</pubDate>
		<guid isPermaLink="false">http://securitycurve.com/wordpress/?p=500#comment-162</guid>
		<description>If the users are being prompted for trying to do the things they are conscious of doing (e.g. deleting a shortcut, changing theme, opening the management application, etc.), then that just accelerates the process of users ignoring the dialog boxes.

It&#039;d be more appropriate if these dialog boxes are generated not by user initiated events, but rather by (untrusted) background processes - you know, like a sane virus scanner or firewall. Don&#039;t know what MS is thinking...
</description>
		<content:encoded><![CDATA[<p>If the users are being prompted for trying to do the things they are conscious of doing (e.g. deleting a shortcut, changing theme, opening the management application, etc.), then that just accelerates the process of users ignoring the dialog boxes.</p>
<p>It&#8217;d be more appropriate if these dialog boxes are generated not by user initiated events, but rather by (untrusted) background processes &#8211; you know, like a sane virus scanner or firewall. Don&#8217;t know what MS is thinking&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dave H.</title>
		<link>http://www.securitycurve.com/wordpress/archives/500/comment-page-1#comment-161</link>
		<dc:creator>Dave H.</dc:creator>
		<pubDate>Thu, 29 Mar 2007 17:13:59 +0000</pubDate>
		<guid isPermaLink="false">http://securitycurve.com/wordpress/?p=500#comment-161</guid>
		<description>If the users are being prompted for trying to do the things they are conscious of doing (e.g. deleting a shortcut, changing theme, opening the management application, etc.), then that just accelerates the process of users ignoring the dialog boxes.

It&#039;d be more appropriate if these dialog boxes are generated not by user initiated events, but rather by (untrusted) background processes - you know, like a sane virus scanner or firewall. Don&#039;t know what MS is thinking...
</description>
		<content:encoded><![CDATA[<p>If the users are being prompted for trying to do the things they are conscious of doing (e.g. deleting a shortcut, changing theme, opening the management application, etc.), then that just accelerates the process of users ignoring the dialog boxes.</p>
<p>It&#8217;d be more appropriate if these dialog boxes are generated not by user initiated events, but rather by (untrusted) background processes &#8211; you know, like a sane virus scanner or firewall. Don&#8217;t know what MS is thinking&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Adam</title>
		<link>http://www.securitycurve.com/wordpress/archives/500/comment-page-1#comment-160</link>
		<dc:creator>Adam</dc:creator>
		<pubDate>Mon, 26 Mar 2007 17:12:13 +0000</pubDate>
		<guid isPermaLink="false">http://securitycurve.com/wordpress/?p=500#comment-160</guid>
		<description>Speaking for me, it gets a lot better once you get through the setup process.  I have UAC on, and see a prompt a week or so.

Adam
</description>
		<content:encoded><![CDATA[<p>Speaking for me, it gets a lot better once you get through the setup process.  I have UAC on, and see a prompt a week or so.</p>
<p>Adam</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: kurt wismer</title>
		<link>http://www.securitycurve.com/wordpress/archives/500/comment-page-1#comment-159</link>
		<dc:creator>kurt wismer</dc:creator>
		<pubDate>Wed, 21 Mar 2007 04:40:47 +0000</pubDate>
		<guid isPermaLink="false">http://securitycurve.com/wordpress/?p=500#comment-159</guid>
		<description>actually, i think asking in general is the right thing to do but you have to be careful not to ask too often... the problem with windows is that too many behaviours have significant enough security implications to warrant the prompt...

the reason these sorts of prompts exist is because applications don&#039;t come pre-loaded with a fingerprint or baseline of what normal behaviour is, much less what YOUR normal behaviour is (the general your, not you specifically) and some designers have had the presence of mind to use those prompts as a means to develop that fingerprint over time... UAC (from what i gather, i avoid vista on philosophical grounds) apparently doesn&#039;t do that and that probably is a failure in the design of UAC...

</description>
		<content:encoded><![CDATA[<p>actually, i think asking in general is the right thing to do but you have to be careful not to ask too often&#8230; the problem with windows is that too many behaviours have significant enough security implications to warrant the prompt&#8230;</p>
<p>the reason these sorts of prompts exist is because applications don&#8217;t come pre-loaded with a fingerprint or baseline of what normal behaviour is, much less what YOUR normal behaviour is (the general your, not you specifically) and some designers have had the presence of mind to use those prompts as a means to develop that fingerprint over time&#8230; UAC (from what i gather, i avoid vista on philosophical grounds) apparently doesn&#8217;t do that and that probably is a failure in the design of UAC&#8230;</p>
]]></content:encoded>
	</item>
</channel>
</rss>
