Microsoft in retreat over Vista security claims

UAC has flaws, says expert.

Microsoft has made a high-profile pitch to lower public expectations of the security mechanisms built into Windows Vista, particularly User Account Control (UAC).

Mark Russinovich, technical fellow in Microsoft's Platform and Services Division, used a talk at last week's CanSecWest security conference to assure professionals that despite UAC malware "will end up thriving in the standard user environment, setting up botnets, grabbing your keystrokes," according to a blog report by industry journal ZDNet.

Russinovich's talk was intended to give professionals an idea of how to work with UAC to avoid excessive pop-up warnings and avoid breaking the UAC model. But he also explained in detail that UAC isn't intended as a "security boundary", since there are a number of ways around it, and that even in standard-user accounts malware can inflict plenty of damage.

For instance, it can read all the user's data, can hide itself via a user-mode rootkit, and can control which applications the user can access, allowing it to block security programs.

Russinovich predicted that malware would find ways of elevating its privileges, through social engineering or by compromising applications that run with higher privileges, the report said.

However, UAC does "raise the bar" on security, he said.

This isn't the first time Russinovich has thrown cold water on Vista's security mechanisms, which Microsoft originally made out to be one of the principal improvements in Vista over Windows XP. In February, he made the surprising declaration that UAC is not really a security feature.

At CanSecWest he went further in giving details of how malware could work around UAC, even without elevating privileges.

He said malware authors will be able to do more or less what they like within UAC boundaries, such as setting up botnets and infiltrating user data, without taking over the entire system. But UAC will, at least, help protect the overall system and other user accounts, he said.

UAC and their underlying technology, "integrity levels", were not intended to guarantee that processes with higher privileges are protected from compromise by lower-level privileges, but rather as a way of changing the way Windows software is developed, Russinovich said in a February blog post.

"If you aren't guaranteed that your elevated processes aren't susceptible to compromise by those running at a lower IL, why did Windows Vista go to the trouble of introducing elevations and ILs? To get us to a world where everyone runs as standard user by default and all software is written with that assumption," he wrote.

Microsoft's drive is to get users off of administrative accounts and onto those with limited privileges, even if the new arrangement isn't water-tight from a security point of view, Russinovich said.

"The elevation and Protected Mode IE sandboxes might have potential avenues of attack, but they’re better than no sandbox at all," he wrote.

His comments followed a lengthy analysis of UAC and its shortcomings by hacker Joanna Rutkowska, who said she was surprised by Microsoft's dismissive attitude to bugs in UAC's implementation.

"Is this supposed be a joke?" she wrote. "We all remember all those Microsoft’s statements about how serious Microsoft is about security in Vista and how all those new cool security features like UAC or Protected Mode IE will improve the world's security. And now we hear what? That this flagship security technology (UAC) is in fact... not a security technology!"


What are your views on this subject? Use the form below to post a comment on this article up to 500 characters.


Characters remaining: 500

Add your commentComments

Zafar A khan | Published: 15:40 GMT, 25 April 2007

I think Vista is half cooked, half baked dish, not fit for human consumption!!!

Related Security news

Microsoft denies building security 'backdoor' in Windows 7

Privacy organisations shouldn't read too much into NSA involvement it says

Pentagon expands exclusive deal with McAfee

Department of Defense uses McAfee products

Police arrest pair over global banking web scam

Man and woman arrested in Manchester for using notorious Zeus Trojan

Security star Fortinet sets price for IPO

Investors still have taste for tech.



Email this article to a friend or colleague:


PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.

Techworld White Papers

Database security: Preventing enterprise data leaks at the source

IDC discusses the growing internal threats to business information, the impact of government regulations on the protection of data, and how enterprises must adopt database security best practices...

Download Whitepaper

Service-oriented security

SOA has become an integral part of enterprise software by providing a framework to efficiently develop software as services that is easily sharable, reusable, and integrated. No where is the need more apparent than in the Identity Management space. Welcome to the age of Service-Oriented Security (SOS).

Download Whitepaper

Data protection prospective vendor checklist

Organisations need a way to map business needs against all these challenges in procuring a technical solution. To help, SANS has developed the following Prospective Vendor Checklist.

Download Whitepaper

Unlock the power of the mainframe

This whitepaper presents the notion of CICS as an integration hub based on a component-based, service-oriented architecture supporting Web services. Highlights will review the challenges and contrasted support for Web services natively in CICS.

Download Whitepaper

Techworld UK - Technology - Business

COLT White Paper

Are all VoIP services the same?

Questions to ask your service provider to ensure you get the VoIP service you need
With careful choice of partner, your business can have all the advantages of VoIP access - reduced costs, flexibility and simplicity - without the drawbacks.
This white paper is your guide to ensure you get right the VoIP service and details the pitfalls which businesses would do well to avoid.

Download white paper
BMC

Ride the express lane in the journey to speed ITIL adoption

Explore the challenges in making the journey to ITIL and the criteria for selecting consulting services
By following ITIL practices, your IT organisation will become more closely integrated with the business. We recommend making the journey to ITIL in a sequence of six incremental steps, the phases of which are driven through execution of a strategic transformational roadmap.

Download white paper

Webcast: IT Financial Management: Cost Optimisation for Efficiency and Agility.
On Demand Webcast
Join this webcast to learn about the techniques and technologies that can help you prove the value of IT to the business by understanding the true cost of today's IT services and those that will be necessary to deliver future success.

Register Today

Site Map

IDG Network

* *