Sunday, April 29, 2007

Vista + UAC == Security by Annoyance


I have been using Vista for the past few months and I have not been very happy with it. It is annoying, slow and gets in my way more than any other OS I have used. A great example of this is something I ran into the other day. Here is the filesystem setup.

* Inetpub
  * logs
    * w3svc1

So, that is nothing special. The IIS logs have been moved to Inetpub so what, right? Well you get a UAC prompt when you go to access Inetpub you click okay fine. Then navigate down to w3svc1, guess what? You get another UAC prompt at w3svc1, wtf. If I just elevated my privs for the parent folder why do you f'ing ask me again. I can understand it from the security person's perspective. The user might not have any qualms going into a folder but the folder down below they might not have access or it might be something they shouldn't be accessing. But, if you do have access and it has been within a certain time period (say 1 minute) let me through without prompting me! I remember when I first got Vista and I was playing with it I counted the prompts for making a folder and renaming it, it was 6 prompts kind of sad. Granted it wasn't in a folder you don't normally do it (Program Files) but it should still not prompted me that much. I then came up with a phrase "Security through annoyance" which is exactly what the Mac ads are targetting. Rather sad to see this, I wish I could talk to the people who wrote UAC and see what they were thinking.

0 Comments:

Post a Comment

<< Home