User Account Control and Security

While Windows XP went a long way towards correcting some of the biggest problems in previous versions of Windows, it's also had some significant problems where its age has not been good to it. Paramount among these is the overall security of Windows, a two-fold problem involving some arguably poor programming practices at Microsoft, and an operating system that nearly expects all users to be full administrators. Microsoft has made some effort to correct this in Widows XP, especially with Service Pack 2 which added support for the no-execute security bit and a dramatically improved firewall, but there's only so much Microsoft can do without completely overhauling the operating system.

With Vista of course, now that Microsoft has the chance to do so, they have made some significant changes to the underpinnings of Vista in order to better lockdown the operating system; specifically, with a feature called User Account Control. The basic premise behind UAC is that the previous way of running everything as an Administrator was wrong, and by doing so it not only allowed applications to make system-wide changes when they shouldn't, but it also meant that compromised applications could be used as a vector to attack the system. As a result, even an administrator isn't really an administrator under Vista.

The most noticeable change as a result of this is that Vista will attempt to run most programs using standard permissions, effectively turning administrators into standard users. For many programs, especially programs included in Vista, this won't be a problem, and they'll be able to run fine with standard permissions. Windows Media Player 11 is one such example of a program that had problems under XP that has been fixed for Vista.

For a second class of programs, those that think they need admin permissions but really do not, Microsoft has engineered what amounts to a partial sandbox for those applications, so that when they attempt to make changes in global locations (the Windows directory, certain registry locations, etc.), they'll instead be secretly redirected to locations inside of the user's home folder and the user's local branch of the registry, allowing these programs to make the file and registry changes they want without having true access to the global operating system. A number of programs that haven't been modified to be completely compliant with standard permissions can be made to work fine under this still-protected mode.

Click to enlarge


Last, but not least, there are certain programs and actions that simply require administrator privileges, such as deletions outside the user's home folder and most control panel changes. Here, Vista is implementing a very Unix-like system of getting the user's permission, rather than implicitly granting the user permission to undertake the action based on their administrator credentials. Vista will bring up a secure dialog box that informs the user of the action that is to be taken, and gives them the option to either approve or deny it (non-admin users will need to provide an admin account first).

Click to enlarge


It's this last change that will likely be most jarring for users coming from XP, as it turns out there are a number of actions Windows undertakes right now that are administrator level and are based on implicit permission. At this point, UAC will ask for confirmation a lot; entirely too much in fact (we ended up turning off UAC at one point). We've had to deal with other quirks with UAC as well, for example it's now harder to terminate an administrator-privileged program that's run amok (you have to elevate your permissions in the task manager to do it). There's also the ultimate issue of working out which programs need to be run in administrator mode; if a program isn't working, is it because it's incompatible with Vista, or because it needs administrator powers?

Microsoft is aware of this, and is working on streamlining the process for the release version of Vista, so the obtrusions should not be as bad as with the current beta. Nevertheless, it puts users in the odd position of picking an OS mode that either is secure because it makes it much harder for malware to infect the system at the cost of making every action potentially less convenient, or a more liberal system that gives up the security benefits. This is an especially odd position for enthusiasts who tend to have the skills to prevent a malware infection in the first place; not only is UAC not as helpful for them, but as one of the biggest new features in Vista, is it worth buying Vista if you're not going to use UAC?

Ultimately, UAC is a huge part of the new security systems within Vista, and even if it isn't perfectly streamlined by release, it will be much better for virtually all users to have it enabled and slightly bothered by it, rather than being in the open. If too many users end up turning off UAC, it can create a chicken/egg situation where application developers will not bother to make their programs work without administrative powers (just like today), and where Vista is left with much of the same security mess that XP has today as the other security systems aren't enough to completely secure Vista on their own. Everyone is going to find it's a significant change compared to the easy-going XP, but it's without a doubt this kind of overhaul is going to be for the best: what you don't know can hurt you.

It's also worth mentioning that IE7+ (the Vista version of IE7) will be tied into UAC. Its own sandbox mode, which is intended to keep ActiveX controls from running amok, requires UAC to be active to be effective; otherwise it will only have similar protections to what IE6 offers today. However, given the immense use of IE6 right now as a vector of attack for spyware, on paper it seems like these changes should significantly strengthen IE7 and Windows as a whole.

Besides UAC, Microsoft has made a couple other significant additions to Windows, largely as a tool of last resort, since the ultimate power to install spyware lies with the users; some will still continue to run malicious applications with administrative privileges, and will need tools to deal with that. The Windows firewall has been upgraded to a full-service product that is capable of blocking both inbound and now outbound connections, which provides an additional method of warning users that they have malicious applications attempting to get out to the internet, and a way of containing them until removal. Microsoft Anti-Spyware has also been integrated into Vista, given the new name Windows Defender. Defender has been given a significant upgrade from the previous incarnation as MAS, and now is a real-time scanning application that on top of removing spyware can monitor IE downloads for known spyware and warn users of suspicious user-level changes to programs like IE.

Lastly, Microsoft has implemented a range of parental control features intended to better help parents control their kids' activities, extending some of the previous business-class control features of Windows. On top of the already limited abilities of standard user accounts, new control features includes the ability to lock down computer usage to certain times, and Microsoft has indicated they may expand this in the future to specific applications at specific times. Other features are the ability to outright block specific programs and websites, and to monitor certain activities enacted by controlled accounts (with special attention to internet activity, instant messenger usage, email, and time spent playing games).

DirectX 10 Performance Improvements
Comments Locked

75 Comments

View All Comments

  • stash - Friday, June 16, 2006 - link

    Sleep is more effecient in the long run. Shutting down and doing a cold boot every day uses a lot more electricity than sleep. When the machine is in sleep, it uses a fraction of a single watt. Yes, this is obviously more than zero (completely off), but when you cold boot a system, it uses many times more power.

    As a side benefit, you get back to where you left off almost instantly because sleep combines standby with hibernation.
  • Griswold - Friday, June 16, 2006 - link

    Oh so wrong. Why would a cold boot use more power? Because the HDDs spin up? Going from sleep to full on does the same. Because the OS has to be loaded from the HDD? Sleep mode also writes to disk. And thats actually it. This is a computer, not an engine that uses more fuel at startup than when it runs.
  • stash - Friday, June 16, 2006 - link

    When you can resume from sleep in a few seconds compared to 45-60 seconds from a cold boot, then yes, a cold boot uses much more power.
  • johnsonx - Friday, June 16, 2006 - link

    Stash, your logic is faulty. Please give up.
  • stash - Friday, June 16, 2006 - link

    Why should I give up? How is my logic faulty.
  • smitty3268 - Friday, June 16, 2006 - link

    <I>Is Expose the same as the new compiz and XGL?</I>

    No, that is more like the Aero interface or OSX's Quartz Extreme. Expose lets you hit a button and then automatically scales and moves every window so that you can see them all and pick out which program you want to use. Think of it as a replacement for ALT-TAB. There is a plugin in compiz that does the same thing.
  • Locutus465 - Friday, June 16, 2006 - link

    Not sure what your issues with 3D were, I only skimmed the artical so I'm sure which video card you used... But it's possible that if you're using ATI you experienced problems due to their drivers. I've seen many more ATI issues in the MS groups than nVida. My 7800GT has no problem with 1600x1200 (full 3d acceloration, no apparent crashing). My only concern wth Vista 64 is drivers... As of right now there's no driver avaailable for the Promies Ultra100TX2 controller card which is a huge issue for me as I have my secondary drive (used to store installers and as my page file drive in XP). I hope MS manages to convince to support 64b as well as 32b is supported. When I do upgrade to Vista, it will be to 64b.
  • JarredWalton - Friday, June 16, 2006 - link

    Page 10: using 6800 Ultra card.

    The problem is both with drivers (64-bit are still being worked on), the OS (still being worked on), and resource requierments are increased under 64-bit mode. Compatibility with various hardware is already worse with Vista, but 64-bit mode is even worse still. Can they fix it before shipping? Hopefully, and one way or another we're going 64-bit in the future.

    It could be that other test systems would be more or less stable, but with a preview of Vista Beta 2 that's really too much extra work. The article was already over 12000 words, so trying it out on five other platforms would make this monolithic task even more daunting. The bottom line is that Vista is still interesting, but it's definitely not ready for release. There's a good reason it has been delayed until 2007, just like the XP x64 delays in the past.
  • DerekWilson - Friday, June 16, 2006 - link

    We have tested Vista with both ATI and NVIDIA drivers and see similar issues between the two. While the numbers were gathered under NVIDIA hardware, we are confident that the same patterns would emerge with ATI at this point in time.
  • Locutus465 - Friday, June 16, 2006 - link

    Well, weird... I've had my share of beta issues but thus far Glass + 3D acceleration hasn't been one of them. I have noticed that installing QuickTime 7 on Vista (at least in my case) renders Vista Ultimite 64 unbootable.

Log in

Don't have an account? Sign up now