How avoid having to give repeated permissions

Page 2 of 2 FirstFirst 12

  1. Posts : 74
    Windows XP
    Thread Starter
       #11

    Well this has been a good thread.

    In an effort to do things "By the Book", and supposing the wisdom of others to be greater than my own, I did indeed set things up so that I log in (at present) as a standard user, and switch to Admin when asked to. I did suppose it might give me some further protection, but based on the comments here - not really. I am computer saavy, basically the only one that uses this computer, and I stay away from the places I'm not supposed to go.

    I understand Microsoft wanting to cover themselves, but that doesn't mean I shouldn't exercise a little good sense of my own. I think given what's been said (all the caveats understood), for me, logging in as Administrator and lowering or Eliminating UAC will make me a happier user.

    Thank you for your input
      My Computer


  2. Posts : 45
    7 Ultimate 32Bit / Ubuntu 9.10 64Bit / 9.10 64Bit
       #12

    http://en.wikipedia.org/wiki/Princip...east_privilege gives a good explanation of this issue. It's something that has been inclusive in Unix based OSs since their inception, because they were networking based Operating Systems.

    In the internet age Microsoft has seen that this is a good, tried and tested way of doing things and copied it. It makes it a lot harder for programs to trash anything other than their data directories (or the users /home; if it's anything like the Unix method).

    People who have only ever used Windows don't quite understand the feature and how it might help. http://en.wikipedia.org/wiki/Privile...ion_strategies

    Analogy: If you were an experienced Officer on the battlefield would you not wear body armour and a helmet just because you "knew what you were doing"? Or would you think you were safer with it "just in case". (A bit dramatic I know, but I couldn't think of a better comparison.:) )

    Edited links. (Put wrong one first, lol)
      My Computer


  3. Posts : 231
    Win7
       #13

    veii said:
    Principle of least privilege - Wikipedia, the free encyclopedia gives a good explanation of this issue. It's something that has been inclusive in Unix based OSs since their inception, because they were networking based Operating Systems.

    In the internet age Microsoft has seen that this is a good, tried and tested way of doing things and copied it. It makes it a lot harder for programs to trash anything other than their data directories (or the users /home; if it's anything like the Unix method).

    People who have only ever used Windows don't quite understand the feature and how it might help. Privilege escalation - Wikipedia, the free encyclopedia

    Analogy: If you were an experienced Officer on the battlefield would you not wear body armour and a helmet just because you "knew what you were doing"? Or would you think you were safer with it "just in case". (A bit dramatic I know, but I couldn't think of a better comparison.:) )

    Edited links. (Put wrong one first, lol)
    I don't equate my personal safety with wanting to make my Windows experience more pleasant by turning off that nag of nags, UAC.
      My Computer


  4. Posts : 31,250
    Windows 11 Pro x64 [Latest Release and Release Preview]
       #14

    Putting aside the highly personal choice of if to run UAC or not, and getting back to the original point of the post.

    If you wish to prevent the prompting of the system for enhanced privileges, you need to set the NTFS permissions on the folders, (the root of the tree concerned should be sufficient as permissions are inherited cascade style), to provide the standard user with the permissions required to perform the task at hand.

    In this case you would log in as the admin and set the permissions for the standard user to read & navigate, (assuming you wish to keep write protection to prevent accidental deletions), or Full control, (If you wish to work on the backup files as the standard user)
      My Computers


  5. Posts : 344
    Windows 7, Linux
       #15

    As a Linux/Windows user, I've had huge debates on this topic.... And honestly it's NOT ****ING WORTH IT. The idea of having a SU (or elevated user) is good! But if you do so giving users any upper end on privileges is BAD.

    Our case was this, if you give a user any way of read/write to any elevated files you have just given them SU access. Why? Because it goes as this.... User + file (that has elevated privileges) = SU. How? If they file has higher permissions than the user, even though it's a file, then the user has elevated privileges. Because the user is running at the level of the file that they are getting control of.

    Basically 2 different accounts is GOOD. But since I give a rats ass about security on Windows I just run as an admin all the time. I don't like to deal with UAC or admin rights, when I want something done I want it done now. windows has this problem with over protection, which is good for those retards out there, but bad for those who actually know how to run an OS. I don't like waiting for virus scan to complete, I don't like waiting to elevate privileges, I don't like windows telling me I can't do something. Why? Because I own this computer, and I'll be damned if I can't do it! lol

    In linux I practice it because it's easier to make a mistake and delete important files. since windows won't even let admins delete currently 'in use' files or system files (unless in safe mode) then I have no reason to have a user account.

    Most people who get a virus, have slow computers, or anything on that subject have downloaded the problem and it is their fault. If you follow some basic rules you'll never need virus/UAC/Admin restructions. If it sounds too good to be true.....

    I haven't used AV in almost 8 years, I've had one virus. Blaster32! WOOO FOR BLASTER!!! And one trojan, but that was back when I played around with Sub7... =P Yeah MY BAD. The theory of AV is a joke, because you don't get a virus definition until AFTER it has been infecting computers. That's like having sex and then putting on the condom. WTF!? Really? Do you do that? Your best bet is 2 accounts, one trusted and one untrusted. If you don't give a rats ass and have all your important data BACKED UP! like a good person just use 1 account. It saves time, and really you don't need 2 accounts. Just don't install every program that "makes life easier".
      My Computer


  6. Posts : 2,685
    Windows 7 Ultimate x86-64
       #16

    I'd keep UAC - Windows use defense in depth and you should utilize every last bit of protection you can - and watch what you click.
      My Computer


 
Page 2 of 2 FirstFirst 12

  Related Discussions
Our Sites
Site Links
About Us
Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 01:13.
Find Us