<?xml version="1.0" encoding="utf-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Vista Security A Joke? : Executables Install As Administrator Because It&#8217;s More Convenient</title>
	<atom:link href="http://danielmiessler.com/blog/vista-security-a-joke-executables-install-as-administrator-because-its-more-convenient/feed" rel="self" type="application/rss+xml" />
	<link>http://danielmiessler.com/blog/vista-security-a-joke-executables-install-as-administrator-because-its-more-convenient</link>
	<description>grep understanding</description>
	<lastBuildDate>Fri, 25 May 2012 02:15:50 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
	<item>
		<title>By: Ron</title>
		<link>http://danielmiessler.com/blog/vista-security-a-joke-executables-install-as-administrator-because-its-more-convenient/comment-page-1#comment-143464</link>
		<dc:creator>Ron</dc:creator>
		<pubDate>Sun, 11 May 2008 06:18:59 +0000</pubDate>
		<guid isPermaLink="false">http://dmiessler.com/archives/1141#comment-143464</guid>
		<description>&lt;p&gt;People that say Mac is secure and Unix is secure are wrong. You can&#039;t have a totally secure operating system unless it is a closed system, any system that allows installation of any 3rd party software is inherently insecure. There are many more attacks on Windows because 98% of computers run Windows.&lt;/p&gt;

&lt;p&gt;That said the UAC in Vista is a joke, all the UAC does is verify that you want to run a program when you double click on it...if I didn&#039;t I wouldn&#039;t have clicked on the icon. The UAC is just an illusion of security.&lt;/p&gt;

&lt;p&gt;What the UAC should do is tell you things like a program is setting itself to start automatically at startup, but it doesn&#039;t do that, once you say it is alright for a setup program to run the setup can do whatever it likes without any UAC prompt.&lt;/p&gt;

&lt;p&gt;For an example I recently installed Nero 8 on Vista with UAC on. It prompted for the setup to run, during setup Nero set 3 program to auto start with Windows, without the setup telling me or UAC. After unistalling Nero the 3 programs set to suto start were still there, I had to remove them manually through registry.&lt;/p&gt;

&lt;p&gt;Stuff like that is what causes winrott and malware. All the UAC does is ask when you double click on something are you sure you wanted to, not much else.&lt;/p&gt;

&lt;p&gt;The UAC I guess could be called a start but barely a start, there has been better security software on the market for years such as ZoneAlarm which monitors additions to startup section of registry and keyloggers. &lt;/p&gt;

&lt;p&gt;Viruses can be spread with UAC just as easy as without, simply use an installer, the user gets prompted is it OK, they don&#039;t know its a virus so they click yes, and the installer installs the virus, sets it to start automatically along with 20 other viruses and malware. UAC is an ilusion and a waste of all of our time.&lt;/p&gt;

&lt;p&gt;All that being said Windows is in no jeopardy of losing its dominance because of security, anybody that is serious about security has real security software installed. Security and false security like the UAC and the incompatibility issues something like the useless UAC causes along with a lot of other reasons is losing causing them to slowly lose market share. But it would take many, many years of bad design for MS to lose their dominance.&lt;/p&gt;

&lt;p&gt;I hear a lot of people talking about lazy programmers and how the security problems are because of them. Microsoft enjoys dominance because of these so called &quot;lazy&quot; programmers. All PC buyers should think back to the first time they had to choose between a MAC and a PC and remember that they chose the PC because of all the software that was available for it. Quit blaming lack of security on programmers, give us real security and real information.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>People that say Mac is secure and Unix is secure are wrong. You can&#8217;t have a totally secure operating system unless it is a closed system, any system that allows installation of any 3rd party software is inherently insecure. There are many more attacks on Windows because 98% of computers run Windows.</p>

<p>That said the UAC in Vista is a joke, all the UAC does is verify that you want to run a program when you double click on it&#8230;if I didn&#8217;t I wouldn&#8217;t have clicked on the icon. The UAC is just an illusion of security.</p>

<p>What the UAC should do is tell you things like a program is setting itself to start automatically at startup, but it doesn&#8217;t do that, once you say it is alright for a setup program to run the setup can do whatever it likes without any UAC prompt.</p>

<p>For an example I recently installed Nero 8 on Vista with UAC on. It prompted for the setup to run, during setup Nero set 3 program to auto start with Windows, without the setup telling me or UAC. After unistalling Nero the 3 programs set to suto start were still there, I had to remove them manually through registry.</p>

<p>Stuff like that is what causes winrott and malware. All the UAC does is ask when you double click on something are you sure you wanted to, not much else.</p>

<p>The UAC I guess could be called a start but barely a start, there has been better security software on the market for years such as ZoneAlarm which monitors additions to startup section of registry and keyloggers. </p>

<p>Viruses can be spread with UAC just as easy as without, simply use an installer, the user gets prompted is it OK, they don&#8217;t know its a virus so they click yes, and the installer installs the virus, sets it to start automatically along with 20 other viruses and malware. UAC is an ilusion and a waste of all of our time.</p>

<p>All that being said Windows is in no jeopardy of losing its dominance because of security, anybody that is serious about security has real security software installed. Security and false security like the UAC and the incompatibility issues something like the useless UAC causes along with a lot of other reasons is losing causing them to slowly lose market share. But it would take many, many years of bad design for MS to lose their dominance.</p>

<p>I hear a lot of people talking about lazy programmers and how the security problems are because of them. Microsoft enjoys dominance because of these so called &#8220;lazy&#8221; programmers. All PC buyers should think back to the first time they had to choose between a MAC and a PC and remember that they chose the PC because of all the software that was available for it. Quit blaming lack of security on programmers, give us real security and real information.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ron</title>
		<link>http://danielmiessler.com/blog/vista-security-a-joke-executables-install-as-administrator-because-its-more-convenient/comment-page-1#comment-247009</link>
		<dc:creator>Ron</dc:creator>
		<pubDate>Sun, 11 May 2008 06:18:00 +0000</pubDate>
		<guid isPermaLink="false">http://dmiessler.com/archives/1141#comment-247009</guid>
		<description>&lt;p&gt;People that say Mac is secure and Unix is secure are wrong. You can&#039;t have a totally secure operating system unless it is a closed system, any system that allows installation of any 3rd party software is inherently insecure. There are many more attacks on Windows because 98% of computers run Windows.&lt;/p&gt;

&lt;p&gt;That said the UAC in Vista is a joke, all the UAC does is verify that you want to run a program when you double click on it...if I didn&#039;t I wouldn&#039;t have clicked on the icon. The UAC is just an illusion of security.&lt;/p&gt;

&lt;p&gt;What the UAC should do is tell you things like a program is setting itself to start automatically at startup, but it doesn&#039;t do that, once you say it is alright for a setup program to run the setup can do whatever it likes without any UAC prompt.&lt;/p&gt;

&lt;p&gt;For an example I recently installed Nero 8 on Vista with UAC on. It prompted for the setup to run, during setup Nero set 3 program to auto start with Windows, without the setup telling me or UAC. After unistalling Nero the 3 programs set to suto start were still there, I had to remove them manually through registry.&lt;/p&gt;

&lt;p&gt;Stuff like that is what causes winrott and malware. All the UAC does is ask when you double click on something are you sure you wanted to, not much else.&lt;/p&gt;

&lt;p&gt;The UAC I guess could be called a start but barely a start, there has been better security software on the market for years such as ZoneAlarm which monitors additions to startup section of registry and keyloggers. &lt;/p&gt;

&lt;p&gt;Viruses can be spread with UAC just as easy as without, simply use an installer, the user gets prompted is it OK, they don&#039;t know its a virus so they click yes, and the installer installs the virus, sets it to start automatically along with 20 other viruses and malware. UAC is an ilusion and a waste of all of our time.&lt;/p&gt;

&lt;p&gt;All that being said Windows is in no jeopardy of losing its dominance because of security, anybody that is serious about security has real security software installed. Security and false security like the UAC and the incompatibility issues something like the useless UAC causes along with a lot of other reasons is losing causing them to slowly lose market share. But it would take many, many years of bad design for MS to lose their dominance.&lt;/p&gt;

&lt;p&gt;I hear a lot of people talking about lazy programmers and how the security problems are because of them. Microsoft enjoys dominance because of these so called &quot;lazy&quot; programmers. All PC buyers should think back to the first time they had to choose between a MAC and a PC and remember that they chose the PC because of all the software that was available for it. Quit blaming lack of security on programmers, give us real security and real information.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>People that say Mac is secure and Unix is secure are wrong. You can&#8217;t have a totally secure operating system unless it is a closed system, any system that allows installation of any 3rd party software is inherently insecure. There are many more attacks on Windows because 98% of computers run Windows.</p>

<p>That said the UAC in Vista is a joke, all the UAC does is verify that you want to run a program when you double click on it&#8230;if I didn&#8217;t I wouldn&#8217;t have clicked on the icon. The UAC is just an illusion of security.</p>

<p>What the UAC should do is tell you things like a program is setting itself to start automatically at startup, but it doesn&#8217;t do that, once you say it is alright for a setup program to run the setup can do whatever it likes without any UAC prompt.</p>

<p>For an example I recently installed Nero 8 on Vista with UAC on. It prompted for the setup to run, during setup Nero set 3 program to auto start with Windows, without the setup telling me or UAC. After unistalling Nero the 3 programs set to suto start were still there, I had to remove them manually through registry.</p>

<p>Stuff like that is what causes winrott and malware. All the UAC does is ask when you double click on something are you sure you wanted to, not much else.</p>

<p>The UAC I guess could be called a start but barely a start, there has been better security software on the market for years such as ZoneAlarm which monitors additions to startup section of registry and keyloggers. </p>

<p>Viruses can be spread with UAC just as easy as without, simply use an installer, the user gets prompted is it OK, they don&#8217;t know its a virus so they click yes, and the installer installs the virus, sets it to start automatically along with 20 other viruses and malware. UAC is an ilusion and a waste of all of our time.</p>

<p>All that being said Windows is in no jeopardy of losing its dominance because of security, anybody that is serious about security has real security software installed. Security and false security like the UAC and the incompatibility issues something like the useless UAC causes along with a lot of other reasons is losing causing them to slowly lose market share. But it would take many, many years of bad design for MS to lose their dominance.</p>

<p>I hear a lot of people talking about lazy programmers and how the security problems are because of them. Microsoft enjoys dominance because of these so called &#8220;lazy&#8221; programmers. All PC buyers should think back to the first time they had to choose between a MAC and a PC and remember that they chose the PC because of all the software that was available for it. Quit blaming lack of security on programmers, give us real security and real information.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Bill</title>
		<link>http://danielmiessler.com/blog/vista-security-a-joke-executables-install-as-administrator-because-its-more-convenient/comment-page-1#comment-85776</link>
		<dc:creator>Bill</dc:creator>
		<pubDate>Thu, 04 Oct 2007 01:55:38 +0000</pubDate>
		<guid isPermaLink="false">http://dmiessler.com/archives/1141#comment-85776</guid>
		<description>&lt;p&gt;Ok... what about this:&lt;/p&gt;

&lt;p&gt;I have a simple program (let&#039;s say app.exe) and I can install it just fine on XP as a limited user.&lt;/p&gt;

&lt;p&gt;However, as a &quot;standard&quot; user on vista I cannot install without the admin password.&lt;/p&gt;

&lt;p&gt;What&#039;s up with that?&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Ok&#8230; what about this:</p>

<p>I have a simple program (let&#8217;s say app.exe) and I can install it just fine on XP as a limited user.</p>

<p>However, as a &#8220;standard&#8221; user on vista I cannot install without the admin password.</p>

<p>What&#8217;s up with that?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Bill</title>
		<link>http://danielmiessler.com/blog/vista-security-a-joke-executables-install-as-administrator-because-its-more-convenient/comment-page-1#comment-247008</link>
		<dc:creator>Bill</dc:creator>
		<pubDate>Thu, 04 Oct 2007 01:55:00 +0000</pubDate>
		<guid isPermaLink="false">http://dmiessler.com/archives/1141#comment-247008</guid>
		<description>&lt;p&gt;Ok... what about this:&lt;/p&gt;

&lt;p&gt;I have a simple program (let&#039;s say app.exe) and I can install it just fine on XP as a limited user.&lt;/p&gt;

&lt;p&gt;However, as a &quot;standard&quot; user on vista I cannot install without the admin password.&lt;/p&gt;

&lt;p&gt;What&#039;s up with that?&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Ok&#8230; what about this:</p>

<p>I have a simple program (let&#8217;s say app.exe) and I can install it just fine on XP as a limited user.</p>

<p>However, as a &#8220;standard&#8221; user on vista I cannot install without the admin password.</p>

<p>What&#8217;s up with that?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: dmiessler.com &#124; grep understanding knowledge</title>
		<link>http://danielmiessler.com/blog/vista-security-a-joke-executables-install-as-administrator-because-its-more-convenient/comment-page-1#comment-29066</link>
		<dc:creator>dmiessler.com &#124; grep understanding knowledge</dc:creator>
		<pubDate>Thu, 15 Feb 2007 19:44:43 +0000</pubDate>
		<guid isPermaLink="false">http://dmiessler.com/archives/1141#comment-29066</guid>
		<description>&lt;p&gt;[...] I wrote about Joanna Rutkowska&#8217;s work that highlighted a serious security flaw in Windows Vista. Her [...]&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>[...] I wrote about Joanna Rutkowska&#8217;s work that highlighted a serious security flaw in Windows Vista. Her [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Daniel Miessler</title>
		<link>http://danielmiessler.com/blog/vista-security-a-joke-executables-install-as-administrator-because-its-more-convenient/comment-page-1#comment-29001</link>
		<dc:creator>Daniel Miessler</dc:creator>
		<pubDate>Thu, 15 Feb 2007 15:14:16 +0000</pubDate>
		<guid isPermaLink="false">http://dmiessler.com/archives/1141#comment-29001</guid>
		<description>&lt;p&gt;02.15.07
So it appears I was largely wrong about this. Not about it being an issue (it is), but about my judgment of the design and the severity of the implications. After reading extensively about the issue I came across a comment here on the site that captured it really well:&lt;/p&gt;

&lt;p&gt;&lt;BLOCKQUOTE&gt;So, the crux of the situation is that currently a lot of apps and their installers are written to install for the system, and to do so these apps request admin rights.&lt;/BLOCKQUOTE&gt;&lt;/p&gt;

&lt;p&gt;That&#039;s really it. Microsoft is simply dealing with its insecure past, i.e. a world in which installers had full admin rights to do anything they wanted on the system. As such, most software is still written in this fashion, and since that&#039;s the case, and Vista users are non-privileged, -- old, dirty-style programs have to be installed with elevated rights if you want to use them.&lt;/p&gt;

&lt;p&gt;In short, it&#039;s still a security problem, but the problem comes from Microsoft&#039;s difficult to handle legacy past, not a recent, poor security decision by Microsoft.&lt;/p&gt;

&lt;p&gt;Anyway, I was sloppy, and I apologize for that. I should have nailed down the problem more accurately before posting.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>02.15.07
So it appears I was largely wrong about this. Not about it being an issue (it is), but about my judgment of the design and the severity of the implications. After reading extensively about the issue I came across a comment here on the site that captured it really well:</p>

<p><blockquote>So, the crux of the situation is that currently a lot of apps and their installers are written to install for the system, and to do so these apps request admin rights.</blockquote></p>

<p>That&#8217;s really it. Microsoft is simply dealing with its insecure past, i.e. a world in which installers had full admin rights to do anything they wanted on the system. As such, most software is still written in this fashion, and since that&#8217;s the case, and Vista users are non-privileged, &#8212; old, dirty-style programs have to be installed with elevated rights if you want to use them.</p>

<p>In short, it&#8217;s still a security problem, but the problem comes from Microsoft&#8217;s difficult to handle legacy past, not a recent, poor security decision by Microsoft.</p>

<p>Anyway, I was sloppy, and I apologize for that. I should have nailed down the problem more accurately before posting.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Daniel Miessler</title>
		<link>http://danielmiessler.com/blog/vista-security-a-joke-executables-install-as-administrator-because-its-more-convenient/comment-page-1#comment-247007</link>
		<dc:creator>Daniel Miessler</dc:creator>
		<pubDate>Thu, 15 Feb 2007 15:14:00 +0000</pubDate>
		<guid isPermaLink="false">http://dmiessler.com/archives/1141#comment-247007</guid>
		<description>&lt;p&gt;02.15.07
So it appears I was largely wrong about this. Not about it being an issue (it is), but about my judgment of the design and the severity of the implications. After reading extensively about the issue I came across a comment here on the site that captured it really well:&lt;/p&gt;

&lt;blockquote&gt;So, the crux of the situation is that currently a lot of apps and their installers are written to install for the system, and to do so these apps request admin rights.&lt;/blockquote&gt;

&lt;p&gt;That&#039;s really it. Microsoft is simply dealing with its insecure past, i.e. a world in which installers had full admin rights to do anything they wanted on the system. As such, most software is still written in this fashion, and since that&#039;s the case, and Vista users are non-privileged, -- old, dirty-style programs have to be installed with elevated rights if you want to use them.&lt;/p&gt;

&lt;p&gt;In short, it&#039;s still a security problem, but the problem comes from Microsoft&#039;s difficult to handle legacy past, not a recent, poor security decision by Microsoft.&lt;/p&gt;

&lt;p&gt;Anyway, I was sloppy, and I apologize for that. I should have nailed down the problem more accurately before posting.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>02.15.07
So it appears I was largely wrong about this. Not about it being an issue (it is), but about my judgment of the design and the severity of the implications. After reading extensively about the issue I came across a comment here on the site that captured it really well:</p>

<blockquote>So, the crux of the situation is that currently a lot of apps and their installers are written to install for the system, and to do so these apps request admin rights.</blockquote>

<p>That&#8217;s really it. Microsoft is simply dealing with its insecure past, i.e. a world in which installers had full admin rights to do anything they wanted on the system. As such, most software is still written in this fashion, and since that&#8217;s the case, and Vista users are non-privileged, &#8212; old, dirty-style programs have to be installed with elevated rights if you want to use them.</p>

<p>In short, it&#8217;s still a security problem, but the problem comes from Microsoft&#8217;s difficult to handle legacy past, not a recent, poor security decision by Microsoft.</p>

<p>Anyway, I was sloppy, and I apologize for that. I should have nailed down the problem more accurately before posting.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Goran</title>
		<link>http://danielmiessler.com/blog/vista-security-a-joke-executables-install-as-administrator-because-its-more-convenient/comment-page-1#comment-28984</link>
		<dc:creator>Goran</dc:creator>
		<pubDate>Thu, 15 Feb 2007 13:23:24 +0000</pubDate>
		<guid isPermaLink="false">http://dmiessler.com/archives/1141#comment-28984</guid>
		<description>&lt;p&gt;To Justin:&lt;/p&gt;

&lt;p&gt;First, let me tell you, if you follow Windows security issues at all, you should know the name Rutkowska. Obviously you don&#039;t, which does not serve any favors (hint: Google for &quot;Blue pill&quot; to learn something).&lt;/p&gt;

&lt;p&gt;Second, you don&#039;t seem to understand the issue at all... &quot;Vista only requires programs to elevate using UAC if it actually is necessary, ie, the program would otherwise fail.&quot;&lt;/p&gt;

&lt;p&gt;And THAT is exactly the problem! Here&#039;s the attack vector: JoeFriend surfs around on your machine and finds this great program on the net that he&#039;d like to try. So he downloads it, clicks through UAC, fine and dandy. But the program contains who knows what sort of crap malware (let&#039;s say it even installs itself in the kernel). So you thought JoeFriend can&#039;t create any trouble? Whoops!&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>To Justin:</p>

<p>First, let me tell you, if you follow Windows security issues at all, you should know the name Rutkowska. Obviously you don&#8217;t, which does not serve any favors (hint: Google for &#8220;Blue pill&#8221; to learn something).</p>

<p>Second, you don&#8217;t seem to understand the issue at all&#8230; &#8220;Vista only requires programs to elevate using UAC if it actually is necessary, ie, the program would otherwise fail.&#8221;</p>

<p>And THAT is exactly the problem! Here&#8217;s the attack vector: JoeFriend surfs around on your machine and finds this great program on the net that he&#8217;d like to try. So he downloads it, clicks through UAC, fine and dandy. But the program contains who knows what sort of crap malware (let&#8217;s say it even installs itself in the kernel). So you thought JoeFriend can&#8217;t create any trouble? Whoops!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Goran</title>
		<link>http://danielmiessler.com/blog/vista-security-a-joke-executables-install-as-administrator-because-its-more-convenient/comment-page-1#comment-247006</link>
		<dc:creator>Goran</dc:creator>
		<pubDate>Thu, 15 Feb 2007 13:23:00 +0000</pubDate>
		<guid isPermaLink="false">http://dmiessler.com/archives/1141#comment-247006</guid>
		<description>&lt;p&gt;To Justin:&lt;/p&gt;

&lt;p&gt;First, let me tell you, if you follow Windows security issues at all, you should know the name Rutkowska. Obviously you don&#039;t, which does not serve any favors (hint: Google for &quot;Blue pill&quot; to learn something).&lt;/p&gt;

&lt;p&gt;Second, you don&#039;t seem to understand the issue at all... &quot;Vista only requires programs to elevate using UAC if it actually is necessary, ie, the program would otherwise fail.&quot;&lt;/p&gt;

&lt;p&gt;And THAT is exactly the problem! Here&#039;s the attack vector: JoeFriend surfs around on your machine and finds this great program on the net that he&#039;d like to try. So he downloads it, clicks through UAC, fine and dandy. But the program contains who knows what sort of crap malware (let&#039;s say it even installs itself in the kernel). So you thought JoeFriend can&#039;t create any trouble? Whoops!&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>To Justin:</p>

<p>First, let me tell you, if you follow Windows security issues at all, you should know the name Rutkowska. Obviously you don&#8217;t, which does not serve any favors (hint: Google for &#8220;Blue pill&#8221; to learn something).</p>

<p>Second, you don&#8217;t seem to understand the issue at all&#8230; &#8220;Vista only requires programs to elevate using UAC if it actually is necessary, ie, the program would otherwise fail.&#8221;</p>

<p>And THAT is exactly the problem! Here&#8217;s the attack vector: JoeFriend surfs around on your machine and finds this great program on the net that he&#8217;d like to try. So he downloads it, clicks through UAC, fine and dandy. But the program contains who knows what sort of crap malware (let&#8217;s say it even installs itself in the kernel). So you thought JoeFriend can&#8217;t create any trouble? Whoops!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: jrb</title>
		<link>http://danielmiessler.com/blog/vista-security-a-joke-executables-install-as-administrator-because-its-more-convenient/comment-page-1#comment-28959</link>
		<dc:creator>jrb</dc:creator>
		<pubDate>Thu, 15 Feb 2007 11:06:20 +0000</pubDate>
		<guid isPermaLink="false">http://dmiessler.com/archives/1141#comment-28959</guid>
		<description>&lt;p&gt;i think the problem lies as much with the installers, as it does with the operating system, and it&#039;s all to do with legacy.&lt;/p&gt;

&lt;p&gt;most apps install, by default, files, or registry entries to places that a standard user (non-admin, non-power user) does not have access to. On windows 9x / 2000 / xp this is not an issue as all users by default (at least on a standalone or workgroup pc) have administrative rights and can do what they want. Generally, most applications, if written correctly, do not need to put files / registry entries in to system-wide locations, but they just do because they have been able to for so long, and it&#039;s easier.&lt;/p&gt;

&lt;p&gt;e.g., quicktime will install system wide video codecs, that annoying system tray icon, change system-wide file associations, etc. 
however, as an example of apps that do install correctly, it is possible to install microsoft office without elevated user rights, and by default it will only get installed for that user, and not for others - kind of how you would expect. Especially as it&#039;s a microsoft app.&lt;/p&gt;

&lt;p&gt;so, the crux of the situation is that currently a lot of apps and their installers are written to install for the system, and to do so these apps request admin rights.&lt;/p&gt;

&lt;p&gt;the only option to tighten security for vista was to adopt the linux approach and give users non-administrative rights by default, and install apps that affect the system as an elevated user. As vista&#039;s lifecycle progresses, we shall see more apps written correctly to run in limited user context, and not require admin rights to install.. but for the time being we have badly written apps and installers.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>i think the problem lies as much with the installers, as it does with the operating system, and it&#8217;s all to do with legacy.</p>

<p>most apps install, by default, files, or registry entries to places that a standard user (non-admin, non-power user) does not have access to. On windows 9x / 2000 / xp this is not an issue as all users by default (at least on a standalone or workgroup pc) have administrative rights and can do what they want. Generally, most applications, if written correctly, do not need to put files / registry entries in to system-wide locations, but they just do because they have been able to for so long, and it&#8217;s easier.</p>

<p>e.g., quicktime will install system wide video codecs, that annoying system tray icon, change system-wide file associations, etc. 
however, as an example of apps that do install correctly, it is possible to install microsoft office without elevated user rights, and by default it will only get installed for that user, and not for others &#8211; kind of how you would expect. Especially as it&#8217;s a microsoft app.</p>

<p>so, the crux of the situation is that currently a lot of apps and their installers are written to install for the system, and to do so these apps request admin rights.</p>

<p>the only option to tighten security for vista was to adopt the linux approach and give users non-administrative rights by default, and install apps that affect the system as an elevated user. As vista&#8217;s lifecycle progresses, we shall see more apps written correctly to run in limited user context, and not require admin rights to install.. but for the time being we have badly written apps and installers.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: jrb</title>
		<link>http://danielmiessler.com/blog/vista-security-a-joke-executables-install-as-administrator-because-its-more-convenient/comment-page-1#comment-247005</link>
		<dc:creator>jrb</dc:creator>
		<pubDate>Thu, 15 Feb 2007 11:06:00 +0000</pubDate>
		<guid isPermaLink="false">http://dmiessler.com/archives/1141#comment-247005</guid>
		<description>&lt;p&gt;i think the problem lies as much with the installers, as it does with the operating system, and it&#039;s all to do with legacy.&lt;/p&gt;

&lt;p&gt;most apps install, by default, files, or registry entries to places that a standard user (non-admin, non-power user) does not have access to. On windows 9x / 2000 / xp this is not an issue as all users by default (at least on a standalone or workgroup pc) have administrative rights and can do what they want. Generally, most applications, if written correctly, do not need to put files / registry entries in to system-wide locations, but they just do because they have been able to for so long, and it&#039;s easier.&lt;/p&gt;

&lt;p&gt;e.g., quicktime will install system wide video codecs, that annoying system tray icon, change system-wide file associations, etc. 
however, as an example of apps that do install correctly, it is possible to install microsoft office without elevated user rights, and by default it will only get installed for that user, and not for others - kind of how you would expect. Especially as it&#039;s a microsoft app.&lt;/p&gt;

&lt;p&gt;so, the crux of the situation is that currently a lot of apps and their installers are written to install for the system, and to do so these apps request admin rights.&lt;/p&gt;

&lt;p&gt;the only option to tighten security for vista was to adopt the linux approach and give users non-administrative rights by default, and install apps that affect the system as an elevated user. As vista&#039;s lifecycle progresses, we shall see more apps written correctly to run in limited user context, and not require admin rights to install.. but for the time being we have badly written apps and installers.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>i think the problem lies as much with the installers, as it does with the operating system, and it&#8217;s all to do with legacy.</p>

<p>most apps install, by default, files, or registry entries to places that a standard user (non-admin, non-power user) does not have access to. On windows 9x / 2000 / xp this is not an issue as all users by default (at least on a standalone or workgroup pc) have administrative rights and can do what they want. Generally, most applications, if written correctly, do not need to put files / registry entries in to system-wide locations, but they just do because they have been able to for so long, and it&#8217;s easier.</p>

<p>e.g., quicktime will install system wide video codecs, that annoying system tray icon, change system-wide file associations, etc. 
however, as an example of apps that do install correctly, it is possible to install microsoft office without elevated user rights, and by default it will only get installed for that user, and not for others &#8211; kind of how you would expect. Especially as it&#8217;s a microsoft app.</p>

<p>so, the crux of the situation is that currently a lot of apps and their installers are written to install for the system, and to do so these apps request admin rights.</p>

<p>the only option to tighten security for vista was to adopt the linux approach and give users non-administrative rights by default, and install apps that affect the system as an elevated user. As vista&#8217;s lifecycle progresses, we shall see more apps written correctly to run in limited user context, and not require admin rights to install.. but for the time being we have badly written apps and installers.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Willfe</title>
		<link>http://danielmiessler.com/blog/vista-security-a-joke-executables-install-as-administrator-because-its-more-convenient/comment-page-1#comment-28908</link>
		<dc:creator>Willfe</dc:creator>
		<pubDate>Thu, 15 Feb 2007 05:13:25 +0000</pubDate>
		<guid isPermaLink="false">http://dmiessler.com/archives/1141#comment-28908</guid>
		<description>&lt;p&gt;Justin:&lt;/p&gt;

&lt;p&gt;Not so fast, there. I don&#039;t think the researcher is claiming it&#039;s a bad thing for admin privileges to be granted during an application&#039;s installation.&lt;/p&gt;

&lt;p&gt;The issue here is that once an installer is granted permission to run and install its stuff, it gets those rights indefinitely during the install. That means it can install an application that will &lt;em&gt;always&lt;/em&gt; run as an administrator, with all the privileges that includes.&lt;/p&gt;

&lt;p&gt;This means that your spyware-laden applet can still gain admin privileges as long as your users can be tricked into granting permission to the installer. The installer just installs it stuff as normal, and because it&#039;s got admin rights during the install, it says &quot;it&#039;s okay, the user trusts me, and I trust this little binary I&#039;m installing -- it can run as administrator if it wants, too. Ask the user again if you don&#039;t believe me!&quot;&lt;/p&gt;

&lt;p&gt;In Unix land this is called &quot;setuid root&quot; -- any user with sufficient permission to execute the binary can do so, and any execution of the binary permits it to run as the owning user (if the owner is root and the file is setuid, that means the binary gets to run as root, no matter who runs it).&lt;/p&gt;

&lt;p&gt;Sounds like this is exactly what Vista is permitting -- install a binary as an admin, with admin rights, so every time it runs, it gets to be an admin. Yay.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Justin:</p>

<p>Not so fast, there. I don&#8217;t think the researcher is claiming it&#8217;s a bad thing for admin privileges to be granted during an application&#8217;s installation.</p>

<p>The issue here is that once an installer is granted permission to run and install its stuff, it gets those rights indefinitely during the install. That means it can install an application that will <em>always</em> run as an administrator, with all the privileges that includes.</p>

<p>This means that your spyware-laden applet can still gain admin privileges as long as your users can be tricked into granting permission to the installer. The installer just installs it stuff as normal, and because it&#8217;s got admin rights during the install, it says &#8220;it&#8217;s okay, the user trusts me, and I trust this little binary I&#8217;m installing &#8212; it can run as administrator if it wants, too. Ask the user again if you don&#8217;t believe me!&#8221;</p>

<p>In Unix land this is called &#8220;setuid root&#8221; &#8212; any user with sufficient permission to execute the binary can do so, and any execution of the binary permits it to run as the owning user (if the owner is root and the file is setuid, that means the binary gets to run as root, no matter who runs it).</p>

<p>Sounds like this is exactly what Vista is permitting &#8212; install a binary as an admin, with admin rights, so every time it runs, it gets to be an admin. Yay.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Willfe</title>
		<link>http://danielmiessler.com/blog/vista-security-a-joke-executables-install-as-administrator-because-its-more-convenient/comment-page-1#comment-247004</link>
		<dc:creator>Willfe</dc:creator>
		<pubDate>Thu, 15 Feb 2007 05:13:00 +0000</pubDate>
		<guid isPermaLink="false">http://dmiessler.com/archives/1141#comment-247004</guid>
		<description>&lt;p&gt;Justin:&lt;/p&gt;

&lt;p&gt;Not so fast, there. I don&#039;t think the researcher is claiming it&#039;s a bad thing for admin privileges to be granted during an application&#039;s installation.&lt;/p&gt;

&lt;p&gt;The issue here is that once an installer is granted permission to run and install its stuff, it gets those rights indefinitely during the install. That means it can install an application that will &lt;em&gt;always&lt;/em&gt; run as an administrator, with all the privileges that includes.&lt;/p&gt;

&lt;p&gt;This means that your spyware-laden applet can still gain admin privileges as long as your users can be tricked into granting permission to the installer. The installer just installs it stuff as normal, and because it&#039;s got admin rights during the install, it says &quot;it&#039;s okay, the user trusts me, and I trust this little binary I&#039;m installing -- it can run as administrator if it wants, too. Ask the user again if you don&#039;t believe me!&quot;&lt;/p&gt;

&lt;p&gt;In Unix land this is called &quot;setuid root&quot; -- any user with sufficient permission to execute the binary can do so, and any execution of the binary permits it to run as the owning user (if the owner is root and the file is setuid, that means the binary gets to run as root, no matter who runs it).&lt;/p&gt;

&lt;p&gt;Sounds like this is exactly what Vista is permitting -- install a binary as an admin, with admin rights, so every time it runs, it gets to be an admin. Yay.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Justin:</p>

<p>Not so fast, there. I don&#8217;t think the researcher is claiming it&#8217;s a bad thing for admin privileges to be granted during an application&#8217;s installation.</p>

<p>The issue here is that once an installer is granted permission to run and install its stuff, it gets those rights indefinitely during the install. That means it can install an application that will <em>always</em> run as an administrator, with all the privileges that includes.</p>

<p>This means that your spyware-laden applet can still gain admin privileges as long as your users can be tricked into granting permission to the installer. The installer just installs it stuff as normal, and because it&#8217;s got admin rights during the install, it says &#8220;it&#8217;s okay, the user trusts me, and I trust this little binary I&#8217;m installing &#8212; it can run as administrator if it wants, too. Ask the user again if you don&#8217;t believe me!&#8221;</p>

<p>In Unix land this is called &#8220;setuid root&#8221; &#8212; any user with sufficient permission to execute the binary can do so, and any execution of the binary permits it to run as the owning user (if the owner is root and the file is setuid, that means the binary gets to run as root, no matter who runs it).</p>

<p>Sounds like this is exactly what Vista is permitting &#8212; install a binary as an admin, with admin rights, so every time it runs, it gets to be an admin. Yay.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: PanamaSpace</title>
		<link>http://danielmiessler.com/blog/vista-security-a-joke-executables-install-as-administrator-because-its-more-convenient/comment-page-1#comment-28906</link>
		<dc:creator>PanamaSpace</dc:creator>
		<pubDate>Thu, 15 Feb 2007 05:04:45 +0000</pubDate>
		<guid isPermaLink="false">http://dmiessler.com/archives/1141#comment-28906</guid>
		<description>&lt;p&gt;Joanna Rutkowska ... is a GIRL&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Joanna Rutkowska &#8230; is a GIRL</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: PanamaSpace</title>
		<link>http://danielmiessler.com/blog/vista-security-a-joke-executables-install-as-administrator-because-its-more-convenient/comment-page-1#comment-247003</link>
		<dc:creator>PanamaSpace</dc:creator>
		<pubDate>Thu, 15 Feb 2007 05:04:00 +0000</pubDate>
		<guid isPermaLink="false">http://dmiessler.com/archives/1141#comment-247003</guid>
		<description>&lt;p&gt;Joanna Rutkowska ... is a GIRL&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Joanna Rutkowska &#8230; is a GIRL</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Justin Crites</title>
		<link>http://danielmiessler.com/blog/vista-security-a-joke-executables-install-as-administrator-because-its-more-convenient/comment-page-1#comment-28865</link>
		<dc:creator>Justin Crites</dc:creator>
		<pubDate>Thu, 15 Feb 2007 00:27:08 +0000</pubDate>
		<guid isPermaLink="false">http://dmiessler.com/archives/1141#comment-28865</guid>
		<description>&lt;p&gt;Haha, this &quot;researcher&quot; is a complete moron.  Here&#039;s an excerpt from his blog:&lt;/p&gt;

&lt;p&gt;&quot;Still, even though that might look like a secure configuration, this is all just an illusion of security! The whole security of the system can be compromised if attacker finds and exploits e.g. a bug in kernel driver.&quot;&lt;/p&gt;

&lt;p&gt;Oh really?  You mean an OS is insecure if the attacker can exploit the kernel?  You don&#039;t say?&lt;/p&gt;

&lt;p&gt;OBVIOUSLY.  It&#039;s still real security.  The fact that human mistakes can always occur doesn&#039;t stop it from being real security.&lt;/p&gt;

&lt;p&gt;You can say &quot;what if an attacker can exploit the kernel?&quot; about any OS ever made; and it will remain true for any OS ever made.  It&#039;s a completely pointless FUD statement.&lt;/p&gt;

&lt;p&gt;Mistakes happen.  That doesn&#039;t make security an &quot;illusion&quot;.&lt;/p&gt;

&lt;p&gt;He&#039;s an idiot.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Haha, this &#8220;researcher&#8221; is a complete moron.  Here&#8217;s an excerpt from his blog:</p>

<p>&#8220;Still, even though that might look like a secure configuration, this is all just an illusion of security! The whole security of the system can be compromised if attacker finds and exploits e.g. a bug in kernel driver.&#8221;</p>

<p>Oh really?  You mean an OS is insecure if the attacker can exploit the kernel?  You don&#8217;t say?</p>

<p>OBVIOUSLY.  It&#8217;s still real security.  The fact that human mistakes can always occur doesn&#8217;t stop it from being real security.</p>

<p>You can say &#8220;what if an attacker can exploit the kernel?&#8221; about any OS ever made; and it will remain true for any OS ever made.  It&#8217;s a completely pointless FUD statement.</p>

<p>Mistakes happen.  That doesn&#8217;t make security an &#8220;illusion&#8221;.</p>

<p>He&#8217;s an idiot.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Justin Crites</title>
		<link>http://danielmiessler.com/blog/vista-security-a-joke-executables-install-as-administrator-because-its-more-convenient/comment-page-1#comment-247002</link>
		<dc:creator>Justin Crites</dc:creator>
		<pubDate>Thu, 15 Feb 2007 00:27:00 +0000</pubDate>
		<guid isPermaLink="false">http://dmiessler.com/archives/1141#comment-247002</guid>
		<description>&lt;p&gt;Haha, this &quot;researcher&quot; is a complete moron.  Here&#039;s an excerpt from his blog:&lt;/p&gt;

&lt;p&gt;&quot;Still, even though that might look like a secure configuration, this is all just an illusion of security! The whole security of the system can be compromised if attacker finds and exploits e.g. a bug in kernel driver.&quot;&lt;/p&gt;

&lt;p&gt;Oh really?  You mean an OS is insecure if the attacker can exploit the kernel?  You don&#039;t say?&lt;/p&gt;

&lt;p&gt;OBVIOUSLY.  It&#039;s still real security.  The fact that human mistakes can always occur doesn&#039;t stop it from being real security.&lt;/p&gt;

&lt;p&gt;You can say &quot;what if an attacker can exploit the kernel?&quot; about any OS ever made; and it will remain true for any OS ever made.  It&#039;s a completely pointless FUD statement.&lt;/p&gt;

&lt;p&gt;Mistakes happen.  That doesn&#039;t make security an &quot;illusion&quot;.&lt;/p&gt;

&lt;p&gt;He&#039;s an idiot.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Haha, this &#8220;researcher&#8221; is a complete moron.  Here&#8217;s an excerpt from his blog:</p>

<p>&#8220;Still, even though that might look like a secure configuration, this is all just an illusion of security! The whole security of the system can be compromised if attacker finds and exploits e.g. a bug in kernel driver.&#8221;</p>

<p>Oh really?  You mean an OS is insecure if the attacker can exploit the kernel?  You don&#8217;t say?</p>

<p>OBVIOUSLY.  It&#8217;s still real security.  The fact that human mistakes can always occur doesn&#8217;t stop it from being real security.</p>

<p>You can say &#8220;what if an attacker can exploit the kernel?&#8221; about any OS ever made; and it will remain true for any OS ever made.  It&#8217;s a completely pointless FUD statement.</p>

<p>Mistakes happen.  That doesn&#8217;t make security an &#8220;illusion&#8221;.</p>

<p>He&#8217;s an idiot.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Justin Crites</title>
		<link>http://danielmiessler.com/blog/vista-security-a-joke-executables-install-as-administrator-because-its-more-convenient/comment-page-1#comment-28862</link>
		<dc:creator>Justin Crites</dc:creator>
		<pubDate>Thu, 15 Feb 2007 00:18:53 +0000</pubDate>
		<guid isPermaLink="false">http://dmiessler.com/archives/1141#comment-28862</guid>
		<description>&lt;p&gt;And finally, one more thing that shows this Polish &quot;researcher&quot; is a total hack.  Take this aforementioned Quicktime installer and rename it to &quot;setup.exe&quot;.  Vista doesn&#039;t require it to elevate privileges using UAC.  It works fine.&lt;/p&gt;

&lt;p&gt;Conclusion:  Vista only requires programs to elevate using UAC if it actually is necessary, ie, the program would otherwise fail.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>And finally, one more thing that shows this Polish &#8220;researcher&#8221; is a total hack.  Take this aforementioned Quicktime installer and rename it to &#8220;setup.exe&#8221;.  Vista doesn&#8217;t require it to elevate privileges using UAC.  It works fine.</p>

<p>Conclusion:  Vista only requires programs to elevate using UAC if it actually is necessary, ie, the program would otherwise fail.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Justin Crites</title>
		<link>http://danielmiessler.com/blog/vista-security-a-joke-executables-install-as-administrator-because-its-more-convenient/comment-page-1#comment-247001</link>
		<dc:creator>Justin Crites</dc:creator>
		<pubDate>Thu, 15 Feb 2007 00:18:00 +0000</pubDate>
		<guid isPermaLink="false">http://dmiessler.com/archives/1141#comment-247001</guid>
		<description>&lt;p&gt;And finally, one more thing that shows this Polish &quot;researcher&quot; is a total hack.  Take this aforementioned Quicktime installer and rename it to &quot;setup.exe&quot;.  Vista doesn&#039;t require it to elevate privileges using UAC.  It works fine.&lt;/p&gt;

&lt;p&gt;Conclusion:  Vista only requires programs to elevate using UAC if it actually is necessary, ie, the program would otherwise fail.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>And finally, one more thing that shows this Polish &#8220;researcher&#8221; is a total hack.  Take this aforementioned Quicktime installer and rename it to &#8220;setup.exe&#8221;.  Vista doesn&#8217;t require it to elevate privileges using UAC.  It works fine.</p>

<p>Conclusion:  Vista only requires programs to elevate using UAC if it actually is necessary, ie, the program would otherwise fail.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Justin Crites</title>
		<link>http://danielmiessler.com/blog/vista-security-a-joke-executables-install-as-administrator-because-its-more-convenient/comment-page-1#comment-28861</link>
		<dc:creator>Justin Crites</dc:creator>
		<pubDate>Thu, 15 Feb 2007 00:13:32 +0000</pubDate>
		<guid isPermaLink="false">http://dmiessler.com/archives/1141#comment-28861</guid>
		<description>&lt;p&gt;Update:&lt;/p&gt;

&lt;p&gt;OK, I just did some testing to verify my above hypothesis, and I believe it to be correct.&lt;/p&gt;

&lt;p&gt;The installer for Quicktime for Windows &lt;em&gt;does not&lt;/em&gt; have a shield icon when you download it.  Many other installers will display a shield while visually sitting on your desktop.  Vista has identified these programs in advance as needing administrator privileges to run.&lt;/p&gt;

&lt;p&gt;However, if you run Quicktime, Vista realizes during the installation process that Quicktime requires administrator privileges.  Thus, it pops up a permissions elevation window.  If you deny Administrator access, it means that the object Quicktime is trying to access (say, putting a DLL into the Windows directory) will fail without this permission.&lt;/p&gt;

&lt;p&gt;It makes no sense to attempt to allow the installer to continue, because Vista knows the installer will simply fail.&lt;/p&gt;

&lt;p&gt;Finally, there is another set of installers that need administrator privileges, but which Vista cannot identify. If you run these installers, they will just fail with a security error.  If you re-run them, explicitly requiring the administrator account (say, through the right-click menu on the file) they will succeed.&lt;/p&gt;

&lt;p&gt;So, there appear to be three classes of installers:&lt;/p&gt;

&lt;p&gt;(1) Programs that Vista can identify in advance require administrator privileges. The install would simply fail without it; it knows this, so there is no reason to let you run the program.  It would be like Windows Explorer pretending to let you access a directory it knows you don&#039;t have rights to -- it would be a runtime exception and something would crash.  It not letting you do anything BUT run it as administrator is just a gracious way of crashing.&lt;/p&gt;

&lt;p&gt;(2) Programs Vista can&#039;t identify in advance as requiring administrator privileges, but which Vista can identify while they are running.  Vista asks you at the time it attempts to use those privileges, and presents the elevation dialog.&lt;/p&gt;

&lt;p&gt;(3) Programs that Vista cannot identify at all.  These programs just crash (although the application itself might catch the error and say something like &quot;Failed to install.  Rolling back&quot; or something).  You have to run them as administrator manually.&lt;/p&gt;

&lt;p&gt;Which category an application falls into, whether 1,2, or 3 probably depends on which APIs the program uses to perform its actions.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Update:</p>

<p>OK, I just did some testing to verify my above hypothesis, and I believe it to be correct.</p>

<p>The installer for Quicktime for Windows <em>does not</em> have a shield icon when you download it.  Many other installers will display a shield while visually sitting on your desktop.  Vista has identified these programs in advance as needing administrator privileges to run.</p>

<p>However, if you run Quicktime, Vista realizes during the installation process that Quicktime requires administrator privileges.  Thus, it pops up a permissions elevation window.  If you deny Administrator access, it means that the object Quicktime is trying to access (say, putting a DLL into the Windows directory) will fail without this permission.</p>

<p>It makes no sense to attempt to allow the installer to continue, because Vista knows the installer will simply fail.</p>

<p>Finally, there is another set of installers that need administrator privileges, but which Vista cannot identify. If you run these installers, they will just fail with a security error.  If you re-run them, explicitly requiring the administrator account (say, through the right-click menu on the file) they will succeed.</p>

<p>So, there appear to be three classes of installers:</p>

<p>(1) Programs that Vista can identify in advance require administrator privileges. The install would simply fail without it; it knows this, so there is no reason to let you run the program.  It would be like Windows Explorer pretending to let you access a directory it knows you don&#8217;t have rights to &#8212; it would be a runtime exception and something would crash.  It not letting you do anything BUT run it as administrator is just a gracious way of crashing.</p>

<p>(2) Programs Vista can&#8217;t identify in advance as requiring administrator privileges, but which Vista can identify while they are running.  Vista asks you at the time it attempts to use those privileges, and presents the elevation dialog.</p>

<p>(3) Programs that Vista cannot identify at all.  These programs just crash (although the application itself might catch the error and say something like &#8220;Failed to install.  Rolling back&#8221; or something).  You have to run them as administrator manually.</p>

<p>Which category an application falls into, whether 1,2, or 3 probably depends on which APIs the program uses to perform its actions.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

