Re: IP Packet Filter



Even more : with User Account Controls (UACs) in Windows Vista, everybody
runs as a
standard user, including members of the Administrator group.
Arkady

"Skywing" <skywing_NO_SPAM_@xxxxxxxxxxxxxxxxxxx> wrote in message
news:ObY9djxXGHA.4212@xxxxxxxxxxxxxxxxxxxxxxx
Certainly, and the best way to do that is to have users not run with full
admin permissions all the time. This is *much* more effective than a
battle of catch-up between security software and malware, if you can
prevent the malware from subverting security policies entirely then you
can begin to provide real system security.

Perhaps you might think of this as an idealized case - but you can't
really fully protect the user if they are running as admin and so is the
malware. The real solution starts with making users not run with full
privileges - things like Vista UAC will really begin to help here with
making that a more viable option for non-technical-oriented users,
especially since it's going to be the default scenario where end users
('home users") won't be running as admin. It's certainly possible to run
without administrator privileges on Windows right now (I do so on a daily
basis), but it still takes a bit of knowledge to set that up properly, and
sadly most "home users" are going to be using the default (run as admin)
settings (for current Windows versions).

So, I would rather spend time educating users on how to not run with admin
in the first place rather than trying to plug what becomes a very leaky
ship if malware gets admin privileges. Things like UAC in Vista will help
with this in the future, but for now, we're stuck with trying to educate
users on better security practice.

"Scherbina Vladimir" <vladimir.scherbina@xxxxxxxxxxxx> wrote in message
news:uYFHabxXGHA.1196@xxxxxxxxxxxxxxxxxxxxxxx
Hello, Skywing.

"Skywing" <skywing_NO_SPAM_@xxxxxxxxxxxxxxxxxxx> wrote in message
news:eMzTQHdXGHA.5024@xxxxxxxxxxxxxxxxxxxxxxx
You seem to be missing the point. You're fighting a battle that you
cannot possibly win, all you can hope to do is achieve a (false) sense
of security through obscurity through adding additional layers and
hoping someone isn't clever enough to bypass what you have - which they
will.

Trying to protect a system against an administrator is an exercise in
time wasted.

Not exactly. The fact that the administrator gives you the power of god
does not mean that this power is going to make good things (rather
philosophical sentence, I know). From my expirience - take a look at
http://www.mcafee.com/us/threat_center/default.asp - Adware-Virtumundo -
an adware that I was researching on (when was working in AV company).
This adware makes suffer a half of USA users, I guess. And it's relaying
the fact that the administrator gives it the power of good. VirtuMonde
simply injects into system processes using debug privileges that can be
easialy obtained if you're administrator.

*There are* situatons when there is a need to protect from administrator.

--
Vladimir
manage content: http://www.infostoria.com/
blog: http://spaces.msn.com/vladimir-scherbina/





.



Relevant Pages

  • Re: Run As Adminstrator - why hasnt it saved us?
    ... UAC and Run As Administrator are tied together on Vista and are the new security profile for the Admin and Standard user accounts. ... You set your account to be Super Admin so that you still have UAC enabled because some applications will not work correctly with UAC off, those applications using the Vista UAC manifest as an example, and by being Super Admin, UAC will not prompt you as Super Admin, as stated in the link. ...
    (microsoft.public.windows.vista.security)
  • Re: whats the difference between account NAMED administror and a account with admin privilegious?
    ... The link has a lot of information and directions on sharing in Vista. ... Using the Vista Administrator account does give you greater access while ... I was hoping that being the 'administrator' would cure that problem. ... When logging in....I should select 'admin' ...
    (microsoft.public.windows.vista.general)
  • Re: Help setting up HIGH END user rights (higher than ADMIN)
    ... there to fix things when all your delegated admins and other security ... MUST trust them. ... > everyone needs to log into it as Administrator so they can run a job. ... > nothing is stopping the Admin to edit their profile and give themselves HR ...
    (microsoft.public.windowsxp.security_admin)
  • Re: File permissions and UAC
    ... My account is an administrator and there are no other users on this PC, ... Your account may be able to access the 'run as adnin' function, but Vista ... doesn't let you actually BE the admin unless you activate and use the hidden ...
    (microsoft.public.windows.vista.general)
  • Re: How do I debug a program in non-adminstator mode under Vista
    ... I run as an Admin user, but don't elevate to run VS2005, so it's not running with Admin privileges. ... install Visual Studio 2005 Service Pack 1, or Visual Studio 2005 Service Pack ... and Visual Studio 2005 Service Pack 1 Update for Windows Vista, ... compile my project without running VS as administrator. ...
    (microsoft.public.vstudio.general)

Loading