Re: database install

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



Stefan Wuebbe wrote:
"Cy Welch" <cywelch@xxxxxxxxx> schrieb im Newsbeitrag news:%233wgTy8rHHA.1208@xxxxxxxxxxxxxxxxxxxxxxx
Stefan Wuebbe wrote:
"Cy Welch" <cywelch@xxxxxxxxx> schrieb
Unfortunately, HKLM is verboten in Vista, while HKCU is ok. All the rules allowed before are now out the window, and code that worked from Windows 3.1 on no longer works. Oh what fun.
Hi Cy - On the other hand, HKLM was verboten in Windows2000 and WinXP too, at least for the standard "Limited" and "Power" users.

While this is indeed true, in Vista even Administrative users can only get there by either running the program as Admin (using the property in the shortcut) or by answering a prompt each time you escalate security rights to write to the registry. While it's rather a bit of a pain, it in large part is just MS forcing us to do things by the rules they have tried to get us to do all along.

Yes, I do not really like Vista's UAC implementation either.
But personally I do appreciate the particular idea not to use an Admin
account for daily work. MS is just a little late enforcing it, Unix/Linux
people always did so.

Remember though that we are coming from an environment that initially was neither multi-user or that provided ANY local security. Unix/Linux has ALWAYS been multi-user and security aware. One of the problems caused by this is that MANY commercial applications REQUIRE that they be run as administrator, and they are often programs that the person really should not have admin priviledges other than that. As software developers start changing their software to follow the rules then UAC will become less and less of an issue.

--
Cy Welch
Senior Programmer
MetSYS Inc
http://www.metsysinc.com
.



Relevant Pages

  • (no subject)
    ... Look at the Navy-Marine Corps Internet, a contract ... Security is secuirty and penetration means exactly that. ... You just hit a sore spot w/ me...the CSI/FBI survey. ... it's probably an admin who has ...
    (comp.security.misc)
  • (no subject)
    ... Look at the Navy-Marine Corps Internet, a contract ... Security is secuirty and penetration means exactly that. ... You just hit a sore spot w/ me...the CSI/FBI survey. ... it's probably an admin who has ...
    (comp.os.ms-windows.nt.admin.security)
  • Re: Food for Thought
    ... Look at the Navy-Marine Corps Internet, a contract ... Security is secuirty and penetration means exactly that. ... that telling the reader to do a Google search for sources isn't going to ... it's probably an admin who has ...
    (microsoft.public.win2000.security)
  • Re: Grant Administrative Access to a Domain Controller
    ... Anyone with a good understanding of AD and Windows security will easily see ways of compromising the environment. ... Do not give enhanced rights to Domain Controllers to anyone you don't trust with Domain and/or Enterprise Admins. ... Just know that minimal access can be parlayed into even more access and try as you might, you cannot secure Active Directory from people with server operator or admin or several other levels of access rights on a DC. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Rather funny; looks like page defacement to me
    ... > afford one (and often when they can't afford one this person works ... On top of all that pressure, ... so I was a bit caustic on the "incompetent admin" point; ... Nobody would hire me (I'm a security engineer) to draw structural diagrams. ...
    (Focus-IDS)