Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Or you know, place the ability to disable Windows Update behind policy restrictions and UAC rather than being openly editable in the registry? With policy restrictions, corporate installations could deny all attempts to disable the service. In non-corporate environments, this should at least require a UAC prompt. While too many users would likely click through without understanding, at least knowledgeable users would understand and be able to deny the change.

Windows Update is a serious security requirement for any Windows install. Disabling it should clearly require explicit consent from the user.



Changing the windows update policy requires admin rights and UAC prompting. The Samsung installer would also run as admin (either started from a service running as admin and deployed by the samsung initial image, or by the user allowing UAC when launching the samsung installer), so it can change the registry.


True. To be more specific: while UAC is great for requiring admin privileges, it would be nice if UAC prompts would enumerate the permissions being asked for. The prompt should be asking you if you wish to allow the program to disable Windows Update as opposed to "admin privileges to do anything whatsoever with your operating system".

That said, it's a difficult system to implement properly. Android went that route, and it almost works - almost. Android's available permissions are too plentiful, and yet certain permissions are too broad in scope. I wouldn't want a desktop application to have to ask for separate privileges for every little piece of functionality, but for certain critical actions it would be nice to have some clue as to what is going on.

Perhaps in another 20 years someone will finally invent a privilege escalation system that somehow manages to be both very specific and yet not time consuming for the customer to manage. What a dream. :)




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: