Microsoft admits Vista UAC prompts 'need work'

Scott Charney, head of Microsoft's Trustworthy Computing division, admitted this week that Windows Vista's User Account Control (UAC) prompts are not intuitive and confuse users.

In order to watch video content you need to enable javascript and install Flash player version 8 or above.

In a video interview with ZDNet.com.au at the AusCERT 2008 conference this week, Charney said Microsoft needs to make improvements around UAC.

"Clearly there is work that has to be done around the UAC prompts — in part because of user feedback that they get the prompts at times they don't necessarily expect them and it is not intuitive.

"If you give people too many prompts in too many situations, they view it as an impediment to getting their work done and they just start clicking ok on everything," said Charney.

He said that the language used in prompts is also confusing.

"We give them dialogues and prompts that don't help them make the right decision as often as we would like. You can be surfing the Web and get a warning that this site is out of another site's control, or you may be passing data to another site. What is a user supposed to do with that information?

"You can click cancel and not do what you were trying to do, or you can accept the risk — we need to figure out better ways to mitigate that risk but let the user achieve their objective," he added.

Charney's comments echo those of Ivan Krstić, the former director of security architecture for the One Laptop Per Child project, who opened last year's AusCERT conference by claiming that desktop security was completely broken.

In an interview with ZDNet.com.au at last year's conference, Krstić said: "If you go to a Web site whose security certificate is for any reason not checking out, you get a dialogue box that you [require] strong Internet security [skills] to decipher," he said. "For anyone else, they get to do a random guess between yes, no and cancel. That's no way to protect anyone," he added.

Krstić said software vendors were "weaselling off responsibility for security to users" in order to "legally protect themselves".

Advertisement

Talkback 1 comments

    I turned-off UAC Peter T. -- 23/05/08

    I turned-off UAC. I have only a few applications installed on my computer. All bar one of the applications activating UAC were MS applications or part of Vista! As for the other one, I removed it.

Latest Videos

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Renai LeMay How reliable is IP telephony?
    Have you ever heard a weird kind of hissing, crackling or popping noise when calling someone on an IP telephony line? How rare is the phenomenon these days?
  • Array Forget the NBN, 100Mbps is already here
    Telstra and TransACT will shortly begin offering 100Mbps broadband to many customers. By moving early, the companies have not only raised the bar for Australia's broadband services, but thrown down a challenge to a government that now faces increased pressure to deliver the NBN as promised.
  • Array IT: Govt's cost-cutting bitch
    The government needs to stop looking at IT as a necessary evil or the place to remove costs when the Treasurer comes calling.
  • More blogs »

Tags

Back to top

Featured