Microsoft backtracks on Windows 7 UAC, pretends it was all part of the plan

Sometimes you just gotta laugh. Otherwise, this stuff gets really frustrating.

Here's my beef.

I've complained for a while now that Microsoft has tested Windows 7 in secret, not allowing its tech beta participants, reviewers, and others via the public beta to actually impact the final product in any meaningful way. This is evidenced by the fact that Windows 7 features aren't provided to anyone outside of Microsoft until they are feature-complete and, thus, essentially completed. So all that's left for anyone outside of the inner sanctum to do is find bugs.

Why is this a problem? Because, as it turns out, Microsoft doesn't always have all the answers. And sometimes they make changes that are bad. And even though we outside of the company may have valid complaints, it doesn't matter. That feature you're so concerned about was set in stone months ago. By someone. Somewhere. We don't know how it happens. None of it is transparent.

Which brings us to this week's silliness over User Account Control (UAC).

Here's what happened:

1. Rafael and co. discuss what they feel is a very serious shortcoming in Windows 7's UAC feature.

2. Mary Jo Foley and the Windows blogosphere weigh in, with some wondering aloud whether Windows 7 will be "less secure than Windows Vista."

3. Microsoft tells everyone to back off (twice). Windows 7 UAC works exactly the way they planned it, and they're not changing a thing. They communicated this via a prepared statement. And then again in the Engineering 7 Blog.

4. Microsoft abruptly changes course, says they will change UAC.

But here's the kicker. Microsoft refuses to acknowledge that the complaints about UAC had anything to do with this decision. You see, these changes were planned all along.

LOL. Sure they were.

So here's my take: Not only are Microsoft very serious about not making any changes in Windows 7 after they're locked it down (i.e. handed out to the public in beta form) but now that they've been forced to make such a change, they can't even admit that it's happened.

First, the UAC control panel will run in a high integrity process, which requires elevation. That was already in the works before this discussion and doing this prevents all the mechanics [Rafael discussed in his original complaint] and the like from working.

To summarize, from Microsoft's perspective (paraphrased for your convenience):

Bloggers and testers complained about a very specific issue in Windows 7. We told you it wasn't a problem. But we are fixing that very specific issue. And you had nothing to do with that change.

This is how small children behave.

So is this:

Windows 7 is too much fun and folks are having too much fun for us to be having the dialog we’re having. We hope this post allows us to get back to having fun!

Wow. And here I was thinking that having a dialog about important features in Windows was your fracking job.

By the way, Rafael Rivera has provided me with the following statement in the wake of this mess:

"I'm happy to hear of the changes upcoming in the public Windows 7 Release Candidate build. Regardless of the reasons, the increase in security is a win for all Microsoft Windows users."

Yeah. He's nicer than I am.

Discuss this Article 54

Ocean
on Feb 6, 2009
How many times do I have to say that I am a windows user who has never owned a Macintosh?
whiplash55
on Feb 6, 2009
Good job Paul, Rafael, and Long and other Windows bloggers of note. And a tepid "good on ya" Microsoft for doing the right thing even though you won't admit it.
JamesRayG
on Feb 6, 2009
As long as we're posting random links for no reason, http://www.infoworld.com/article/08/03/27/Gone-in-2-minutes-Mac-gets-hac...
subzerohitman721
on Feb 6, 2009
chuckb84 said, "Geez. These "OSX is just as insecure as Windows" claims are really interesting in that they avoid a little thing that we call "data". There are no, none, zero, zilch, nada, null, bupkus, examples of any propagating worm, virus or malware for OSX in the wild, period, ever. Such things infest Windows computers in the millions, Macs none at all." 10 seconds of research and totally wrong. Worms, virus and malware in the wild for OS-X. February 16, 2006 - 1st every Mac OS-X trojan discovered in the wild. OSX/Leap-A or OSX/Oompa-A. October 2008. iPhone users vulnerable to to URL spoofing attack. http://ithreats.wordpress.com/2008/10/06/iphone-vulnerable-to-url-spoofi... November 2008 - OSX/Jahlav, OSX/Lamsev.A, OSX DNSChanger in the wild. http://community.ca.com/blogs/securityadvisor/archive/2008/11/23/new-tro... http://ithreats.wordpress.com/2008/11/25/about-recent-osx-trojan/ Some were even evading anti-virus. http://ithreats.wordpress.com/2008/12/10/osxjahlav-evading-scanners-dete... January 22, 2009 - OSX.Trojan.iServices.A released in tthe wild in pirated copies of iWork 2009. http://ithreats.wordpress.com/2009/01/23/update-iworkservices-not-just-a... January 27, 2009 - OSX.Trojan.iServices.B found in pirated Photoshop CS4. Variant Krowi found installs DivX. http://ithreats.wordpress.com/2009/01/27/latest-os-x-threat-krowi-instal... Rogue software malware? Check. http://ithreats.wordpress.com/2008/01/15/macsweeper-first-rogue-applicat... Need more information on 2008 OS-X threats. I got ya some. http://ithreats.wordpress.com/2009/01/17/os-x-vulnerability-in-2008/ As you can see, there are plenty, credible, and real threats to OS-X. None at all you say Chuckb84? Just ask the 20,000 or so who found the hard way that OSX.Trojan.iServices.A was very real. If you wish to roll the dice without anti-virus, then maybe you've already acquired OSX.ignoranceisbliss.A. I hear this one is very contageous.

Please or Register to post comments.

IT/Dev Connections

Las Vegas
September 30th - October 4th

Paul ThurottYou'll have the opportunity to experience:
• 120 Technical
Sessions
• Networking with Peers
• Expert Speakers


Come See Paul Thurrott & Mary Jo Foley in Person!

Register Now

Office 365 InfoCenter

Get the latest insight and info from Paul

Read Now!

What I Use