Hacker Newsnew | past | comments | ask | show | jobs | submit | actsof's commentslogin

From https://learn.microsoft.com/en-us/troubleshoot/windows-serve...

>One of the common misconceptions about UAC and Same-desktop Elevation in particular is: it prevents malware from being installed, or from gaining administrative rights. First, malware can be written not to require administrative rights. And malware can be written to write just to areas in the user's profile. More important, Same-desktop Elevation in UAC isn't a security boundary. It can be hijacked by unprivileged software that runs on the same desktop. Same-desktop Elevation should be considered a convenience feature. From a security perspective, Protected Administrator should be considered the equivalent of Administrator. By contrast, using Fast User Switching to sign in to a different session by using an administrator account involves a security boundary between the administrator account and the standard user session.

UAC is not a security boundary, it's not the same thing as sudo on Unix. You only have a security boundary in place if Windows asks you for a password when trying to run as Administrator.


> UAC is not a security boundary

You might be mistaken because what you are quoting specifically talks about Same-desktop Elevation. While on Windows, UAC uses Secure Desktop by default, which is by definition a security boundary.

> You only have a security boundary in place if Windows asks you for a password when trying to run as Administrator.

Per the last sentence of the information that you quoted:

> By contrast, using Fast User Switching to sign in to a different session by using an administrator account involves a security boundary between the administrator account and the standard user session.

Fast User Switching requires the user to enter the administrator credentials in the UAC prompt.


Not that it improves the condition, but psychosis leading to violent outbursts could be used to justify it. Anti-psychotics are also usually sedative in nature, which would explain the rest.


That same justification was used against political dissidents in the Soviet Union

https://en.m.wikipedia.org/wiki/Political_abuse_of_psychiatr...


Sure, but Russians are bad [0]. Western governments are good. So it's totally different!

[0] So we're told by noted perjurer (it's OK because he's good) DNI James Clapper!


>I have to spend hundreds of dollars upfront to buy a phone

But the phone doesn't have to be bought from Facebook, whereas with iMessage you have to pay Apple for a phone.

>maintain a phone line to use WhatsApp.

I wonder what the reason for this is. Maybe to reduce spam? Data collection?


What you're referring to as Linux is actually...

GNU/Linux doesn't automatically choose which program to use for anything (you can't ./file.png like you can in Windows). In my experience file managers tend to use file extensions to choose which application to use, and that application might then use libmagic and ignore the file extension. (e.g. giving a PNG file the .JPG extension will make the file manager think it's a JPEG, and therefore open it with an image viewer, but the image viewer program will use headers to recognise it as a PNG)


xdg-open ./file.png


Exactly, it's the same reason most date formats don't start with the year, even though it is the most significant of the numbers. If I write 12-8-2019, the 12 is the most important number for me, in speech I will usually refer to the date as "the 12th". In the same way, if I'm telling my address to someone, I'll just say the street address, since we can assume I live in the country we're in right now (which of course doesn't work on the internet, hence we specify additional information at the end).


I'd argue most of those are necessary for good content (if we don't view content separately from presentation)

> Putting important text inside of images I'm sure the reason for this is that it's hard to parse text from images, and while Google could use their AI to figure it out, they don't bother. But it also prevents blind people from being able to read the text, so it does worsen the experience. > Duplicate content This makes the site harder to navigate for users as well. > Page performace issues Quite obviously makes the experience worse. > Broken mobile support. -..-


But the richer children are inherently privileged, yet you think providing privilege to poorer children is immoral. Why is one acceptable but the other is not?


You copied the link incorrectly, it throws a 404. https://cards.c13u.com/browse works instead.


Let's say the TSA used names more aggressively, for example checking everyone with the same name as anyone with a criminal record.

Now let's also assume African-Americans are disproportionately incarcerated, and therefore names associated with the ethnic group will be disproportionately represented in criminal records. I'm sure we can agree on that the system would then be biased towards a race.

The problem is that there isn't a single terrorist that caused this, in fact there's no good reason to believe that the hairstyles mentioned in the article are used to hide contraband.


>exactly the same as a verified user on Twitter

from: support@apple-support.example.org [This message was signed by apple-support.example.org (Verified by Let's Encrypt)]

Please send us your Apple ID and password for routine security checks.


No. Do it OpenSSH style. At first every identity is unknown. Then you get a mail signed by a key tied to an identity (on whatever keybase), then as you email each other your trust grows.

Sure, maybe you're trusting a scammer more and more, but at least when you get a new email from a scammer that's trusted by millions (let's say by more than one EV cert signed the key that signed the email), then it's pretty sure you're just being scammed by Apple to further their regular bottom line.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: