> 3. I like UAC. The article claims that giving users a dialog box to permit admin access is good for malware, but the alternative is taking admin away from users altogether on their own computers. I don't think this is an acceptable tradeoff.
The UAC is about persuading legitimate developers to do the right thing. In that respect it has been successful. Many developers have learned they should not be annoying users with the admin dialog unless they really do need enhanced privileges.
The UAC has no other benefit. It's not a security barrier (malware can bypass it, or get the user to). If you're running on an admin account you are admin and all win32 programs running on your desktop have admin rights. They just need an elevated token to make use of them which, as I said, is easy enough to gain. The exception is if programs create their own sandbox to run sub-processes with limited rights.
UWP is an attempt to sandbox applications by default and thus allow the user to be admin without programs being admin by default. However its uptake has been slow.
In short, it's not the UAC that's the issue. It's Windows permission model. Microsoft is aware of this and is attempting change.