No - the problem here is moreso the sheer complexity of Windows and the variety of devs involved and the push for backwards compatibility.
I have not used Windows enough in recent years to know, but there may be differences in what you need to enter your admin password for, which may make users less suspicious when asked. On Linux distros I have used the only regular operation on a desktop that requires it are software installation and updates updates, which has a well defined UI and comes after a specific user action.
clearly you haven't seen all the projects on github where the instructions are "curl ... | sudo sh". Moreover, the security model behind sudo is so hilariously bad that it's trivial to get EoP[1]. UAC might have plenty of exploits (usually around auto-escalation), but at least they make an attempt at making it secure.
[1] tl;dr: modify $PATH to contain a bobbytrapped version of sudo that executes the command you want, plus whatever evil stuff you want.
I have seen them. I do not use them! I very rarely install anything from outside distro repos or language repos.
> Moreover, the security model behind sudo is so hilariously bad that it's trivial to get EoP[1]. UAC might have plenty of exploits (usually around auto-escalation), but at least they make an attempt at making it secure.
You have missed my point. You do not have to use sudo
Especially when they had to drag their developer community kicking and screaming to it. (in Windows Vista ~2006)
Afaicr, there's also a neat bit where the lock screen and UAC prompt actually run under an entirely different, privileged and restricted session (than the normal one the user is interacting with and running programs in).
Ref: https://learn.microsoft.com/en-us/windows/security/applicati...
Apparently now termed the "secure desktop", it's transparently overlaid on top of the user desktop whenever you see a prompt.
[1]: https://learn.microsoft.com/en-us/windows/win32/winstation/d...
Windows only requires escalation for this if you want to install that userspace software to a non-user location,* or if you want to install a driver for the webcam.
If you just want to run the program, this is not required.
A long time ago, in the pre-Vista era, when running programs as administrator was the default, many programs would not work if they were not run as administrator. This is no longer case for programs written after Vista. From Vista onwards, older programs that assume admin rights and attempt to change admin-only files get their reads and writes redirected to a VirtualStore folder within the user's profile, so that the program still works without administrative permissions.
* The exception is with some installers where the UAC installer detection kicks in and demands escalation straight away, even before you select an installation location (which could be a user-writable location). Turning this off requires using the Group Policy Editor or the Registry Editor to flip the EnableInstallerDetection registry key.
Then there is also polkit, which does something similar to sudo, but for a different usecase (authenticating unpriviledged process access to a priviledge process). Polkit to my knowledge can differentiate between actions to "always allow", "requires confirmation" (press yes) and "require password".
A) there is no interception to be had. It’s a fucking “Yes I am Admin” single click a child could do unsupervised.
B) It requires training for the user to know that this is a special UAC mode. That’s high-motivation, high-knowledge user training. Pilots train to recognize unusual signs. Your grandma does not train to recognize what UAC looks like, why it would come up and when. UAC is the biggest cop out of a security excuse and Windows should be ashamed.
UAC is strictly better than sudo IMO.
Does UAC solve security for windows? Of course not, but we were comparing against sudo here.
It's by far the most secure and well thought out implementation of an elevation prompt across all operating systems.
A lot of thought went into designing the Secure Desktop [1] used by UAC, and really mac and linux not having something similar is an embarrassment.
[1] https://learn.microsoft.com/en-us/archive/blogs/uac/user-acc...
You’re right, fake sudo prompts is how people get exploited all day long. I’ve witnessed it on MacOS.
For UAC, the user still has to learn that the darkening on the screen and the prompt is “serious business.” I think that when a password is present and has been willfully supplied, prompting the user for the password guards against automatic/accidental acceptance (button-only user confirmation prompts). I understand that many users have a joke password that might as well not be something that’s not really any more secure than a click on a button.
I see that Sudo for Windows has been restricted to Desktop only. https://hudsonvalleyhost.com/blog/microsoft-officially-exclu...
From the design article you linked, I know it’s 2006 era:
> You hide the real mouse cursor and show a fake one some number of pixels offset to the real one
I think MacOS only in the recent years has “Full Desktop Control” as an accessibility-category permission (a confusing category to boot) it enforces on apps to prevent faking the cursor.