• Some users have recently had their accounts hijacked. It seems that the now defunct EVGA forums might have compromised your password there and seems many are using the same PW here. We would suggest you UPDATE YOUR PASSWORD and TURN ON 2FA for your account here to further secure it. None of the compromised accounts had 2FA turned on.
    Once you have enabled 2FA, your account will be updated soon to show a badge, letting other members know that you use 2FA to protect your account. This should be beneficial for everyone that uses FSFT.

LG Split Screen Drastically Reduces Security

HardOCP News

[H] News
Joined
Dec 31, 1969
Messages
0
Can't get your software to work with the Windows User Account Control? Screw it, just disable it, no one will ever know. ;)

Life is good (LG) is what you may say out loud when using LG stuff. Unfortunately, today I have to tell you that life is horrible. I recently upgraded to an ultra wide LG screen which comes with split screen software. While I am happy with the hardware, I am utterly disappointed how LG treats security. The TL;DR version is that instead of writing software properly, they just disable UAC upon installation in order to make their software work.
 
Haha. We have a database here based on Foxpro that disables UAC upon install. That wasn't really a problem as users are using standard accounts anyway, but on the new Windows 8.1 machines, all of their Metro apps stop running until UAC is re-enabled. Luckily, the app still runs even with UAC.
 
Wait... shouldn't Windows notify you when an application is attempting to change security settings on your computer?
 
Wait... shouldn't Windows notify you when an application is attempting to change security settings on your computer?

LG is using the same SuperDuper Windows root account/password that allows NSA to spy on you....;)
 
The Solidworks PDM client will not function with UAC turned on

Having to have UAC disabled on business computers because of crappy programming is retarded.
 
Everyone at my company is on a PC that has UAC disabled. VBS based login scripts don't work for one. but only certain users are in the Administrators group, everyone else is a normal user.
 
UAC is worthless if it constantly prompts users (which it does). So it puts users into the habit of clicking "yes" without actually paying attention. UAC may make admins feel better, but it doesn't really do anything for the average user. Rights/permissions management is far more important.
 
UAC at minimum is sensible if you value your machines integrity and security.
 
Wait, there are people that want annoying pop ups every time they try to do something in Windows? I am honestly surprised. Disabling UAC is the very first step to a sane Windows user experience.

And someone believing that UAC in any constitutes "security" needs to be checked for brain damage.
 
Wait, there are people that want annoying pop ups every time they try to do something in Windows? I am honestly surprised. Disabling UAC is the very first step to a sane Windows user experience.
If that was happening then you would have a point.
I hardly ever install something.

And someone believing that UAC in any constitutes "security" needs to be checked for brain damage.
It forms part of system security, sorry if you arent party to it.
UAC has stopped me from installing apps that demand higher privileges than they need.
I use other security to prevent unauthorised installations from starting.


People who believe it is worthless do not understand threat mitigation
Its a strange world.
 
The Solidworks PDM client will not function with UAC turned on

Having to have UAC disabled on business computers because of crappy programming is retarded.

You want to know something scary... the software that made our organization turn off UAC?

Microsoft Lync... Yup you read right, Microsoft's own IM software.

Lync's screen sharing feature is really easy to use, everyone from tech support to trainers use to to help people quickly. The problem is it doesn't support UAC (aka can't see the dialogs etc).

MS says its not supposed to be used for tech support or "admin" functions... and then they say many of their clients complain about this lack of feature... they are "thinking" of adding support.

Yet it all comes back down to ease of use... its really handy and easy finding people and remote controlling their computer via Lync.
 
Disabling UAC is a horrible idea, friend of mine who did it got a drive by cryptolocker from groove shark because he did it. The idea that simply visiting a website could give you malware seems like it would be something both businesses and users would be very sensitive about.
 
Wait you like having to hit continue everytime something happens. UAC is a total joke. How about MS make a secure os and screw the UAC because 98% of the average user hits continue anyways.
 
Disabling UAC is a horrible idea, friend of mine who did it got a drive by cryptolocker from groove shark because he did it. The idea that simply visiting a website could give you malware seems like it would be something both businesses and users would be very sensitive about.

You only get cryptolocker if you run the file. which btw is posted on many security sites its bad. Also most antivirus's like norton and symantec pick it up. AVG does not.
 
Wait you like having to hit continue everytime something happens. UAC is a total joke. How about MS make a secure os and screw the UAC because 98% of the average user hits continue anyways.

Not going to argue about it because really I don't care if you want to be idiots, but your post is complete Fud. UAC doesn't nag and hasn't for years. Heck unless you are installing stuff constantly you should hardly ever see it. It is extremely effective and completely unobtrusive. If you are on win 7+ there is absolutely zero reason not to have it running. But go on, don't use it I have no vested interested in your time. If to enjoy removing garbage from your machine that's your deal.
 
People who believe it is worthless do not understand threat mitigation

You do not mitigate a threat by using a system that creates pavlovian responses.

Seriously. Didn't we learn this lesson with early browser security?

If you put up annoyance messages every time a user wants to do something, you're NOT enhancing security. You're programming a lemming to auto-click YES by reflex.

Do you want to run this? YES.
Do you want to run this? YES.
Do you want to run this? YES.
*Half a trillion repetitions later*
Do you want me to maliciously reformat your hard drive? YES. Uh...Wait a sec!

And don't start with any "Well smart users would never..." bullshit.
This is the whole POINT of a programmed response. It happens by REFLEX.
I don't give a damn how careful, smart, educated, paranoid, WTF-EVER you are.

The most successful attacks on a computer attack the weakest link. The user.
UAC does JACK SHIT to mitigate that.
 
UAC is worthless if it constantly prompts users (which it does). So it puts users into the habit of clicking "yes" without actually paying attention. UAC may make admins feel better, but it doesn't really do anything for the average user. Rights/permissions management is far more important.

Ummm, UAC does NOT constantly prompt you. Where the heck are you getting this misinformation from.
 
Wait, there are people that want annoying pop ups every time they try to do something in Windows? I am honestly surprised. Disabling UAC is the very first step to a sane Windows user experience.

And someone believing that UAC in any constitutes "security" needs to be checked for brain damage.

Wait, there are people who do not understand what UAC is or how it actually works after all these years? :rolleyes:
 
You do not mitigate a threat by using a system that creates pavlovian responses.

Seriously. Didn't we learn this lesson with early browser security?

If you put up annoyance messages every time a user wants to do something, you're NOT enhancing security. You're programming a lemming to auto-click YES by reflex.

Do you want to run this? YES.
Do you want to run this? YES.
Do you want to run this? YES.
*Half a trillion repetitions later*
Do you want me to maliciously reformat your hard drive? YES. Uh...Wait a sec!

And don't start with any "Well smart users would never..." bullshit.
This is the whole POINT of a programmed response. It happens by REFLEX.
I don't give a damn how careful, smart, educated, paranoid, WTF-EVER you are.

The most successful attacks on a computer attack the weakest link. The user.
UAC does JACK SHIT to mitigate that.

If you do not setup a standard and admin account then I might agree with your partially. However, UAC does not prompt you repeatedly and since Vista SP1, it hasn't. I hate that folks believe all you have to do is sneeze and UAC comes up.

I have no doubt you all run root access 24/7 on Linux too, right? :D
 
I don't personally like the 21:9 monitors, but I have to say this guy is running Win10 beta and basing his sentiments on that. Seems to me all he would have to do after the LG splitscreen software installs is reenable UAC...
 
Apparently so, makes me sad.

You know, I don't see anyone bitching about and disabling their cell phone passwords and sudo on their linux machines and claiming that they reduce security. Seems to be a lot of biased people out there.
 
I don't personally like the 21:9 monitors, but I have to say this guy is running Win10 beta and basing his sentiments on that. Seems to me all he would have to do after the LG splitscreen software installs is reenable UAC...
That did bother me about the article. He says he had to uninstall it, but did he even try to enable UAC after it installed and giving the splitscreen program exclusive elevated rights manually like he preaches? What it sounds like is that this program creates a second virtual monitor, and doing that would trigger a UAC response. LG simply wanted to prevent that from happening.
You do not mitigate a threat by using a system that creates pavlovian responses.

Seriously. Didn't we learn this lesson with early browser security?

If you put up annoyance messages every time a user wants to do something, you're NOT enhancing security. You're programming a lemming to auto-click YES by reflex.

Do you want to run this? YES.
Do you want to run this? YES.
Do you want to run this? YES.
*Half a trillion repetitions later*
Do you want me to maliciously reformat your hard drive? YES. Uh...Wait a sec!

And don't start with any "Well smart users would never..." bullshit.
This is the whole POINT of a programmed response. It happens by REFLEX.
I don't give a damn how careful, smart, educated, paranoid, WTF-EVER you are.

The most successful attacks on a computer attack the weakest link. The user.
UAC does JACK SHIT to mitigate that.
Maybe for the casual user. Unless it is an application or installer that I, myself, have explicitly executed then I always take the time to read what is running. And I have clicked "No" on several occasions.

I think since Vista SP2 that UAC is actually a good stop condition at this point. People do stupid things accidentally or instictively all the time. Whether or not people develop an automatic response or not, that sound and popup does make your mind stop for a second to assess what is happening. But then again, self-awareness and common sense are rare attributes to have in this day and age...
 
UAC is fucking retarded. I get why people use it in business, I won't argue that point. For home use? I've had it disabled since it came out and have NEVER gotten a virus. The way you avoid viruses isn't by some stupid UAC prompt, it's by using your brain. It still boggles my mind how people get viruses.

Did you download your favorite game of thrones episode and it's a 5mb file? Did you get a internet explorer pop up warning you that you're infected and you need to download a cleaner? Did you get some leet warez from some totally reputable website that's half written in russian and broken english? Guess what? THOSE ARE VIRUSES. I just solved your need for UAC.
 
Its not only about virii, its also about being alerted to and preventing unwanted elevation of privileges.
This could lead to giving control to programs that shouldnt have it, unwanted monitoring, unwanted leaking of information, virii, other malware ...

Stress and loss of time should be factored into this as a breach of your data not only puts it somewhere that can cause loss, but it can cost you a stack of time and worry correcting it, if it can be corrected.
A computer is a treasure trove repository of the lives of those using them.
It makes sense to be alerted when something attempts to make changes that can have far reaching consequences.
 
Disabling UAC is a horrible idea, friend of mine who did it got a drive by cryptolocker from groove shark because he did it. The idea that simply visiting a website could give you malware seems like it would be something both businesses and users would be very sensitive about.

I deal with organizations all the time that get hit with Crypto, ransom ware and all kinds of intrusive software and virus's that have UAC enabled. It does nothing to protect the end user, other then asking their permission to run whatever program they shouldn't be in the first place.

It's a useless feature.

Educating end users goes a lot further when coupled along with good security software(Av & Firewalls) and a proper backup and recovery options.

Everybody gets a virus or a piece of malware running amok in the environment at some point in time, it's inevitable.
Having a proper plan in place to deal with it, is the key.
 
I deal with organizations all the time that get hit with Crypto, ransom ware and all kinds of intrusive software and virus's that have UAC enabled. It does nothing to protect the end user, other then asking their permission to run whatever program they shouldn't be in the first place.

It's a useless feature.

I was about to respond with how UAC has been great at limiting damage to user profiles and not the system, but then I realized that was more thanks to employees being on standard user accounts. UAC only matters on administrator logins as far as I know.
 
Everyone at my company is on a PC that has UAC disabled. VBS based login scripts don't work for one. but only certain users are in the Administrators group, everyone else is a normal user.
Then everyone at your company are fucking retards, and your administrators are novices that don't understand how to setup permissions correctly.

Running with "least privilege" is a fundamental tenet of information security, and it is simply best practice to do so. By separating admins and users, you have role-based separation... but not least privilege. UAC forces you to run with elevated privileges only when you need to do so. The rest of your processes run at the lowest-privilege level possible. If you think that all UAC does is stop you from installing programs, you obviously don't understand it. A quick google search would solve the problem of finding the information, though laziness and ignornance will prevent you from reading and understading it:

How UAC works:
https://technet.microsoft.com/en-us/library/dd835561(v=ws.10).aspx

UAC is worthless if it constantly prompts users (which it does). So it puts users into the habit of clicking "yes" without actually paying attention. UAC may make admins feel better, but it doesn't really do anything for the average user. Rights/permissions management is far more important.
Wait, there are people that want annoying pop ups every time they try to do something in Windows? I am honestly surprised. Disabling UAC is the very first step to a sane Windows user experience.

And someone believing that UAC in any constitutes "security" needs to be checked for brain damage.

UAC does come installed at a higher level that may be feasible to some people. This can be turned down, while still keeping the critical token-separating function of UAC mostly intact. Simply disabling a security feature of an OS... whether it is UAC in Windows, or sudo in Linux, is what ignorant/lazy people do.

Not going to argue about it because really I don't care if you want to be idiots, but your post is complete Fud. UAC doesn't nag and hasn't for years. Heck unless you are installing stuff constantly you should hardly ever see it. It is extremely effective and completely unobtrusive. If you are on win 7+ there is absolutely zero reason not to have it running. But go on, don't use it I have no vested interested in your time. If to enjoy removing garbage from your machine that's your deal.
This. I have not heard of anyone who seems to be a sysadmin type actually chime in. All the negatives I'm hearing seem to be "users" who are annoyed by UAC, without understanding what it actually does (see above link).

Any good sysadmin will know what things were like in the WinXP days. Simply consider the number of viruses that affect WinXP vs Windows Vista/7/8.

You do not mitigate a threat by using a system that creates pavlovian responses.

Seriously. Didn't we learn this lesson with early browser security?

If you put up annoyance messages every time a user wants to do something, you're NOT enhancing security. You're programming a lemming to auto-click YES by reflex.

Do you want to run this? YES.
Do you want to run this? YES.
Do you want to run this? YES.
*Half a trillion repetitions later*
Do you want me to maliciously reformat your hard drive? YES. Uh...Wait a sec!

And don't start with any "Well smart users would never..." bullshit.
This is the whole POINT of a programmed response. It happens by REFLEX.
I don't give a damn how careful, smart, educated, paranoid, WTF-EVER you are.

The most successful attacks on a computer attack the weakest link. The user.
UAC does JACK SHIT to mitigate that.
A pavlovian is considered "[url="http://en.wikipedia.org/wiki/Classical_conditioning]classical conditioning[/url]". ANY repeated activity can cause this. The difference between people and animals is our ability to reason. If you're not using your God-given abilities... well... I can't help you.

Again, you don't understand UAC. It prompts you to elevate WHEN NEEDED, and keeps you from running processes 24/7 in an elevated (exploitable) state.

This is no different than what other OSs do.

With Windows, you can:
1) Use UAC and be prompted when you need an elevated token (most-restrictive)
2) Disable UAC and run processes in an elevated state 100% of the time

With linux, you can:
1) Use sudo and elevate a command when needed
2) Not use sudo and su to a root account when needed (in which people usually leave those processes opened until they log off)

You can mitigate #2 in each instance by separating user and admin accounts, but this doesn't accomplish "least privilege".

Personally, I like UAC better. I cannot tell you how many times I've put together a command in linux, only to have it not work, or only partially work/not work as expected. Usually, it is the latter. With Windows, it is usually the former: you are told you cannot run the process. Also, with UAC, the elevated process goes away when you close the process/window/etc. If you simply su to a root account in linux, most people do not exit out. Sudo is better... but you have to remember to add "sudo" to the command. At least Windows will prompt you after the fact.

As for your browser security question, again... humans behaving as animals. If you click "yes", "ignore", or anything else... that is akin to putting your hand in hot water, even after you've been warned it might be hot.
 
I deal with organizations all the time that get hit with Crypto, ransom ware and all kinds of intrusive software and virus's that have UAC enabled. It does nothing to protect the end user, other then asking their permission to run whatever program they shouldn't be in the first place.

It's a useless feature.

Educating end users goes a lot further when coupled along with good security software(Av & Firewalls) and a proper backup and recovery options.

Everybody gets a virus or a piece of malware running amok in the environment at some point in time, it's inevitable.
Having a proper plan in place to deal with it, is the key.

Educating users doesn't do much because users are complex and some simply aren't going to ever learn even if they do the best they will still make mistakes. You can't seriously expect any computer let alone ones used by many employees to consider education a solution. Education is only somewhat effective against the most obvious attacks and Microsoft nor any company I am aware of has implemented a system that makes it easier for tech support to help guide educated users. I don't get why people keep saying this when decades of user failures have and the ubiquity of computers has proven we cant solve the problem through education, even people here at hard can get hit by viruses how is a soccer mom supposed to get that education? Attacks were even coming in from hard forum a couple years ago. This is my largest complaint with UAC, UAC should ALWAYS force you to know the admin password just like Linux, then if you have an uneducated user you don't give them the password, it won't stop everything but it will stop a lot. This is why UAC is such a failure because in its default state on a consumer machine it still relies on "user education" it still relies on the user to not click yes to everything they see and it does nothing at all to stop any idiot from sitting down at another persons computer and get it infected, even a 4 year old kid, because all you have to do is click yes. In my experience even when I try to educate people you get 2 major groups of people, click yes to everything group, and click yes to nothing group. Both groups are screwed because the click no to everything group quickly ends up with tons of out dated software full of vulnerabilities in stuff like flash and java that will get them a drive by malware. And after all that many users are still bothered and pissed off by the nagging UAC does, realize that much of the nagging UAC does is because the user has not or cannot update software (I am looking at you java on windows 7 that can NEVER update).

The simplest solution is for MS to always require an admin password for UAC, this stops several things. 1 it means that not any 4 year old that goes to some shady kids game website can infect you simply by clicking yes, or that idiot that comes over and wants to install something. Second for educated and uneducated users it heavily reduces the chance of an accidental yes click, third for uneducated users it forces them to pause and think even for just a split second and that may help.


You only get cryptolocker if you run the file. which btw is posted on many security sites its bad. Also most antivirus's like norton and symantec pick it up. AVG does not.

We were doing nothing but listening to grooveshark on his computer, not clicking anything not even touching a mouse. I have done the same on grooveshark with UAC enabled for a long time and never been hit although my antivirus has blocked many attempted attacks from grooveshark ads. Maybe flash or something else "ran" a file but there was no user interaction. We were literally standing up trying to see if his subs were balanced. That said he was running MS AV which I suggested he not use after the reinstall. Luckily he did have backups and a reformat was done.
 
Back
Top