NotebookForums.com › Forums › Notebook Manufacturers › Dell Forums › Dell Home (Inspiron, XPS, Studio) › Run as Non-Admin ?
Recent Reviews
-
So I just got a Lenovo Yoga 13. This is my review. As what I primarily do is writing and programming, having a good keyboard is critical for me, which is why a tablet alone can’t work for me, and...
-
I have owned dozens of laptops in a variety of brands, and had many different laptops provided for my use at work. Without question, this is the finest I have owned. The Alienware M17x R2 is a...
-
N/m
-
Lenovo Thinkpad W530 Review by Djembe One of the longest and most enduring brands in computers is Thinkpad. Originally developed by IBM in the USA, Thinkpad notebook computers are now...
-
I have this memory installed in my Inspiron 14R. 6gb (one 2gb & one 4gb). Great performance! I highly recommend Kingston.
Run as Non-Admin ?
Poll Results: Do you use a Limited account on Windows ?
-
84% (54)No.
-
12% (8)Yes.
-
3% (2)What security does limited account provide ?
64 Total Votes
post #2 of 41
12/20/05 at 12:24am
post #3 of 41
12/20/05 at 12:30am
- Dog Soldier
- 0
- Werewolves ate my platoon
- offline
- Joined: 12/2005
- Location: Scottish highlands
- Posts: 22
- Select All Posts By This User
<b>I</b> run as admin, <b>you</b> should not.
-DS
EDIT:
-Hardware firewall
-Software firewall
-Real-time antivirus
-Real-time antispyware/antimalware (x3)
-Realtime antirootkit
-Full encryption of personal and irreplaceable information
-RAID1 realtime backup of personal and irreplaceable information to encrypted external drive
-Tight knot in network cable to keep out the bad stuff
-DS
EDIT:
-Hardware firewall
-Software firewall
-Real-time antivirus
-Real-time antispyware/antimalware (x3)
-Realtime antirootkit
-Full encryption of personal and irreplaceable information
-RAID1 realtime backup of personal and irreplaceable information to encrypted external drive
-Tight knot in network cable to keep out the bad stuff
post #4 of 41
12/20/05 at 12:37am
post #5 of 41
12/20/05 at 12:45am
post #6 of 41
12/20/05 at 4:16am
post #7 of 41
12/20/05 at 4:21am
Quote:
|
Originally Posted by Revenent
We encourage people to run as non-admin. Vista also has the concept of UAP, which limits what an account can do, even if it is an admin.
|
BTW, where do you work in MS?
post #8 of 41
12/20/05 at 12:16pm
- Doc.Caliban
- 0
- The Man of Bronze
- offline
- Joined: 1/2005
- Location: Caribbean 17°37'52.47"N 63°14'00.51"W
- Posts: 1,884
- Select All Posts By This User
Quote:
|
Originally Posted by Revenent
We encourage people to run as non-admin.
|
However, I don't know anyone there who uses a non-admin account. I just did my own informal poll last night of friends who are still there, some of which have been there for more than 12 years. I asked, "Do you, or anyone you know at work, use non-admin level accounts in Windows on any machine you have at home or at work?"
100% said, "No." The only sort-of exception were people who used multiple accounts at home on the family machines where the SO or kids used the computer, but the account of the person in question is admin level.
The only conclusion in this is that people all share the same, "It won't happen to me." attitude.
EDIT: And it could be seen as an indication that the non-admin accounts are just too problematic to deal with.
I too use a non-root account in Linux because of it's better implementation. If Vista has a better way to protect the admin functions of the OS without hampering the user as much as it does now, then I'd happily go along with that. After all, if it's done well, there would be no reason not to.
-Doc
post #9 of 41
12/20/05 at 12:52pm
I too use a non-root account in Linux because of it's better implementation.
I wonder what in the world you could mean by that. There is nothing at all wrong with the "implementation" of non-adminsitartive accounts in WinNT derivatives; in fact, the security model they implement is quite a bit more sophisticated than what many Unix variants offer. The DEC heritage shows...
Anyway, the only "problem with non-administrative accounts on Windows systems" is the massive incompetence of many software developers, who routinely violate Windows XP compatibility standards that have been out for at least a decade. Stuff like, as a normal user, you never, ever, write or modify files in system folders, or modify keys in HKLM, etc., etc.
We should be very clear about one thing: If a user mode application does not run properly without administrative rights, what that means is that this application is not compatible with Windows XP, and does not meet XP logo requirements. As an aside, I might mention that on this very machine I am sitting on right now, I have more applications installed than most people in this forum have probably ever heard of, and every single one of them runs just fine without administrative rights, just like any well-designed application should.
Finally, from a security point of view, routinely running with adminsitrative rights is pure insanity, period. Nobody who is the least bit interested in system security, has a minimum amount of competence, and is in his right mind (well, there's a list of caveats there...) would run his day-to-day work logged in with administrative rights.
I wonder what in the world you could mean by that. There is nothing at all wrong with the "implementation" of non-adminsitartive accounts in WinNT derivatives; in fact, the security model they implement is quite a bit more sophisticated than what many Unix variants offer. The DEC heritage shows...
Anyway, the only "problem with non-administrative accounts on Windows systems" is the massive incompetence of many software developers, who routinely violate Windows XP compatibility standards that have been out for at least a decade. Stuff like, as a normal user, you never, ever, write or modify files in system folders, or modify keys in HKLM, etc., etc.
We should be very clear about one thing: If a user mode application does not run properly without administrative rights, what that means is that this application is not compatible with Windows XP, and does not meet XP logo requirements. As an aside, I might mention that on this very machine I am sitting on right now, I have more applications installed than most people in this forum have probably ever heard of, and every single one of them runs just fine without administrative rights, just like any well-designed application should.
Finally, from a security point of view, routinely running with adminsitrative rights is pure insanity, period. Nobody who is the least bit interested in system security, has a minimum amount of competence, and is in his right mind (well, there's a list of caveats there...) would run his day-to-day work logged in with administrative rights.
post #10 of 41
12/20/05 at 12:56pm
- Boogieman117
- 0
- sR Radio Promo Guy
- offline
- Joined: 10/2004
- Location: MD
- Posts: 1,036
- Select All Posts By This User
Quote:
|
Originally Posted by drizek
i havent seen any of this stuff in any of the vista builds ive tried, so i cant comment, but for windows xp, it just doesnt work. i tried to setup limited accounts once before for my family members on win xp and they werent able to use many of their apps.
BTW, where do you work in MS? |
If Vista comes out, provide the user system of previous server admin. IE: User, Power User, Administrator, etc. for home users.
post #11 of 41
12/20/05 at 1:08pm
- Joined: 5/2005
- Posts: 8,029
- Select All Posts By This User
Quote:
|
Originally Posted by Pirx
I too use a non-root account in Linux because of it's better implementation.
I wonder what in the world you could mean by that. There is nothing at all wrong with the "implementation" of non-adminsitartive accounts in WinNT derivatives; in fact, the security model they implement is quite a bit more sophisticated than what many Unix variants offer. The DEC heritage shows... Anyway, the only "problem with non-administrative accounts on Windows systems" is the massive incompetence of many software developers, who routinely violate Windows XP compatibility standards that have been out for at least a decade. Stuff like, as a normal user, you never, ever, write or modify files in system folders, or modify keys in HKLM, etc., etc. We should be very clear about one thing: If a user mode application does not run properly without administrative rights, what that means is that this application is not compatible with Windows XP, and does not meet XP logo requirements. As an aside, I might mention that on this very machine I am sitting on right now, I have more applications installed than most people in this forum have probably ever heard of, and every single one of them runs just fine without administrative rights, just like any well-designed application should. Finally, from a security point of view, routinely running with adminsitrative rights is pure insanity, period. Nobody who is the least bit interested in system security, has a minimum amount of competence, and is in his right mind (well, there's a list of caveats there...) would run his day-to-day work logged in with administrative rights. |
Thanks for a few laughs
post #12 of 41
12/20/05 at 1:45pm
- Joined: 5/2005
- Location: Edinburgh, UK
- Posts: 2,183
- Select All Posts By This User
Quote:
|
Originally Posted by Pirx
I too use a non-root account in Linux because of it's better implementation.
I wonder what in the world you could mean by that. There is nothing at all wrong with the "implementation" of non-adminsitartive accounts in WinNT derivatives; in fact, the security model they implement is quite a bit more sophisticated than what many Unix variants offer. The DEC heritage shows... Anyway, the only "problem with non-administrative accounts on Windows systems" is the massive incompetence of many software developers, who routinely violate Windows XP compatibility standards that have been out for at least a decade. Stuff like, as a normal user, you never, ever, write or modify files in system folders, or modify keys in HKLM, etc., etc. We should be very clear about one thing: If a user mode application does not run properly without administrative rights, what that means is that this application is not compatible with Windows XP, and does not meet XP logo requirements. As an aside, I might mention that on this very machine I am sitting on right now, I have more applications installed than most people in this forum have probably ever heard of, and every single one of them runs just fine without administrative rights, just like any well-designed application should. Finally, from a security point of view, routinely running with adminsitrative rights is pure insanity, period. Nobody who is the least bit interested in system security, has a minimum amount of competence, and is in his right mind (well, there's a list of caveats there...) would run his day-to-day work logged in with administrative rights. |

post #13 of 41
12/20/05 at 1:52pm
Quote:
|
Originally Posted by Pirx
I too use a non-root account in Linux because of it's better implementation.
I wonder what in the world you could mean by that. There is nothing at all wrong with the "implementation" of non-adminsitartive accounts in WinNT derivatives;......... |

Tell me, how do I change User permissions in Windows XP Home? I just want to use this:User1 can write/access "User1[My Documents]"
User1 can write/access "C:\user1temp"
User2 cannot access "C:\user1temp"
(Both User1 and User2 are non-admins)
Just this.... Please, tell me, Windows advocate

post #14 of 41
12/20/05 at 2:03pm
- Doc.Caliban
- 0
- The Man of Bronze
- offline
- Joined: 1/2005
- Location: Caribbean 17°37'52.47"N 63°14'00.51"W
- Posts: 1,884
- Select All Posts By This User
Quote:
|
Originally Posted by Pirx
I too use a non-root account in Linux because of it's better implementation.
I wonder what in the world you could mean by that. |
Quote:
|
Originally Posted by Pirx
Finally, from a security point of view, routinely running with administrative rights is pure insanity, period. Nobody who is the least bit interested in system security, has a minimum amount of competence, and is in his right mind (well, there's a list of caveats there...) would run his day-to-day work logged in with administrative rights.
|
I do agree with you, as indicated in my initial reply in this thread where I implied "Do as I say, not as I do."
-Doc
post #15 of 41
12/20/05 at 2:18pm
I dont see how it is an issue with the applications that make limited accounts not work. developers shouldnt have to jump through hoops to get their apps to work with it. In linux, it is very simple. you cant modify system files as non-root, however, you can view them. This means that a non-root cant install/uninstall software, but can run anything already on the system. period. application developers dont have to add any extra code for it.
More importantly, if a non-root wanted to install an app in linux, all it would rquire is typing in the root password in a dialog box that comes up. in windows, it requries logging off and logging in as admin. pain in the ass.
More importantly, if a non-root wanted to install an app in linux, all it would rquire is typing in the root password in a dialog box that comes up. in windows, it requries logging off and logging in as admin. pain in the ass.
post #16 of 41
12/20/05 at 4:06pm
There are no hoops that developers have to jump through. It's very simple. MSDN has had this information freely available for 10 years or more. If you want to save a document, start by saving to the "My Documents" area. Users always have access to their own "My Documents" folder, period. Don't save to "Program Files". That folder should hold Program Files, which is why it's not called "Data Files". Don't save to the root of a volume. Don't start cluttering the root of the volume with yet another folder. Saving a file is saving a file is saving a file, the process is the same no matter what. WHERE the file is saved is where the difference lies. Incompetent developers don't get it.
Don't save data to HKEY_LOCAL_MACHINE. There's no need except on installation, which should only be done by admins anyway. Save to HKEY_CURRENT_USER. Not new. Not a hoop. The process of writing to one or the other is identical, it's just that one will always be available no matter who is logged on, while the other may be in read-only mode. Incompetent developers don't get it.
Now, I do agree that the Linux implementation is better. However, 99% of the reasons people don't use limited accounts in Windows were created by shoddy third party programming, as stated above.
Don't save data to HKEY_LOCAL_MACHINE. There's no need except on installation, which should only be done by admins anyway. Save to HKEY_CURRENT_USER. Not new. Not a hoop. The process of writing to one or the other is identical, it's just that one will always be available no matter who is logged on, while the other may be in read-only mode. Incompetent developers don't get it.
Now, I do agree that the Linux implementation is better. However, 99% of the reasons people don't use limited accounts in Windows were created by shoddy third party programming, as stated above.
post #17 of 41
12/20/05 at 4:13pm
post #18 of 41
12/20/05 at 4:18pm
Run As works for most things but not all, namely explorer.exe and 16-bit application that use shell calls to open other executables. This is where the Linux implementation is better, because you're prompted with something that basically says, you can't do this unless you gimme a password of an account that can. I've also encountered some difficulties with Run As when managing a trusted domain, but that's a pretty rare thing. Most people can't be bothered to use Run As, and I don't blame them. However, you can modify your shortcuts to fire off with Run As, so you're automagically prompted for a password without mucking around with command prompts or context menus. Most people don't want to be bothered with that either. Vista is showing promise in making this process less hassling, though.
post #19 of 41
12/20/05 at 5:58pm
Just this.... Please, tell me, Windows advocate
Boot into safe mode, log in as the administrator, and set the permissions you want. You might want to google the subject if you need more help.
is your friend
Doc Said: "I do agree with you..."
I was hoping that you would not misunderstand my comments; from other posts of yours that I have seen I had the impression that you generally know what you are talking about, so my comments were not so much directed at yourself, but at the ignorant masses (you know, the ones who so seemed to like my post...)
Drizek said. "developers shouldnt have to jump through hoops to get their apps to work with it.
They don't have to "jump through any hoops". They should just not do stuff that they would not be allowed to do on a Unix system either. See, the difference is that Unix developers understand security, whereas many Windows developers do not seem to have progressed beyond an understanding of DOS' security model... If a developer is stupid and/or lazy enough to store per-user settings in HKLM, and store program configuration files in the installation directory, rather than doing these things in HKCU or the user's Documents and Settings tree, they should be run out of business.
Boot into safe mode, log in as the administrator, and set the permissions you want. You might want to google the subject if you need more help.
is your friendDoc Said: "I do agree with you..."
I was hoping that you would not misunderstand my comments; from other posts of yours that I have seen I had the impression that you generally know what you are talking about, so my comments were not so much directed at yourself, but at the ignorant masses (you know, the ones who so seemed to like my post...)
Drizek said. "developers shouldnt have to jump through hoops to get their apps to work with it.
They don't have to "jump through any hoops". They should just not do stuff that they would not be allowed to do on a Unix system either. See, the difference is that Unix developers understand security, whereas many Windows developers do not seem to have progressed beyond an understanding of DOS' security model... If a developer is stupid and/or lazy enough to store per-user settings in HKLM, and store program configuration files in the installation directory, rather than doing these things in HKCU or the user's Documents and Settings tree, they should be run out of business.
post #20 of 41
12/20/05 at 6:04pm
- Doc.Caliban
- 0
- The Man of Bronze
- offline
- Joined: 1/2005
- Location: Caribbean 17°37'52.47"N 63°14'00.51"W
- Posts: 1,884
- Select All Posts By This User
Quote:
|
Originally Posted by Pirx
Doc Said: "I do agree with you..."
I was hoping that you would not misunderstand my comments; from other posts of yours that I have seen I had the impression that you generally know what you are talking about |
-Doc
Return Home
Back to Forum: Dell Home (Inspiron, XPS, Studio)
- Run as Non-Admin ?
NotebookForums.com › Forums › Notebook Manufacturers › Dell Forums › Dell Home (Inspiron, XPS, Studio) › Run as Non-Admin ?
Currently, there are 173 Active Users
(3 Members and 170 Guests)
Recent Discussions
- › Where minds meet 58 minutes ago
- › DIAMOND WR300NSI 300Mbps 802.11n Wireless Repeater Range Extender 2 hours, 57 minutes ago
- › Problem Aspire 8920G goes on and off with power supply 3 hours, 2 minutes ago
- › HP ENVY Rove20 mobile All-in-One PC 3 hours, 20 minutes ago
- › X501U Downgrading Windows 8 to Windows 7 4 hours, 9 minutes ago
- › Aiseesoft MXF Converter (for Win and Mac) 4 hours, 15 minutes ago
- › Cool (at times) Free Mac Software 4 hours, 15 minutes ago
- › For freewares hunters 4 hours, 16 minutes ago
- › Minor Touch issues with S500C 5 hours, 45 minutes ago
- › Cool (maybe) and Free Android Apps 14 hours, 28 minutes ago
View: New Posts | All Discussions
Recent Reviews
- › Lenovo Yoga 13 IdeaPad Convertbale Ultrabook (tablet) 13.3"... by The Bard sRc
- › Alienware M18X by MrFox
- › Kensington Black Contour Pro 17" Notebook Carrying Case Model... by great white
- › Lenovo W530-24382LU i7-3720QM 2.60GHz 4GB 500GB 7200rpm NVIDIA... by Djembe
- › Kingston 8GB (2 x 4GB) 204-Pin DDR3 SO-DIMM DDR3 1333 Laptop Memory by Nicadraus
- › Synology DiskStation 1-Bay (Diskless) Network Attached Storage... by Mr T
- › Barnes & Noble Nook Color by sewshoplady
- › Cooler Master CM Storm Spawn 3500 DPI Optical Sensor Gaming Mouse... by Rotterdamblues
- › Samsung MV-3T4G4 4GB DDR3 Laptop SDRAM (1333MHz PC3-10600) by Rotterdamblues
- › Alienware Aurora m9700 by amythompson172
View: More Reviews
New Articles
- › Intel Summer 2012 SSD Scavenger Hunt - Full... by ranjanis
- › Intel's Maple Crest 330 Series Promotion... by ranjanis
- › Intel Cherryville SSD Spring 2012 Giveaway by ranjanis
- › Intel Cherryville SSD Giveaway 2012 - Terms... by ranjanis
- › Advertise by jdz2287
- › Search And Advanced Search Tutorial by NotebookForums
- › Tagging Tutorial by NotebookForums
- › Add A New Item Tutorial by NotebookForums
- › Image And Video Tutorial by NotebookForums
- › Subscription Tutorial by NotebookForums
View: New Articles | All Articles
Home | Reviews | Forums | Articles | My Profile
About NotebookForums.com | Join the Community | Advertise
© 2013 NotebookForums.com is powered by Huddler Tech | FAQ | Support | Privacy/TOS | Site Map
About NotebookForums.com | Join the Community | Advertise
© 2013 NotebookForums.com is powered by Huddler Tech | FAQ | Support | Privacy/TOS | Site Map




