<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Short: Windows 7 (beta build 7022) white list loses one</title>
	<atom:link href="http://www.withinwindows.com/2009/02/13/short-windows-7-beta-build-7022-white-list-loses-one/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.withinwindows.com/2009/02/13/short-windows-7-beta-build-7022-white-list-loses-one/</link>
	<description>Not your usual Microsoft enthusiast blog.</description>
	<lastBuildDate>Tue, 07 Feb 2012 15:02:00 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Мурат</title>
		<link>http://www.withinwindows.com/2009/02/13/short-windows-7-beta-build-7022-white-list-loses-one/#comment-4804</link>
		<dc:creator>Мурат</dc:creator>
		<pubDate>Sun, 18 Oct 2009 09:43:24 +0000</pubDate>
		<guid isPermaLink="false">http://www.withinwindows.com/2009/02/13/short-windows-7-beta-build-7022-white-list-loses-one/#comment-4804</guid>
		<description>Народ в подобных случаях так говорит - Ах, ах, а пособить нечем. :)</description>
		<content:encoded><![CDATA[<p>Народ в подобных случаях так говорит &#8211; Ах, ах, а пособить нечем. :)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Kevin Nguyen</title>
		<link>http://www.withinwindows.com/2009/02/13/short-windows-7-beta-build-7022-white-list-loses-one/#comment-2547</link>
		<dc:creator>Kevin Nguyen</dc:creator>
		<pubDate>Sat, 28 Feb 2009 03:16:27 +0000</pubDate>
		<guid isPermaLink="false">http://www.withinwindows.com/2009/02/13/short-windows-7-beta-build-7022-white-list-loses-one/#comment-2547</guid>
		<description>Leo, it seems this issues is getting quieter every day. 

Has MS responded in anyway to the issues?</description>
		<content:encoded><![CDATA[<p>Leo, it seems this issues is getting quieter every day. </p>
<p>Has MS responded in anyway to the issues?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Leo Davidson</title>
		<link>http://www.withinwindows.com/2009/02/13/short-windows-7-beta-build-7022-white-list-loses-one/#comment-2501</link>
		<dc:creator>Leo Davidson</dc:creator>
		<pubDate>Wed, 18 Feb 2009 10:07:56 +0000</pubDate>
		<guid isPermaLink="false">http://www.withinwindows.com/2009/02/13/short-windows-7-beta-build-7022-white-list-loses-one/#comment-2501</guid>
		<description>werejag:

It&#039;s hard to say at this point. Build 7022 is the latest built to have leaked to the public but it&#039;s still an old build which pre-dates Rafael&#039;s Rundll32 (etc.) discovery.

Microsoft are not making it easy for others to check/verify what they are doing to improve upon the UAC issues. Rather than let us help them make something that&#039;s (more) secure, it feels like they want to ignore/dismiss the issues as much as possible and just go with what they&#039;ve got, with a few band-aids over the axe wound more for PR purposes than anything else.

They still have not bothered to even ask me for the full details of my code-injection exploit, despite my offer.

Sadly, it seems the PR band-aids are working so far on most people. My code-injection exploit hit The Register last Friday and straight away was met with people saying MS had already fixed it in the comments, ignorant of the fact it was a different issue which MS had said nothing about and of the fact that nobody has been able to validate exactly what MS have changed or fixed.

I imagine people&#039;s attitudes will change if the first release candidate comes out and there are still big holes in UAC. It&#039;s surely in Microsoft&#039;s interests to work with us now and avoid the bad PR of them saying they&#039;d fix something but turning out not to have done so (in any meaningful way). Unless they&#039;re just going to put their heads in the sand and try to dismiss the whole thing with illogical/contradictory arguments. (e.g. &quot;Local process elevation isn&#039;t important, but UAC prompts are still needed for third-party code, even though we&#039;re happy to allow them to be bypassed by malicious code.&quot;)</description>
		<content:encoded><![CDATA[<p>werejag:</p>
<p>It&#8217;s hard to say at this point. Build 7022 is the latest built to have leaked to the public but it&#8217;s still an old build which pre-dates Rafael&#8217;s Rundll32 (etc.) discovery.</p>
<p>Microsoft are not making it easy for others to check/verify what they are doing to improve upon the UAC issues. Rather than let us help them make something that&#8217;s (more) secure, it feels like they want to ignore/dismiss the issues as much as possible and just go with what they&#8217;ve got, with a few band-aids over the axe wound more for PR purposes than anything else.</p>
<p>They still have not bothered to even ask me for the full details of my code-injection exploit, despite my offer.</p>
<p>Sadly, it seems the PR band-aids are working so far on most people. My code-injection exploit hit The Register last Friday and straight away was met with people saying MS had already fixed it in the comments, ignorant of the fact it was a different issue which MS had said nothing about and of the fact that nobody has been able to validate exactly what MS have changed or fixed.</p>
<p>I imagine people&#8217;s attitudes will change if the first release candidate comes out and there are still big holes in UAC. It&#8217;s surely in Microsoft&#8217;s interests to work with us now and avoid the bad PR of them saying they&#8217;d fix something but turning out not to have done so (in any meaningful way). Unless they&#8217;re just going to put their heads in the sand and try to dismiss the whole thing with illogical/contradictory arguments. (e.g. &#8220;Local process elevation isn&#8217;t important, but UAC prompts are still needed for third-party code, even though we&#8217;re happy to allow them to be bypassed by malicious code.&#8221;)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: werejag</title>
		<link>http://www.withinwindows.com/2009/02/13/short-windows-7-beta-build-7022-white-list-loses-one/#comment-2498</link>
		<dc:creator>werejag</dc:creator>
		<pubDate>Tue, 17 Feb 2009 16:54:44 +0000</pubDate>
		<guid isPermaLink="false">http://www.withinwindows.com/2009/02/13/short-windows-7-beta-build-7022-white-list-loses-one/#comment-2498</guid>
		<description>so they really didnt do something becuase of rafeal&#039;s find</description>
		<content:encoded><![CDATA[<p>so they really didnt do something becuase of rafeal&#8217;s find</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dan</title>
		<link>http://www.withinwindows.com/2009/02/13/short-windows-7-beta-build-7022-white-list-loses-one/#comment-2497</link>
		<dc:creator>Dan</dc:creator>
		<pubDate>Mon, 16 Feb 2009 17:24:10 +0000</pubDate>
		<guid isPermaLink="false">http://www.withinwindows.com/2009/02/13/short-windows-7-beta-build-7022-white-list-loses-one/#comment-2497</guid>
		<description>wmpconfig is a helper app for WMP used to execute administrator commands.  It sounds like the ideal candidate for auto-elevation.

However it looks like it&#039;s only used to manipulate the network sharing service for WMP, and the DVD parental control level.  Such things wouldn&#039;t need to be done frequently so auto-elevation wouldn&#039;t be necessary...

http://msdn.microsoft.com/en-us/library/bb262178(VS.85).aspx</description>
		<content:encoded><![CDATA[<p>wmpconfig is a helper app for WMP used to execute administrator commands.  It sounds like the ideal candidate for auto-elevation.</p>
<p>However it looks like it&#8217;s only used to manipulate the network sharing service for WMP, and the DVD parental control level.  Such things wouldn&#8217;t need to be done frequently so auto-elevation wouldn&#8217;t be necessary&#8230;</p>
<p><a href="http://msdn.microsoft.com/en-us/library/bb262178(VS.85).aspx" rel="nofollow">http://msdn.microsoft.com/en-us/library/bb262178(VS.85).aspx</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rafael</title>
		<link>http://www.withinwindows.com/2009/02/13/short-windows-7-beta-build-7022-white-list-loses-one/#comment-2495</link>
		<dc:creator>Rafael</dc:creator>
		<pubDate>Sun, 15 Feb 2009 17:09:57 +0000</pubDate>
		<guid isPermaLink="false">http://www.withinwindows.com/2009/02/13/short-windows-7-beta-build-7022-white-list-loses-one/#comment-2495</guid>
		<description>If I knew guys, I would&#039;ve posted it! :)</description>
		<content:encoded><![CDATA[<p>If I knew guys, I would&#8217;ve posted it! :)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tommo</title>
		<link>http://www.withinwindows.com/2009/02/13/short-windows-7-beta-build-7022-white-list-loses-one/#comment-2494</link>
		<dc:creator>Tommo</dc:creator>
		<pubDate>Sun, 15 Feb 2009 17:08:59 +0000</pubDate>
		<guid isPermaLink="false">http://www.withinwindows.com/2009/02/13/short-windows-7-beta-build-7022-white-list-loses-one/#comment-2494</guid>
		<description>@werejag Excelent question, dear boy!

Soooooooooooo, Rafael? Anyone? ... Microsoft?</description>
		<content:encoded><![CDATA[<p>@werejag Excelent question, dear boy!</p>
<p>Soooooooooooo, Rafael? Anyone? &#8230; Microsoft?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: werejag</title>
		<link>http://www.withinwindows.com/2009/02/13/short-windows-7-beta-build-7022-white-list-loses-one/#comment-2487</link>
		<dc:creator>werejag</dc:creator>
		<pubDate>Sat, 14 Feb 2009 06:01:34 +0000</pubDate>
		<guid isPermaLink="false">http://www.withinwindows.com/2009/02/13/short-windows-7-beta-build-7022-white-list-loses-one/#comment-2487</guid>
		<description>why just that single exe</description>
		<content:encoded><![CDATA[<p>why just that single exe</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tom</title>
		<link>http://www.withinwindows.com/2009/02/13/short-windows-7-beta-build-7022-white-list-loses-one/#comment-2486</link>
		<dc:creator>Tom</dc:creator>
		<pubDate>Sat, 14 Feb 2009 03:24:12 +0000</pubDate>
		<guid isPermaLink="false">http://www.withinwindows.com/2009/02/13/short-windows-7-beta-build-7022-white-list-loses-one/#comment-2486</guid>
		<description>Good deal.</description>
		<content:encoded><![CDATA[<p>Good deal.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tommo</title>
		<link>http://www.withinwindows.com/2009/02/13/short-windows-7-beta-build-7022-white-list-loses-one/#comment-2484</link>
		<dc:creator>Tommo</dc:creator>
		<pubDate>Fri, 13 Feb 2009 11:51:57 +0000</pubDate>
		<guid isPermaLink="false">http://www.withinwindows.com/2009/02/13/short-windows-7-beta-build-7022-white-list-loses-one/#comment-2484</guid>
		<description>hehehe. yay.</description>
		<content:encoded><![CDATA[<p>hehehe. yay.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

