February 2007

Sun Mon Tue Wed Thu Fri Sat
        1 2 3
4 5 6 7 8 9 10
11 12 13 14 15 16 17
18 19 20 21 22 23 24
25 26 27 28      
Blog powered by TypePad

« MSDN Wiki | Main | Videos from Lang.NET 2006 »

Windows Integrity Control

This posting does a good job explaining the new feature, but here's a quick summary.

In addition to the normal ACL security checks that we've come to know and love, Vista has added a new layer called integrity control. Effectively, every ACL controlled item (you, files, folders, processes, threads, registry keys, etc.) now has an integrity level of one of the following: low, medium, high or system.

So, a process running at low integrity (IE7 uses this in it's protected mode) doesn't have access to anything marked above that (e.g., the user's files). This is why IE7 items downloaded from the internet (which run in low integrity) can only access special temp folders and not your documents.

Unlike the UAC aspects of Vista, which are hard to miss, this new layer is going to be mostly hidden to everyone except the hackers - it primarily blocks standard attack routes into Windows. However, if you do experience an issue with it, or know of software that is going to have problems, please feel free to post it here - or better yet, let Steve Riley know!

TrackBack

TrackBack URL for this entry:
http://www.typepad.com/services/trackback/6a00d83424ed4953ef00d835099def53ef

Listed below are links to weblogs that reference Windows Integrity Control:

Comments

Verify your Comment

Previewing your Comment

This is only a preview. Your comment has not yet been posted.

Working...
Your comment could not be posted. Error type:
Your comment has been posted. Post another comment

The letters and numbers you entered did not match the image. Please try again.

As a final step before posting your comment, enter the letters and numbers you see in the image below. This prevents automated programs from posting comments.

Having trouble reading this image? View an alternate.

Working...

Post a comment