The Rough Edges

The first thing that bothers us is a technical matter, and that is the addition of various levels of UAC , and the security ramifications of that. We’ve talked about this before in our look at the release candidate, but it bears repeating.

With the changes made to Windows 7, at the default UAC level of 2, signed Microsoft executables are auto-elevated to admin privileges when run by an admin. This primarily manifests itself in the Control Panel, where most of the panels are allowed to auto-elevate so that users may make changes without facing a UAC prompt.

There’s certainly a benefit to this in terms of user interaction, since the Control Panel and installing software are the two most common admin-level tasks a user will do. The latter is a repeating occurrence, but the former is something that usually only happens once when the computer is set up. So by making this change, the new-user experience involves less UAC.


The UAC Control Panel With Level Slider

It’s the security ramifications of this that concern us. Someone already managed to exploit this in the pre-RC phase (where the UAC control panel itself was auto-elevating) to disable UAC entirely. The concern we have is that all of these auto-elevating programs are an obvious target for a local privilege escalation attack to accomplish something similar, if not the same. Imagine finding a way to make the Display control panel execute a 3rd party application with admin privileges, for example.

Now to be clear, it’s not as if this is the only way to achieve local privilege escalation attacks. The Windows kernel itself is a target, and I can’t think of any major desktop OSes that haven’t seen such an attack in the past. But this makes that easier, potentially much easier. And that’s a risky proposition when a UAC prompt may be all that’s left between malware executing and running amok or not.

Certainly someone is going to bite my head off for this, but I don’t think Microsoft should have made such a fundamental change to UAC. More casual users may not have been fond of how Vista or UAC Level 3 handle security, but it was a more secure choice than Level 2. To that end, I certainly wouldn’t recommend running Win7 at the default UAC level for any computer connected to the internet.

On a lighter note, even after using the release version of Win7 for 2 months now, I’m still wondering who thought it was a good idea to make the title bar of maximized windows semi-transparent. Certainly for windowed windows it makes some sense, as you can see what’s underneath. But for maximized windows? If I was concerned for what was under the window, why would I have it maximized?

Finally there’s Windows Mail, or rather the lack of it. Obviously email clients have come under diminished importance in the last few years as web-based email (e.g. Gmail) continues to rise in popularity, but this doesn’t mean that an email client is not necessary.  And I get that Microsoft wants to separate the email client from the operating system so that they can push out major client updates outside of major OS releases.


  Windows Mail: Have you seen me?

But what I don’t get is why there’s any reason good enough for Windows to not come with an email client at all. It’s 2009, why is there an operating system being released without an email client? I only hope that OEMs are adding email clients to their prebuilt computers, otherwise there may be some very confused Windows 7 users as people start snapping up new machines.

The Only 3 Editions You’ll Care About Test Setup
Comments Locked

207 Comments

View All Comments

  • Tewt - Monday, November 2, 2009 - link

    Toms pretty much had the same conclusion as Anandtech. Here is a quote from their conclusion:

    "From the benchmarker’s standpoint, the change from Windows Vista to Windows 7 is simply a matter of documentation."

    I wish someone would quantify the "snappy" feeling or the "it feels faster" they get from Windows 7 because I'm not seeing a compelling reason to move from Vista from either article on the two sites.
  • werfu - Monday, October 26, 2009 - link

    I absolutely love Win7. I've installed the RC on my Thinkpad T61p and it's a real pleasure to use it compared to Vista. It's more responsive, not like Vista sluggish experience. However, the ACPI driver for the T61p don't work right. The screen doesn't dim and power management don't work right. I think that's really odd, as it's been working right under Vista and Linux.

    Also, I wonder if the NAS test was done using a Large Packet enabled NAS. It do make a huge difference on networking gear that support it.
  • strikeback03 - Monday, October 26, 2009 - link

    Have you checked for updated drivers recently? Lenovo had a bunch of Win7 drivers for my T43 which were all dated within the past week.
  • 7Enigma - Monday, October 26, 2009 - link

    Did you happen to do any benchmarking or "general user responsiveness" when you upgraded the systems? I have upgraded 3 systems since Windows 95 and in every case I ended up reformatting and doing a clean install; not because of a hardware/software issue, but rather because some unknown demon made the systems chug.

    I've seen this same issue with the move from XP SP2 to SP3 on my dad's computer (in this case to the point where we actually rolled back to SP2). In that instance it is possible the extra security features/etc. on an older system that just couldn't take it, but in the other instances it seemed to be a major problem.

    Any comments by the authors would be greatly appreciated.
  • Ryan Smith - Monday, October 26, 2009 - link

    One of the systems that I did the upgrade install on was my personal system. I'm not going to publish any numbers since they aren't rigorous enough, but before and after testing didn't reveal any differences in performance. It continues to perform just as well as any other Win7 system I have.
  • 7Enigma - Tuesday, October 27, 2009 - link

    Thank you for the response Ryan. Honestly while the articles are fantastic, it is the timely comments from the authors that make this site the best.
  • Postoasted - Monday, October 26, 2009 - link

    Had been using XP64 for about 4 years and lived through all its teething problems. Had been totally satisfied except that with some programs it couldn't regulate the RAM efficiently. I have 6 gigs of RAM and would ofter run out while using some apps. With 7 Ultimate I can watch an H264 movie, have FF open and encode a movie all at the same time and have RAM left over. For me Windows 7 was the fix.
  • nafhan - Monday, October 26, 2009 - link

    I'll go out on a limb and say that anyone who feels comfortable configuring POP3/SMTP settings would also be comfortable downloading the free mail client from MS (or Thunderbird, etc.). Businesses will likely have MS Office installed (including Outlook). Non-technical users generally use webmail.

    So, the only group I can come up with who would want it installed by default is tech-savvy users without Office, that prefer MS's free desktop client over webmail, and don't have admin rights to install it themselves or access to IT support to install it for them.
  • jay401 - Monday, October 26, 2009 - link

    Gary - Whatever happened to the P55 motherboard reviews and round-up articles you mentioned last month? Are they still on the way? I think we've seen 3 or 4 P55 motherboards reviewed so far at Anandtech. Are you still going to review the others?

    It's not so much the performance that's important or unknown, since they're all relatively similar. It's the technical specs comparisons, the board layout images and commentary, any issues you experienced while testing with them, etc. Would love to see the round-ups.
  • Gary Key - Monday, October 26, 2009 - link

    They are coming shortly. We went back and purchased 8 retail boards to do additional testing on the Foxconn socket compared to the Lotes/Tyco Amp. I have finished that testing and guess what, no changes on air or water, plus it appears the revised Foxconn socket is certainly working better, not perfect, but much better.

Log in

Don't have an account? Sign up now