LegitPC Desktop Config

I don't see the issue with apps that are on my system using admin rights. I put the apps there in the first place, even if UAC was enabled I would press yes to the prompt. Which brings me to the reality of the situation: everything will stay the same but I will have to go through a popup when I launch some apps.

Same thing for smartscreen and stuff like WOT, it is useful for people who do not have enough information to make their own conclusion. I know what I am downloading and running, the only risk I see is if a developer's site gets compromised and I download a hacked executable. It might still be signed though, so smartscreen wouldn't do anything in such a situation.

These are useful tools and I absolutely suggest that most people use them, but its like the Dynamic Stability Control on my car - I turn it off when I want to turn corners.

Thread is going into "broken record" mode. Spamming "enable UAC" won't get him to enable UAC. He's explained his reasoning above. He believes that because he only has self-approved software installed on his PC and he doesn't download anything he isn't 100% sure about, he can do without UAC. There are already great explanations in the thread for why he should enable UAC, should he change his mind.
 
It seems you don't want to enable UAC or smartscreen, may I ask why? I don't see a downside.
Clicking YES to a prompt multiple times a day 365 days a year is the downside. I have literally never clicked No to a UAC prompt it is useless for me.

Also I'm not sure that UAC is even off. In registry EnableLUA=1 and on UAC settings it is set to Never Notify. There's no thread field that matches those settings.
 
  • Like
Reactions: askmark and frogboy
There's no reason to be so negative about this whole thing we're not fighting this is for benefit not for insult.
@Umbra expresses himself very flamboyantly. He doesn't mean to be offensive...

About spyshelter: even if it does protect against process hollowing (although it probably does not have this capability on x64), the pop-up you will see will be very non-alarming, and you will probably click on okay. You just can't tell from HIPS pop-ups whether the action is legit or not. So during installation of an app, they won't help you decide.
They will help you if they come out of the blue, when nothing special was supposed to be happening on your system.
 
Clicking YES to a prompt multiple times a day 365 days a year is the downside. I have literally never clicked No to a UAC prompt it is useless for me.

Not worse than clicking a prompt from a BB or an HIPS. Personally, i put it at max and i'm under a SUA , i tweaked it to ask my Pin instead of "yes/no" and i get maybe max 5 prompts a day max; i don't spend my day using apps or options that needs elevation.

You want less prompts create an Standard User Accounts, since most of your actions will run i low/medium-level integrity, only admin tasks will generate prompts.

example : portable CCleaner

in SUA : no UAC prompts, run in medium Integrity Level
in Admin Account: Generate UAC prompt , run as High Integrity level , riskier than above.

Anyway running in SUA is far safer than on Admin Account. files/folder and the registry will be virtualized.

read this : https://malwaretips.com/threads/protecting-system-files-with-uac-virtualization.57722/

About the tweak you mentioned i have no idea , because i don't need it. and im way more safer than in Admin Account.
 
Enough already. :)
He's sticking to his guns. No need to persuade him, as he has his own reasons, good or bad they may be. Just respect his decision. He may or may not change that in the future. :)
Let him use his PC with UAC=Off (Never Notify).

The thread title is enough to discourage other members from following his config. :)
 
Clicking YES to a prompt multiple times a day 365 days a year is the downside. I have literally never clicked No to a UAC prompt it is useless for me.

Also I'm not sure that UAC is even off. In registry EnableLUA=1 and on UAC settings it is set to Never Notify. There's no thread field that matches those settings.
That doesn't explain the smartscreen though
 
That doesn't explain the smartscreen though
smartscreen was off initially for privacy reasons during windows setup, after researching it I turned it on in post #14. so far it has not annoyed me.

Not worse than clicking a prompt from a BB or an HIPS.
I can set a rule in HIPS and never have to answer the same prompt but UAC pops up over and over.
 
  • Like
Reactions: _CyberGhosT_
smartscreen was off initially for privacy reasons during windows setup, after researching it I turned it on in post #14. so far it has not annoyed me.


I can set a rule in HIPS and never have to answer the same prompt but UAC pops up over and over.
Ok, turn it off and play with VS free and see what you think, whats the harm ? Hell you might even thank me later.

As far as Umbra goes, he is passionate about security, and knows his stuff. I have had the pleasure of hanging out with
him here on the site and in the voice server and I must say he is a class act so don't read too much into his replies.
He is well respected and known in some very good circles, but hey the call is yours brother ;)
 
You cannot please people from the first place, since UAC by its vague concept may not be useful, however through straightforward answers on technical terms then the benefits have been shown clearly.
 
  • Like
Reactions: askmark and XhenEd
UAC is back off. Patience ran thin, even after altering multiple shortcuts to run as elevated via service my workflow and thought was still being interrupted by pesky UAC. It is gone now. Good riddance.