Software Review The biggest risk with Windows: LOLBINS

Reviews reflect the reviewer's setup and methods. Check the evidence and limitations.
Thread details
Content created by
PC Security Channel
Standar user account is offered by MS to limit the ability of inexperienced users to make changes to settings, while keeping this right to those who know (Admin account).

Of course it might limit post-execution damage, but this is not its main use, otherwise MS would make it the default account on Windows install to keep its OS secure.

@Shadowra can tell how many samples were blocked using SUA compared to Admin account (repeat the test one time for each type of accounts).
What you are stating is absolutely not correct.

Shadowra is an amateur, non-professional YouTube tester. He is not a subject matter expert (SME) on Windows or Microsoft.
 
SUA is still estimated today to reduce risk by 80–95%, especially combined with other mitigations.

Microsoft prioritizes convenience over security on the whole. This is perfectly exemplified by the default setting for UAC, which was lowered following its implementation in Vista: "Notify me only when apps try to make changes to my computer."

Microsoft's rationale for the relatively weak default setting and variety of ways to bypass it is that UAC is not a security boundary.
Microsoft does it because it ships a SINGLE Windows image that contains all the Edition, Version, and Features in a single ISO or image.

Microsoft intends that any user configure their system and then always use a "Guest" (SUA) account unless the Administrator is required for administration.

Microsoft NEVER intended to provide an OS that users can willy-nilly do whatever they want.

Microsoft prioritizes user knowledge and responsibility. That is 100% on the user to figure it all out and to work with their system and behave safely.
 
You can lock down a system with SUA. But beware of attacks targeting services. Services run with high privileges, and some are toned down. But if an attack on a service succeeds, it can give you a hell of a mess. Don't give me the excuse that it doesn't happen nowadays. I disable services I don't need. I do it my way, you go try your luck. And I can't prove it because I don't have a black belt in forensics,
SUA's purpose is not to protect the user, data, or system 100%.

Exploits and attacks happen on SUA the same as they do on a Administrator account. The difference is that the path to pwn is much shorter and faster in a privileged account.

Everybody should be using a SUA for 99.9% of their system use.
 
The fact that installing a random software usually requires administrator privileges is the greatest Windows design security flaw.
UAC was supposed to protect the system. Instead, Windows conditioned users to blindly approve elevation just to do normal tasks.
That’s not a user failure, that’s a design failure. A security system that depends on users not being annoyed is already broken.
No. It is a user flaw.

UAC was never intended to protect ANY Windows system.

UAC "not working" is 100% a user failure and not a UAC nor Microsoft failure.
 
I see your point, but the main issue relies: Windows has a poor security design.

UAC isn’t just “friction”, it’s a gateway to a flat trust model. Once elevated, a process doesn’t merely do the one thing the user intended, it inherits broad, ambient authority over:

-system-wide services
-shared registries
-COM objects
-named pipes
-IPC channels
-user and system processes

At that point, Windows isn’t asking “did you initiate this?”, it’s implicitly saying “everything this process touches is now trusted.”

That’s not human error; that’s overprivileged design.
Microsoft Windows has extremely robust security. To accomplish that the user must configure it.

It is the user's responsibility to know all of it and then implement it.
 
Microsoft is responsible for catering to a very large public.
Microsoft does not cater to a very large public. It never has and it never will. The way that Microsoft does things are to maximize efficiency and profit. Then it does everything it can to minimize headaches caused by users.

Microsoft's Terms of Service put everything 100% onto the user.
 
For experienced users, like you, they make very little difference.
I know how to defend, and heap on defense layers. But I believe every little bit of security counts. As Divergent says :
It fails to write to HKLM. It fails to drop the DLL into System32. It fails to register the Service.
There a lots of prevention going on when you are a standard user. Then you can home in on the weak spots of your defense. But forensics, I believe, is what can help me progress.
 
The issues you described, software not appearing, shortcuts missing, are not flaws in the security model. They are flaws in your installation methodology.

When you run an installer as Administrator, many legacy or poorly coded setup wizards default to installing for "Current User Only" (%AppData% or C:\Users\Admin).

You install it as Admin. The files go into the Admin's profile. Then you log in as Standard User.
The Standard User cannot see the Admin's desktop, cannot read the Admin's AppData, and therefore sees "broken" software.

Competent sysadmins select "Install for All Users" (writing to C:\Program Files and C:\Users\Public). If the installer doesn't offer that, it is garbage software, but you can still manually move the shortcuts to C:\ProgramData\Microsoft\Windows\Start Menu.

You mentioned the program wouldn't run. This is almost exclusively caused by developers who are stuck in 1998.

Proper software writes binaries to Program Files (Read-Only for Users) and configuration/save data to Documents or AppData (Writable for Users).

Bad software tries to save your settings directly into C:\Program Files. The OS blocks this because users should not be modifying application binaries.

You do not need to make the user an Admin to fix this. You simply find that specific folder, Right Click -> Properties -> Security, and grant "Modify" rights to the Users group for that one folder.

You have opened a tiny window in the house, rather than removing the front door entirely.

Calling the Standard User model "lipstick on a pig" is a confession of defeat.

Fortune 500 companies, military networks, and banks run millions of PCs on Standard User accounts. The software works because their IT staff knows how to configure Access Control Lists (ACLs).

The Diagnosis: The "trouble" you experienced was not the system failing, it was the system working exactly as designed, stopping a low-privileged user from accessing high-privilege data, and you lacking the knowledge to bridge the gap correctly.
I tried this too, and still had problems....

Blame me if you want, and I may be at fault, but someone is not making this very easy for the normal user, of which I am one... If MS wants to strongly suggest standard accounts then, I strongly suggest they make it achievable without jumping thru hoops

Competent sysadmins select "Install for All Users" (writing to C:\Program Files and C:\Users\Public). If the installer doesn't offer that, it is garbage software, but you can still manually move the shortcuts to C:\ProgramData\Microsoft\Windows\Start Menu.
 
Help them out a bit. Point out those options. I haven't touched Windows Home for many years so I can't do it.
@bazang I like that as well. Also, in a post not to long ago, you mentioned if you were to install F-Secure on a family (friends) PC, would would make a couple of Windows security changes, to help harden the system. What changes would those be as well, if not the same as to mitigate LOLBin abuse?
 
I tried this too, and still had problems....

Blame me if you want, and I may be at fault, but someone is not making this very easy for the normal user, of which I am one... If MS wants to strongly suggest standard accounts then, I strongly suggest they make it achievable without jumping thru hoops

Competent sysadmins select "Install for All Users" (writing to C:\Program Files and C:\Users\Public). If the installer doesn't offer that, it is garbage software, but you can still manually move the shortcuts to C:\ProgramData\Microsoft\Windows\Start Menu.
As a last-ditch effort, I made a clean install of windows and my fav software in an admin account. When I was all done, installing, updating ETC. I then tried to change the admin account to a SUA and this led me to having to create another Admin account (if memory serves me correctly) ... My theory was OK what If I install everything on this admin account and then change it to a user account, maybe all the shortcuts and software will work then? Nope.
 
As a last-ditch effort, I made a clean install of windows and my fav software in an admin account. When I was all done, installing, updating ETC. I then tried to change the admin account to a SUA and this led me to having to create another Admin account (if memory serves me correctly) ... My theory was OK what If I install everything on this admin account and then change it to a user account, maybe all the shortcuts and software will work then? Nope.
How is it possible that all your software broke?

Every major software vendor (Microsoft, Google, Adobe, Mozilla, Valve, Spotify) has designed their applications to run seamlessly under Standard User accounts for over 15 years.

If everything failed, you are either, exclusively using abandoned shareware from the Windows XP era that ignores all modern file hierarchy rules, lying about the scope of the failure, or you completely botched the migration.

My bet is on the latter. You likely didn't just "demote" the account, you probably created a new account or messed up the ownership of your user profile folder (C:\Users\<Name>).

If shortcuts disappeared and settings vanished, that isn't the software "breaking." That is you trying to access the private data of Admin_User from the profile of Standard_User.
 
I don’t know how to audit services or talk about hashes, but I do know I’d rather click through a UAC prompt than deal with a nasty surprise.
If most people agree that using a standard account lowers the risk, I’m fine with that. At the end of the day, it’s easier to put up with that little UAC pop‑up than to put up with malware.
For me, cheap prevention beats expensive recovery. And I try to add a few extra layers of protection, among other things.🥸
 
The fact that installing a random software usually requires administrator privileges is the greatest Windows design security flaw.
UAC was supposed to protect the system. Instead, Windows conditioned users to blindly approve elevation just to do normal tasks.
That’s not a user failure, that’s a design failure. A security system that depends on users not being annoyed is already broken.
From an UX you have got a point for users who have known Vista. UAC was so annoying it lost its meaning. The fix of M$ to weaken UAC in Windows7 and starting to require co-signing for drivers helped to reduce the UAC annoyance. Nowadays local admins running new Admin Protection feature with SAC should be fine when the use their PC as a tool (not many new installs), when they are using it as toy (most MT members are PC-hobbyist) it still throws prompts at you;
 
expensive recovery.
Recovery doesn't have to be expensive. Just do a fresh install and install all your software, staying offline if possible - it helps to know that tthe image is clean. Then use Hasleo to do a drive image. My Macrium can make an image of a 500GB drive resulting in a file of 25GB. Store that image on a portable hard drive. When you're in trouble, you just restore using that image - takes 10 mins. You then do a windows update and you are good to go. Add 20 mins more to restore your from your data backup (which you do regularly). Hashleo backup suite is free. And a portable 1TB hard drive is about $60. $10 for a USB stick to put Hashleo recovery software onto ( you boot this USB stick to do image recovery ) And there you have it - painless recovery in about 30 mins.
 
Last edited:
From an UX you have got a point for users who have known Vista. UAC was so annoying it lost its meaning. The fix of M$ to weaken UAC in Windows7 and starting to require co-signing for drivers helped to reduce the UAC annoyance. Nowadays local admins running new Admin Protection feature with SAC should be fine when the use their PC as a tool (not many new installs), when they are using it as toy (most MT members are PC-hobbyist) it still throws prompts at you;
How is it different from Linux? For example on Ubuntu id you open anything that requires admin privileges, you get a prompt requiring you to enter your admin password.
 

Recently browsing

Members who viewed this thread in the last 5 minutes

Back
Top