Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Users dislike it on Windows because requesting elevated privileges became so common that they rationally chose to tune out. Had Windows been designed from the start with UAC, developers would have been less cavalier in requiring administrator abilities, then maybe a UAC request might actually have meant something. Given that so many legacy games request privilege authorization, it's no wonder the users don't take it seriously.

Look at the mobile platforms for an example of implementing this idea correctly. Android users, the same who are likely to detest UAC, rave about the ability to see which parts of the system an application accesses before they install it. I'm an iPhone user, and I've always appreciated its piecemeal approach to authorizing location and notification services.

Zach's article is about making the message more meaningful, such that it's not just another automatic clickthrough. My guess is that users would much prefer this screen to what twitter is using now.



> "Had Windows been designed from the start with UAC, developers would have been less cavalier in requiring administrator abilities"

Android and the Android Marketplace appear to contradict that theory.


Your point about Android is half correct, yes I like seeing what the app needs to access, but I don't see why. Why does your calculator app need access to the internet? I know the author can just offer some bullshit excuse, but it's better than nothing...


I would very much like the checkboxes in Android too, although obviously they'd place a greater burden on developers. For example, I tried installing the official XBMC remote app a while back; it requested all sorts of crazy permissions ("read SMS" etc) which they were intending to use for debatably useful features but I ended up not installing it because of the privacy concerns. In the end I installed a third-party remote app which didn't ring as many alarm bells on installation, but I'd have been happier to stick with the 'official' one if I could selectively disable some of the permissions they wanted.

I can certainly see why that isn't an option; it'd make things much harder for developers if they suddenly have to test against different sets of security permissions. But it's on my wishlist.


XBMC remote needs that because it has a "show your texts on the TV" feature which you really, really shouldn't turn on. Trust me.

It's a shame that you can't pick and choose, as a user, because they can't remove that permission without breaking that feature for everyone [who?] that uses it. It's open-source though, so the good news is you could remove that permission and feature yourself if you really want it (you should: it's pretty nifty).


Oh, no, I don't need checkboxes (I realise it would make development hard). I only need a justification under each permission to see if the app has a good reason to want to read my texts, but I'm quite happy denying it as a whole.


They need access to the internet so they can dynamically fetch the ads they are going to show you which is where they get their money from.

This has the advantage of generally being true, and being unobjectionable enough that most people will grant access.


That was an example, though.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: