George56 Posted November 16, 2013 Report Share Posted November 16, 2013 I think I have discovered a serious security bug in Windows 8.1. Today I was using my (non-Admin) user account and with Internet Explorer I saved a file in the default Downloads folder (under This PC). The file was saved, but when I went to that folder, the file was not there! Now, I was about to download it again, using IE, same as before, when I noticed in the Save dialog box that the file had indeed been downloaded, and that it was there, in the Downloads folder under This PC. Frustrated, I went to that very folder, but the file was nowhere to be found. I was really puzzled. Then, by chance, while logged in another account (namely the Admin account), I happened to go to the Downloads folder, and there was the file that I had downloaded using the other account. Obviously, what I described above represents a security problem: firstly because my private files may get saved by mistake into another person's account without me even realizing it, and secondly because I was able to access another person account (i.e. the Admin account) via the IE's Save dialog box, seeing the list of the files there, and possibly even accessing them (I have not tried the latter, though). Has anyone experienced anything like the situation I described? I must also say that I later tried to replicate this abnormal behavior, but for some unknown reason I couldn't. Quote Link to comment Share on other sites More sharing options...
ɹəuəllıʍ ʇɐb Posted November 17, 2013 Report Share Posted November 17, 2013 There is no such thing as a file not being there when it's actually there. This means you are not seeing the file that is there, possibly due to your Windows Explorer settings. Quote Link to comment Share on other sites More sharing options...
George56 Posted November 17, 2013 Author Report Share Posted November 17, 2013 You did not understand what I said. The file was shown to be there, but in the Downloads folder of the Admin account, where is was saved. The place where I was looking for it, but could not find it, was the Downloads folders of the current account, where I assumed it had been saved.So, the point is that unbeknown to me the file had been saved into another account. And this is a security problem. Quote Link to comment Share on other sites More sharing options...
ɹəuəllıʍ ʇɐb Posted November 18, 2013 Report Share Posted November 18, 2013 Ok, I understand now. What is your Internet Explorer's default save location (for that non-admin user)? Quote Link to comment Share on other sites More sharing options...
George56 Posted November 18, 2013 Author Report Share Posted November 18, 2013 It's the Downloads folder, for both the Admin and the non-Admin account. And I did save into the Downloads folder, only into the Downloads folder of the Admin account, instead of that of the current (non-Admin) account. Quote Link to comment Share on other sites More sharing options...
ɹəuəllıʍ ʇɐb Posted November 19, 2013 Report Share Posted November 19, 2013 Well, it seems that you have found yet another reason to stay away from Windows 8.x Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.