Page 1 of 1

Secure Erase doesn't work with elevated Admin credentials

Posted: Sat Jul 24, 2010 2:10 pm
by Bikr
I've started to follow the security principle of least privilege, so I made my daily Windows 7 login account, a standard user (as opposed to administrator). So far the rest of Ace Utilities runs fine, as I use "Run as Administrator" when I launch AU from the Start menu (although I didn't like the fact that I had to re-do all my AU settings for the Admin credentials...but that was just a one-time annoyance).

But Secure Erase doesn't seem to work properly in this setup. If I right-click a file in Windows Explorer and choose Secure Erase, I get the Confirm Wipe dialog. When I choose Yes (with the administrator icon next to it), I get the Windows User Account Control (UAC) dialog asking for my admin password. When I correctly enter my admin password, the dialog goes away but the file isn't deleted!

Interestingly, I can delete the file and do a Wipe Recycle Bin, which then warns me that "This program should be run by a user with administrator privileges." But then it proceeds without a UAC prompt, it still works!?

Secure Erase works perfectly when I'm fully logged in as administrator. So it seems Secure Erase isn't properly elevating the credentials when logged in as a standard user even with the UAC prompt.

I'm running Windows 7 Ultimate 64-bit and Ace Utilities 5.2.3 64-bit. Let me know if you need more details.

Re: Secure Erase doesn't work with elevated Admin credential

Posted: Sat Jul 24, 2010 6:36 pm
by Aneesh
Yes, there's an issue using 'Secure erase' shell call in an non-administrative account, it seems. :-\ You need to do the erasing process through Ace Utilities > Protect > Securely Delete Files.