Microsoft: WGA to Require Revalidation
By David Worthington | Published May 24, 2005, 8:20 PM
A mechanism used by Microsoft to validate genuine copies of Windows and weed out counterfeiters has been bypassed, but Microsoft says the method is ineffective due to required revalidation and expiring keys.
Security researcher Debasis Mohanty produced a proof of concept technique that circumvents Microsoft's Windows Genuine Advantage (WGA) piracy check by using an alternate tool provided by Microsoft for customers without ActiveX support in their Web browsers.
Mohanty, a security researcher based out of India, contributed his findings to the Full Disclosure security mailing list on Monday. Using a secondary validation program called "GenuineCheck.exe," unscrupulous users may generate legitimate product keys to validate Windows installations.
But the technique is far from fool proof and Microsoft appeared to be unfazed, telling BetaNews that the keys generated by GenuineCheck expire quickly and that the system will check to revalidate on a regular basis.
This means that even if a reseller sold a machine after doing this, the end user will still be prompted to re-enter a key when they attempt to download more content. "We have no plans to make any changes based on the concept's lack of scalability and the keys expiring rapidly," a Microsoft spokesperson said.
Windows Genuine Advantage is a carrot and stick approach toward reducing counterfeiting that requires users to validate their Windows license in exchange for special perks at the Microsoft Download Center, such as Windows AntiSpyware, and full access to updates from Windows Update. Microsoft asserts that WGA protects customers by ensuring the security and integrity of Windows installations, and also protects resellers by reducing the number of competitors that practice counterfeiting.
The program was initially opt-in in, but Microsoft will make WGA mandatory in the United States this summer. Other markets will follow suit.
Microsoft is compensating customers that come forward and report counterfeited copies of Windows with genuine copies of Windows or a value price product key. For more details on WGA, see the extensive BetaNews interview with David Lazar, Director of Genuine Windows at Microsoft.
Just buy a valid copy and quit whining you fricken thieves.
Score: 0
|I do own a legit copy. What pisses me off is the fact that I have to go through this crap for my valid copy.
I reload XP on a different box at my house because I got rid of my old box. I had to call their stupid center on the phone and activate it.
What a joke. They make it harder for their regular customers and people still pirate it. It makes me (a paying customer) want to pirate it so I don't have to deal with the BS. It also makes me want to consider an Apple computer and also Linux.
Microsoft is a joke.
Score: 0
|Exactly--I have a legitimate copy (I'm assuming HP doesn't pirate...), and this is a pain to go through for a simple download from Microsoft's website, especially since I don't use Internet Explorer. This tool has actually failed on my several times.
Score: 0
|How about pirated Office ?
Microsoft need to work on this software too. and if possible to lock the pirated even when they did not want to download updates.
need an idea?
Score: 0
|BetaNews, this article is crediting the wrong person for the discovery. This was discovered by me, if you read the rest of the Full Disclosure list you would see there was an argument over who did actually discover and publish it first and I came out with the credit. Please update your story.
Score: 0
|Your an idiot!
Score: 0
|we have to validate windows to install it, then have to pass it through WGA, and THEN have to revalidate? whats next? we have to use some sort of retinal scanner, submit a blood sample, a urine sample, pass a drug test, show proof of identiry and sign away our 1st born?
Makes me glad I am surfing the web using a linux based system. I bought the cde's, ran the install and away I went. no jumping through hoops, bending over backwards, or getting a** r**ed
Score: 0
|http://www.ubuntulinux.org/shipit/link_view
Don't even have to pay for shipping to get Linux CD's these days. :-) My shipment arrived the other day, and I've handed nearly all of them out.
Score: 0
|Send me one FEWT. :-)
EDIT: I signed up too. That is cool. They didn't tell you anything about the make but we will see.
Score: 0
|They come in professional paper jewel cases with both an install cd and a live cd within. It's very well done, and I think Breezy will be even better.
Check this out
http://www.paul.sladen.org/lugradio-shuttleworth/
Score: 0
|Up an iso of one so i don't have to wait 6 weeks.
Score: 0
|http://us.releases.ubuntu.com/releases/5.04/
Score: 0
|Who cares about the WGA? There are several Windows XP keygens that can generate a valid working key, that is happily accepted by the GenuineCheck. I actually tested this - instead of my "legal" key I used keygen. Verified Windows, all WGA things work etc etc.
This is yet another stupid check that drives legal users away but doesn't even hinder pirates. Just lower the price of Windows XP to a reasonable level and piracy will go down 90%. You cannot expect an 3rd world user with a montly pay of $100 or less to cough up that money for operation system.
Score: 0
|You deserve to use Linux Get a clue!
Score: 0
|I agree completely. After living in a country where your monthly pay is 150 a month, piracy is the only option for those people. That is why the DOS days were so good =), not that I would go back =)
Score: 0
|how does someone earning 150 dollars a month buy a computer in the 1st place. i agree that microsoft do overcharge for thier operating system, i know that linux is next to if not free.
but for some ppl linux is not a viable option solely because of the dominating position of windows based systems and most software commercialy released is for the windows enviroment. linux is still not particularly user friendly. however much ppl berate microsoft, they are one of the main reason that hardware is as cheap as it these days. without windows the pc would never have become a mass market domestic commodity. however i think microsoft are guilty of abusing what amounts to a near monopoly.
Score: 0
|Just don't try asking any questions at the Ubuntu forums unless you're prepared to be called all the names under the sun, when you're trying to install a simple something under Ubuntu or (for that matter) anything else Linux. I know, I've been there, and have neither the time nor the patience to want go back and be abused in that manner by mean spirited, unpleasant people.
They're not all bad, but don't say I didn't warn you.
Score: 0
|Huh? Do you have a thread we can follow to validate that claim?
Score: 0
|with a remark like that you desserve windows. it is made for the ignorant.
Yes, I do deserve linux. I am an intelligent person who asks questions and has a modicum of computer literacy. I am a person who isnt lazy and likes the idea that I can compile my programs to run optimally for my specific computer. I am a person wh looks for gutz, not glitz. Lastly, I am a person who doesn't appreciate being told I have to pay for something, then to use it I have to do this, that and the other thing, and get Bill gate's seal of approval to be a gates lackey.
so yes, I deserve linux. because I have a brain.
Score: 0
|Lol, too true.
Score: 0
|