Ads by TechWords

See your link here
Receive the latest technology news and information.
Security
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
Cloud Computing
View all newsletters




Privacy Policy
 

Judge protects Microsoft's WGA secrets

Request granted to seal antipiracy SDK in 2006 lawsuit over WGA tool

October 16, 2008 12:00 PM ET

Active Comments
Anonymous says: Interestings, for Microsoft to do business it MUST hide everything.... Linux is open source, nothing to hide, makes nobody a...
Jake says: Microsoft Windows 7 is NOT binary compatabile with legacy software that your using in Windows XP. And should you want...


Computerworld - A federal judge has granted Microsoft Corp.'s request to keep secret the details of its Windows antipiracy technology after the company claimed hackers could exploit the information if it were made public.

U.S. District Court Judge Richard Jones last week granted Microsoft's motion that some documents be sealed in a two-year-old lawsuit that accuses the company of misleading customers when it updated its Windows Genuine Advantage (WGA) antipiracy software via its Windows Update service.

In a deposition filed with Jones three weeks ago, Alex Kochis, director of Microsoft's Genuine Windows group, said that revealing sensitive sections of the WGA software development kit (SDK) would give hackers a field day.

"Public release of the WGA SDK Integration Specifications information would allow hackers to defeat the WGA Validation function by causing WGA to generate false results indicating that the system being tested is genuine, thereby creating great risk of harm to both Microsoft and users of Microsoft's software," Kochis asserted.

By deciphering WGA's error codes and its test protocols, attackers would be able to sidestep the validation process that the technology uses to determine whether a copy of Windows is legitimate, Kochis said.

In turn, that would put users in danger, he said. "Windows XP users would be at risk because pirated copies of Windows XP often contain unauthorized software that pirates have added to copies of Windows XP that can lead to a corrupted system, a loss of data or even identity theft," Kochis said.

WGA has a checkered history, and has often met with resistance from Windows users. In June 2006, it pushed a version of WGA to XP users via Windows Update by tagging it as a "high priority" update that was automatically downloaded and installed to most machines. That event is the one at the center of the current lawsuit.

A year later, a day-long server outage riled thousands of users who were mistakenly fingered for running counterfeit copies of Windows.

The lawsuit, which seeks class-action status, has not yet been scheduled for trial.

In related news this week, in a separate case involving its "Windows Vista Capable" marketing program, Microsoft asked U.S. District Court Judge Marsha Pechman to block an attempt to use the Windows Update service to distribute a class member notification to nearly 150 million Windows users.

Read more about security in Computerworld's Security Knowledge Center.



Jump to comments

WGA

Additional Resources

EFD vs. HDD - What You Need to Know
WHITE PAPER
Enterprise flash drives provide a new Tier 0 storage layer capable of delivering high I/O performance at a very low latency. Proper use of EFDs in an Oracle environment can deliver increased performance compared to fibre channel drives. Read the recommendations for identification of the best DB components for EFDs.
Gartner Research Report: Magic Quadrant for Application Delivery Controllers, 2009
WHITE PAPER
The market for products to improve the delivery of application software over networks remains dynamic and innovative. Vendors focused on solving enterprises' most-pressing application problems have become the top players.
Eight Criteria for Server Load Balancing
WHITE PAPER
Server load balancers are a simple yet highly effective means to scale an application environment while ensuring its availability. Today's solutions should also address application performance and security. Read about the top eight criteria you should consider when choosing a server load balancer and how Citrix NetScaler meets those requirements.

What People Are Saying

White Papers & Webcasts

Death to PST Files
Download Now  

Web 2.0, Social Media and the Dark Web - A Web Criminals Paradise?
In this discussion, learn about the challenges of protecting your users from the potentially unsafe content hidden in the "Dark Web".

eGuide: Enterprise Security
Smart Security Strategies for 2010. Read now!  

Disaster Recovery 2008: Reduced Costs and Improved Performance
How long can your Enterprise afford to be without your data? With an accelerated disaster recovery program, you never have to answer this...


IT Jobs