Activation - down side

  • Thread starter Thread starter Crusty \(-: Old B@stard :-\)
  • Start date Start date
C

Crusty \(-: Old B@stard :-\)

I have thought long and hard about submitting this, as I am about to bite a
hand that feeds me.

As everyone who frequents these news groups know, I have been on Microsoft's
side regarding activation since Windows XP was introduced. I am against
piracy and thievery of any sort! But I have reached my breaking point.

Since late August I have cleaned the w32.blaster.worm off of more than 300
computers. One hundred and seventeen (117) of these computers, by my
records, had nothing on them, when I was called in, but the retail version
of Windows XP. The owners did not have the opportunity to install anything
additional. Every one of these 117 computers was set up using a clean
install by the client. None of these 117 was an upgrade install.

All of these computers were activated, prior to the client being presented
with the initial desktop (Do You Wish To Activate Now?). This, of course, is
prior to them being able to turn on the firewall, install a copy of an
antivirus and prior to them having the opportunity to install SP1 (if they
were using an older CD) or the security rollup (even if they knew about
these necessary items).

All of these computers was infected during the process of activation -
during the brief time frame that these honest people were connected to the
internet, doing the correct, and proper thing! Their first view of the
desktop was marred by an automatic shutdown.

I am fully cognizant of the fact that Microsoft has a right to protect their
copy rights. But what has evolved due to Microsoft forcing activation,
before the computer can even be secured by a knowledgeable person (forget
those with limited or no knowledge) borders on the insane!

YES! I fault the people who disseminated this virus on the internet. But
it was Microsoft who unlatched the lid and allowed the serpent to escape!

Shame on you Microsoft!
 
Back when beta2 preview was released I told them on the beta news groups
this would happen, I thought the hackers would do it, but Microsoft wouldn't
listen, they said that couldn't happen.
 
I feel your pain. These are the problems that were never
envisioned. Most OEM's still don't have a clue, or they
would up-date their installs. How many units are setting
in warehouses unsold that are still at risk. Botton line
MS does not care !!!!!! If they did you would see some
action.
 
"By the act of scrolling this post on your computer, and/or printing or
replying to this post, you agree that I am your everlasting Lord &
Saviour. Breach of this term will result in you burning in hell for
ever and ever! Amen!"
I have thought long and hard about submitting this, as I am about to
bite a hand that feeds me.

As everyone who frequents these news groups know, I have been on
Microsoft's side regarding activation since Windows XP was
introduced. I am against piracy and thievery of any sort! But I have
reached my breaking point.

Since late August I have cleaned the w32.blaster.worm off of more
than 300 computers. One hundred and seventeen (117) of these
computers, by my records, had nothing on them, when I was called in,
but the retail version of Windows XP. The owners did not have the
opportunity to install anything additional. Every one of these 117
computers was set up using a clean install by the client. None of
these 117 was an upgrade install.

All of these computers were activated, prior to the client being
presented with the initial desktop (Do You Wish To Activate Now?).
This, of course, is prior to them being able to turn on the firewall,
install a copy of an antivirus and prior to them having the
opportunity to install SP1 (if they were using an older CD) or the
security rollup (even if they knew about these necessary items).

All of these computers was infected during the process of activation -
during the brief time frame that these honest people were connected
to the internet, doing the correct, and proper thing! Their first
view of the desktop was marred by an automatic shutdown.

I am fully cognizant of the fact that Microsoft has a right to
protect their copy rights. But what has evolved due to Microsoft
forcing activation, before the computer can even be secured by a
knowledgeable person (forget those with limited or no knowledge)
borders on the insane!

YES! I fault the people who disseminated this virus on the
internet. But it was Microsoft who unlatched the lid and allowed the
serpent to escape!

Shame on you Microsoft!

Welcome back from the Dark Side of the Force! ;-)

It all comes down to MS is gonna protect it's cash cow at the expense of
anything & everything. Just look how they are dragging their feet
patching up the IE Address Bar Exploit. Hell, OpenWares.org put out
their own patch to keep from being fooled by people who use this exploit
for nefarious reasons

http://security.openwares.org/

My 2 two examples of this exploit:

http://microscum.com/misc/devil/

http://www.microscum.com/misc/intransigence/intransigence.htm

"Trustworthy Computing" is nothing but lip service. And when it comes
to protecting the cash horde, or protecting the customer, the customer
is always the loser.

--
Peace!
Kurt
Self-anointed Moderator
microscum.pubic.windowsexp.gonorrhea
http://microscum.com
"Trustworthy Computing" is only another example of an Oxymoron!
"Produkt-Aktivierung macht frei!"
 
I concur with your assessment. I think MS should remove and amend all current retail copies of XP from the retailers and include documentation and instructions that the XP firewall must be enabled before connecting to the internet for activation completion. Also all OEMs must recall or supply information on how to avoid the blaster worm when they make their initial boot up

XPblues !-(
 
I concur with your assessment. I think MS should remove and amend all current retail copies of XP from the retailers and include documentation and instructions that the XP firewall must be enabled before connecting to the internet for activation completion. Also all OEMs must recall or supply information on how to avoid the blaster worm when they make their initial boot up.

XPblues !-(

Actually, it would be as simple as issuing an SP1 CD with all non SP-1
systems and retail packages in the retail chain. It would be as simple
as slapping the CD on the box.

Me, I took care to procure and install an SP1 CD before I connected to
the internet.
 
Blaster virus can also comes in with SP1 installed!

Y.

current retail copies of XP from the retailers and include documentation and
instructions that the XP firewall must be enabled before connecting to the
internet for activation completion. Also all OEMs must recall or supply
information on how to avoid the blaster worm when they make their initial
boot up.
 
You are so right.

You have to go onto the internet and, possibly, become infected, to download
the patch that prevents infection!
 
Greetings --

You raise some very good points, and I don't see how you're
"biting the hand that feeds you." Something needs to be done, but
what, exactly?

Unfortunately, I can't see any solution that would satisfy
everyone. For Microsoft and the various OEMs to recall _all_ of the
currently unsold copies of the OS, and replace them with a "patched"
version would be a mind-bogglingly huge logistics nightmare. (I'm not
even thinking about the huge cost of such a program. I'm fairly
confident that Microsoft and the bigger OEMs could absorb the expense
if they truly wanted to, but it would be a hard sell to the various
boards and stock-holders. The costs would probably get passed on to
the consumers, in the end.) And this could happen only have the
specific nature of the "patched" theoretical "WinXP, Part Deux" has
been determined, developed, and thoroughly tested, which would take
many months.

I do think that Microsoft should immediately start working on a
release that has all of the currently known vulnerabilities patched,
and should modify the Activation mechanism to allow a delay of a few
days _before_ prompting the user to connect and activate.
Additionally, any such prompting should also include warnings to
enable the firewall and install anti-virus software before proceeding.
(On a similar note, it would also be a good idea for antivirus
manufacturers to modify _their_ products so that they don't
immediately seek an Internet connection to obtain new definition
files; Blaster could sneak in then, as well.) Either that, or dump
WPA entirely, in favor of some other copy-protection mechanism.
Perhaps a hardware key that attaches to the now mostly used parallel
port? This method has worked well for a lot of other software
manufacturers over the years.

Until the newer, "patched" edition is ready and shipped, I think
it might behoove Microsoft, the OEMs, and the large software
retailers/distributors to affix large, colorful warning labels to each
and every software box, warning consumers to secure their PCs _before_
connecting to the Internet. A small pamphlet with specific
instructions could also be included. The problem with this idea is
that not everyone will read and/or heed the warnings. If warnings
were enough, Blaster would have stopped spreading in August, when it
first made all of the major mass media news outlets.

Service Pack 2 is already rumored to automatically enable the
firewall, which is good for most home consumers, but very troubling -
and rightly so - to professional network admins, who can see their
enterprise LANs screeching to a halt as the firewalls kick in on each
and every freshly upgraded workstation. Perhaps Microsoft can modify
the service pack so that only WinXP Home's firewall is automatically
turned on. Which will inconvenience and upset a lot of people who
have home networks or small business peer-to-peer workgroups. Just
how do you please everyone?

One final note: You've quite properly placed the blame for this
problem upon both the virus creator(s) and Microsoft. However, you
left out the third responsible party: the consumer. In this day and
age, with all of the media coverage that technical and computer
security issues and computer viruses receive, it boggles the mind how
anyone can possibly still be so completely uninformed and so utterly
naive as to trustingly connect his/her brand new, relatively
expensive, computer to the Internet without taking any precautions,
whatsoever. People really should know better, by now.


Bruce Chambers

--
Help us help you:



You can have peace. Or you can have freedom. Don't ever count on
having both at once. -- RAH
 
Hi Bruce!

About 6 weeks ago I was loading XP onto a computer I had assembled for a
client. While connecting everything to the rear, I had a "brain fart" and
plugged in the LAN connection (used DSL at the time).

Everyone, by now, knows that the install configures everything, including
the dial-up/DSL/LAN automatically, during the process. Even though I opted
NOT to activate at the prompt, when the first desktop was available, so was
the "shutdown" popup! It took less than 5 seconds for the computer to become
infected.

Was I ever pissed! I mean, I KNOW BETTER! Yet, I had been bitten.

In this case it took only a couple of minutes, using Drive Image 2002 boot
floppies, to bring the computer back to the state it was in "prior" to the
final boot! At least I hadn't forgotten to create that image (I always
create a 5 gig hidden partition on the computers I assemble - another "shame
on you to the companies that no longer supply floppy drives with their
computers)! This image has proven itself to be invaluable to my clients 5-6
months down the road, and it saves me a hell of a lot of time when an end
used mucks up the works (-:

I know it would be difficult, and not impossible to implement, but I have
the following vision.

1. A second CD in the retail package. A free disk mailed to users and
available in magazines and at the thousands of stores that sell
computers/software. Hell, put them in the post office along side the AOL
CD's.

2. Install SP1 and the latest Security Rollup.

3. Hold off final implementation of configuring any dial-up/DSL/LAN
connection. This, of course, should not occur using the Windows XP CD
either!

4. Turn on
A: the built-in firewall or
B: give the user the chance to install a supplied version of something like
ZoneAlarm (free version).

If neither box is checked - HALT the install. Make the used check boxes 2-3
times, each time explaining loudly, and explicitly, what the consequences
will be if he/she proceeds without making a choice of A or B.

5. Install, automatically, a version of antivirus (any companies is better
than none at all)!

6. Finish configuration of dial-up/DSL/LAN

7. Automatically update, not just Windows. Also get all updates for the
antivirus and Firewall chosen.

Yes! The above would be a pain in the ass for Microsoft to implement. But,
it is the Microsoft visionaries who did not look far enough down the road
and see what effects activation would have on the public.

Finally, some way to block a users computer from internet/LAN access if the
computer starts exhibiting a form of strange behavior (worms, virus, back
doors, DOS attacks - out, etc)! Hell, if someone had a device on their
telephone that was interfering with all phone connections within a 5 mile
area, how long do you think they would be connected to the grid. Their
connection would be broken at the pole by phone company!

Anyway, the above is only my vision, along with any built-in flaws, because
as I have proven to myself, time and time again, I also make mistakes (-:

Anyway, Microsoft now has an opportunity to "do the right thing", as they
expect their customers to do. Lets hope that they can find a way to put this
unfortunate situation to bed - once and for all!
 
Crusty (-: Old B@stard :-) wrote:
<snip>

Hi Crusty

The following URL is a public document about the changes that are
implemented in XP SP2. You will likely enjoy the read. :)

Security Developer Center: Windows XP Service Pack 2: A Developer's View
(Windows XP Technical Articles):
http://msdn.microsoft.com/security/default.aspx?pull=/library/en-us/dnwxp/html/securityinxpsp2.asp


--
Ronnie Vernon
Microsoft MVP-Windows Shell/User

Please reply to the newsgroup so all may benefit.
http://www.dts-l.org
http://www.mvps.org
 
Hi Bruce!

About 6 weeks ago I was loading XP onto a computer I had assembled for a
client. While connecting everything to the rear, I had a "brain fart" and
plugged in the LAN connection (used DSL at the time).

Everyone, by now, knows that the install configures everything, including
the dial-up/DSL/LAN automatically, during the process. Even though I opted
NOT to activate at the prompt, when the first desktop was available, so was
the "shutdown" popup! It took less than 5 seconds for the computer to become
infected.

Was I ever pissed! I mean, I KNOW BETTER! Yet, I had been bitten.

In this case it took only a couple of minutes, using Drive Image 2002 boot
floppies, to bring the computer back to the state it was in "prior" to the
final boot! At least I hadn't forgotten to create that image (I always
create a 5 gig hidden partition on the computers I assemble - another "shame
on you to the companies that no longer supply floppy drives with their
computers)! This image has proven itself to be invaluable to my clients 5-6
months down the road, and it saves me a hell of a lot of time when an end
used mucks up the works (-:

I know it would be difficult, and not impossible to implement, but I have
the following vision.

1. A second CD in the retail package. A free disk mailed to users and
available in magazines and at the thousands of stores that sell
computers/software. Hell, put them in the post office along side the AOL
CD's.

2. Install SP1 and the latest Security Rollup.

3. Hold off final implementation of configuring any dial-up/DSL/LAN
connection. This, of course, should not occur using the Windows XP CD
either!

4. Turn on
A: the built-in firewall or
B: give the user the chance to install a supplied version of something like
ZoneAlarm (free version).

If neither box is checked - HALT the install. Make the used check boxes 2-3
times, each time explaining loudly, and explicitly, what the consequences
will be if he/she proceeds without making a choice of A or B.

5. Install, automatically, a version of antivirus (any companies is better
than none at all)!

6. Finish configuration of dial-up/DSL/LAN

7. Automatically update, not just Windows. Also get all updates for the
antivirus and Firewall chosen.


More or less my course of action when I re-install the OS on this PC.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Similar Threads

Activation Numbers for XP 11
3 Days to Activate? 13
XP Activation question 2
Activated Too Many Times 13
Windows un-activated and wont re-activate 2
MS Security Essentials 3
ACTIVATION ISSUE 7
Flops' new build 5

Back
Top