Windows XP WGA and WGA Notification Tool, 'from a certain point of view'

muckshifter

I'm not weird, I'm a limited edition.
Moderator
Joined
Mar 5, 2002
Messages
25,739
Reaction score
1,204
A new version of the Windows Genuine Advantage Notification Tool was recently downloaded out of cycle (it was not the first Tuesday of the month) from Microsoft on my computer which got me wondering what was up.

Well ...

I found this posting Windows XP Update may be classified as spyware on the Lauren Weinstein's Blog and a further posting Microsoft Responds;

Microsoft Responds Regarding Windows XP Update vs. Spyware

Luke: "You lied to me. You said that Darth Vader killed my father."
Obi-Wan: "When Anakin Skywalker turned to the Dark Side of the Force, the good man that was your father ceased to exist. So, what I told you was the truth -- from a certain point of view."
-- Star Wars: Return of the Jedi - 1983

Pat (to Mystic Seer): "You're just a stupid piece of junk, aren't you?"
Don (reading response): "It all depends upon your point of view."
-- Twilight Zone ("Nick of Time") - 1960

Greetings. In yesterday's blog posting, I asked the implicit question: "Is Microsoft's update of their 'Genuine Advantage' OS validity verification tool behaving as spyware?"

Within hours of that text becoming widely public, I received e-mail and a call from the director and the senior program manager for Microsoft "Genuine Windows" (their anti-piracy division). We three had a lengthy and friendly chat, and I believe that I can now answer this question. However, as you have probably already guessed, the answer is, "It depends upon your point of view."

And perhaps of more importance, it's not clear that the spyware question alone is really the key issue in this case, since this is all part of a larger MS anti-piracy effort with broader implications for all concerned. In the long run, the real issues are clarity and control, as we shall see.

Microsoft has major piracy problems, on a massive scale -- this we all know. They have been ramping up their infrastructure to prohibit "non-validated" copies of Windows XP from installing non-critical software updates. What many people don't realize is that MS does not consider validation to be a necessarily permanent state. Even after a copy of XP has been validated, MS may choose to "revoke" that validation (via communications with their Windows Update site) at a later date if activation codes are found to be pirated in the future.

Why is the new version of the validity tool trying to communicate with MS at every boot? The MS officials tell me that at this time the connections are to provide an emergency "escape" mechanism to allow MS to disable the validation tool if it were to malfunction.

While most users will routinely accept the tool update from Windows Update, MS considers it to be (for now) an optional upgrade as part of a pilot program, as described in accompanying license information that (as we know) most users will never read. (I should note that while these materials do discuss Internet connections, they do not appear to notify users that the updated tool will make multiple connections to MS at various intervals, even on systems that are already validated.)

I was told that no information is sent from the PC to MS during these connections in their current modality, though MS does receive IP address and date/timestamp data relating to systems' booting and continued operations, which MS would not necessarily otherwise be receiving.

Apparently these transactions will also occur once a day if systems are kept booted, though MS intends to ramp that frequency back (initially I believe to once every two weeks) with an update in the near future. Further down the line, the connections would be used differently, to provide checks against the current validation revocation list at intervals (e.g., every 90 days) via MS, even if the user never accessed the Windows Update site directly.

Can you safely block the tool from communicating with MS using ZoneAlarm or another third-party firewall? The answer appears to be yes. I'm told that if the tool can't communicate with MS, validation checks will be made the next time the system communicates directly with the Windows Update site, in the same manner as has been done up to now since validation began.

We can argue about whether or not the tool's behavior is really spyware -- there are various definitions for spyware, and the question of whether or not you feel that the notice provided at upgrade installation time was sufficient is also directly relevant. I believe that the MS officials I spoke to agree with my assertion that additional clarity and a more "in your face" aspect to these notifications in such cases would be highly desirable.

But this is where an even more important question comes into play. Microsoft (and other software vendors) are moving inexorably toward a more "distributed" computing model where users are really "renting" software services, rather than buying commodity software products. The "rental" model implies long-term vender control over the use and applications of such software, with associated communications between user PCs and vender servers for ongoing authentication and other purposes.

The entire concept of authentication revocation will be utterly foreign to many users, who are used to assuming that once they've bought something that they believe to be legitimate -- and that in fact has initially been verified as legitimate -- it's then theirs forever and can't be disabled or restricted later.

And as we've now seen yet again, the communications issues associated with the rental/service model introduce a range of both real and perceived privacy factors and concerns that we've hardly yet begun to explore in depth as technologists or as a society.

One thing is certain regardless of your point of view -- the sorts of issues that relate to this particular case are but harbingers of what's to come, in terms of capabilities, controversies, risks, and more. The old models are dying, and if we don't get ahead of the curve by understanding and properly framing the new models, we are likely to be very sorry after the fact.


--Lauren--

Posted by Lauren at June 6, 2006 09:40 PM
Well, I have my Linux Suse 10.1 working sweet, how 'bout you? ;)

user.gif
 

muckshifter

I'm not weird, I'm a limited edition.
Moderator
Joined
Mar 5, 2002
Messages
25,739
Reaction score
1,204
This is the interesting bit ... well for me;

But this is where an even more important question comes into play. Microsoft (and other software vendors) are moving inexorably toward a more "distributed" computing model where users are really "renting" software services, rather than buying commodity software products. The "rental" model implies long-term vender control over the use and applications of such software, with associated communications between user PCs and vender servers for ongoing authentication and other purposes.

The entire concept of authentication revocation will be utterly foreign to many users, who are used to assuming that once they've bought something that they believe to be legitimate -- and that in fact has initially been verified as legitimate -- it's then theirs forever and can't be disabled or restricted later.

And as we've now seen yet again, the communications issues associated with the rental/service model introduce a range of both real and perceived privacy factors and concerns that we've hardly yet begun to explore in depth as technologists or as a society.

One thing is certain regardless of your point of view -- the sorts of issues that relate to this particular case are but harbingers of what's to come, in terms of capabilities, controversies, risks, and more. The old models are dying, and if we don't get ahead of the curve by understanding and properly framing the new models, we are likely to be very sorry after the fact.
:rolleyes:

Rent a Vista ... must be returned in two weeks.
happywave.gif

 

darcy

Enjoyin' the Breeze
Joined
Jul 6, 2006
Messages
300
Reaction score
37
uninstaller for WGA Notifications tool { not WGA Validation } being here: ~ RemoveWGA

N.B., ~

The last WGA notification update KB905474, cannot be removed in a clean way, because it purposefully blocks the deletion of the WgaLogon.dll.
Because of that, the only way is to force the WGA dll to unload from memory, prior deleting it. Doing so, it will crash your system (you should do a hard reboot before it happens). It is not a proper way though, and you shouldn't do it if you haven't backups. If you prefer to not take any risk, Microsoft has published an article explaining how to remove the WGA notification PILOT (not the final release) manually :
http://support.microsoft.com/?scid=kb;en-us;921914
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Similar Threads

WGA 5
XPSP3 & WGA 1
WGA now compulsory for getting Windows updates ??? 52
wga validation tool 5
MS WGA Talkback 4
WGA (KB905474) Revisited 10
WGA! 16
WGA 2

Top