Judge protects Microsoft's WGA secrets

Microsoft successfully argues that revealing sensitive sections of the WGA software development kit (SDK) would give hackers a field day.

A federal judge has granted Microsoft's request to keep secret details of its Windows antipiracy technology after the company claimed hackers could exploit the information if it were made public.

US District Court Judge Richard Jones last week granted Microsoft's motion that some documents be sealed in a two-year-old lawsuit that accuses the company of misleading customers when it updated its Windows Genuine Advantage (WGA) antipiracy software via its Windows Update service.

In a deposition filed with Jones three weeks ago, Alex Kochis, the director of Microsoft's Genuine Windows group, said that revealing sensitive sections of the WGA software development kit (SDK) would give hackers a field day.

"Public release of the WGA SDK Integration Specifications information would allow hackers to defeat the WGA Validation function by causing WGA to generate false results indicating that the system being tested is genuine, thereby creating great risk of harm to both Microsoft and users of Microsoft's software," Kochis asserted.

By deciphering WGA's error codes and its test protocols, attackers would be able to sidestep the validation process that the technology uses to determine whether a copy of Windows is legitimate, Kochis said.

In turn, that would put users in danger, he said. " Windows XP users would be at risk because pirated copies of Windows XP often contain unauthorized software that pirates have added to copies of Windows XP that can lead to a corrupted system, a loss of data, or even identity theft," Kochis said.

WGA has a checkered history, and has often met with resistance from Windows users. In June 2006 it pushed a version of WGA to XP users via Windows Update by tagging it as a "high priority" update that was automatically downloaded and installed to most machines. That event is the one at the center of the current lawsuit.

A year later, a day-long server outage riled thousands of users who were mistakenly fingered for running counterfeit copies of Windows.

The lawsuit, which seeks class-action status, has not yet been scheduled for trial.

In related news this week, in a separate case involving its "Windows Vista Capable" marketing program, Microsoft asked US District Court Judge Marsha Pechman to block an attempt to use the Windows Update service to distribute a class member notification to nearly 150 million Windows users.

Join the newsletter!

Or

Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.

Tags Microsoftwga

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.
Gregg Keizer

Gregg Keizer

Computerworld
Show Comments

Most Popular Reviews

Latest Articles

Resources

PCW Evaluation Team

Cate Bacon

Aruba Instant On AP11D

The strength of the Aruba Instant On AP11D is that the design and feature set support the modern, flexible, and mobile way of working.

Dr Prabigya Shiwakoti

Aruba Instant On AP11D

Aruba backs the AP11D up with a two-year warranty and 24/7 phone support.

Tom Pope

Dynabook Portégé X30L-G

Ultimately this laptop has achieved everything I would hope for in a laptop for work, while fitting that into a form factor and weight that is remarkable.

Tom Sellers

MSI P65

This smart laptop was enjoyable to use and great to work on – creating content was super simple.

Lolita Wang

MSI GT76

It really doesn’t get more “gaming laptop” than this.

Featured Content

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?