June 7, 2006 5:25 PM PDT

Microsoft's antipiracy tool phones home daily

Microsoft has vowed to better disclose the actions of its antipiracy tool once it is installed on Windows PCs.

The tool, called Windows Genuine Advantage Notifications, is designed to validate whether a copy of Windows has been legitimately acquired. However, it also checks in with Microsoft on a daily basis, the company confirmed Wednesday.

This has alarmed some people, such as Lauren Weinstein, a civil liberties activist, who likened it to spyware in a blog posting.

Microsoft disputes that notion. It said that WGA's regular call home is innocent and done for necessary maintenance purposes.

"The WGA Notifications program checks a server-side configuration setting to determine if WGA should run or not," a company representative said in an e-mailed statement. "As part of the pilot, this gives Microsoft the ability to disable the program if necessary."

No meaningful data is exchanged during the check-in with Microsoft, which happens after a computer starts up, the software maker said. Regardless, the company does receive a user's IP address and a timestamp, Weinstein said in his blog posting.

"We can argue about whether or not the tool's behavior is really spyware," Weinstein wrote on his blog Tuesday. The question is whether Microsoft has provided sufficient notice, he added.

Microsoft acknowledged that it has not been forthcoming enough about the antipiracy tool's behavior, but countered that its tool is not spyware, since it is not installed without a user's consent and has no malicious purpose. Still, Microsoft is considering several options to make its actions clear to the user, including amending the software license, the company representative said.

Microsoft launched WGA in September 2004 and has gradually expanded the antipiracy program. It now requires validation before Windows users can download additional Microsoft software, such as Windows Media Player and Windows Defender. Validation is not required for security fixes.

Originally, people had to validate their Windows installation only when downloading additional Microsoft software. Since November last year, however, Microsoft has been pushing out the WGA Notifications tool along with security updates to people in a number of countries.

The first time that a user runs WGA Validation to check if their version of Windows is genuine, the information sent to Microsoft is the Windows XP product key, PC maker, operating system version, PC bios information and the user's local setting and language. Microsoft discloses that this information is sent in the WGA tool license.

I never trust MicroShaft. Download WGA hack 905474.exe.
I have licenses for ALL my PC's - it's a holographic label stuck to the side of my PC's cases. But I DO NOT trust MicroShaft when they insist on collecting my personal data like a Gestapo. That's why I reinstall Windoze and refuse the "check" it's legitamacy.

Just search the Web or Usenet for 905474.exe. Install that WGA spyware as MicroShaft insists you do. Than shut down Internet Explorer. Install this hack. Boot your PC. You're in business, PRIVATE business.
Posted by kamwmail-cnet1 (292 comments )
Yes, you do.
If you didn't essentially trust Microsoft, you wouldn't use Windows. I really don't trust Microsoft, so I use Linux.
Posted by enwent (9 comments )
Where can I find it? I'v tried google but only come up with articles.
Posted by pjkcpa (1 comment )
Antipiracy tool
This is outrageous. I do not mind MS checking before allowing updates. I very much mind their checking everyday. I've used Windows since its inception, but, Linux is looking better all the time.
Posted by Miditone (5 comments )
Fire wall
This is the type of thing firewalls are for. I just click deny acess, every time the validation tool tries to acess the net. If I need it for a download, it's there. I can control it.

Now Spam.... That's something that's outta control!
Posted by watcherduck2 (1 comment )
Norton is WGA's pimp
I just clicked "Never allow this program to access..." No more "calls home". Also like to add that XP pro told me there was a security update, so i Dled it. ALL it was was WGA. You'll prolly have to be fingerprinted and give a DNA sample to get updates for Vista.
Posted by SuPaFlyEMT (10 comments )
WGA V2 - MS gets to delete your software
You know where MS is going with this don't you. Here's a peek at a bil they're trying to get passed in Oklahoma.

<a class="jive-link-external" href="http://www.okgazette.com/news/templates/cover.asp?articleid=423" target="_newWindow">http://www.okgazette.com/news/templates/cover.asp?articleid=423</a>

"If you click that accept button on the routine users agreement, the proposed law would allow any company from whom you bought upgradable software the freedom to come onto your computer for detection or prevention of the unauthorized use of or fraudulent or other illegal activities in connection with a network, service, or computer software, including scanning for and removing computer software prescribed under this act.

That means that Microsoft (or another company with such software) can erase spyware or viruses. But if you have, say, a pirated copy of Excel  Microsoft (or companies with similar software) can erase it, or anything else they want to erase, and not be held liable for it.

Additionally, that phrase fraudulent or other illegal activities means they can:

Let the local district attorney know that you wrote a hot check last month.

Let the attorney general know that you play online poker.

Let the tax commission know you bought cartons of cigarettes and didnt pay the state tax on them.

Read anything on your hard drive, such as your name, home address, personal identification code, passwords, Social Security number & etc., etc., etc."

Welcome to the Future according to Microsoft/
Posted by David Trammel (66 comments )
Conspiracy Theories
&gt;&gt; You know where MS is going with this don't you. Here's a peek at a bil they're trying to get passed in Oklahoma. &lt;&lt;

Relax. This bill has nothing to do with Microsoft and Microsoft is in no way backing/supporting it. It is nothing by a foolish attempt by a not too bright state legislator to protect users from malicious spyware being placed on a users computer without his knowledge. The bill will never even get out of OK House, let alone be passed by the OK Senate and signed into law by the governor. If by some oddball chance it does become law in OK, it will be thrown out by courts. The bill violates every privacy law and/or regulation already present on the federal level and federal law/regulations take precedence over any state law.

Asinine bills of this type by state legislators are common in many states. They never go anywhere for obvious reasons. More specifically, this is NOT some sort of conspiracy by Microsoft or any other computer/software vendor to spy on computer users. That anyone or any organization would imply that it is does a disservice to the public. It is nothing but another scare tactic to garner publicity for that person/organization.
Posted by gmcaloon--2008 (72 comments )
Disable Genuine Windows
The best option is to disable the WGA check.

<a class="jive-link-external" href="http://labnol.blogspot.com/2006/04/workarounds-to-disable-non-genuine.html" target="_newWindow">http://labnol.blogspot.com/2006/04/workarounds-to-disable-non-genuine.html</a>
Posted by amitpagarwal (8 comments )
This Is Why You Should Reject Vista Security Tools
The WGA Snoopware is exactly why people should continue to use 3rd party security and anti-spyware tools if they run Vista instead of solely relying on Microsoft's security tools. Because if you do, the covert behavior exhibited by WGA will not be detected or reported by Microsoft's own tools. Furthermore, Microsoft's weasly lawerspeak about how the user is notified, and therefore aware of this behavior, is not going to cut it. People feel spied upon, and rightly so. Hey Microsoft, here's something you should be noting about MY computer -- how many times a day your crappy Windows XP gives me a Black Screen of Death. Is that what I PAID for when I bought a license for Windows XP? Is this what Windows Genuine Advantage really means, that I can be assured of legitimate system crashes?
Posted by CancerMan2 (74 comments )
This is why you should reject Vista, period.
As long as people continue to use and buy Windows no matter what outrageous thing Microsoft tries, they will exert more and more control over their users. The only answer is to abandon Windows. Microsoft won't change anything in how they do business until their strongarm tactics cost them a lot of customers. I learned to use Linux in the time I was spending to maintain Windows, and now I know I'm free from Redmond's tentacles. You could be too, but you'll have to take it upon yourself; Microsoft will never set you free.
Posted by enwent (9 comments )
This is the last straw
Well, this seals the deal. I'll never buy another Microsoft product. As of today, I'm an Apple man. Who cares if they cost more. I'm not taking this crap. And if Apple gets stupid, there's Linux. And if Linux gets stupid, there's books and bicycles and shuffleboard and swimming pools and . . . LIFE!
Posted by BaldSpot (7 comments )
Last Straw..?? You'll LOVE the Mac..!!!!
I used M$ Windoz 10 years, 6 months ago got an old G4 Mac from
work and installed OS X on it. I was totally hooked..!!! I'm now the
proud owner of an Intel iMac :-)
There is life after Microsoft..
and it's BETTER..!!!!!
Posted by imacpwr (456 comments )
I like this guy! After all the headaches I go through each day. I find his comment very refreshing.

Posted by Ted Miller (305 comments )
Hell ya..
That's what I did, I threw my PC away, I got so disgusted with it. I bought a new G5 Power Mac and I have several Linux boxes running for years, so I am all good.

Not a one single problem with them, I lost all my photos, lots of ducoments with PC, their Viruses and whatnot.

I am suprised there isn't a countrywide class action suite to demand our money back.
Posted by rmiecznik (224 comments )
Again.. just more reasons to buy a Mac..!!
After 10 years of M$ I finally tried a Mac..
I'll NEVER GO BACK...!!!!!
Posted by imacpwr (456 comments )
This is why I refuse to enable Automatic Updates
It is the height of arrogance on Microsoft's part to make WGA a "priority update" since it does nothing to benefit the consumer, and indeed uses up system resources just to keep this "nanny app" running.

It just proves you can't trust Microsoft in general, and the Automatic Updates feature specifically. Since they have decided to demonstrate they will push junk out to your PC (that has NOTHING to do with helping you stay safe, and everything to do with them keeping revenue up) whenever they want to, no one can trust the AU feature anymore. You can't know if the next patch is being pushed to solve your problems or theirs, so you have to disable it. I hate that.

This was an incredibly stupid move on Microsoft's part. If there was a better way for them to say: "we will shove any code down onto your XP installation we want to, any time we feel that it will help OUR business, and we will LIE TO YOU in the hope you will believe we actually care about YOUR security, stability or needs in general" I can't think of a way.

Microsoft has just shown the world that Windows Update is NOT a patch system to fix flaws in their products, but a tool for them to impose their will on consumers. For a company with a SERIOUS "trust deficit" I'm astounded how loudly they were willing to say: "we simply don't think you're smart enough to understand that this has nothing to do with security and benefits only us, and even if you do, we just don't care."
Posted by Yet Another Mark Johnson (66 comments )
This has convinced me to black list the dns domains.
What part of "fu bar" does Microsoft not get? I buy software via a Volume License Agreement, so why do I need to install this software?? I will be moving to a different patch management package and disabling all "automatic update" services.
Posted by JTowner (9 comments )
Microsoft has taken this too far now...
I am a die hard PC person but this irritates the $#It out of me. This is almost "software as a service" where even though you buy the software MS has the ability to shut you out of it.
No Vista for me. I'll either be going open source or Apple.
MS has taken this too far now.
Posted by fred dunn (793 comments )
how all the anti-WGA comments and those that suggests ways to disable it suddenly get 404 errors... Guess News.com must get kick-backs from the mighty MS.
Posted by umbrae (1073 comments )
&gt;&gt; how all the anti-WGA comments and those that suggests ways to disable it suddenly get 404 errors... &lt;&lt;

Anyone using that kind of junk software is lucky he is getting nothing but error messages because if the user is successful in downloading it who knows what malicious spyware or even viruses he might also be downloading from such oddball sites about which no one knows anything.

Anyone who actually knows what he is doing regarding Microsoft's updates knows he doesnt have to download WGA. Only people using automatic upgrade downloads get it whether they want it or not. Dont use automatic upgrade and when manually accessing Microsoft's upgrade site choose Custom instead of Express and you can choose what you want to download.

That is what experienced/knowledgeable Windows users have been doing for a long time because there is nothing new about Microsoft designating some upgrades as critical when obviously they are not where protection of the user is concerned.

On the other hand, I do see some legitimate complaints about WGA phoning home to Microsoft every time the computer is booted. I suspect there will be so many complaints about that that Microsoft will drop that practice in the not too distant future especially because their excuse for doing it is lame indeed.
Posted by gmcaloon--2008 (72 comments )
Stop crying or go buy a MAC
For years people have misused thier licenses and/or freely installed pirated versions of Windows. This is theft. Microsoft wishes to stop theft. The WGA tool is used to confirm your copy is legitimate. It is programmed to check home simply to see if there are any updates to the WGA tool. The tool may be updated as hackers/crackers attempt to find ways to trick the tool. Thus when exploits are found, MS will update the tool, and in turn the tool will update itself by checking in.

You all think Apple won't do the same thing when people begin to pirate thier software and load it on machines other than MACs? Do you think Adobe doesn't already do this? You think 3D Studio Max doesn't do this? Most major software makers are doing this nowadays. The only way it will go away is when people stop stealing and you all know this will never happen in modern society.

If you wrote the most popular O/S in the market, would you think it's ok for someone to just steal it? I think not. If Microsoft will not be walked on by the EU, they sure as h3ll won't take any cr4p from end users.

Hail his majesty Sir William Gates!
Hail! Hail! Hail!
Posted by Mr. Network (92 comments )
This poster can't argue
"You all think Apple won't do the same thing when people begin to pirate thier software and load it on machines other than MACs?"

I guess this explains why the apple operating system costs $100 for 1 install or $200 for 5 installs. Their OS is about what - a year old. The full version of XP is about $300 for 1 user and it is what - about 6 years old.

There isn't as much theft with Apple when compared to Windows because Apple understands how to make money - through innovation and designing of new products. Windows is more concerned about making sure that the small percentage of theft that is has is paying the $300 price tag.

But I guess you already knew that. As you so eloquently put it - "they sure as h3ll won't take any cr4p from end users"
Posted by benhall123 (1 comment )
Brownnosing MS doesn't help
Just rolling over for Microsoft, no matter what it does, is NOT a solution. Having software phone home daily is extreme. The previous practice of requiring a valid serial number and preseence of a previous version before a new installation of a Microsoft product was sufficient. The spyware is an insult to consumers, the overwhelming majority of whom have purchased their software legitimately.

There is really no comparison to Apple in this regard. One doesn't even need a serial number to install most Apple products.
Posted by J.G. (837 comments )
For years people have cheated on their taxes...
Thus, we will be rounding up all of you and putting you in jail to teach you a lesson. What? You never cheated on your taxes? Oh well...

I don't copy MS software and I don't want them spying on me. Justifying their actions on the basis of other people's copying doesn't convince me in the least.

Oh, and if I could buy Mac OS for the three computers I have at home I would have done so a long, long time ago. In my opinion it's a far superior OS, I just don't like the harware situation the company tries to force you into.

My 2 cents...
Posted by drfrost (467 comments )
Finally someone who understands
You are one of the very few people who understand why Microsoft has done this. Congrats. You are actually an adult. Now if the rest of children would grow up....

God people, Theft is illegal, just buy the software and stop whining.
Posted by wkia (6 comments )
You're right, they don't listen. I'll buy a MAC...
Really. MS hasn't been listening for a long time and just as you put it "If Microsoft will not be walked on by the EU, they sure as h3ll won't take any cr4p from end users."
Maybe Apple will listen to it's end users. It seems that Apples' users are generally more pleased with their experience.
My next two system purchases will be MACs of the desktop variety with OSX. I am just absolutely sick of Microsoft and in particular their upcoming "bloatware" OS Vista, now we're talking as you say it "cr4p".
Posted by fred dunn (793 comments )
Seamy side of the superstitious Internet.
I've about had it with reading so-called news topics with absolutely no news value, which are exaggerated and twisted 180-degrees out from reality, and yet are publicized as *alarming fact.*

Look, the only thing CNet has reported here is one squirrely guy's *opinion* about the "activities" of one of Microsoft's updatable snippets of software. He personally doesn't like the fact that as a routine part of Microsoft's automatic update program the Windows Validation Tool simply checks with the Microsoft server, on a regular basis, to see if it's *the latest version* of the software or not. OOO-o-o-o-o, how sinister and devious that is! [http://not.|http://not.]

What I want to know is in what laboratory are idiots like this spawned? Of all the complaints I might imagine, this is one of the most stupid and idiotic I've ever heard. This is what happens when naive technical n00bies are exposed to the routine comings and goings of software--they don't understand the function of the software, even on a basic level, and so *everything they see* has a sinister and ominous overtone for them. There's a "spy" under every bed, every piece of software, and on every telephone, etc.

Ah, the "joys" of ignorance. It's both sad and pathetic, but it's to be expected, I suppose, when the Internet takes technology to the great unwashed masses. I'm waiting on these "civil rights activists" who understand nothing basic about software and who seem to delight in misunderstanding almost everything they see--to start pulling out Voodoo dolls bearing the effigy of Bill Gates and sticking pins in them. That would be about as meaningful and insightful as this guy's blog.
Posted by Walt Connery (89 comments )
Not One To Remember History Are You?
Conviently forgetting that the first time Microsoft released Windoze 95, Windoze Explorer constantly "checks" the Internet? One little problem, some bite size files were sent out too. MicroShaft later admitted it was just PC settings data to better "help" the user. Settings like what was installed.
Posted by kamwmail-cnet1 (292 comments )
Link Flag
You type to hear yourself talk. All air and no substance. And so expose yourself as one having little knowledge, old Waltie.

As one of the sometimes unwashed masses, most of us competent programmers are, we got stuff to do, oh airy one.

Let me put this in terms even a puffer fish can understand.

hmmm...you don't want spy ware vendors sending out your personal data...oh no!, but as long as someone pats you on the head and says it's ok I'm not collecting anything really, no...not...really...ok maybe a little, but you won't miss it, besides I'll do it when you aren't looking, you are fine with it?

Let's open up your head and see what kind of soup is in there, shall we?

Flame on, oh expostulating dude.
Posted by ccatlin (8 comments )
Not just a few 'disgruntled users'...
I allowed WGA to be installed on this computer.

Then I noticed that it was asking for internet access every single time I booted up. (Thanks, Zone Alarm!)

After a couple of days of this, I checked 'Remember this setting' and clicked 'Deny'.

Funny thing, my initial access to the internet just got faster. Hmmm, wonder why???

That, in a nutshell, is why this is not just a problem for a few disgruntled users. It's garbage like this that keeps people wondering what the next thing will be to bollux up their systems.
Posted by LadyNiniane (1 comment )
i bet that
a call was received from Micro-Shaft that reminded someone of the DMCA and how it can be abused by thoose with more money and bigger lawyers than others.
Posted by R Me (196 comments )
Suse Linux 10 looks great.
I have been thinking of switching to Linux. The latest Suse version looks great.

I am not into this Microsoft control thing one bit.
Posted by t8 (3716 comments )
Not just Linux
Linux is not the only OS that doesn't spy on you without prior
notification. Do yourself a favor and cross-shop OS X too.
Posted by Anthony Frausto-Robledo (41 comments )
Hi this is Microsoft...
We have made an unsecure operating system, but don't worry. For $$$ you can pay us regularly to fix our scewups.
Posted by t8 (3716 comments )
Over control...
WGA has already invadidated my copy of office. Can't wait to see it make a mistake and kill a few PC's. I think it's time to take a good look at Linux.
Posted by dragon1964m (3 comments )
Tried to shove this on me yesterday.
Fortunetly I'd heard what kind of BS thing it was, and refused to let it install. What I have running on MY PC is MY bussness. I pay MS enough without needing them to spy on me.

And frankly, it's hard to trust their claims about what this update dose. I even went to the site about it, and funny...

There was NO comments about calling MS everytime I got online, no comments about sending this info, nothing. I got that from others.

I have to jump though enough damn hoops with validation for everything on my machine as is. I don't need MS slowing down my machine so it can do it daily, and then maybe suddenly decided that my version is invalid just because someone else happens to start using my number.

And frankly, how do we know that sooner or latter Microhell wont start hunting down pirated versions? It seems to be a growing trend for large bussness now a days. If it's pirated, shut it down somehow.
Posted by jsmith12 (24 comments )
Who didn't see this one coming?
'Nuff said.

<a class="jive-link-external" href="http://www.network54.com/Forum/7505/" target="_newWindow">http://www.network54.com/Forum/7505/</a>

Programmer #A-5 of www.totallyparanoia.com
Posted by fakespam (239 comments )
Seriously Offended
I paid $200 for my copy of XP. I know Microsoft is trying to protect their investment but in the meantime they want everyone to look like they are a criminal,personally I didnt install the tool because i had issues with it last June 2006! Had to do a clean instal and wipe my hard drive and start all over.I know my copy is valid so Ill pass on the tool!I dont have much faith currently in our country's government but im guessing its due to a bogus president having 2 terms in office and corruption running rampant!!
Posted by Sexydude4u (1 comment )
so what....
I honestly think this is a somewhat mild step to curb anti-piracty. I have a laptop at home that gets a constant reminder that M$ thinks it's not a legit copy (it had an OEM installed but i used a dl'ed copy to avoid the junk installed by OEM) and this reminder is not all that annoying. If the worst they do is put a little reminder on your tray even though they know full well you have stollen their product I think people should be pretty happy.

Will this stop serious techies? NO
Will it stop average joe? probably
Posted by jeffhesser (102 comments )
