On mySimon: Holiday Gifts for the Hostess
BNET Business Network:
BNET
TechRepublic
ZDNet

June 12th, 2006

Microsoft presses the Stupid button

Posted by Ed Bott @ 8:42 am

Categories: WGA

Tags:

Update 12-August: For a detailed discussion of what you’ll see if WGA flags your copy of Windows as "not genuine," see Busted! What happens when WGA attacks and the accompanying image gallery.

When you’re the Evil Empire, it’s only natural to get a bad rap for everything you do. Microsoft gets bad-mouthed a hundred times a week for things that would be perfectly acceptable coming from anyone else. Given that level of criticism, it’s easy to ignore the times when they’re just completely, egregiously wrong.

The uproar over Microsoft’s new Windows Genuine Advantage authentication software, which is now being pushed onto Windows users’ machines via Windows Update, is one of those occasions. Someone at Microsoft just pushed the Stupid button. And things aren’t going to get better until they stop pushing it.

In a nutshell, here’s what’s happening. Two months ago, Microsoft released an update to its Windows Genuine Advantage authentication system via Windows Update. The WGA code checks your system to see if it’s been properly activated. If the activation is messed up – as it would be if you were using a pirated copy of Windows – you see a message telling you your copy of Windows is “not genuine” and your access to some Microsoft resources is cut off. WGA was originally intended to be part of Microsoft’s carrot-and-stick strategy for reducing piracy. Lawsuits against software pirates are the stick; WGA is the carrot. In theory, after you run the WGA code and prove that your copy of Windows is legit, you get access to cool downloads that aren’t available to Windows users who haven’t jumped through the WGA hoop.

Fellow ZDNet blogger David Berlind has done an excellent job of unpacking the spin from Microsoft’s multiple statements about this situation. For details, see Does Microsoft’s new WGA disclosure fall short? and With WGA, is Microsoft forcing Windows users to install and test pre-release software? Read both those posts and follow the links for the full details of this story.

I’m not all that concerned with the hysteria over the revelation that this app “phones home” to Microsoft. These days, I fully expect that any program I install will have a mechanism for updating itself or accessing help content online. As long as those mechanisms for online access are disclosed during installation and the actual update process isn’t malicious, careless, or deceptive, I have no problem.

No, the problem with Microsoft’s whole WGA program boils down to a simple rule: Do not mess with security. This episode violates that rule in three incredibly stupid ways.

Stupid mistake #1: This update should never have been included with Critical Updates. The Automatic Updates mechanism in Windows XP (and in the upcoming Windows Vista) is supposed to be a delivery vehicle for Critical Updates that fix security flaws in Windows. (From the Microsoft Update FAQ: “Automatic Updates is the easiest, most reliable way to help protect your computer from the latest Internet threats by delivering security updates right to your computer automatically.” [emphasis added]) There is no way, short of the most outrageous spin, that the WGA update can be considered a security update. By delivering a non-security-related update through this mechanism, Microsoft is breaking that promise.

Stupid mistake #2: The new WGA tool is wrong too often. If you’re going to punish your users, you had better be 100% right about identifying the offenders. Sadly, the new WGA code doesn’t come close to reaching this level of performance. A commenter on my blog reports that he’s now getting incessant notifications that his copy of Windows is not genuine. A close business associate of mine reports the same problem. What do they have in common? Both are using notebooks that had to be returned to their manufacturer for service. The repaired notebooks fail the validation process. A quick scan of recent posts at Microsoft’s WGA forum suggets this problem is unfortunately common.

Stupid mistake #3: The user is left high and dry. If you get a notification that WGA failed, what are you supposed to do? I haven’t seen the failure message myself, but my correspondents tell me it doesn’t offer any helpful steps for resolution. Neither does the Genuine Microsoft Software FAQ, which says:

What if my copy of Windows or Office fails the validation process?

See your reseller and ask for genuine Microsoft software, using the report provided during the validation session for support. The report explains why your system was unable to validate and provides instructions for further follow-up.

Oh, great. Have you ever phoned Dell’s support line? The apparently defective WGA tool is about to plunge an unknown number of users into a support nightmare for no good reason.

So what should Microsoft do now? Simple:

They should send a new update that disables and/or removes the WGA tool immediately, until it’s fixed.

They should set up a toll-free hotline that any Windows user can call if they’re experiencing problems with Windows Genuine Activation. (Microsoft already offers toll-free support for anyone who suspects they may be infected with a virus or a worm, so this doesn’t require a new infrastructure.) The agents on this line should have the authority to help a user override WGA problems.

They should apologize, publicly and profusely, for mixing an anti-piracy tool in with security updates and take steps to make sure that it never happens again.

And they should find whoever pushed the Stupid button in this case and put them on telephone support duty for the next six months. That might be an appropriate punishment. 

[Updated 12-June to fix typo.]

Ed BottEd Bott is an award-winning technology writer with more than two decades' experience writing for mainstream media outlets and online publications. See his full profile and disclosure of his industry affiliations.

Email Ed Bott

Subscribe to Ed Bott's Microsoft Report via Email alerts or RSS.

  • Talkback
  • Most Recent of 122 Talkback(s)
RE: Microsoft presses the Stupid button
Microsoft really pressed the stupid button with forcing people to switch to Live messenger even if they hat/don't want/ can't use it.... (Read the rest)
Posted by: _DC_ Posted on: 09/15/07 You are currently: a Guest | | Terms of Use
Can't argue with any of your points.  No_Ax_to_Grind | 06/12/06
Not to mention  Michael Kelly | 06/12/06
What's in it for Microsoft?  Yagotta B. Kidding | 06/12/06
That would be stupid  Yagotta B. Kidding | 06/12/06
Mailing them back ?  pkrdk | 06/13/06
I don't think he was sufficiently harsh, but I can't argue either...  shawkins | 06/12/06
What are you talking about?  mdemuth | 06/12/06
I don't know..... you tell me.....  shawkins | 06/13/06
I think you missed the point  smoring | 06/12/06
EULA  Anti_Zealot | 06/13/06
Shoot the lawyers-too easy  dewey56 | 06/16/06
Obedience  Harry Bardal | 06/12/06
Huh?  Ed BottZDNet Moderator | 06/12/06
If it looks like, sounds like, and  msolgeek | 06/12/06
Are you happy with your choices?  No_Ax_to_Grind | 06/12/06
Choice  Harry Bardal | 06/12/06
Nice straw man you got there, Harry  Ed BottZDNet Moderator | 06/12/06
He did allow for that possibility  tic swayback | 06/12/06
Bring It  Harry Bardal | 06/12/06
Clarification  Harry Bardal | 06/12/06
Harry, check the source material  Ed BottZDNet Moderator | 06/12/06
Slight correction  Ed BottZDNet Moderator | 06/12/06
My Mistake  Harry Bardal | 06/12/06
No_Ax, what are you talking about?  msolgeek | 06/12/06
What Advice?  nelson.robert@... | 06/12/06
If you're "mostly happy"...  techboy_z | 06/12/06
Stupid?  Yagotta B. Kidding | 06/12/06
shill?  jshaw4343 | 06/12/06
Barrels and more barrels  cfostel | 06/13/06
Microsoft pushes STUPID button  bstalli397 | 06/12/06
Another Stupid Button  ThomasAnderson | 06/12/06
Hidden?  Yagotta B. Kidding | 06/12/06
Yagotta B. Kidding  IceTheNet@... | 06/13/06
Using Knoppix to Explore My Filesystem....  ThomasAnderson | 06/14/06
revealing the stupidness  sevasek | 07/26/06
Most accurate line...  bws111 | 06/12/06
Typo fixed.  Ed BottZDNet Moderator | 06/12/06
Like what?  Chad_z | 06/12/06
Butt.........  mypl8s4u2 | 06/12/06
Why Sue when you can Suse?  IceTheNet@... | 06/13/06
dumb  Suicida| | 06/12/06
The perfect definition....  tic swayback | 06/12/06
Hit the wrong button...  tic swayback | 06/12/06
Limitting Automatic Updates  ssedlson | 06/12/06
Butt.........  mypl8s4u2 | 06/12/06
Auto Updates Off  joseph.r.wagner@... | 06/16/06
Linux copied?  mypl8s4u2 | 06/12/06
No, MS didn't copy Linux  mdemuth | 06/12/06
What?  IceTheNet@... | 06/13/06
Microsoft needs all those pirated copies of Windows out there  Shinsengumi | 06/12/06
Google is your friend  Ed BottZDNet Moderator | 06/12/06
Google shows something that you aren't seeing  smoring | 06/12/06
Did you actually look at those prices?  Ed BottZDNet Moderator | 06/12/06
I absolutley did look at those prices  smoring | 06/12/06
A little context  Ed BottZDNet Moderator | 06/12/06
Show me the link for Windows XP starter edition  smoring | 06/12/06
Sorry, forgot this point in my reply  smoring | 06/12/06
Oh, shoot, I see ... you are the expert  smoring | 06/12/06
Keep searching  Ed BottZDNet Moderator | 06/12/06
Did You Dig Deeper to see what you were buying.  IceTheNet@... | 06/13/06
I think you're looking at multi-user licenses  rock06r | 06/13/06
Good Point: HP doesn't really sell XP Pro for $97  WiredGuy | 06/13/06
Re: Good Point: HP doesn't really sell XP Pro for $97  101010101 | 06/28/06
Ummm!  IceTheNet@... | 06/13/06
Good News  Ole Man | 06/12/06
Just more arrogance from a company out of control...  rayted32 | 06/12/06
Your first point is completely incorrect  rock06r | 06/13/06
Sorry, not true  Ed BottZDNet Moderator | 06/13/06
His first point is correct.  DNSB | 06/13/06
No, he's ABSOLUTELY right  ghastly | 06/13/06
Asinine......Besides That  Ole Man | 06/13/06
Re. Asinine......Besides That  qquidd@... | 06/13/06
Re: Asinine......Besides That  r.allen | 07/07/06
No. He's correct  darkonc | 06/15/06
I'm tempted to ad hominize as I see others doing...  MageOfChaos | 06/15/06
Not a good idea, Ed  Tony Agudo | 06/13/06
microsoft manual  IceTheNet@... | 06/13/06
Stupid a year later!  tonyo711 | 06/13/06
Tired of inane critics  KorVet_z | 06/13/06
Read it again  Ed BottZDNet Moderator | 06/13/06
Stupid How?  IceTheNet@... | 06/13/06
Sorry Dave,  LittleGuy | 06/13/06
It would be nice to have ....  ShadeTree | 06/13/06
I know that these were legitimate installations  Ed BottZDNet Moderator | 06/13/06
I was not suggesting that the examples ...  ShadeTree | 06/13/06
They went back to the mfr  Ed BottZDNet Moderator | 06/13/06
Then it sounds like the bug is associated ...  ShadeTree | 06/13/06
Redefine "fixed"...  techboy_z | 06/13/06
You warez kiddies have no such rights  IceTheNet@... | 06/13/06
Endless whining from MS about piracy  mreilly19 | 06/13/06
You Mean Microsoft Linux  IceTheNet@... | 06/13/06
Novell and IBM are still trying to ...  ShadeTree | 06/13/06
Plenty  IceTheNet@... | 06/13/06
You Mean to tell me that there was a time when they didn't  IceTheNet@... | 06/13/06
Congratulations  shanedr | 06/13/06
Amen Brother!  timbc | 06/13/06
ISA-MCA situation all over again??  Beejaybee | 06/13/06
Piracy not a security issue ?  arty@... | 06/13/06
No its not  quantumstate | 06/13/06
Right On the Money  Sonictoad | 06/13/06
Came on ... dont be so harsh with them. They  michael_t | 06/13/06
WGA  madmaven | 06/14/06
I didn't install it  BlazeEagle | 06/14/06
It still installed something  Free_Thinker | 06/15/06
THAT'S why  btljooz | 06/16/06
WGA Failure Story  Steven_Fuhrman@... | 06/17/06
Genuine Disadvantage  flyby12345 | 06/20/06
MS pain vs migration to other platform pain  jeff_knx | 06/20/06
The last straw  devlin_X | 06/27/06
As Always, Under Control Again  edward_pease@... | 06/27/06
Statute of limitations?  fairness | 06/27/06
Excellent title and article!  LilBambi_z | 06/27/06
my opinion on WGA Micro"bluescreenodeath"soft  101010101 | 06/28/06
Validation  tspo | 06/30/06
Microsoft and their brane storm idea-Genuine Advantage  urncherylsworld | 07/17/06
"Kill Switch" for XP and about WGA  DaveyCrocket | 07/29/06
I Don't Approve Of Theft In Any Form  Cardhu | 09/06/06
So what is the point of buying a new computer system?  troy.loyd@... | 08/03/06
Why Buy Any Microsoft Product  Cardhu | 09/06/06
NOW I get it. Arg!! I HATE Microsoft!!  sevenof9fl | 08/04/06
The Button  lee_in_ftc | 08/04/06
RE: Microsoft presses the Stupid button  _DC_ | 09/15/07

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

Click Here
advertisement

Recent Entries

Premier Vendor Content Whitepapers, webcasts & resources from our Power Center Sponsors
advertisement

Archives

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here