Windows IT Pro is the authoritative and independent resource for windows nt, windows 2000, windows 2003, windows xp. Features a collection of resources and magazines for windows IT professionals.
  
  
  Advanced Search 


April 2008

What You Need to Know About WGA Changes in Windows Vista SP1


RSS
Subscribe to Windows IT Pro | See More Products / Hardware Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!

Executive Summary:

Windows Genuine Advantage (WGA) is an antipiracy technology that Microsoft first implemented with XP in 2001. For several reasons, hackers have been racing to circumvent Vista's WGA in various ways. Microsoft has implemented code in WGA for SP1 that disables two of the most common exploits that bypassed activation in the initial shipping version of Vista. But Vista doesn't remove any functionality if WGA determines that your system has become non-activated or non-validated.


While Windows Vista SP1 has been a known quantity since September 2007, Microsoft made a final change to this service pack at the last moment that will affect many customers. Responding to complaints about the way Windows Genuine Advantage (WGA) works in Vista, the company has changed how the antipiracy technology works, beginning with SP1. Now, WGA in Vista will function in a similar fashion to WGA in XP. Here’s what you need to know about the WGA changes in Vista SP1.

What is WGA?
WGA is an antipiracy technology that Microsoft first implemented with XP in 2001. Similar in motive to Windows Product Activation (WPA), which ensures that each copy of Windows is installed only once, WGA raises its ugly head in other situations. You’ll encounter it if you allow an unactivated copy of Windows to reach the activation timeout limit, or, after activation, when connecting to Microsoft’s Web site to download software updates. In this second case, WGA determines whether the copy of Windows is legitimate or illegitimate by examining your system’s product key, hard drive serial number, PC BIOS, and other information. In some cases, legitimate copies of Windows have been flagged as illegitimate by WGA, causing headaches for users, who have been forced to manually try to re-validate their systems or contact Microsoft support. For this and other reasons, hackers have been racing to circumvent Vista’s WGA in various ways.

How WGA Used to Work in Vista
In the original shipping version of Vista, WGA is very aggressive. In instances where the product activation period has expired, Vista switches into something called Reduced Functionality Mode (RFM), where the user can access only Microsoft Internet Explorer (IE) and then only for 60 minutes at a time; at the 60-minute mark, the user is automatically logged out. In RFM, users can also boot into Safe Mode to access documents, perform certain housekeeping tasks, and retrieve important data from a system that will need to be reinstalled. Or, they can use IE to navigate to Microsoft’s Web site to obtain a legal copy of Vista.

If an activated version of Vista fails a validation check while attempting to download a software update of some kind, Vista will switch into a second special functional mode called Non-Genuine State (NGS). NGS can occur if a user makes an unusual number of hardware changes to a system in a short time, causing Windows to believe it has been installed on an entirely different PC. While in this state, certain Vista features—Windows Aero and Windows ReadyBoost—are completely disabled, while other, security-oriented features— Windows Update and Windows Defender—work in limited ways only. Windows Update, for example, will let you download only critical security fixes, while Windows Defender will remove only the most dangerous spyware from your system.

How WGA Works in SP1
After SP1 is installed on a Vista system, RFM and NGS are disabled. Instead, WGA triggers a notifications-based UI that’s very similar to how WGA worked in XP. Users will immediately notice several changes while running a non-activated or non-validated version of Vista SP1. First, a pop-up dialog box appears over the logon screen which can’t be dismissed for 15 seconds; this dialog box warns about the non-activated or non-validated state and provides a button the user can click to rectify the problem.

Second, after the user logs on, several interruptions will occur every hour: The system wallpaper or background will revert to a plain black color, an activation dialog box will flash in the center of the screen, and a yellow Help balloon will appear by the system tray. Each of these notifications can be dismissed and the wallpaper or background changed back. But the same thing will happen again every hour.

Under the covers, there’s another change: Microsoft has implemented code in WGA for SP1 that disables two of the most common exploits that bypassed activation in the initial shipping version of Vista. The first is a grace timer hack that resets the activation grace period out a number of years (in one version of the hack, all the way to 2099). The second is an OEM BIOS hack that intercepts WGA calls to the system BIOS, preventing WGA from accurately determining which hardware changes have been made to the system. Users who are utilizing either of these hacks and install Vista SP1 will have an interesting experience: Their PCs will suddenly enter a grace period countdown after SP1 is up and running and work as Microsoft intended. After the grace period expires, they will be presented with the new WGA behavior unless they successfully activate the system. The big change is that Vista doesn’t remove any functionality if WGA determines that your system has become non-activated or nonvalidated— other than the hourly interruption of a black screen, which is surprisingly subtle and not as annoying as it sounds. Vista SP1 otherwise works normally and to full capacity.

Recommendations
Microsoft’s changes to WGA are a huge improvement over the initial shipping version of Vista and should make Vista more attractive to businesses of all sizes. The issue here isn’t so much piracy. There have been too many instances over the past year where WGA incorrectly flagged legitimate Vista systems as illegitimate. The only solution to this problem is for Microsoft to drop WGA entirely. But since that’s not going to happen, this change is welcome, if overdue. Vista SP1, overall, remains highly recommended: This is an update that all Vista users should install as soon as possible.

End of Article



Reader Comments

You must log on before posting a comment.

If you don't have a username & password, please register now.




Learning Path To Learn More About Reduced Functionality Mode
"Learning About Vista's Reduced Functionality Mode"


To Learn More About WGA
"What You Need to Know About Microsoft’s Antipiracy Efforts"


Top Viewed ArticlesView all articles
Friday at PASS Europe 2006

Kevin talks about the closing day of the event and shares a funny Microsoft film. ...

More fun TechEd 2005 Resources

Kevin points out some more TechEd resources ...

What service packs and fixes are available?

...


Related Articles How Do People Hate Vista? Let Me Count the Ways…

Windows OSs Whitepapers Why SaaS is the Right Solution for Log Management

Are You Satisfied?

A Preliminary Look at Deployment Plans for Microsoft Windows Vista

Related Events Check out our list of Free Email Newsletters!

Windows OSs eBooks Understanding and Leveraging Code Signing Technologies

A Guide to Windows Certification and Public Keys

SQL Server Administration for Oracle DBAs

Related Windows OSs Resources Become a VIP member of the Windows IT Pro community!
Get it all with the VIP CD and VIP access. A $500+ value for only $279!

Subscribe to Windows IT Pro!
Solve your toughest technical problems with our experts and access 10,000 + articles online. 30% off

Monthly Online Pass - Only $5.95!
Get instant access to 10,000+ articles from Windows IT Pro Magazine!

TechNet Virtual Labs
Evaluate and test Microsoft's newest products.

Job Openings in IT


ADS BY GOOGLE SPONSORED LINKS FEATURED LINKS

Microsoft Exchange & Windows Connections event returns to Las Vegas Nov 10 - 13
Connections returns to Las Vegas for this exciting event where each attendee will receive SQL Server 2008 standard with 1 CAL. Co-located with Microsoft ASP.NET, SQL Server, and SharePoint Connections with over 250 in-depth sessions.

Free Online Event! Virtualization:Get the Facts!
Register now and attend this free, live in-depth online conference on November 13 and 20, 2008, produced by Windows IT Pro. All registrants are eligible to receive a complimentary one-year digital subscription to Windows IT Pro (a $49.95 value)!

Check Out Hyper-V Video on ITTV
Watch Karen Forster's interview on Hyper-V's performance on ITTV.net.

Ease Your Scripting Pains with the Flexibility of PowerShell!
Join MVP Paul Robichaux on December 11, 2008 at 11:00 AM EDT as he equips you with PowerShell basics in 3 introductory lessons, each followed by a live Q&A session—all on your own computer!

Latest Advancements in SSL Technology
There are a variety of different kinds of SSL to explore to ensure customer data is kept confidential and secure. In this paper, we will discuss some of these SSL advances to help you decide which would be best for your organization.

PASS Community Summit 2008 in Seattle on Nov 18-21
The don’t-miss event for Microsoft SQL Server Professionals. Register now and you’ll enjoy top-notch Microsoft and Community speakers and more.



Solving PST Management Problems
In this white paper, read about the top PST issues and how to administer local/network PST Files.

Get Protected -- Data Protection Manager 2007
Protect your virtualized environment with Data Protection Manager

Order Your SQL Fundamentals CD Today!
Learn how to use SQL Server, understand Office integration techniques and dive into the essentials of SQL Express and Visual Basic with this free SQL Fundamentals CD.

Maximize Your SharePoint Investment: Get Your Data Moving
Watch this web seminar now to learn how to maximize your SharePoint investment! Join us as we take a look at the complex business of securing, accessing and managing vast amounts of information in a global network and various ways to get your data moving.
Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro Windows Dev Pro IT Job Hound ITTV
IT Library Technology Resource Directory Connected Home Windows Excavator Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 Copyright © 2008 Penton Media, Inc., All rights reserved. Terms and Use | Privacy Statement | Reprints and Licensing