The Active Network
ActiveWin Anonymous | Create a User | Reviews | News | Forums | Advertise | VBA in Excel | Users Online: 0  
 

neowin.net

Amazon.com

  *  

  Cancelling WGA Installation sends a report to Microsoft
Time: 00:09 EST/05:09 GMT | News Source: *Linked Within Post* | Posted By: Kenneth van Surksum

The German computer magazine CT (English translation using google translate) analyzed the new WGA Notification that is installed during Windows Update. They decided to cancel the installation and immediately after doing so the firewall reported that update.exe tried to connect to the internet. This caught their attention of course and they decided to analyze the data that was send after the connection was established.

They used Wireshark to analyze the traffic and found out that update.exe sends data to genuine.microsoft.com. Some of the data seems to be encrypted while some could be identified. It sends registry information, namely the SusClientID as well as information about the version of the WGA tool, the windows version and the language of the operating system. It also sets a cookie which contains a GUID which could possibly be used to identify the computer.

Microsoft confirmed to the magazine that data is send but it would only be used to optimize the service. The GUID in the cookie would only be used to count all attempts in the most thorough way possible, it would not be used to identify the host.

Read Only Comments
Return to News
  Displaying Comments 1 through 8 of 8
  This is an archived static copy of ActiveWin.com.
#1 By 3653 (68.52.143.149) at Wednesday, March 07, 2007 01:19:19 AM
calling all tinfoil-hat wearing morons... please comment below.

#2 By 37047 (216.191.227.68) at Wednesday, March 07, 2007 07:44:00 AM
Calling all brown-nosed Microsoft apologists... please comment above.

#3 By 8556 (12.207.97.148) at Wednesday, March 07, 2007 08:26:54 AM
My hat is aluminum foil with gold lace trim. Very effective against people that call other people names when they have a different point of view.

#4 By 28801 (65.90.202.10) at Wednesday, March 07, 2007 10:09:20 AM
#3: You chrome dome!

#5 By 8556 (12.207.97.148) at Wednesday, March 07, 2007 10:32:47 AM
#4: Chrome would be so cool!

#6 By 13030 (198.22.121.110) at Wednesday, March 07, 2007 02:15:23 PM
#3: gold lace trim

l33t!

#7 By 48398 (130.13.157.134) at Thursday, March 08, 2007 12:05:38 AM
Honestly though, I've cancelled this update many times because I have a lot of computers that run the DG8FV key for one reason or another and I don't want to see the prompt. It's the only code I have memorized so far. On a couple of the PCs I've hit the cancel button, it takes quite a while to exit. I never checked ISA to see what was going on but I've always suspected this.

When it comes to illegal software, what's to stop somebody from going to a Fry's or Best Buy or Comp USA, writing down the OEM code on a display machine, and calling it in? Nothing. That's why this activation garbage is all irrelevant.


#8 By 2960 (24.254.95.224) at Friday, March 09, 2007 10:50:40 AM
If the freakin' thing would not ask me to validate EVERY SINGLE TIME I went to a MS download page, I wouldn't give a crap.

As it is now, it's a 100% annoyance, plain and simple.

Install once. Check once. Then leave me the hell alone. That's the way it should be.

TL



 

  *  
  *   *
 
replica watches