Slashdot Mirror


WGA — Too Many False Positives

An anonymous reader writes, "Microsoft insists that its Windows Genuine Advantage anti-piracy program is nearly flawless. But that's not the impression you get when you visit the company's WGA Validation Problems forum. Ed Bott at ZDNet went through 137 problem reports submitted there during a two-week period, each one accompanied by the output from the official Microsoft diagnostic utility, and found that 42% of the people reporting problems were actually running Genuine software. From the article: 'One large group consists of people who, for some unexplained reason, were displaying cryptographic errors related to digital signatures. The problem is so common, in fact, that Microsoft representatives have a canned response they paste into replies to forum visitors who appear to be showing false positives caused by these errors.' In a related story, the first WGA errors from Windows Vista and Office 2007 have appeared in the wild."

20 of 268 comments (clear)

  1. 42% by LinuxGeek · · Score: 5, Funny

    42%? I guess that is why WGA should be described as "Mostly harmless" rather than "nearly flawless".

    --

    Kindness is the language which the deaf can hear and the blind can see. - Mark Twain
  2. The Spin of the Dot by eldavojohn · · Score: 4, Insightful
    I'm glad Ed Bott was able to discern which people were using genuine software and which had copies. People can get copies from machine vendors without knowing it, you know. Did he have access to Microsoft's database?

    It's more than likely that one of the very few problems you could experience with this software is that it gives you a false positive--therefore a high percentage of forum posts are based on this problem.

    Honestly, do you think that every person who used this with success went straight to the forum boards and posted "Success! Thanks Microsoft!"?

    In a related story, the first WGA errors from Windows Vista and Office 2007 have appeared in the wild.
    Wait, you're trying to tell me that a software program run on thousands of machines has failed in some cases!? No fscking way. That never happens--WGA should be error free--this is unacceptable.

    In the software world, 137 problems on say 5,000 cases of average people using your brand new product is "nearly flawless." I would guess 50% are user error, 42% false positives and 8% other.

    How is this news? Come on guys, I hate Microsoft as much as the next Linux user but I'm not blindly stupid about it ... leave bending percentages and pointing out unavoidable errors to the politicians & corporate America, please! WGA sucks. But let's tear down its principle and theory--not the implementation.
    --
    My work here is dung.
    1. Re:The Spin of the Dot by eln · · Score: 5, Insightful

      The percentage may be exaggerated, but the problem is still significant. The WGA software basically shuts you off from the upgrades you should be entitled to as a valid Windows user. In theory, this would be fine if Microsoft had reliable data as to who is a legitimate user and who isn't. However, it seems that Microsoft's data is not as reliable as it should be. Shutting your customers off from updates the already paid for (by virtue of paying for the software) because you don't have accurate data on who actually bought your product is irresponsible at best.

    2. Re:The Spin of the Dot by Dynedain · · Score: 5, Informative
      I'm glad Ed Bott was able to discern which people were using genuine software and which had copies. People can get copies from machine vendors without knowing it, you know. Did he have access to Microsoft's database?


      If you RTFA, you'd see that they limited their survey to people on the WGA forum who were having problems and upon request ran MS's "WGA Diagnostic" utility and posted the results. That utility throws back one of 4 results: Genuine, Blocked VLK, Invalid Product Key, and Not Activated. So as far as MS is concerned, they are legit, and not copies, but the WGA program still flagged them as not legit because of things other software (like a McAffe "quick clean" product) did to their system.
      --
      I'm out of my mind right now, but feel free to leave a message.....
    3. Re:The Spin of the Dot by nine-times · · Score: 5, Insightful

      Wait, you're trying to tell me that a software program run on thousands of machines has failed in some cases!? No fscking way. That never happens--WGA should be error free--this is unacceptable.

      I think the point is that there are a significant number of apparently legitimate Windows users who are having problems with their computers because of WGA. Since WGA offers no benefit to users, this is an instance of Microsoft taking actions which harm their own legitimate customers because of a policy which doesn't help any customers.

      What I'm saying is, we accept software to malfunction now and then, so when the whole complicated piece of software has a couple bugs, that's expected. When a developer tries to integrate a new feature that benefits large numbers of customers but harms a small number due to a bug, that's forgivable. However, when a developer takes action to punish illegitimate users, developers should tread very lightly. It almost feels like vigilante justice, and you should make sure that it's not an issue for legitimate customers. They might have every legal right to do it, but as a customer, I do find it unacceptable. Microsoft purposefully shutting down an otherwise working system, causing a loss of man-hours, because they've falsely identified it as "suspect"-- I find that to be sufficient reason to complain.

      As if we needed another reason.

  3. My Experience with a WGA False Positive by Kelson · · Score: 5, Interesting

    Back in July(?) when Microsoft issued an update to the WGA tool, I figured I may as well install it (I'd be forced to eventually) on my one Windows box. So I installed it, and rebooted, and the login screen proclaimed loudly that Windows was not genuine. (Well, not literally loudly, it didn't shout over the speakers or anything -- which would be an interesting deterrent, now that I think about it.)

    This came as something of a surprise, given that:

    1. This was a Dell, not some no-name computer.
    2. It still had the original OS install, and no hardware had been changed.
    3. The previous version of WGA had reported no problems.

    I logged in, did some searching on Microsoft's knowledge base, and found a link that said something like "Validate here." I clicked on it.

    To my surprise, it told me my copy was perfectly valid.

    I eventually concluded that Norton Internet Security had blocked the initial validation attempt. Because there was no desktop shell, there was no opportunity for it to pop up a notice and ask me if I wanted it to let the data through.

    After that experience, I can't say I'm surprised that Microsoft found many of their false positives to be the result of security software. Admittedly, they were looking at registry changes, crypto problems and McAfee, rather than a transient error with Norton.

  4. Umm, selection bias....? by Otter · · Score: 4, Insightful
    Ed Bott at ZDNet went through 137 problem reports submitted there during a two-week period, each one accompanied by the output from the official Microsoft diagnostic utility, and found that 42% of the people reporting problems were actually running Genuine software.

    Wild guess here -- people with legitimate software are a lot more likely to submit problem reports than people with bad copies are to post "My 1337 w4r3z w0n7 w0rk! G00d j0b!"

  5. The Question Is... by TheGreatHegemon · · Score: 5, Interesting

    How many false copies of windows pass as authentic?

  6. What about false Positives? by LinuxGeek · · Score: 4, Funny

    Hmmm, I wonder how long it will be before someone is able to get Wine to run the WGA utils well enough to get accepted as genuine.

    --

    Kindness is the language which the deaf can hear and the blind can see. - Mark Twain
  7. What's counted as false positive by dtfinch · · Score: 4, Interesting

    That's when WGA says the copy is non-genuine, and Microsoft's Genuine Advantage diagnostics tool disagrees and says it's genuine.

    What I don't get is why they don't just take the flawless detection code from the diagnostics tool and put it into WGA.

  8. Shouldn't even exist by XanC · · Score: 4, Insightful

    WGA should not exist. It causes hassle for paying customers, that's all. Pirates find their way around. If it worked perfectly, it would be bad enough, but if even one legitimate person is locked out of his computer, MS has some serious explaining to do.

  9. I just don't understand by pembo13 · · Score: 4, Insightful

    Is Windows drug like in nature? It keeps doing things to people, that said people don't seem to like. Yet they keep coming back. I used Windows since 3.1, I never really liked it..but always thought that it was the best thing out there. As soon as I found that things could be better, I slowly moved away from Windows. I am now free enough of Windows that I don't suffer any of these problems that people seem to complain about regularly. It's like windows is the abusive husband, and you all , Windows addicts, are the abused wife....get help people.

    --
    "Thanks for all the money you paid to us. We've used it to buy off ISO among other things" -Microsoft
  10. Re:Not as many as it seems. by Firehed · · Score: 4, Insightful

    How many Windows users could submit a report to the WGA Problems Forum if they had a problem?

    Unlike Slashdotters, not everyone has a spare computer or six kicking around, to deal with just such an occasion. Of course since I switched to Macs, I'm not quite sure what failing the WGA does at this point, but since I've seen the term 'locked out' more than once in this topic, I'll assume it's a bit more hostile than it used to be.

    --
    How are sites slashdotted when nobody reads TFAs?
  11. Re:Apple by garcia · · Score: 4, Insightful

    I had been an anti-Windows person on Slashdot for a long time. Back in November of 2002 I received a computer as a present that included XP (with a key!) I switched over to being a Windows desktop user with a Linux server running everything else.

    Now, with WGA (and my valid key invalidated for whatever reason), I'm now using my Mac and my Linux machines only. I have absolutely no desire to deal w/verifying with MSFT that my install is a valid one. I shouldn't have to as it's THEIR problem.

    While I never trusted MSFT, there was a 3.5 year stretch there where I didn't much care either way. This one incident has turned me around right quick.

    And now, for the machine that I need to have XP on for my wife to do her job, we have used several hacks to get around the WGA and get it what it needs to run. I don't feel the slightest bit guilty about it either. I paid for it and now I'm going to run it.

  12. Why I'm running Linux on this PC by rts008 · · Score: 4, Interesting

    Here at home, out of my 3 PC's connected to the network and internet, 2 of the 3 PC's are currently running pirated copies of XP and have safely passed WGA and currently get their updates flawlessly via AutoUpdate at MS. The reason that is not 3 out of three, is last month I had to replace my HDD, reinstalled my legit, retail WinXP Pro cd, went to MS updates only to be barred from updates and activation because they determined my retail cd was pirated- have had it running on old HDD for 3 years prior with no problems.

    The reason the other two are running pirated XP was an experiment after the legit pirated fiasco on this PC.

    I decided I had had enough, booted into FC5, repartioned the drive to all Linux and haven't looked back.
    Don't care what Vista is like, as I will not even reinstall XP anymore. This weekend, both of the other PC's will get their XP partitions deleted and go back to dual boot Win98se and Ubuntu only. The XP partitions are too small to be more than barely functional, so no sense in trying to leave them running.

    So here is 3 sales/upgrades that MS won't get.

    --
    Down With Slashdot BETA!!! I've been around the corner and seen the oliphant; you can only abuse me from your perspecti
  13. WGA locking legitimate users out by jonasj · · Score: 5, Informative

    I worked in a small local computer shop for a couple of months this summer. The following happened to me two times during that period.

    Some customer would bring in a computer that wouldn't start. We determined that the motherboard was faulty, and replaced it with a similar one.

    Windows starts up, everything works, except it wants to be re-activated again. Online activation fails, so I phone Microsoft, enter the forty-something digit number, reads the product key to someone, who then tells me that they are very sorry, but no, for some reason they cannot give me a re-activation code, so I will have to reinstall Windows in order to get it working with that product key. However, changing the product key works fine.

    So I call the customer and explain the situation to them, and let them choose between:
    1) me taking their harddisk out, attaching it to our backup machine, backing up all their stuff, reinstalling Windows, and all their programs, and all updates, then restoring the backups, and
    2) buying a new xp home license,

    they both chose option 2. That way they would get their machine back with their entire configuration intact, and if they chose option 1, all that work I would have to do would take so long time that they wouldn't be saving much anyway, compared to buying a new license.

    This only happened these two times; most times when we replaced a motherboard, either the reactivation over the internet would work, or the phone representative would give a working reactivation code.

    But these two customers payed for a new XP Home license even though they owned a fully legal one already.

    --
    You know, Microsoft's street address also says a lot about their mentality.
  14. Re:No point whining by Fortran+IV · · Score: 5, Insightful
    You should jump ship to a competitor... Oh wait, you can't be bothered. In that case, tough cheese.
    Oh, please just grow up. What competitor? What other OS runs MasterCAM, Autodesk Inventor, JobBOSS, <shudder>Quickbooks</shudder> and all the other software companies like ours depend on to keep revenue coming in and the IRS satisfied?

    I am sick of Windows, but I'm even sicker of the geek who assumes that just because he switched his home computer—or even his office server—over to Linux that anybody should be able to ditch Windows whenever they feel like it.

    There is a real world out here, and in it there are thousands of small companies that have to use computers to communicate with their customers and suppliers and to keep up with their competitors but that are too small to afford even a part-time IT guru. Companies like that have to buy their accounting software, their production software, their shop management software, their design software—and what's for sale out here in the real world only runs on Windows.

    It's not, "can't be bothered to jump to a competitor". There is no competitor, not realistically.
    --
    I figure by 2030 or so my 6-digit UID will be something to brag about.
  15. nothing is as aggravating as... EXACTLY! by jonasj · · Score: 4, Insightful

    "nothing is as aggravating as realizing how many of the problems are intentional design decisions". You said it.

    --
    You know, Microsoft's street address also says a lot about their mentality.
  16. Re:No point whining by linguae · · Score: 4, Insightful

    Wine isn't perfect. Some Windows applications do not work well under Wine.

  17. Re:No point whining by Pengo · · Score: 4, Insightful

    Some???

    Your joking right.. In my humble opinion, wine is a piece of shit.

    Computers aren't many thousands of dollars anymore, buy a $300 emachine, and run windows on your office computer if you need to. Come on, get real.. who can't afford to buy windows that needs to be running it?

    I can go down to Walmart and BUY a computer with windows and be just fine. If I need to run Peachtree. I have a small business myself (Am a partner), we have about 6 Linux servers.. 1 is running PGSQL, one is running Resin/Java... the rest are running Asterisk. We put them into a 1/2 rack that we pay $400 a month for. We have a office full of windows workstations for our Customer Service, though all of them are using Windows & Xten phones for SIP taking incoming calls on Asterisk from a phone provider who has a sip gateway. Yes , we are windows friendly... but shit.. come on!

    We have an accountant that keeps our books in order, taxes in line.. she uses Peach-tree. if someone thinks a -real- business is going to have a hard time paying $375 for a low end dell, with windows.. to do NOTHING but run Peach-tree... they have their head on backwards. You will spend more than that in man hours trying to get some linux goon trying to get whatever wacky-ass hack-accounting package to work.

    Windows is a commodity, cost of doing business. Running Linux or Mac is nothing more than a luxury, being a linux/java programmer myself.. I don't see any savings at all, I find nothing more than comfort in working in my own familiar environment (My Mac doing Java programming and voiceapp work on Asterisk for Linux servers).. but that's just as expensive as a MSDN membership and paying for windows licenses on servers...