WGA Meltdown Blamed On Human Error
Erris writes "As commentators like Ars Technica slam WGA as deeply flawed, Microsoft is blaming human error and swears it won't happen again. 'Alex Kochis, Microsofts senior WGA product manager, wrote in a blog posting that the troubles began after preproduction code was installed on live servers. ... rollback fixed the problem on the product-activation servers within 30 minutes ... but it didnt reset the validation servers. ... "we didnt have the right monitoring in place to be sure the fixes had the intended effect"' Critics were not impressed. 'A system thats not totally reliable really should not be so punitive, said Gartner Inc. analyst Michael Silver. Michael Cherry, an analyst at Directions on Microsoft in Kirkland, Wash., said he was surprised that it was even possible to accidentally load the wrong code onto live servers ... [and asks], "what other things have they not done?' This is not the first time this has happened, either."
http://slashdot.org/comments.pl?sid=280723&cid=203 75627
This sort of ties in with what I was saying on IRC with my friends yesterday. My central point was that all operating system have got worse over the past ten years.
I'm currently reading the Mythical Man Month (which I imagine most of you of heard of and already read) and in it he talks about the OS/360 operating system in great detail. I'm recalling this from memory so I'm sure someone will correct my mistakes but anyway, the machine had 2MB of memory and the operating system cost 400Kb of the memory. They charged something like $9.50 a month for 1Kb of system memory. That meant that every Kilobyte of memory saved was worth hundered or even thousands of dollars over the life time of the machine.
It made me realise what is in retrospect a fairly obvious statement. The cost of the operating system on your hardware is an effect that should be minizimed. The operating system exists as a framework for runs tasks and applications, not for being a self-serving execuse to munch resources.
While Moore's Law technically means something different; the adage has held true that computing power has doubled every eighteen months. This means that my machine which I bought in January should be roughly 100 times more powerful than the machine I had in 1997. Yet do I have hundred times more power to run my applications on a modern Operating System? Absolutely not.
Strictly speaking, there are no tasks I do today that I couldn't do in 1997. I can be honest that computing hasn't really got easier since then either. There's the odd innovation here and there that's nice from a usability point of view, but fundamentally nothing has really changed. For an example, Office 97 and Windows 98 are no harder to use than XP and Office 2003. The addition of an extra monitor to my compute has impacted my productivity more than the choice of software in this period.
In short, where did all these cycles go?
Now Microsoft Vista is a sort of a post-modern operating system. In every sense it is a regression. It does not allow tasks to be managed easier yet requires an enormous amount of extra resources just to operate. WGA in a sense breaks the very stability of the system. The point of the OS is to perform tasks and applications yet Microsoft can take this away from you either by malice or stupidity.
When are we going to demand more from OS vendors? When are we going to demand that future versions do the same as the previous version with less memory and less CPU overhead? Why do we pay to upgrade only to find our upgrades are wiped out by OS bloat? All of these are interesting questions, and while off-topic slightly, I'd like to see what you think!
Simon
I don't get it?
People make mistakes and as long as people are involved in any process they will cock up from time to time.
The point about systems not being so punitive is a valid one and should be brought up more often and louder. People who've paid money for their product should not be punished for an error on microsofts end.
You are not entitled to your opinion. You are entitled to your informed opinion. -- Harlan Ellison
Sure, for a 24 hour window pirates would have a free-for-all in getting perfectly valid WGA results.
Actually, pirates would probably very quickly figure out how to set the WGA server failure condition in Windows to get the automatic pass without ever actually contacting the real WGA servers, which would render WGA completely worthless. Well... more so.
I don't use Windows, can't stand Microsoft, and had a hearty laugh at the news of the WGA meltdown, but the problem is not as easy to solve from a technical standpoint as you believe.
Microsoft is blaming human error and swears it won't happen again.
Self-contradictory: of all things that could happen out there, one thing will keep happening, and that's human errors.
Realistically, it's just another fail point on your OS that will blow up from time to time.
"we didnt have the right monitoring in place to be sure the fixes had the intended effect"'
This sounds a lot like the Bush administration's excuse... oops!
Seriously, Microsoft is great at monitoring YOUR computer, but they can't monitor their own?
Seven puppies were harmed during the making of this post.
If the pirates are having no problems and it's the legit users who are getting fucked in the ass, why the hell does Microsoft continue to bother with WGA?
.DLL and get on with it, while the legit users will get boned because their serial key wasn't recognized or whatever.
What do they gain? Was WGA suppose to convince people using illegitimate versions of Windows to turn to the light? Fuck that, they'll just download the latest cracked WGA
WGA does NOTHING to hinder piracy, at least not with any level of success that compensates for the negative affects to legit users. It's a complete joke - and yet Microsoft doesn't have the balls to admit this yet. It pisses me off to see such short-sightedness from a bunch of guys who are suppose to be experienced in business.
Look, most of us here work (directly or indirectly) in software. Who hasn't had a launch fail, or a product go bad, in a way that's negatively impacted customers. Such things DO happen. Usually not out of malice, and even sometimes not from carelessness--there are things that sometimes you can't catch on a test system. So to that extent, I feel for the folks who caused this problem..
So why do I call it unacceptable? Because of the difference in standards. On Microsoft's side, they are holding the user to a high level of scrutiny, and reserve the right to cripple some OS features if Microsoft believes the install is pirated. No discussions. Go directly to "aero jail".
Which is possibly understandable if their stance is "look, we're losing billions here--we need to fight piracy." But if they're going to take such radical and punitive measures as locking down OS features based on their tool, then they have to have an absolutely rock solid fail resistant totally monitored system. Basically, they need to hold WGA to a higher standard than most business software. This needs to be the gold standard if they want people to trust the system (and TFA links to a number of other reasonably well-balanced Ars articles that suggest it is not).
Oops, we forgot to monitor the validation boxes? You can't be organic about this--add monitoring for problems as they're discovered on a system this critical not just to Microsoft, but to their customers. You have to anticipate what MIGHT happen, even if "there's no way that should ever occur." You have to think of things that should never happen, but would be problematic if they did.
The fact that they failed here, if it never happens again, might not be a huge deal. But their answer shreds confidence that this is an isolated issue. The fact that this specific failure might not happen again gives me no comfort. Because their answer indicated that they didn't get it when they designed the system, and the don't get it now.
What they SHOULD have said is "boy, this was something we never thought could happen. We have fixed the issue, and are confident we have the monitoring to prevent this specific issue going forward. And we are undertaking a comprehensive review of our validation and monitoring systems to make sure nothing even remotely close to this could ever possibly happen again." Nothing less should be acceptable.
else
default = TrustTheCustomer
I wonder if they considered that?
If WGA or other Microsoft activities are p*ssing you off as a user, then have some strength of conviction and DO SOMETHING ABOUT IT!
Just stop with the continual whining about it...
Gentoo Linux - another day, another USE flag.
So why didn't MSFT just kill the server to let people's software default to "genuine" instead of leaving the server connected with faulty software?
It's an anti-piracy feature. It prevents a business from firewalling the WGA server to get "genuine" status. Remember there was an un-authorised software update site? If it works without the real MS saying it's OK, the anti-piracy feature does not work.
Unfortunately for MS is this feature does not prevent users from migrating to the alternatives. It's hard to run a monopoly when Ubuntu is legal and free for the taking. If they had a choice, the first would be that I run Windows fully paid for. Second choice is that I run a pirated copy, but they are using WGA to prevent that to encourage me into the first choice, but the result is I have gone to their worst option.. I've gone legal to the competition. MS is helping themselves break their monopoly by reducing piracy.
The truth shall set you free!
Don't MS customers like being treated like criminals and being abused in other ways? They are getting what they bargained for. Sorry, no sympathy here.
If you want your life to be different, live it differently.
Humans designed WGA, afterall.
Copyright infringement is "piracy" in the same way DRM is "consumer rape"
What I really wonder about is when will these servers go down permanently? While I hate to do it, I can still install NT3.51 on an old machine if there is a critical need to pull something off an old tape. What happens in the future when WGA goes dark? Will they issue a patch to unlock the OS? At some point MS may have to limit or eliminate backward compatibility. Will virtualization be good enough? This WGA debacle leads me to more questions and concerns than comfort. To me it is not about today. Like the fun with MS formats, it is about tomorrow.
Oh please. You're talking as if there aren't already full cracks for every version of Windows and WGA. That horse left the barn a long time ago. It's perfectly reasonable for Microsoft to prevent "casual" piracy by people who don't know any better, but going to absurd measures to foil serious crackers has never yielded anything but a few days' delay.
LOAD "SIG",8,1
Over the years, I've watched a zillion methods employed to prevent various forms of digital piracy. Generally, the more comfortable a company is that a method will safeguard their product from piracy, the more annoying it is for their legitimate users to employ it. Anyone remember dongle-protected software?
I've worked at several places that legitimately purchased licenses to software, then used cracked versions of what they'd paid for, simply so that they could work in piece without juggling dongles, CD Keys, and other such.
Essentially, any wall that can keep out invaders also hinders legitimate travelers. Any wall that allows access to legitimate guests also allows for the egress of the unwanted.
When we employ truly draconian or paranoid means to safeguard intellectual property, it carries with it subtle risks. Among them, the risk that it won't work well, or will hinder legitimate users while still being exploitable by illegitimate ones.
It's a little like the death penalty. A lot of people would be more in favor of it, if they didn't fear that it was employed unfairly against people who don't deserve it.
If a system is put into place to protect a company against digital pirates, that randomly hassles the company's legitimate users, or if it is, as many pieces of software are today, just completely buggy and bloated (the product of an industry driven just as much, if not moreso, by marketing and artificial deadlines as by a desire for a properly-working product), is it worth it?