WinXP Keygen Foils Product Activation

timothy posted more than 12 years ago | from the next-generation-will-require-dongles dept.

Microsoft 559

Bill Gates' Friend's Brother's Roommate writes: "The Register has a story on a working key generator that produces 25 valid Windows XP Product Activation Keys in a few hours. As author John Lettice summarizes, 'So the question as regards keymaking software is whether or not Microsoft has any way to differentiate between generated keys and the ones it has issued itself. If not, this generation of WPA is now surely toast.'"

Weird (5, Interesting)

glh (14273) | more than 12 years ago | (#3009768)

Don't they have some kind of database with all the keys in it.. (after all, a lot of games out there such as anything newer by blizzard works that way)!

Re:Weird (5, Insightful)

MattRog (527508) | more than 12 years ago | (#3009802)

I don't know entirely how WPA works, but I know with most games you *can* use a keygen for most of the codes. If they are 'well-formed' and comply with their format then the game will accept it. However, only a select number of the 'possible' working keyset is actually *valid*, meaning it exists in their large database.

I would suspect that would be the case here; the question is whether or not that false key once accepted by the program is transmitted back to Microsoft for validation.

Re:Weird (5, Informative)

Mister Snee (549894) | more than 12 years ago | (#3009830)

Actually, some companies do it the way you describe (with a database of known keys) but Blizzard does something slightly different, which Microsoft may do as well.

In Blizzard's games, the routines used by the installer to verify authenticity of a CD key actually checks for compliance to a much more broad algorithm than the keys are actually manufactured by. This means that methods of generating keys reverse-engineered from the game itself will produce keys that work for installing the game but are very likely outside of the real algorithm, which usually constitutes a tiny subset of the one used for installation. This REAL algorithm is used to manufacture the CD keys and is what is checked for on, for instance, the multiplayer servers. Since that checking is serverside it theoretically can't be reverse-engineered to a keygen. Lots of companies are doing this now -- most game keygens are fine for installing but won't play online, and while it's possible for the keygen to randomly hit on a key that falls within the real algorithm and thus allow online play, it's astronomically unlikely.

Quite smart, really. :D

Re:Weird (-1, Flamebait)

Anonymous Coward | more than 12 years ago | (#3009949)

In Blizzard's games, the routines used by the installer to verify authenticity of a CD key actually checks for compliance to a much more broad algorithm than the keys are actually manufactured by.

/me scratching head

Am I the only one wondering if this sentence was generated by a crypto algorithm?

Re:Weird (3, Funny)

Lord Sauron (551055) | more than 12 years ago | (#3009971)

I know of a CD-Burner software that if you enter a fake serial number, appears to be registered ok, but when you would burn a CD, it'd say there was an error, and your CD was lost.

Windows could pretend it was registered ok, and then start crashing, after some time.

But, oops, no one would notice between a crashing windows and regular windows :)

Re:Weird (4, Interesting)

govtcheez (524087) | more than 12 years ago | (#3009992)

> Quite smart, really.

Except that every Blizzard game I've ever played would be just peachy if a reg-code of all 3's was typed in. Seriously.

Re:Weird (1, Insightful)

AdTropis (6690) | more than 12 years ago | (#3009993)

one note: this method assumes that the auth key will actually make it to the auth server. it is entirely possible for someone to write their own version of the auth server and then, through creative /etc/hosts entries, DNS entries, or whatever, have the game verify auth from a locally running server (that takes anything and simply says "VALID").

i don't know if you could really get away with this since blizzard's stuff is more centralized, but i think this is a problem that id has had to face.

Re:Weird (3, Funny)

Luminous (192747) | more than 12 years ago | (#3009940)

They do have a database of the keys, but it was secured with a password and they can't remember what it is. They would use one of those programs that crack Access passwords, but that just seems wrong.

Stating the obvious (0, Redundant)

Joe U (443617) | more than 12 years ago | (#3009769)

It's doubtful the keys are completely random, so It's possible that Microsoft may have a way to detect them.

The Register (0)

Anonymous Coward | more than 12 years ago | (#3009783)

I guess this story will turn out to be a complete fabrication then.

But what about Microsoft snooping on your key? (5, Insightful)

2Flower (216318) | more than 12 years ago | (#3009788)

While this gets you out of the gate and running, it still means you have an unregistered key. If ever your key is reported back to Microsoft and they do a simple record check, they can tell if you're valid or not. And then the FBI is just a phone call away...

I don't mean to say WinXP is spyware (although I wouldn't doubt it) but I can't see keeping your activation key a secret for long, with it likely being tied into so many products and services. It's like running around town buying beer with a blatantly fake ID that claims you're a 78 year old airline instructor from Zanzabar -- sooner or later you'll get caught.

Re:But what about Microsoft snooping on your key? (2, Insightful)

Anonymous Coward | more than 12 years ago | (#3009823)

Spyware is not easy to sneak by. Think of how many smart people have a BSD firewall sitting in front doing transparent firewalling while logging every single packet that goes by?

If anything goes to a MS address, they'll be sure to let us know. I mean, outside of major contributions to the Linux kernel, catching Microsoft red-handed trying to fsck us over is one damn quick way of becoming a folk hero among the Slashbots, if not the internet geek population in general.

Re:But what about Microsoft snooping on your key? (1)

Lord Sauron (551055) | more than 12 years ago | (#3009919)

Not only this, but the FTC and lots of organizations would go after MS, if it spyed on its users.

But, even if MS did this, they'd at most know that there's a machine running a fake license on IP address xxx.xxx.xxx.xxx .Specially in the case of home users, it's not that easy to phisically locate a machine given its IP address. It requires colaboration of the ISP, and this usually only would do this with a court order.

MS wouldn't risk being fscked by the government for a mostly useless information.

It's safe to say: Windows XP is no spyware.

Re:But what about Microsoft snooping on your key? (3, Funny)

strAtEdgE (151030) | more than 12 years ago | (#3009828)

Ya, so, I mistyped my key and the computer thingy said it was okay. I threw away my boxes and manuals and what have you because windows XP is so stable that I'll never have to install it again. So what?

Re:But what about Microsoft snooping on your key? (2)

micromoog (206608) | more than 12 years ago | (#3009864)

Ya, so, I mistyped my key and the computer thingy said it was okay

So I think "there's only a one in 80 zillion chance of this happening" would hold up in court for Microsoft.

Re:But what about Microsoft snooping on your key? (1, Funny)

Anonymous Coward | more than 12 years ago | (#3009911)

So I think "there's only a one in 80 zillion chance of this happening" would hold up in court for Microsoft.

Like it held up for the Rpublic of California vs O.J. Simpson?

Re:But what about Microsoft snooping on your key? (1)

coug_ (63333) | more than 12 years ago | (#3009937)

So I think "there's only a one in 80 zillion chance of this happening" would hold up in court for Microsoft.

Well.. it didn't put OJ away..

Re:But what about Microsoft snooping on your key? (2)

geekoid (135745) | more than 12 years ago | (#3009948)

So, theres a chance?
that is all anybody would here.
How do you think OJ got arond the genetic evidence?

Re:But what about Microsoft snooping on your key? (1, Funny)

Dixie_Flatline (5077) | more than 12 years ago | (#3009861)

But I AM a 78 year old airline instructor from Zanzabar. Am I in trouble?

Re:But what about Microsoft snooping on your key? (-1, Redundant)

Anonymous Coward | more than 12 years ago | (#3009939)

It's like running around town buying beer with a blatantly fake ID that claims you're a 78 year old airline instructor from Zanzabar -- sooner or later you'll get caught.

But I AM a 78 year-old Zanzibarian flight instructor!

Big Surprise (2)

Renraku (518261) | more than 12 years ago | (#3009791)

"The more you tighten your grip, the more people that will slip between your fingers" The more you try to make people jump through to get their OS, the less will put forth the effort and will seek 'alternative' methods to get it.

Well, yes (1, Interesting)

Anonymous Coward | more than 12 years ago | (#3009803)

We can tell by checking your Activation ID against our database. If it isn't in their, it isn't properly registered.

We've got your MAC address, so it isn't like it's a big deal to verify the AID against that to make sure you aren't just loading the OS across multiple machines.

Basically, this system will work as long as you don't connect to the internet.


It's a security issue (2, Interesting)

NewtonsLaw (409638) | more than 12 years ago | (#3009806)

Given that the activation code is used to secure XP from unauthorized use -- I guess you could say that this is a security issue.

Given Microsoft's rather lackluster track-record in the area of security, is it any wonder that their own protection scheme has (allegedly) been cracked so soon?

Maybe they wrote it with the new C++ compiler :-)

Re:It's a security issue (0)

Anonymous Coward | more than 12 years ago | (#3009907)

It warms my heart they work as hard on their own security protection as they do everyone else's.

Bound to happen... (1)

Daniel Wood (531906) | more than 12 years ago | (#3009813)

While this may be stating the obvious, we all knew that a key generator would eventually come along. After all, nothing is unbreakable....

Re:Bound to happen... (3, Funny)

jhaberman (246905) | more than 12 years ago | (#3009900)

After all, nothing is unbreakable....

The only exception being, of course, Bruce Willis in the movie of the same title...

But I digress...


Similar "Ooops" in Microsoft Office X (4, Informative)

BoarderPhreak (234086) | more than 12 years ago | (#3009818)

If you use MacOS X's built-in firewalling capabilities (really just ONE command-line) you can not only block their anti-piracy, network-broadcasting bullshit...

But fix the security hole they put in box, as well!

Woohoo! :-D

Re:Similar "Ooops" in Microsoft Office X (1)

kwj8fty1 (225360) | more than 12 years ago | (#3009875)

If you only have ONE command line, I don't expect your firewall to really be very effective, or flexible.

*real* firewalls (PIX, Ipf, ipchains, etc) allow you configure any aspect of the IP/ethernet traffic.

Regardless, I'd bet my lucky dollar that they use standard http[s] for sending out registration, etc. Otherwise, many corp. firewalls & proxies will block it.

Re:Similar "Ooops" in Microsoft Office X (-1)

SweetAndSourJesus (555410) | more than 12 years ago | (#3009986)

and the code is:

ipfw add 0 deny udp from any to any 2222
ipfw add 0 deny tcp from any to any 3464

This just generates the keys... (2, Interesting)

reemul (1554) | more than 12 years ago | (#3009819)

As far as I can tell, the user still needs to contact the MS server and go through the validation process. At the very least a key that has already been used will be rejected. At worst, MS will log all attempts and check that the key came from the correct geographical region that the boxed product was shipped to, and disable copies that don't match even if the key hasn't been used before. It's a huge hole in the security, but the end users are still going to be bothered. The worst of all possible worlds.

All of the folks looking for a free copy are better off finding a copy of the corporate edition, which doesn't phone home.

Re:This just generates the keys... (1)

kkith (551310) | more than 12 years ago | (#3009843)

"All of the folks looking for a free copy are better off finding a copy of the corporate edition, which doesn't phone home."...totally agree

Re:This just generates the keys... (3, Interesting)

Aexia (517457) | more than 12 years ago | (#3009938)

I couldn't tell from the article, but I assume you would go through the "I don't have internet access so I'm 'talking' on the 'phone' to a 'representative' of 'Microsoft' who has 'provided' me with this 'key'" process.

Otherwise, it'd be pretty useless.

Re:This just generates the keys... (2)

Wesley Felter (138342) | more than 12 years ago | (#3009963)

This app generates CD keys, which you have to send to MS to get the activation key that you need to activate Windows. So the only way to use this tool is to "phone home" to MS.

Can we say Service Pack 1? (1)

glh (14273) | more than 12 years ago | (#3009822)

see subject :)

Re:Can we say Service Pack 1? (0)

Anonymous Coward | more than 12 years ago | (#3009932)

Bet you 10 dollars that M$ will make service packs look for hacks to XP and disable the OS if it does find them.

Many responses (0, Flamebait)

Kphrak (230261) | more than 12 years ago | (#3009829)

My guess is that there will be many responses to this article...and the gist of most of those postings will be:

"D00d M$ sux...anyone got that keygen yuo're talking about I wanna crack it and be l33t oki? I just want ot use XP with my RedHat Linux b0x..."

Etc etc etc. :)

Intellectual build up (1, Funny)

acherrington (465776) | more than 12 years ago | (#3009831)

This goes with the same old balance theorey. For every person building, there is an equal and opposing balancing force in the destruction of code. The question here, is which is the person building, and which is the one destructing?


Changes? (1)

NWT (540003) | more than 12 years ago | (#3009833)

Well, what will they do with these keys? Sell them? IMHO it doesn't matter if you've got a generated key, or if you just grad one from the noumerous crack-serial sites around the net!
If MS detects these generated serials, they may also detect duplicate Keys ...

25 keys in one night with one PC (5, Interesting)

J.D. Hogg (545364) | more than 12 years ago | (#3009834)

That means you probably could get 25000 keys in one hour if distributed.net was setup to do that. Even DES is harder to crack. That should tell you something about the extent of Microsoft's understanding of security issues if they can't even protect their own bread and butter correctly.

If Microsoft doesn't have a database of #s... (3, Funny)

Navius Eurisko (322438) | more than 12 years ago | (#3009836)

then they are grossly mishandling their activation system or they seriously underestimate the intelligence of most Windows users.

Considering M$, I think it's a little of the former and the latter.

Re:If Microsoft doesn't have a database of #s... (0)

Anonymous Coward | more than 12 years ago | (#3009886)

....or they seriously underestimate the intelligence of most Windows users

Isn't that one obvious? We are talking about Windoze users aren't we?

Re:If Microsoft doesn't have a database of #s... (0)

Anonymous Coward | more than 12 years ago | (#3009976)

then they are grossly mishandling their activation system or they seriously underestimate the intelligence of most Windows users
Microsoft seriously underestimating the users intelligence? You mean the "Start" button with the spiffy "-- Click Here to Begin" wasn't a good giveaway?

build a better mouse-trap... (0)

Adolatra (557735) | more than 12 years ago | (#3009837)

...and someone will build a better mouse. The only solution I can see is for Microsoft to hire a 6'8" Sicilian named Rocco Knuckles to traverse the country and check every end-user running XP, enforcing the DMCA and MS's activation code policies with extreme prejudice.

You have the right to use the software you buy (0, Informative)

Fair Use Guy (556967) | more than 12 years ago | (#3009838)

...and Microsoft has no right to force you to register it with them first. It's kind of like asking for I.D. when you pay with cash to "keep the honest people honest."

To that end, here is a copy of the keygen. Please do not use it if you have not paid for Windows XP.

For the curious (5, Informative)

Starship Trooper (523907) | more than 12 years ago | (#3009895)

I was trying to decode this, but was having trouble with it until I figured out that it is in base64 encoding, not uuencode (as it appeared at first). If your Linux or Unix distribution does not have base64 installed by default, you can get it at http://www.fourmilab.ch/webtools/base64/ [fourmilab.ch] . Thank you, Fair Use Guy, for promoting this tool.

Decoder (4, Informative)

Anonymous Coward | more than 12 years ago | (#3009920)


use MIME::Base64; $x = ""; while(<>) { $x .= $_; $x =~ s/[\r\n\t ]//g; } print decode_base64($x); exit 0;

Re:You have the right to use the software you buy (2, Insightful)

Sc00ter (99550) | more than 12 years ago | (#3009925)

If their licence agreement says you have to register with them. Guess what, you have to register with them. You don't like that policy, don't buy the product!

Re:You have the right to use the software you buy (2, Insightful)

bnenning (58349) | more than 12 years ago | (#3009958)

Assuming that license agreements are valid, which is far from certain.

Re:You have the right to use the software you buy (2, Insightful)

Rude Turnip (49495) | more than 12 years ago | (#3009988)

If I can't see the "license" before I purchase the software and actually sign a contract, then there is no "license," IMO. The only rights retained by MS are copyright...meaning I can't distribute copies of the software to third parties...period.

If I treated my clients this way, I'd be out of business. The fact that MS has tons of money and lawyers to strongarm people into complying with their wishes does not make them right by any means.

How is this news? (1)

Multiple Sanchez (16336) | more than 12 years ago | (#3009846)

This is no different than the cracks for popular video games like Quake or Wolfenstein. The false serial will pass the local algorithm check, but try to register it online, and it fails a simple database lookup of serials actually issued. And the chances of generating a serial that's actually been issued by MS are beyond remote.

The only application I can see is creating a large list of valid serials and trying to bombard the authentication server with requests. But that seems both unweildy and rediculous.

Hasn't the software industry learned? (2)

reynaert (264437) | more than 12 years ago | (#3009854)

Any registration key scheme can be cracked. Shareware people have know this for decades. They can make it difficult to crack (and a couple of hours to generate a few keys is quite good), but they can't make it impossible.

The best way is to verify the key on-line if the key is assigned to you, but this is only feasible with small-scale shareware programs, because in that case very few of the possible keys are assigned (so the chance of generating an assigned key by accident is very low), and the author of the program knows of every sold copy (while Microsoft doesn't know of a particular copy of XP is actually installed somewhere, or is lying in some warehouse)

Even if they can detect the difference... (2, Insightful)

immanis (557955) | more than 12 years ago | (#3009856)

Does anyone expect jack-booted MS employees to come kicking in their doors and arresting them for having a invalid product key?

Let's face it, as much as MS needs to say they will come after people who pirate their software, they aren't going to come after individuals. Unless you are killing a significant portion of their business, they are likely to leave you alone.

They would rather an individual use a pirated copy of their software than someone elses, because it still puts them in your house. They still have a good chance of branding, selling you MS Money, Office or some other product.

Can't say that out loud though. Might loose too much business.

kinda like many online games (0, Redundant)

chronos2266 (514349) | more than 12 years ago | (#3009858)

the WinXP activation key seems very similar to the key used by many online games. sure you can play single player, but if you try to go online, you will be rejected when you try to authencate.

And the award for thinking short-term goes to... (3, Funny)

Tackhead (54550) | more than 12 years ago | (#3009862)

> [ ... ] while forum operators are in general managing to keep a lid on people posting locations for the program,

The Register's editors have obviously misspelled "Now that it's made Slashdot's front page, for about 10 more minutes..."

Shouldn't it say.. (1)

attackiko (170417) | more than 12 years ago | (#3009863)

"If not, this generation of WPA is now surely toast"

If true, this John Lettice is now surely toast.

True Protection (1)

eastshores (459180) | more than 12 years ago | (#3009866)

So long as there is a desire to have the product without paying for it, there WILL be someone capable of producing software which makes the masses giggle as they unlock their new free software. It looks as if MS is doing better if this software takes hour(s) to generate a key. I must be run on each computer individually if my understanding is correct? Eventually their efforts will pay off in the same way the rediculous measures many companies are putting in place to stop CASUAL copying of software. Either that, or it will explode into a revolution where skilled crackers have had enough and produce cracks that render the measures transparent for entire masses of people. Downloading ISO's is getting much easier these days.. they will have to do something.

The ultimate protection (5, Insightful)

tuxlove (316502) | more than 12 years ago | (#3009869)

There's no way to make a crackproof piece of software. If a user has access to software, he can crack that software. Period.

However, as the article notes, cracked software can be detected. No matter how good the cracker, there's little that can be done against online verification. If MS keeps a record of all valid keys, then anyone attempting to use online MS services of any kind with a genned key can be detected and denied/disabled.

This is an old trick for online games, etc. Crackers come out with keygens for such games almost simultaneously with the release of the games (or even before :), but these keygens only work for the offline version of the game. As soon as the someone tries to use that game online, they're denied access by the game server because their genned key isn't in the database of valid keys in the field.

So, this story has little import as far as MS' protection being faulty. I have no doubt they expected it, and I have no doubt that they don't care too much. Using Win XP w/o the ability to update or connect to certain online services safely will probably end up being more than sufficient protection from MS' viewpoint.

Show me the proof. (1)

Ruis (21357) | more than 12 years ago | (#3009870)

I'm going to need to see this program for myself..

Re:Show me the proof. (0)

Anonymous Coward | more than 12 years ago | (#3009954)

I've already downloaded several different crackers and techniques for sidestepping this WPA crap.

They are easily available on the web. Just do a google search for "WPA crack keygen"
and you're off and running.

In other news... (0)

Anonymous Coward | more than 12 years ago | (#3009871)

In other news,

Today, M4d 1337 cr3w released a totally k3wl cr4k for 0ffic3 2003 and Bryce 8.8.
Props to Phr0zen Kru, and D0D and all mah bitch3z j00 know who j00 are.

Props to all dead homi3z.

PS .. The cr3w who r3l3asd the XP K3yg3n are 14m3.

I wonder how that program works... (3, Funny)

m_chan (95943) | more than 12 years ago | (#3009879)

BILL: Are you the keymaster?

VENKMAN: Not that I know of.

(Bill slams the door in his face - Venkman knocks again.)

BILL: Are you the Keymaster?

VENKMAN: Yes! Actually I'm a friend of his, he asked me to meet him here.

Wash, rinse, repeat...

bUT tHEN (0)

Anonymous Coward | more than 12 years ago | (#3009884)

as soon as you hop on the web with your bogus activation MS sends a squad car to your house and then you're downtown quick for a violation of the DMCA.

Ultimately crackin is going to put more people in the pokey than crack. JMO.


Eventually (1)

balthan (130165) | more than 12 years ago | (#3009885)

Eventually I suspect they'll track each copy individually (which store it was shipped to, if/when it was sold, etc.) and be able to research discrepancies. Like if a copy is activated, but the store it was send to still has it listed in their inventory. It would just be a matter of getting the retail stores to cooperate.

Tell me.... (2, Funny)

tfurrows (541222) | more than 12 years ago | (#3009944)

... if a group of people follows you in committing Karma suidicde, does that make it a cult suicide?

Aren't they're laws against this sort of thing? Moderators, can't you do something to stop this madman before he gets a following? Is nothing holy?

In any case, it sounds like a load of fun to me. Count me in My Master.

This is a bit late in the game to even care... (4, Interesting)

Da VinMan (7669) | more than 12 years ago | (#3009893)

WPA was 'cracked' before the product even went retail. From the device game circumvention game to binary hacked versions of XP on the 'net, WPA is not a barrier to obtaining an illegal copy of WinXP.

Given that WPA is effectively not a barrier at all (for any but the most in-need-of-a-clue user), why even bother? Windows-based revenue will clearly not rise because of these measures, and it will in fact scare away the set of users that qualify as casual copiers. Microsoft won't gain any money out of this, but they will lose mindshare.

But really, all the above only applies to those who would venture to re-install Windows. I would guess that involves less than 5% of Windows users. In other words - almost no one. Microsoft is still VERY dependent upon the OEM teat AFAIK.

If I'm right about that, then WPA doesn't even matter. Why they're putting up such a fuss with consumers over this is a complete mystery to me. They will not profit by it.

Am I missing the boat on this somehow? This whole thing just seems stupid to me.

It's not the serial number that's important. (3, Interesting)

gpinzone (531794) | more than 12 years ago | (#3009902)

It all depends whether or not Microsoft keeps a world-wide database of valid product keys for each and every version of Windows XP sold. I used to work for an employer that had a system that registered EACH and EVERY serial number of a product BEFORE it was sent out to distribution. We could track the usage and blacklist any of the "products" we wanted. The system even was smart enough to detect fraud based on a number of criteria (like if two serial numbers showed up at the same time). any serial numbers that existed that weren't in the database were blacklisted automatically.

I have to wonder if Microsoft has done this? I mean, logging every single serial number for every copy of WindowsXP produced everywhere in the world...and then maintaining it. That's a tall order, even for them. I think they'd get more bang for the buck by blacklisting every copy of XP that uses that "FCK" serial that was distributed like crazy.

I can hear the DMCA lawyers warming up now ... (2, Insightful)

Bob Loblaw (545027) | more than 12 years ago | (#3009908)

Since Microsoft has a nice cache of anti-trust laywers acquired to create a vaccuum for the government, they now have a new task to throw them at.

Time to send the code underground a la decss.

I think they will let it go (5, Insightful)

tester13 (186772) | more than 12 years ago | (#3009909)

The article makes mention of Microsoft possibly breaking illegally copied versions of XP corporate via patch in the future. They have not done this yet, and I do not think they will. Think of the public relations nightmare that would ensue if MS broke even some legitimate copies (licensed copies with wrong serials).

It has been said before, but the determined "pirate" will not be deterred by inconvenience.

I think they know its not worth their while.

MS priorities? (1)

krony (213134) | more than 12 years ago | (#3009914)

We'll now see where Microsoft's real Security Initiative priorities lie. They'll probably secure this issue faster than securing holes in IE or OE, based purely on the fact that it is reducing their cash flow in. Sad, but true...

Well they won't accept their license agreement... (5, Interesting)

Nailer (69468) | more than 12 years ago | (#3009916)

By allowing me to decline their license and give me the refund they promise if I do so, I don't see why I should accept it and activate periodically.

ncftp -u xpkey -p xpkey -P 6473

Corperate codes (2, Insightful)

Red Weasel (166333) | more than 12 years ago | (#3009921)

Who here doesn't know of at least 1 person who has a corp code. I'm in a shop full of geeks so it was only a matter of time before someone somewhere got a hold of a decent CD key.

Add to that the number of times people will reload there machines to get it "just right". Everyone and thier brothers are using any code they can get so that they don't have to bother Microsoft in order to just play.

So now a new hack that will do it for you. To late as far as most are concerned.

Already A Crack (2)

Angry Black Man (533969) | more than 12 years ago | (#3009926)

Released on 1/07/2002 was a "Universal Activation Crack" by a major warez group. I would confirm that it works, however in fear of the FBI raiding my house (a la Hackers the movie) I will say that I haven't tried it.

want to copy xp the easy way? (4, Informative)

Anonymous Coward | more than 12 years ago | (#3009927)

Just find a copy of the license pack edition - it requires no activation. I use this at work - you can even change a whole motherboard out and it doesn't say a thing. Perfect for ghost (which is what we use it for)

The Possible Dark Use of Distributed Computing (2)

EXTomar (78739) | more than 12 years ago | (#3009928)

Evidently the generation of keys takes a lot of crunching and may take awhile to generate one useable key. If you want to hack out more keys or at a faster rate you must throw more hardware at it or parallelize it.

Not knowing the details of how they think keys are generated (which is probably a wise thing to keep tight lipped about it) one wonders if you can break the key generation into idependant parts. It may not be possible because it breaks the crypographic nature of the key but that isn't for certain either since MS doesn't want to make key generation the slow part in its production.

If this is true then WPA is done(as in stick a fork in it). How many thousands of people outside of the US(and heck inside of the US) who would contribute CPU to generate thousands and thousands of keys?

new name (3, Funny)

graveyhead (210996) | more than 12 years ago | (#3009929)

If not, this generation of WPA is now surely toast. If so, I guess they'll have to change the name to "Product Cracktivation" :-D Sorry, I couldn't resist.

keygen (3, Interesting)

Graspee_Leemoor (302316) | more than 12 years ago | (#3009934)

I was wondering about this after I heard the story somewhere else first, ( hoho ).

Most people not paying for XP are either going to be using the crack on the "trial" version or downloading the corporate version from their fave p2p network.

Thinking about the 2nd scenario, the corporate version requires a key, but doesn't need activation. The key is printed on the back of the cd case and every corporate version.rar I have seen has the same key- starting, (amusingly) "FCK..."

Anyway- the corporate versions of Win2000 didn't need a key- they filled it in for you (unless I am getting mixed-up with other MS software of the same period).

So, the big question is: Why does the corporate version need a key? MS knows it is damn easy to write it down, so there's no security there, but if MS wants to check the key when the system connects to the internet, checking against a database (oh look, 3 million people all using the same key!), then isn't this a similar hassle to product activation, only done sneakily with no dialogs ?

Presumably if you install the corporate version with the "FCK..." key and never connect to the internet then it will never hassle you or expire or need to be activated, but if you do connect to the net then it *could* be sort of activating itself by checking the key with microsoft. If this turns out to be the case then you could always block it with your favourite firewall, since as this would be a sneaky check they could hardly deactivate your machine if they couldn't connect...

Then again, we all know that MS loves home piracy and the product activation is just to stop small and medium businesses from using one cd on their whole lan.


This only applies to Windpws XP Corporate Edition (0)

CitznFish (222446) | more than 12 years ago | (#3009962)

Why is anyone even trying to talk about XP Home edition with this key generator? Does it phone MS for you and get the activation code? NO! So all of your tirades about XP Home edition are really moot. Who in their right mind would even BUY software that requires you to phone in for an activation key?

Heres another way to foil product activation (2, Funny)

mrroot (543673) | more than 12 years ago | (#3009985)

If you already are using Windows 2000, just say, "I'm not going to spend $199 to upgrade to Windows XP when there are virtually no new features except for UI enhancements." Really, you can do anything on Win2000 that you can on WinXP.

Of course if you are running Linux you have already foiled product activation.

Don't ruin MY key (4, Interesting)

innate (472375) | more than 12 years ago | (#3009990)

What if someone using this keygen generates my key that has already been activated? It will look to Microsoft like the key-in-question is being installed on a different computer with different hardware. Then the next time I go to re-install XP my legitimate key won't work.
Load More Comments
