Microsoft acknowledged on Friday that hackers had successfully bypassed its Windows Update antipiracy check. The process implemented earlier last week aims to ensure only owners of legitimate Windows copies can use the download service.
The WGA program makes users run a program that verifies that their copy of Windows is not pirated before they can use Microsoft's software update services. Microsoft introduced it as a pilot program in September but made the validation system a requirement on Wednesday.
A Microsoft spokesman confirmed on Friday that hackers had indeed succeeded in cracking the WGA program, and that the software giant will fix the flaw they had exploited in an upcoming version of the WGA program.
The exploit came soon after the launch of the program, the spokesman said. "Within 24 hours hackers claimed to have circumvented the process and it appears that they did," he said. "This is a hack that exploits a feature that enables repeat downloads in the same session so that a hacker never has to validate as a genuine user," he added.
The move to lock out pirated copies of Windows from the update sites is part of Microsoft's effort to fight software piracy, which is a major issue for the software vendor.
The Boing Boing hack is not the only way to get around WGA's restrictions.
David Keller, founder of PC consulting and services firm Compu-Doctor in Florida was able to change his Internet Explorer settings to bypass WGA when he experienced a flaw in the program that flagged a legitimate product key on a customer's machine as invalid.
"The customer was the original owner, no hardware was changed since purchase, nor was Windows ever reinstalled on the system," Keller said in an email to the IDG News Service. WGA rejected the operating system, nevertheless, which prevented Windows Update from working, he said.
Keller wrote that he did not have much luck with Microsoft support technicians, so he found a way to bypass the validation process on his own and moved along with the update. He accomplished this by disabling the Windows Genuine Advantage add-on. He was then able to do a Windows Update without the validation step.