Monday, March 19, 2007

Run Vista without activation for a year

Brian Livingston By Brian Livingston

Microsoft always says it opposes "software pirates" who sell thousands of unauthorized copies of Windows.

But the Redmond company has made things a lot easier for pirates by adding a line to the Registry that can be changed from 0 to 1 to postpone the need to "activate" Vista indefinitely.

Activation doesn't stop true software piracy

As most Windows users know, Microsoft has required "product activation" since the release of Windows XP in 2001. XP must be activated by communicating with servers in Redmond within 30 days of installation. By contrast, Microsoft Office XP, 2003, and 2007 require activatation before the package is used 5 to 50 times, depending on the version, according to a company FAQ. If a PC has no Internet connection, a user may activate a product by dialing a telephone number in various countries.

The activation process will complete successfully only if the software has not been previously activated, such as on a different machine. If activation isn't completed within the trial period, Microsoft products temporarily shut down some of their features. MS Office loses the ability to edit and save files. After Vista's activation deadline runs out, the user can do little other than use Internet Explorer to activate the operating system or buy a new license.

Microsoft describes its product activation scheme as a way to foil software pirates. However, as I previously described in an InfoWorld Magazine article on Oct. 22, 2001, activation does nothing to stop mass piracy. The Redmond company actually included in Windows XP a small file, Wpa.dbl, that makes it easy for pirates to create thousands of machines that validate perfectly.

Far from stopping software piracy, product activation has primarily been designed to prevent home users from installing one copy of Windows on a home machine and a personal-use copy on a laptop. As I explained in an article on Mar. 8, buying a copyrighted work and making another copy strictly for personal use is specifically permitted to consumers by the U.S. Copyright Act and the copyright laws of many other countries.

For example, courts have repeatedly ruled that consumers can make copies of copyrighted songs or television programs for personal use (not for distribution or resale). This principle is legally known as "fair use." The home edition of Microsoft Office 2007 reflects this principle, allowing consumers to activate three copies of a single purchased product. Microsoft Windows XP and Vista, however, allow only one activation.

Surprisingly, Microsoft has embedded into its new Vista operating system a feature that makes things easier than ever for true, mass software pirates. These tricksters will be able to produce thousands of Windows PCs machines that won't demand activation indefinitely — at least for a year or more.

Leaving the activation barn door open

I reported in a Feb. 1 article that the upgrade version of Windows Vista allows itself to be clean-installed to a new hard drive. The new Microsoft operating system completely omits any checking for a qualifying previous version of Windows. This allows the upgrade version of Vista to successfully upgrade over a nonactivated, trial version of itself.

After my article appeared, ZDnet blogger Ed Bott summarized the secret in a post on Feb. 15. He flatly states, "You satisfied every condition of the license agreement and aren't skating by on a technicality. The fact that you have to use a kludgey workaround to use the license you've purchased and are legally entitled to is Microsoft's fault."

In my own piece, I had speculated that clean-installing the upgrade version of Vista "probably violates the Vista EULA (End User License Agreement)." But more and more computer experts are saying that the procedure is fully compliant with the EULA and, in any event, is perfectly legal.

I wrote a follow-up story on Feb. 15. I reported that Microsoft includes in Vista a one-line command that even novices can use to postpone the product's activation deadline three times. This can extend the deadline from its original 30 days to as much as 120 days — almost four months.

PCWorld.com posted a report on my story on Feb. 17. The magazine quotes a Microsoft spokeswoman as saying that extending Vista's activation deadline as I described it "is not a violation of the Vista End User License Agreement." I'm glad that's clear.

The feature that I've revealing today shows that Microsoft has built into Vista a function that allows anyone to extend the operating system's activation deadline not just three times, but many times. The same one-line command that postpones Vista's activation deadline to 120 days can be used an indefinite number of times by first changing a Registry key from 0 to 1.

This isn't a hacker exploit. It doesn't require any tools or utilities whatsoever. Microsoft even documented the Registry key, although obtusely, on its Technet site.

But dishonest PC sellers could use the procedure to install thousands of copies of Vista and sell them to unsuspecting consumers or businesses as legitimately activated copies. This would certainly violate the Vista EULA, but consumers might not realize this until the PCs they bought started demanding activation — and failing — months or years later.

The following describes the Registry key that's involved.

Step 1. While running a copy of Windows Vista that hasn't yet been activated, click the Start button, type regedit into the Search box, then press Enter to launch the Registry Editor.

Step 2. Explore down to the following Registry key:

HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows NT \ CurrentVersion \ SL

Step 3. Right-click the Registry key named SkipRearm and click Edit. The default is a Dword (a double word or 4 bytes) with a hex value of 00000000. Change this value to any positive integer, such as 00000001, save the change, and close the Registry Editor.

Step 4. Start a command prompt with administrative rights. The fastest way to do this is to click the Start button, enter cmd in the Search box, then press Ctrl+Shift+Enter. If you're asked for a network username and password, provide the ones that log you into your domain. You may be asked to approve a User Account Control prompt and to provide an administrator password.

Step 5. Type one of the following two commands and press Enter:

slmgr -rearm or rundll32 slc.dll,SLReArmWindows

Either command uses Vista's built-in Software Licensing Manager (SLMGR) to push the activation deadline out to 30 days after the command is run. Changing SkipRearm from 0 to 1 allows SLMGR to do this an indefinite number of times. Running either command initializes the value of SkipRearm back to 0.

Step 6. Reboot the PC to make the postponement take effect. (After you log in, if you like, you can open a command prompt and run the command slmgr -xpr to see Vista's new expiration date and time. I explained the slmgr command and its parameters in my Feb. 15 article.)

Step 7. To extend the activation deadline of Vista indefinitely, repeat steps 1 through 6 as necessary.

Any crooked PC seller with even the slightest technical skill could easily install a command file that would carry out steps 1 through 6 automatically. The program could run slmgr -rearm three times, 30 days apart, to postpone Vista's activation deadline to 120 days. It could then run skip -rearm every 30 days, for a period of months if not years, by first resetting the SkipRearm key.

read more

Extracted from the original source: http://windowssecrets.com/comp/070315/#story1



The AnalyXer © 2007 | Contact | About Me