Microsoft 'wait-and-see' on Vista BIOS hack
Tic-tock
Posted in Enterprise Security, 11th April 2007 20:15 GMT
Free Download - Security Web 2.0
Microsoft has no immediate plans to tackle a reported hack to Windows Vista product activation that could allow illegal copies of Windows to be widely installed.
The hack is not yet viewed as a wide-scale threat, although Microsoft indicated it may act if more hackers view breaking Windows Vista's OEM product activation as a challenge worth taking.
Alex Kochis, a Microsoft senior product manager, blogged: "Because Windows Vista can't be pirated as easily as Windows XP, it's possible that the increased pressure will result in more interest in efforts to hack the OEM Activation 2.0 implementation."
Microsoft responded following reports Windows Vista's OEM Activation (OA) 2.0 has been broken. OA uses pre-installed code on the BIOS of an OEM'd PC motherboard to identify the system as pre-installed with a licensed copy of Windows.
The company has so-far identified two approaches to cracking OA 2.0. One involves editing the BIOS on the motherboard to make it appear as if it's from an authorized OEM, and the second uses software to convince Windows Vista it's running on OA 2.0-enabled hardware.
Microsoft last saw product activation hacked when it introduced Windows XP in 2001.
According to Kochis, Microsoft is taking a wait-and-see approach on this latest challenge: "Our goal isn't to stop every 'mad scientist' that's on a mission to hack Windows. Our goal is to disrupt the business model of organized counterfeiters and protect users from becoming unknown victims. This means focusing on responding to hacks that are scalable and can easily be commercialized." ®

Implementing Energy Efficient Data Centers [WP114]
An Improved Architecture for High-Efficiency, High-Density Data Centers [WP126]
Web application security [3-2APYM3X]
Securing your Online Data Transfer with SSL
The Register Guide to Extended Validation

Inmate hacked prison network, broke into employee database
Miscreants hijacking machines via (freshly patched) Adobe flaw
Martial law planned for Craigslist's red-light district
Cocaine addicted IT manager hacks ex-employer's mail servers