+ Reply to Thread
Results 1 to 15 of 15
  1. #1
    ExcaliMod
    Paper Towels? Who needs paper towels, Under the sink they go!

    Join Date
    Oct 2005
    Posts
    4,967
    BG Level
    7
    FFXI Server
    Sylph

    Vista activation cracked by brute force

    http://www.theinquirer.net/default.aspx?article=37941

    Interesting, and Id like to see what MS will do about it. The biggest concern is the guesser getting legit keys.

  2. #2

  3. #3
    Relic Weapons
    Join Date
    Apr 2006
    Posts
    361
    BG Level
    4
    FFXI Server
    Lakshmi

    I really liked the part where he said it was hacked, and then one line below says it works by simple brute force.

  4. #4
    Relic Horn
    Join Date
    Mar 2006
    Posts
    3,223
    BG Level
    7

    I never thought of those terms as mutually exclusive before. And how did MS not see this coming 5 years ago? If it can be broken by a dictionary attack, it will be. It's a rule.

  5. #5
    Relic Weapons
    Join Date
    Jan 2006
    Posts
    374
    BG Level
    4

    Or in other words someone brute forced a 'single' key out of the activation scheme. It doesn't say how long it took to brute force a single key anywhere in there, which lends the question of how effective this methodology is for finding keys. Since it took a month for a key to be bruteforced, I'd say the answer is "Not very". If anything, it just says microsoft shoulda changed to a 30 or 35 character key instead.

    Not to say I support this method of anti-piracy, because in the end a *LOT* of people get boned when they buy Windows and get a "You're a thieving cunt" message. Just saying this doesn't mean anything yet.

    More effective cracks will come with time, though. And maybe by that time there will be a point to having Vista!

  6. #6

    The Inquirer.

  7. #7
    Relic Shield
    Join Date
    Dec 2006
    Posts
    1,704
    BG Level
    6
    FFXI Server
    Asura

    Don't we agree any passwords/keys can be revealed by brute force? it's not so surprising to me given they allow brute force mechanism to operate for trying out different keys.

  8. #8
    Relic Horn
    Join Date
    Mar 2006
    Posts
    3,223
    BG Level
    7

    Quote Originally Posted by VZX
    Don't we agree any passwords/keys can be revealed by brute force? it's not so surprising to me given they allow brute force mechanism to operate for trying out different keys.
    The term "can" is a little misleading. A simple forced delay between attempts puts the time required for a dictionary attack on the order of years or centuries. There's really no reason for MS not to do exactly that (like the op's article suggests) in the first place.

  9. #9
    Black Belt
    Join Date
    Jul 2004
    Posts
    5,745
    BG Level
    8
    FFXI Server
    Bahamut

    Saw this a while ago and laughed.

  10. #10

    Any program can be hacked with enough time effort and resources.

  11. #11

    Only really retarded people try to stop single cases of piracy and m$ actually doesn't care if people crack a key or two and use a copy for themselves.. it just isn't worthwhile to try and stop that.

    People that don't want to pay for software won't, but when they use your software anyway it is free advertising and microsoft's entire business model is about locking people in to windows and making them depend on it and that works better when as many people as possible use Vista so it HAS to be crackable to a certain extent.

    What software companies like microsoft try to stop is companies selling pirated copies of windows for profit. Many companies out there have and will continue to sell copies of windows that they didn't not purchase in the first place, thats what the whole 'genuine advantage' program is for in the first place.

    People that paid money and thought they bought windows find out they were ripped off with a pirated copy through the genuine advantage program, and microsoft gives them a free copy of windows in return for details and proof about who sold them the pirated copy in the first place.

    Back to the article.. Lets say you can brute force one key every 30 days.. you won't sustain much of a business if you can only sell one thing a month.

  12. #12

  13. #13
    Relic Horn
    Join Date
    Mar 2006
    Posts
    3,223
    BG Level
    7

    Quote Originally Posted by some_guy_on_KezNews
    So, about 200 keys per hour. Keyspace roughly 25^25. And valid keys guesstimated at sqrt(keyspace).

    That would give a valid key every ~3*10^17 keys, which comes to.. 170 bill years per key? And if MS is smart and WGA keeps a list of all issued keys, the list of true valid keys is a lot smaller.

    This sounds like a job for NSA's codebreakers and not for a VB script.
    3*10^17 looks right according to his original numbers, although I have no idea what attempts/second he's using to get 170 billion years. Anyway, it looks like we can all go home now.

  14. #14
    Physicist
    Join Date
    Feb 2005
    Posts
    4,493
    BG Level
    7
    FFXIV Character
    Raineer Severus
    FFXIV Server
    Hyperion
    FFXI Server
    Siren
    WoW Realm
    Area 52

    eh

    http://it.slashdot.org/it/07/03/03/1339209.shtml

    Basically, 5000 monkeys given infinite time would create the works of Shakesphere, right?

    No biggie

  15. #15

    lolvista

Similar Threads

  1. Replies: 166
    Last Post: 2011-09-08, 10:16
  2. Replies: 90
    Last Post: 2011-06-02, 09:00
  3. Replies: 111
    Last Post: 2009-04-30, 23:14
  4. Replies: 46
    Last Post: 2008-08-09, 08:57
  5. Silly attempt by "forces that be" to provoke war.
    By guartz in forum General Discussion
    Replies: 93
    Last Post: 2008-01-13, 19:26