Send to Printer

windows

Why WGA is a bad idea

November 20, 2006 14:11:02.869

Tim Bray gives more than a few examples of what kind of havoc is likely to erupt from the new kill switch piece of WGA in Windows Vista:

Let’s see, suppose I’m a black-hat profiteer sitting beyond the reach of Western law but with control over a few botnets . If I can get my hands on your Kill Switch, I’ll have a nice little extortion business, as in “Pay up or all your desktops will decide they’re unlicensed and turn off.” It’d work best in a sales-centric business near end-of-quarter. Another potential victim would be any government (or company even) that has a lot of enemies; they don’t want your money, they just want to take you down. So, without thinking too hard, here are some attack vectors I’d consider: If I can subvert your network routing, gotcha! If I can subvert the registry on your desktop machines, gotcha! If I can subvert the NTP protocol (how most computers learn what time it is), gotcha! I’m sure that an actual seasoned network engineer could think up a half-dozen more attack scenarios over a cup of coffee. Finally, never ascribe to malice that which can be explained by incompetence; WGA is software and software has bugs and if one of those bugs flipped the Kill Switch on your sales infrastructure offline during the Christmas rush, well, there wouldn’t be any malice involved, but it’d sure be a pity. What prudent businessperson, I wonder, is going to install critical infrastructure that can be turned off remotely, trusting the claims that only the good guys will be able to find the key to the “off” switch?

That last part is instructive - do you want to be manning the help desk at a critical part of the year after Windows decides that it's not genuine?

Technorati Tags: ,

Comments

Bad Ideas'R'Us

[Toby] November 20, 2006 20:19:15.456

Well, they do rather specialise in bad ideas. Is anyone surprised at this?

 Share Tweet This