Urgent.News

What's breaking now, across thousands of outlets.

Tech

Retired Microsoft Engineer details the story about the famous leaked FCKGW Windows XP key — copy protection used 10MB of encrypted Microsoft Bob for validation

Retired engineer recounts the saga of the leaked Windows XP key.

Retired Microsoft Engineer details the story about the famous leaked FCKGW Windows XP key — copy protection used 10MB of encrypted Microsoft Bob for validation

For those who spent time working with PCs during the early to mid-2000s, the FCKGW-RHQQ2-YXRKT-8TG6W-2B7Q8 Windows XP key is likely etched in memory. It was the most recognized key, allowing users to install and run the operating system using a single CD. The question that often arises is how Microsoft permitted such a conspicuous weakness in their copy protection system. Former Microsoft engineer Dave Plummer explained the reason behind this apparent oversite in an X post.

There were two versions of the original Windows XP media: Retail and Volume. Retail media was meant for consumers who purchased the OS off the shelf, while Volume media was designated for Microsoft partners and OEMs who needed to install it on numerous machines without activating every single copy at install time. The two types of media had different keys, and the installer would verify the key input against specific data on the disk that was encrypted so heavily that even today it remains unbroken.

The key was essentially Microsoft Bob, a short-lived assistant that debuted in 1995 to help newcomers with basic computing tasks. Microsoft Bob was not intended for the Volume disc, as those were exclusively for enterprise use. The final version of the CD, known as Release to Manufacturing (RTM), was completed on August 24, 2001, two months prior to the official launch on October 25. OEMs and partners received the discs before the release date so they could prepare their products with Windows XP pre-installed.

Plummer suggests that only a few organizations had access to the Volume image and the corresponding Volume License Key (VLK), and he believes that a major OEM, possibly Dell or Intel, leaked the Volume media and the key before the official release. Shortly after, the pirate group Devils0wn disseminated it online for anyone to obtain.

Later, when Service Pack 1 was released, the FCKGW key was included among 640 blacklisted keys due to its unauthorized distribution. Service Pack 2 and its Windows Genuine Advantage checks went a step further and blocked updates on machines with blacklisted VLKs. Plummer states that Microsoft did not wish to cause unnecessary issues for customers, hence its approach of simply blacklisting the affected keys.

Various theories have arisen over the years suggesting that the FCKGW key functioned because Microsoft's key generation algorithm was extremely simplistic. However, Plummer firmly refutes this notion, stating that the algorithm was developed by exceptionally skilled individuals with minds as large as the doorframes they encountered when entering the office. The real culprit behind the key's success is a more straightforward explanation - as is often the case in computing, the problem lay between the keyboard and the chair.

Written by urgent.news from Tom's Hardware's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

This story

This is one outlet's version. Read the fullest account.

Read the original at tomshardware.com →

More in Tech

More from Thursday 17 September →