Putting aside system bugs for the time being, Microsoft is about to roll out much stricter restrictions on users of its pirated software.
Those of you who have had your system installed at a computer city must have more or less seen this magical tool called KMS.
No matter if you are using a Windows system or Office software, as long as the technician runs this tool, the screen will show activation successful and thank you for your purchase.
Surprisingly, KMS, which has long been present in various cracking tools, was originally developed by Microsoft itself.
However, just a couple of days ago, Microsoft released a new regulation that plans to add stricter hardware authentication to KMS.
In other words, this simulated KMS activation method that has survived since the Windows Vista era may really be coming to an end.
Source: Windows Official Blog
To start with, let's give a brief introduction to the origin and working logic of KMS for those who are not familiar with it.
Simply put, KMS is a software activation service built by Microsoft for large enterprises, mainly used to activate Windows and Office software in batches.
The reason for launching KMS is that the previous activation methods had major vulnerabilities and were too cumbersome to operate.
Anyone who has run a company knows that in the Windows XP era, as long as you purchased a batch of genuine Windows licenses as an organization, Microsoft would provide a dedicated system image and a product key.
After that, the IT department only needs to deploy the system image to company computers in batches via the server and configure the key, then these systems can run normally.
But soon, Microsoft found a problem: since one key could be used to install the system on every computer in the company, once the key leaked out, it could theoretically be used to activate systems all over the world.
Therefore, starting from the Windows Vista and Windows Server 2008 generation, Microsoft redesigned the volume activation system, and KMS came into being.
Specifically, the enterprise-exclusive KMS key is stored on the server; the administrator first lets this server connect to Microsoft to complete activation, and then all Windows devices in the company can be activated directly on the internal network by connecting to this server.
After all, the key is always bound to the server, so theoretically, the security level is much higher.
But as per the tradition of Microsoft products, something is bound to go wrong at this point.
When Microsoft issues KMS keys, it only verifies whether the server has the corresponding permission; when the server activates the system, the system only verifies whether the KMS content meets the activation requirements, and will not further verify the server's authorization or the source of the key.
This creates a vulnerability between the server and the system activation process. Since the system does not check the source of KMS, as long as someone can crack the KMS protocol and simulate a server that returns the same response, they can trick Windows into completing activation...
As a result, many skilled users on the internet started to perform reverse engineering on this tool, restore Microsoft's checksum and protocol, and finally make it into a usable tool;
Users only need to click a button, and the tool will simulate a local server that returns a response that can pass Microsoft's verification to Windows.
In this way, an ordinary home computer can take advantage of the green channel that Microsoft originally prepared for enterprises and get successfully activated.
Moreover, to solve the problem that KMS activation only lasts for 180 days at a time, these activation tools will leave a scheduled wake-up task in the background, which will call the fake server to perform authentication every once in a while.
Over time, KMS has evolved from an enterprise activation solution to a standard tool used by technicians at computer city stores.
Finally, as this vulnerability is about to turn 20 years old, Microsoft has finally decided to fix it with TPM.
Many of you may first hear of TPM when Windows 11 was released in 2021. Back then, for so-called security reasons, Microsoft required that hardware must support TPM 2.0 to upgrade to the latest system.
In fact, this technology can be traced back to the last century.
At that time, the internet was in a period of explosive growth, and viruses and Trojans were rampant. So in 1999, giants such as IBM and Intel established a dedicated organization called TCPA (Trusted Computing Group), and released a security module standard for computer hardware, which is TPM.
Simply put, this standard defines what kind of security module should be built into a computer to store keys and verify device status;
Since the information stored in TPM cannot be simulated by software, it can be regarded as a reliable ID for the hardware.
This kind of module that can prove hardware identity and cannot be cracked is exactly what Microsoft needs to fix its software activation vulnerability.
Therefore, Microsoft plans to bind the server to TPM this time. In the future, if you want to activate the system via a server, you will not only need to provide the KMS key, but also the TPM, to prove that you have obtained official authorization from Microsoft.
In other words, even if someone simulates KMS in the future, they still cannot activate the system through a virtual server without a Microsoft-certified TPM.
But there is no need to worry too much, this change will not take effect immediately.
According to Microsoft, starting from August this year, they will first add corresponding prompts to Windows Server 2025, allowing enterprises to check whether their existing KMS hosts can meet the new requirements.
As for the mandatory TPM verification, it will not be implemented until the official release of the next generation of Windows Server.
That means Microsoft is only notifying enterprises to prepare for upgrades now, it will not shut down the existing KMS activation in August, let alone cause all ordinary users' Windows systems to fail suddenly.
Of course, once this set of rules is fully implemented, traditional KMS simulation tools will no longer work as well as before. Following this trend, in a few years, the traditional KMS activation method may really become completely unusable.
That said, Microsoft's move to patch the KMS vulnerability itself is completely reasonable.
After all, Windows is commercial software. We cannot treat this activation method as a built-in benefit of the system just because it has been used for nearly 20 years.
But this matter is somewhat ironic for today's Windows. After all, the main reason why Windows can retain so many users is the software, games, drivers and workflows accumulated over decades, not that users think it is exceptionally easy to use.
So of course Microsoft can continue to tighten the activation rules, but we just hope that Microsoft can devote as much effort to improving the system experience as it does to patching vulnerabilities, so that Windows will not be constantly criticized for its bugs.
Since the activation mechanism is going to be completely redesigned from the hardware level, when will those conflicting new and old UIs in the system get the same treatment?
This article is from WeChat Official Account "X.PIN", Author: Siyi, Editor: Milo & Mianxian, published with authorization from 36Kr.