Stories
Slash Boxes
Comments

News for nerds, stuff that matters

Slashdot Log In

Log In

Create Account  |  Retrieve Password

Why Does XP Auto-Connect to sa.windows.com?

Posted by Cliff on Fri Jul 26, 2002 12:50 PM
from the why-does-it-need-this? dept.
termigator asks: "I have a private home network that has a Windows XP system on it (I know, the horrors, but it allows my wife to do some of her work at home). With recent discussions about DRM and the Microsoft EULA (which allows Microsoft to autodownload software), I decided to block all traffic on my Linux firewall from Microsoft systems (207.46.0.0/16) to the Windows XP box. This morning there was trapped traffic from Microsoft, after my wife was doing some work on the XP system the day before. I talked with my wife, and I could not determine what she could have done to cause the traffic to happen. Can anybody provide some insight?" Why can't Microsoft be up front about when it tries to phone home? Of course, phoning home isn't the big problem with most people, it's the fact that they try to be sneaky about it for certain tasks. With Microsoft pushing XP into the home, consumers should definitely be wary about storing private information on such systems until Microsoft provides some answers.

"Here is the logwatch summary:

Rejected packets from sa.windows.com (207.46.226.40).
  Port 1053     (tcp,eth0,output): 4 packet(s).
  Port 1054     (tcp,eth0,output): 4 packet(s).
Total of 8 packet(s).
Port 1053 is 'remote-as' and port 1054 is 'brvread'. I am guessing that the remote-as is related to the Remote Assistant feature in XP, but I've had no luck on finding any technical information about brvread via a Google search."
+ -
story
This discussion has been archived. No new comments can be posted.
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
 Full
 Abbreviated
 Hidden
More
Loading... please wait.
  • by jeffy124 (453342) on Friday July 26 2002, @12:58PM (#3959708) Homepage Journal
    ...if she had difficulties using the system. eg... did any programs crash? did any error messages pop-up? etc.

    Also, how about you try using the box? Do exactly what she does, keeping watch on the firewall status for anything of interest. Experiment with the system and see what happens on the firewall.

    Lastly, consider removing the firewall block, and instead doing a tcpdump of the suspicious packets. See if anything of interest comes up.
  • It's all about trust (Score:2, Interesting)

    by Anonymous Coward
    Face it, if Microsoft wants, they can transmit all the information they want from your XP system. There are literally thousands of ways when it comes to sneaking something through a firewall that is not an airgap. It's only trust which matters and while Microsoft is not easily trusted, a detected breach of confidentiality would be a public relations nightmare for them. This is the single most important reason why you should not lose to much sleep over XP phoning home. You did buy that license, right? Most if not all phone home functions are just normal convenience functions btw: The system is keeping it's clock in sync, checking for security updates, looking for new codecs, giving up to date help information, etc.
      • "I don't have this particular software, but anyone who does paid money for a product, not a license."

        Not according to the license.

        And therein, some would say, lies the problem.

  • by crisco (4669) on Friday July 26 2002, @01:03PM (#3959752) Homepage
    A search [google.com] on google for sa.windows.com reveals nothing. But notice the line that says: Find web pages that contain the term "sa.windows.com". Click that link [google.com] and you get plenty of results. Hmm, first search result [windows.com] is to a privacy page on that domain, that provides some clues. Second link [indenial.com] is to an archived message from the NTBugTraq list, that might be a great place to find an answer. The eighth result is a link to an article [lockergnome.com] on LockerGnome, a page or two down and you have a nice concise explanation of what sa.windows.com does.

    Now should I complete the whoring and post a cut and paste?

    naaa....

    • By default, Windows XP looks to be configured for behind- the-scenes connection to sa.windows.com whenever any sort of search is required, particularly when using the search feature within Internet Explorer. I was quickly able to prove that by hitting the search button, the connections were opened immediately. You can turn that off by changing the preferences once you open the search dialog... after getting rid of that cheesy animated pooch, anyway. In the Change Preferences list, click "Change Internet search behavior" and choose "With Classic Internet search". Now when you open the search dialog, the connection to sa.windows.com will no longer be initiated. There may very way be other areas within Windows XP that are tied to that thing, but IE is the most obvious one.

      someone had to paste it! :) (from http://www.lockergnome.com/issues/techspecialist/2 0020314.html)
    • Whoring completed:

      Open Connections to sa.windows.com

      When performing a "netstat -o" in Windows XP, you may see connections opened to host sa.windows.com, which is quite obviously a Microsoft site, but why the connections? It has to do with the Search Companion features within Windows XP. With a little quick testing, I found that IE6 on Windows 2000 also has a similar Search Assistant feature, but it does not connect to sa.windows.com, using auto.search.msn.com instead, which is a bit more intuitive.

      By default, Windows XP looks to be configured for behind- the-scenes connection to sa.windows.com whenever any sort of search is required, particularly when using the search feature within Internet Explorer. I was quickly able to prove that by hitting the search button, the connections were opened immediately. You can turn that off by changing the preferences once you open the search dialog... after getting rid of that cheesy animated pooch, anyway. In the Change Preferences list, click "Change Internet search behavior" and choose "With Classic Internet search". Now when you open the search dialog, the connection to sa.windows.com will no longer be initiated. There may very way be other areas within Windows XP that are tied to that thing, but IE is the most obvious one.

      • The question, as summarized in the title, is "Why does Windows XP connect to sa.windows.com. The guy you're responding to, and others, answered this question -- it's for Search Assistant in Windows. Information can be found all over using google.

        If the guy wants the gnitty gritty details, he can install a packet sniffer and analyze it. People have already done this and written up summaries, though (see google again).
        • Actually, the only question in the article is "Can anybody provide some insight?" -- "Why does Windows XP connect to sa.windows.com?" is the title, which usually has little connection to the subject, as any /. veteran would know. So, has anyone provided any insight into "brvread"? So far, no. If "People have already [installed a packet sniffer and analyzed it] and written up summaries," as you say, where are they? A Google search for "brvread packet sniffer summaries" [google.com] turns up nothing. So how exactly would you phrase the search so Google finds these summaries? Surely you [slashdot.org] found them, since you cite them, right?

        • Now heres where the fun lies.

          My (admittedly inflammatory) post currently stands at Flamebait=1, Informative=5, Overrated=2, obviously moderation points are being wasted. But are all of those fair? Surely it wasn't worth 5 Imformative points. So the Overrated is valid. Flaimbait, yes, maybe even a few more of these. But not really a good flame, it is so predictable.

          Even better, the response to my post calling me on karma whoring and incomplete Google linkage has even better moderation. Flamebait=1, Insightful=1, Overrated=1, Underrated=1 currently. Personally, I'd say the Insightful is the only one it really deserved, the Overrated and Underrated cancel each other out and I'm not interested in responding so it can't be a proper flame, right?

          Oh, and this post? -3 Offtopic, definately.

  • Ad (Score:3, Interesting)

    by s|eeper (110769) on Friday July 26 2002, @01:03PM (#3959754)
    That huge ad blocks out some of the post. Wonderful.
    • Re:Ad (Score:3, Interesting)

      by MrResistor (120588)
      I was going to post the same thing. I'm glad I'm not the only one.

      I don't mind the ads, I realize /. needs the money they bring in, but when ads start interfering with the content it's a real problem that needs to be addressed.

      • Mozilla just writes the text over the ad picture so you can still read it. Not that I would ever be one of those people to push one browser over another on people...

        I agree that the ads shouldn't be uber-obtrusive to the point where they hurt the site, though.
        • I would love to be using Mozilla right now, as I think it's much better than IE. Unfortunately, I have only a 2GB HDD in my work system, and it's mostly filled with work stuff.

        • Mozilla just writes the text over the ad picture so you can still read it.
          No, it doesn't. I'm using Mozilla 1.0 in Windows 2000, and the ad covers the text.

          • Re:Ad (Score:3, Funny)

            by foobar104 (206452)
            Ok, just so nobody patents it: Slashdot hereby provides prior art for putting an ad behind semi-transparent content.

            I'm not 100% sure, but I believe it has to be on purpose to qualify as prior art.
  • I believe this is the address used to send error-reporting data after a system crash.
  • One minute worth of searching on google explains that this is for the Search Assistant part of Windows XP. It appears to be benign, but you can block traffic and everything still works OK. Consult this google search [google.com] for more info.
  • Search Assistant (Score:2, Informative)

    by topside420 (530370)
    It is a search assistant for Internet Explorer. A previous post had a great link [lockergnome.com] for info.

    You can turn the feature off by changing the search method to 'Classic' in Internet Options.

  • by AnalogBoy (51094) on Friday July 26 2002, @01:49PM (#3960171) Journal
    It connects to sa.microsoft.com.

    Then it proceeds to do a scan of all of your hard disk, counting the mp3's and divx's you have. It reports these figures to the MPAA and RIAA right off the bat.

    In stage two, it scans all images on your PC searching for even the slightest bit of nudity. It then analyzes the photo for age, race, sex and fetish information. If it finds anything underage or otherwise disturbing, it notifies the police. And your ISP. And the feds.

    Due to provisions of the PATRIOT act, the newest revision reports if you've visited aclu.org or any democratic candidate sites. It also counts the number of baptist websites you visit on a daily basis (minumum of 10 required).

    It then audits your system for any source code you have. If it finds any, it will append to it a microsoft copyright and copy it over to microsoft. (You *DID* see that in the ELUA, right?)

    In other words, it does everything you suspect of it. And more!

  • XP Experiences (Score:3, Interesting)

    by Pampaluz (163324) <pampaluzNO@SPAMcox.net> on Friday July 26 2002, @02:07PM (#3960340) Journal
    This seems to be a similar situation; in that Microsoft is intercepting data entered in a browser, and acting upon the contents of that data:

    My father has a couple of computers, and I had to run a program on his Windows XP machine, because I needed to use the "QTopia Desktop" synchronization software that came on the CD accompanying my handheld Linux-based Sharp Zaurus (why they didn't give software on the CD that would work with a Linux-OS computer, I'll never understand...)

    Anyway, I needed to do a search for some Zaurus sites (I didn't want to bother to go and check the URLs I had on my computer which was in the other room...so, not thinking, I cleared the URL window in Internet Explorer, and typed in "google" (to get the full URL automatically, the way you can in Mozilla). When I did this, I got a page that said: "If you wish to search the Internet, use MSN.COM"-- complete with the four-color butterfly/Windows XP logo...then, I was transferred to MSN.COM! I didn't even get a chance to say whether or not I really wanted to "Go There Today".

    OK fine...I figured it was my fault, I should have typed in the full URL, I should have guessed that Microsoft would do this. So, I cleared the URL window again, and typed in "http://www.google.com/". The computer LOCKED UP-- then came a glimpse of the "Blue Screen of Death" (I think, I am not sure), and then the computer simply rebooted!

    When I told me father about this, he laughed, and then when the computer had booted again, he drilled down through his "Favorites" menus, and came to the entry for "Google," and I was finally able to "Google". Since then, I only use the "Favorites" to get to Google whenever I'm using my Dad's machine, so that I don't get rebooted again.

    Another thing: if you want to find a book online, Windows XP does it's level-best to make you buy it from Barnes & Noble. I have nothing against B&N, but I do like to use Amazon.com, or ThinkGeek, or some of the other tech bookstores online. But Barnes & Noble is paying Microsoft to be first with XP, and so they get all the traffic if somebody is new to computers, like a friend of mine who recently bought his first computer (this is how I learned about XP's desire to make you buy books only from B&N). My friend's system came with XP pre-installed.

    At the time he was looking for a computer, I couldn't convince him that Linux would be a better choice (anyway, all the $800 dollar systems advertised in the newspapers come pre-loaded with XP, no Linux systems in sight) and now he's been spooked because the folks at the place where he bought the computer told him they couldn't (wouldn't?) help him if he switched the operating system (I said "So What! I'll help you!), but it seems that someone there implied that he would lose ALL support if he put Linux on his computer--that it would "Void the Warranty". They can't say it officially, but I wasn't there when the threat was made. Now my friend won't even consider switching; he is having problems with the CD-RW, a hardware problem. (In fact, nobody seems to know how to make it work; it just keeps screwing up blank CD's.)

    However he is getting wary of Microsoft, now that some of the things I told him would happen are coming true, plus worse things I didn't even think would be problems (hours on the phone, but nothing gets fixed when they finally answer; being bounced back & forth between Microsoft, the company that sold the machine, & the manufacturer; nobody taking responsibility for tech support, and his "Free MSN Subscription for TWO Years" being WORTHLESS, because he can never get connected: either the lines are busy, or he gets tossed offline during important "secure" transactions, and doesn't know if orders went through or not. He likes use uBid.com (I think it is called). He finally gave up & got a cable modem subscription, and never uses his "Free MSN account" anymore.

    --MarkVII

    • Ok, I can tell you 100% you clearly bought a cheap shoddy computer with lowend components, it's no wonder you get lockups!!! I love it when people buy cheapass parts and then automatically assume it's microsoft. Here's a counter example--my personal computer currently has an uptime of 17 days (at which point I installed a new harddrive). My work computer (both are running XP, in case it wasn't obvious) which is used about 10 hours a day by me and another person, has an uptime of 47 days last I checked! The OS is NOT the problem.
        • If you can't even do some simple error checking of what your device drivers are doing, I blame the OS, not the hardware.

          If a hardware driver has to run in supervisor mode on the processor - and this is true of many Linux drivers as well - there's only a limited amount that the kernel can do to prevent it fux0ring things up. The difference I think is that open source kernel drivers for/in stable kernels tend not to crash very much, because of the peer review thing. Unless they're quite obscure drivers that hardly any developers use.

      • I'll bet his dad's PC has "MSN Explorer" and you wife's PC has "Internet Explorer" -- there's a difference! You can tell which is which by looking at the icon in the upper right corner: It's a Windows logo in Internet Explorer and it's an MSN logo in MSN Explorer. You get MSN Explorer if you use MSN or your PC came with "2 free years of MSN" or if you've ever loaded one of those MSN trial CDs. I don't know how to remove it -- once you have MSN Explorer it appears impossible to restore Internet Explorer. (/. geeks will now post flames saying it's possible, but not telling me how)

  • you can block windows explorer (explorer.exe) from accessing the network with zone alarm (or a similar product).

    (and this doesn't interfere with internet explorer accessing the network, FYI)

  • Here is a (probably incomplete) list of ways Windows XP connects to Microsoft's servers. To generate this list yourself, disable Microsoft's firewall, and use the ZoneAlarm firewall, which is free for personal use. When Windows XP tries to connect to Microsoft, ZoneAlarm will bring up a dialog box asking whether that is okay. If you say no to some of the requests, some functions of Windows XP will not work (like networking).
    1. Application Layer Gateway Service (Requires server rights.)
    2. Fax Service
    3. File Signature Verification
    4. Generic Host Process for Win32 Services (Requires server rights.)
    5. Microsoft Application Error Reporting
    6. Microsoft Baseline Security Analyzer
    7. Microsoft Direct Play Voice Test
    8. Microsoft Help and Support Center
    9. Microsoft Help Center Hosting Server (Wants server rights.)
    10. Microsoft Management Console
    11. Microsoft Media Player (tells Microsoft the music you like)
    12. Microsoft Network Availability Test
    13. Microsoft Volume Shadow Copy Service
    14. MS DTC Console program
    15. Run DLL as an app
    16. Services and Controller app
    17. Time Service, sets the time on your computer from Microsoft's computer.
    18. Microsoft Office keeps a number in each file you create that identifies your computer. Microsoft has never said why.
    19. Microsoft mouse software has reduced functionality until you let it connect to Microsoft computers.
    These are just the ones I know. There may be others.

    So, if you use Windows XP, your computer is dependent on Microsoft computers. That's bad, not only because you lose control over your possession, but because Microsoft produces buggy software and doesn't patch bugs quickly. For example, as of July 26, 2002, there are 20 unpatched security holes in Microsoft Internet Explorer [pivx.com]. This is a terrible record for a company that has $40 billion in the bank. Obviously, with that kind of money, Microsoft could fix the bugs if it wanted to fix them. Since the bugs are very public and Microsoft has the money, it seems reasonable to suppose that top management at Microsoft has deliberately decided that the bugs should remain, at least for now.

    It seems possible that there is a connection between all the bugs and the U.S. government's friendly treatment of Microsoft's law-breaking [usdoj.gov]. The U.S. government's CIA and FBI and NSA departments spy on the entire world, and unpatched vulnerabilities in Microsoft software help spies.

    There are many other big shortcomings in Windows XP. Windows XP, and all current Windows operating systems, have a file called the registry in which configuration information is written. If this one (large, often fragmented) file becomes corrupted, the only way of recovering may be to re-format the hard drive, re-install the operating system, and then re-install and re-configure all the applications. The registry file is a single, very vulnerable, point of failure. Microsoft apparently designed it this way to provide copy protection. Since most entries in the registry are poorly documented or not documented, the registry effectively prevents control by the user. There are many areas like this where what Microsoft's design conflicts with the needs of the users.

    Note that Microsoft does not support making functional complete backups under Windows XP. Look at Microsoft's policy about this: Q314828 Microsoft Policy on Disk Duplication of Windows XP Installation [microsoft.com]. Only those who work with Microsoft software will understand the true meaning of Microsoft's policy. Since almost all programs use the registry operating system file, if you cannot make a functional copy of the operating system you cannot make a functional copy of all your application installations and configurations. There are other software companies that try to fix this, but the fixes don't work well, and Microsoft can, of course, break their implementations, as they have often done with other kinds of competitors.

    Because the configuration information for the motherboard and the configuration information for the applications are mixed together in the registry file, the registry tends to prevent you from moving a hard drive to a computer with a different motherboard. That's another implication of the above Microsoft policy. So, if you have a motherboard failure, and a good complete backup, you may not be able to recover unless you have a spare computer with the same motherboard.

    Only technically knowledgeable people know how to avoid signing up for a Microsoft Passport account during initial use of Windows XP. The name Passport gives an indication of Microsoft's thinking. A passport is a document issued by a sovereign nation. Without it, the nation's citizens cannot travel, and, if they leave, won't be allowed back in their own country. In Microsoft's corporate thinking, the company seems to be moving in the direction of believing that they own the user's computer. Most people are both honest and intimidated. Apparently about 95% do whatever they are asked on the screen. They give their personal information to Microsoft. They don't realize that, if they feel forced to get a Passport account, they should enter almost completely fictitious information, since the real question is not "What is your name and address", but "Can we invade your privacy". The honest answer to this is "No, you cannot invade my privacy", and the only effective way to communicate that is to give completely fictitious information. Since it is the educated people who have computers, Microsoft is building a database of the personal lives of educated people. Microsoft knows when they connect and from what IP address (which tends to show the area), what kind of help they ask, and information about what they are doing with their computers, including what music they like. It is not known, and there is no way to know, how much Microsoft or other organizations make use of this information, or their plans for future use.

    Not only has Windows XP definitely gone further in the direction of allowing the user less control over his or her own machine, but with Palladium, Microsoft apparently intends to finish the job: Microsoft will have ultimate control over the user's computer and therefore all his or her data. Even now, under Windows XP, a recent security patch requires that the user agree to a contract that gives Microsoft administrator privileges over the user's computer [theregus.com]. The contract says that if a user wants to patch his or her system against a bug which would allow an attack over the Internet, he or she must give Microsoft legal control over the computer. See this article also: Microsoft's Digital Rights Management-- A Little Deeper [bsdvault.net]. You may need to be a lawyer to take apart the crucial sentence. "These security related updates may disable your ability to copy and/or play Secure Content and [my emphasis] use other software on your computer" legally includes this meaning: "These updates may disable your ability to use other software on your computer." Note that the term "security related updates" is meaningless to the user because the updates have no relation to user security. So, the sentence effectively means that Microsoft can control the user's computer without notice and whenever it wants. That kind of sentence is known in psychology as "testing the limits". If there is no strong public complaint about this, expect to see more and stronger language like this.

    This Register article shows the direction Microsoft is going: MS Palladium protects IT vendors, not you [theregus.com]. Absolute power corrupts absolutely, and Microsoft is well down that road. See this ZDNet article, also: MS: Why we can't trust your 'trustworthy' OS [zdnet.com].

    These Microsoft policies mean that any government which wants to be independent of the United States government, and any government which represents itself as controlled by the people, cannot use Microsoft operating systems, or other Microsoft proprietary systems.

    Microsoft's self-destructiveness does not mean that the user should be self-destructive. There is no need to apologize for using Microsoft software. The correct solution to abuse is persuading the abuser to stop being abusive. Once I posted to a Slashdot story a link to an article on a web site of mine. By far the majority of visitors from the Slashdot story used Microsoft operating systems. Rather than feel embarrassed because Microsoft is abusive, action needs to be taken to prevent the abuse. If you are against Microsoft abuse, you are not against Microsoft; you are more pro-Microsoft than Bill Gates.

    In some areas, Microsoft Windows XP has reduced functionality. For example, the command line interface does less in some ways than the CLI in Windows 98 SE (Second Edition). The CLI is a big embarrassment because of its limited capabilities, but at least in Win 95 it worked. With every version since then it has worked less well. (There are two kinds of command prompt, and, according to Microsoft employees, the differences between them are not fully documented.)

    The command line prompt sometimes begins to display short file names. Microsoft employees say that Microsoft has no fix, although someone not connected with Microsoft did make a work-around.

    Cutting and pasting into a command line program often puts successive extra spaces before each line. Microsoft employees say that there is no plan to fix this.

    The fast paste mode that is in Windows 98 is gone in Windows XP. Microsoft employees say there is no plan to fix this.

    The DOS QuickEdit mode sometimes flashes wildly when trying to edit from a DOS box.

    When using the command line interface, Windows XP doesn't always update the time. After several hours, the time reported to command line programs can be several hours in error.

    There is a DOS program called START.EXE that can be used to start other programs. But it does not operate the same way as in other versions of Windows. It starts a program, but cannot be made to return control to the command line program as previous versions did. There is no technical reason for this; it is just one of the shortcomings that are allowed to exist.

    People often say that DOS has gone away. But Microsoft still calls the commandline interface DOS, and in Windows XP Microsoft has added new programs for configuring the OS that work only under DOS.

    There are many other insufficiencies in Windows XP. Sometimes when you press a key while using Windows XP, it is seconds until there is any response. Apparently there is something wrong with the CPU scheduler in XP, because there are a lot of complaints about this in the forums and MS people have said that they are working on it. On one particular fresh installation of XP, on an Intel motherboard with either a Matrox G550 or an ATI Radeon video adapter, it requires 18 seconds to display a directory listing of 94 items. This is apparently related to a bug in the video software, not the adapter drivers.

    Something is wrong with the Alt-Tab display of running programs under Windows XP. If there are a lot of programs, not all of them are displayed. The order jumps around in a seemingly random way.

    Another indication of the direction Microsoft is taking Windows XP is that menus are sometimes 7 levels deep.

    The most recent version of this article is available at http://www.hevanet.com/peace/microsoft.htm [hevanet.com].
    • FUD Alert!! Troll alert!!! 99% of this post is such BS that it's not even worth responding too...however, I'll tackle possibly the most egregious point (it kinda proves the rest as BS as well).

      There are many other big shortcomings in Windows XP. Windows XP, and all current Windows operating systems, have a file called the registry in which configuration information is written. If this one (large, often fragmented) file becomes corrupted, the only way of recovering may be to re-format the hard drive, re-install the operating system, and then re-install and re-configure all the applications.

      BULLSHIT! Microsoft has the ability (I know AT least since Win98) that Windows automatically backs up the registry periodically (ie, at shutdown or boot, major hardware change, etc). IF it ever gets corrupted, there will be a backup to restore from. That's also bullshit what you claim about not being able to backup--it works fine. If you had actualyl read the link you linked to, you would see it's refering to SID--a special identifier used on MS networks (somewhat akin to an IP address, not some evil ploy). Duplicate SID's, just like duplicate IP's, conflict.

      How bout you go get a life and stop verbally stabbing at microsoft from your parents home (PennyArcade ;)

      • Microsoft has the ability (I know AT least since Win98) that Windows automatically backs up the registry periodically (ie, at shutdown or boot, major hardware change, etc).

        Irrespective of the whether the rest of his post is right, that's not true. Windows 2000 does not backup the SOFTWARE hive automatically, although it does back up the other even more important one, SYSTEM I think (this is completely moronic, because the system is almost unusable without an uptodate SOFTWARE hive). If you have a power cut, as I discovered to my cost, your registry may be corrupted beyond Windows ability to repair it. Your only option (unless there's some expensive payware I don't know about) is to completely reinstall Win2K.

        You might say that I should have backed it up myself. But that would be nonsense. Is this covered anywhere in the getting started documentation? (I didn't see a copy of that, actually, because we have a site license and I just installed it from a CD) Does it say when you first install: "Tip of the Day: Windows 2000 is a crappy operating system, so you'd damn well back up your registry after every change if you don't want to have to reinstall everythign after a power cut!"

        I think not.

        • Actually, in XP, the registry backup IS automagically made - that's what the "System Volume Information" folder in the root of your HD is used for. And that Application in the Accessories\System Tools Folder - called "System Restore"? That's how you access it. It'll work in safe mode, too.

          Not a cureall for Registry Corruption, but it's an improvement from Windows 2000.

      • "It's a direct ... copy of the second link."

        I wrote the story at the second link. But I wrote the present story AFTER the link was posted. The story needed to be updated. So I hastily updated it, FTP'd it to the server, and decided to post most of it directly to the story.

        The story was modded up because it addresses a very, very serious issue. We are seeing a sickness among large companies. Consider Enron and WorldComm and Microsoft as part of a larger social illness. They all lost their way and began to be adversarial toward the world and towards themselves.


      • Without going into a long story, there is a problem in making backups of Windows XP that actually can be used to make a copy that restores full functioning. The Microsoft article [microsoft.com] says,

        "Microsoft does not provide support for computers on which Windows XP is installed by duplication of fully installed copies of Windows XP. Microsoft does support computers on which Windows XP is installed by use of disk-duplication software and the System Preparation tool (Sysprep.exe)."

        There is only one kind of backup that is a true backup: A fully installed copy, or some method of creating a fully installed copy. Microsoft is saying that that is "not supported". That language hides the fact that Microsoft made it difficult.

        You said, "You most certainly can (and I have) use disk imaging software to back up and restore your system, complete with registry."

        I've done it too. But, as Microsoft says, Microsoft does not support this. Think about that for a moment. Suppose Linus Torvalds said, "I don't want Linux to support fully functional backups". That would be preposterous. Why, then, do people accept the same statement from Microsoft? Maybe that is because they have been habituated to being abused.

        Please take Microsoft's statement seriously. Consider a real life situation. If you have had a hardware failure, when you do the restore it may not be to a computer that is identical to the one on which Win XP was first installed. (If several years have passed since the computer was made, it may not be possible to buy identical components, for example.)

        There can be serious problems with using a restored copy since, with Windows XP, most of the configuration is thrown into one pot, the registry. Yes, you may be successful hand-editing the registry, but maybe you won't. Even if you are successful, you could not call a backup that needs considerable adjustment a "fully functional backup". In a real life situation, the cost of doing a restore to alternate equipment may be more than the cost of completely re-installing the software.

        The problem is not in changing the SID. SysInternals [sysinternals.com] provides a free utility, NewSID [sysinternals.com], to change the SID. The problem is that Microsoft has deliberately made it difficult to make functional backups, apparently as a method of copy protection. Remember, we are NOT talking about manufacturers making copies that work on identical equipment. We are talking about a backup that can actually be used immediately after a hardware failure to do a repair in which the new system is not identical.

        It is not impossible that someone could move a backup to new hardware. But, in practice, it may be impossible or too expensive under some circumstances.

        I use disk cloning software when the hard drives are not identical, and a mirroring controller like the Promise FastTrak when the drives are identical. Remember, I am making copies that are fully legal because I have purchased licenses for them. I am only trying to save time; re-installing all the software might cost far more than the cost of Windows XP. The issue is not with rollout of new machines. The issue is whether your backup can actually be used to make a fully functional copy.

        Most people who use Windows XP don't know of the existence of hard disk cloning software or hardware. One effect of Microsoft's policy is that Microsoft does not tell them. Even if they did have such software, and they new how to use it, most users might still have the difficulties mentioned here.
        • on which Windows XP is installed by duplication

          They are not referring to backups, they are referring to GHOST images. That's what "installed by duplication" means.

          Again you are not technically competent to be discussing this matter. Stick to "Paper or plastic" as your career choice.

          If you are willing to learn, feel free to send me an email and I can answer your questions. But quit trying to pass yourself off as a subject matter expert.

          • "Ghost" is a term created by a company that was later bought by Symantec.

            Symantec's product is expensive. Most users of Windows XP don't know it exists. In the situation mentioned, it doesn't always work as a backup.

            I stand by my comments.
            • Of course it doesn't work as a backup. It's not meant to. Ghosting is a way to install one copy of Windows on one computer, get it set up the way you want all of your systems to look, run the sysprep (to clear the SID), and make a ghost image. Burn that image to a CD, and get it out to a bunch of other computers in a one (or two) step install, quickly and efficiently.

              And suprise, suprise... if you change the hardware, the ghost image won't work. It's not meant to.

          • He's not referring to ghosting, or rolling the same installation out to multiple different computers, he's referring to the ability, or more accurately the lack of ability, to recover from catastrophe. Lose a power supply, motherboard, cpu or such, and if you've got another computer you can cannabalize or take over you can be back in business very shortly. Microsoft seems to be throwing away at least one 9 in the high-reliability game. For FUD value, you pass that one degree of separation and that server will never play the violin again.

      • I was not able to get the time service to use any but Microsoft's computers. Please explain how to do this. Microsoft certainly does not make it easy to use NIST servers.

        Sysprep does not allow fully functional backups, as Microsoft says. Sysprep is used to prepare new systems.

          • What is most interesting about your comment is that you are using this situation as a way of acting out your anger.

            I stand by what I said about making functional backups. Most people don't try to do restores, so they don't realize how many times backups aren't really backups.

            It is interesting how difficult it is for people to deal with an abuser. Instead of efficiently moving to limit the destructiveness of the abuser, the the abused people often begin to attack each other, as you have done.

            When I first tried to change the time server in Windows XP, I got error messages. The system I was testing would not let me make the change. I got error messages when I tried to use any but Microsoft's time server. Now, it works. Thanks for the info. I changed my article to reflect this new information.

            I don't say that I know everything about Windows XP. You undoubtedly know things that I don't know. I think it is very likely I know things you don't know. It is interesting that you have the presumption that, if you know something I don't know, that gives you a license to make an angry attack. It is also interesting that you have the presumption that, if I say one thing that is mistaken, you can ignore everything else I said.

      • There's some misunderstanding here. First, it is not a registry backup that you want, it is a backup that you can restore. I don't know any way of replacing an entire registry with an exported text file. If there is a way, would someone tell me?

        More details about registry problems: The problem with the registry is this. Suppose the registry becomes corrupted, but the software that the corruption affects is not used for a considerable time. After the corruption occurs, the computer is upgraded, perhaps with new application software, perhaps with new drivers. Then maybe new system preferences are applied. Suppose the company has saved backups of all previous versions of the registry on CD (an unlikely event).

        See the problem? Since all the software is connected to all the other software by the registry, corruption that goes unnoticed for a while can create an impossible situation. If the company goes back to the original, known good registry, they must give up all the time they spent upgrading the computer. This may be substantial, especially since they may not have complete records about what upgrading was done.

        In actuality the situations caused by the registry are far, far more complicated than this. For example, you may think that some failure you are having is caused by registry corruption. However, it may take far too much time to prove whether that is the case. If you think of all the combinations of difficult circumstances, you will see that having most configuration settings in one file is sometimes devastating for the user.

        Consider that the person who is using the computer probably has an important job in the company, and wants to use the computer, since only some functions don't work, but others do. Consider that a repair person must be supervised 100% of the time at some companies, because of security needs.

        Please educate me if I'm wrong, but there is nothing like this in Linux or BSD. First, there is no single file in which corruption can make an entire installation worthless. Second, there is far better error checking, so corruption of any kind is less likely to occur. With Windows XP, sometimes a faulty program can cause the entire OS to become unstable. (I have personally seen this at least 50 times.) My experience with Linux is that the OS just throws the faulty application out of memory and comes back and says, okay, what else do you want to do?

        With Linux, a software upgrade that you much later discover was bad causes you to re-install a known good version. With Microsoft Windows XP, because of the connection between all programs by the registry, you may have to start over with a re-formatted hard drive. This usually takes many hours, especially in situations in which a company employee uses a system with special adjustments or programs, which is often the case.

          • I suggest you deal with your anger problem, and not bring it to Slashdot.

            Your comments do not apply to the situation mentioned. You apparently haven't read my comment carefully.

            Users have always had the option of making backups of the registry. Making useful backups is often difficult or impossible. Backing up the registry in Windows XP is even more difficult, because the registry in now not all in one file, but is partly spread to several files, and the OS prevents you from making copies with xcopy.exe or the copy command. So, you cannot create your own backup tools, as you could in Windows 98.
          • The obvious solution is to have NT on a 2gig max DOS FAT16 partition and from a DOS boot, use DOS means to save/restore all the files in C:\WINNT\SYSTEM32\CONFIG.
            But it really really bugs me to see people who clearly have no desire to learn, and show no technical competence go off trying to sound like an expert and offer advice.
            Self-referential?

          • I don't think I expressed the question very well. Those files do not pose the same problem as the registry in Windows. The registry connects the configuration of the OS with the configuration of all of the software that is installed.

            In the registry, if you get corruption and don't realize it, and do other installations and changes that write to the registry, it can become impossible to go back to an earlier backup without losing all of the work of upgrading.

            There is nothing like this in Linux or BSD, apparently. See the section "More Details about Registry Problems" in the article, Windows XP Shows the Direction Microsoft is Going. [hevanet.com]
      • That is a good question. If you buy a Microsoft mouse, you don't get the full functionality until you let the mouse software(!) connect to the internet. So, that gives you an idea of what Microsoft would do. The question is, what does Microsoft do now? First, they make it quite difficult to upgrade your computer to fix bugs. Sometimes the downloadable updates lag behind those available with Windows Update.

        Also, it is the direction that Microsoft is going that is even more alarming. Windows Media Player already reports your music choices to Microsoft. The EULA for a security bug fix [bsdvault.net] to Windows Media Player gives Microsoft complete control over your computer: They own it, not you. That shows that Microsoft can and will be sneaky. (The EULA says that it is limited to Digital Rights Management, but Microsoft is trying, with Palladium, to extend Digital Rights Management to everything you do on your computer.)
        • the direction that Microsoft is going that is even more alarming
          One of the cheap shots for effective security is to never use the machine to be patched to download the patches. Use something else, anything else. I'm very comfortable using Microsoft Windows NT to download RedHat patches.

          gives Microsoft complete control over your computer: They own it, not you.
          That's the My of My Computer. I think the "My" has to refer to whoever named it so.

  • is there any way to find out all of the subdomains at microsoft.com (or msn.com) ?
    ie:
    sa.microsoft.com
    windowsmedia.microsoft.c om
    msid.msn.com

    or can they create subdomains that are completly secret (until found out)
    as i would like a list of every microsoft subdomain (and msn domains) so i can add them to the Host file project [remember.mine.nu] so they can be selectivly blocked ?

    any help would be apreciated as i already have an extensive list of MS domains but i would really like to grab them all (and any future ones) :)