Charlie does not let Lisa near those scary ultra loud crinkly biodegradeable Sun Chips bags.
[email protected] Fri, 25 Sep 2020 11:29:29 -0700 (PDT)
Newsgroups
alt.alt
Message-ID
<[email protected] >
Stories
Windows XP Source Code Leaked
from the breaking-news dept.
Artem S. Tashkinov writes:
Gizmodo Australia reports: On Thursday, users on 4chan posted what they claimed was the source code of Windows XP. Posting an image of a screenshot allegedly of the source code in front of Window's XP iconic Bliss background, one user wrote 'sooooo Windows XP Source code leaked'. Another Redditor helpfully has uploaded the code as a torrent, assisting in its spread. While there is no confirmation that this code is definitely Windows XP, independent researchers have begun to pick through the source code and believe it stands up to scrutiny.
The Windows XP source code is not the only code which might have leaked. A screenshot of the torrent files contains files and folders named, Xbox, Windows Research Kernel, MS DOS 6.0, Windows NT 3.5 and 4 source code, Windows Embedded and CE and many others. If true, that could spell a disaster for Microsoft because large chunks of Windows XP source code are still used in Windows 10, and as for Open Source, this leak could become a boom for Wine development because Microsoft is notorious for having a great number of internal APIs and various hacks in their APIs which make it difficult to reimplement them properly.
Posted by msmash 4 hours ago
it windows microsoft technology windowsxp
Close Ad
117 Comments
Help
All
Outstanding
Funny
Yay, they win a cookie (+1)
Malays2 bowman a few seconds ago
Awesome, they posted a Windows source that is 20 years old, as well as a Dos source that is pushing 30.
"oOoH lOoKiE. iZ gOtZ tEh xP k0De" would have gotten them a massive parade and a throne carried by slaves back in the 90's/00's. Today, not so much.
Reply Share
Flag
Great, (+1)
Mr. Dollar Ton 4 hours ago
we can finally have a working wine.
Reply Share
Flag
Re: Great, (+4, Interesting)
nbritton 4 hours ago
Are you sure about that, this could end up being a poison pill. Microsoft could allege that any reverse engineered code was derived from the original source code. If Microsoft wants to be seen as friendly to the open source community, they're going to need to open source whatever code was apart of this disclosure or at least agree to not sue anyone for reverse engineered implementations. This significantly damages the ReactOS project, probably killing it dead. In theory, this could be an intentional act by Microsoft to damage various open source projects.
Reply Share
Flag
Re: Great, (+1)
JustNiz 3 hours ago
Microsoft can allege all they like. Without direct proof they can't do shit.
Reply Share
Flag
Re: Great, (+5, Insightful)
ZiggyZiggyZig 3 hours ago
With a lot of money and a good lawyer, you don't need direct proof to do shit.
Reply Share
Flag
Re: Great, (+1)
JustNiz 3 hours ago
Why haven't they done it already then?
Reply Share
Flag
Re: Great, (+1)
fustakrakich 3 hours ago
Timing is everything
Reply Share
Flag
Re: Great, (+1)
nipslan 2 hours ago
Not to mention M$ has definitely already sued companies out of business already.
Reply Share
Flag
Re: Great, (+1)
saloomy 2 hours ago
It would be impossible for them to sue individuals who release those code based on torrents and open source repositories. Especially since many of them will be hosted beyond jurisdictions that give a flying fuck about IP.
Reply Share
Flag
Re: Great, (+1)
segin an hour ago
The problem then is that if you used leaked code, you can then only release in those places that don't care about IP. This can never help Wine users in the Occident, for example.
Reply Share
Flag
Re: Great, (+1)
Smidge204 2 hours ago
You can't allege that leaked source code was used to develop new code, if there isn't any leaked source code.
But now there is leaked source code, so anything created on or after today could potentially be a target for legal harassment.
=Smidge=
Reply Share
Flag
Re: Great, (+1)
jcr an hour ago
What's the point? Is there some big, deep-pockets WINE user that could cough up anything like what MSFT would spend on the litigation?
-jcr
Reply Share
Flag
Re: Great, (+4, Insightful)
DarkOx 3 hours ago
Are you sure about that these would be civil suits you realize. Microsoft has deep pockets to do what Caldera tried to do to IBM and Novel. They can sit and litigate every little file, and unusual data structure. That ties up a lot of lawyer, court, and discovery time. Gets expensive fast. The sort of expensive that cause OSS products without the wealth patron like IBM to just fold up. I don't how deep CodeWeavers pockets go but probably not Microsoft litigants deep.
Reply Share
Flag
Re: Great, (+1)
ArchieBunker 3 hours ago
One month later and WINE suddenly has 100% compatibility...
Reply Share
Flag
Re: Great, (+3, Insightful)
jittles 3 hours ago
Are you sure about that, this could end up being a poison pill. Microsoft could allege that any reverse engineered code was derived from the original source code. If Microsoft wants to be seen as friendly to the open source community, they're going to need to open source whatever code was apart of this disclosure or at least agree to not sue anyone for reverse engineered implementations. This significantly damages the ReactOS project, probably killing it dead. In theory, this could be an intentional act by Microsoft to damage various open source projects.
You probably should have disclaimed that with a "IANAL" because you clearly do not understand how this works. It is perfectly legal to reverse engineer your competition's products. What is not legal is to use that reverse engineering effort to develop your own competing project and there is a very simple workaround. You have one team reverse engineer the product and draft a specification based on that effort. You have a second team perform the implementation. This has been done for decades. They can also go the route of relocating their project to a country that simply does not care where the material came from. This is very common in open source projects that may be subject to the DMCA - they ensure that all of their infrastructure and contributors are not bound by the DMCA and go on as if the law never existed.
Reply Share
Flag
Re: Great,
Aighearach 2 hours ago
He didn't give any legal opinions, don't be a maroon.
Reply Share
Flag
Re: Great, (+1)
pak9rabid 2 hours ago
See also: IBM PC compatible
Reply Share
Flag
Re: Great, (+1)
OrangeTide 2 hours ago
IANAL but hiring a third party to reverse engineer and write you a spec is not illegal. Most of what is needed are not algorithms but interfaces and architectural behavior. Once you have a clean room spec the implementation can move forward.
It's too bad if this third party decides to use some stolen code. That's a copyright violation. And entirely the third party's problem. Business relationships are usually insulating like that. We have numerous scandals of contractors using illegal practices and rarely is the original company found at fault. The key is you don't want to ever know for certain that your business partner is doing something shady. Don't have emails or voicemails that can show up in discovery.
P.S. not only am I not a lawyer. I am not YOUR lawyer.
Reply Share
Flag
Re: Great, (+1)
sjames 30 minutes ago
Also IANAL, but there's nothing illegal about looking at leaked code and writing up a detailed description of the ABI. The person who gave you that code might have violated copyright, but you didn't.
Unfortunately, that doesn't insulate you from a never ending train of civil suits alleging essentially "you didn't say Mother May I" and "I didn't say Simon Says". And it's more expensive than most people can bear even if they win every single time.
Consider the crazy SCO lawsuit. Even when the plaintiff was reduced to just a CEO and a Lawyer with no hope of ever resuming business, the shambling zombie continued to be a time and money suck for 10 years. Even to this day, the rotting remains occasionally quiver as if trying to get back up. Even the revelation that they didn't actually own the copyright to the code they were suing over couldn't kill it.
Reply Share
Flag
Re: Great, (+1)
nbritton 2 hours ago
Yeah, you also probably should have disclaimed that with an "IANAL" as well, because that strategy only works if you can prove the second team has never seen the source code, and now that the source code is public information, Microsoft can easily argue that any person writing new code snuck a peek at the original source code. The coder writing new code would for all intents and purposes need to try to prove a negative.
https://www.amc.com/shows/halt...
Reply Share
Flag
Re: Great, (+1)
jittles 43 minutes ago
Yeah, you also probably should have disclaimed that with an "IANAL" as well, because that strategy only works if you can prove the second team has never seen the source code, and now that the source code is public information, Microsoft can easily argue that any person writing new code snuck a peek at the original source code. The coder writing new code would for all intents and purposes need to try to prove a negative.
https://www.amc.com/shows/halt...
I don't know how your legal system works but in an MS lawsuit the plaintiff would most certainly have to prove that not only did the defendant do something wrong but that what they did somehow caused harm to the plaintiff. If you don't ever download the leaked code and you don't have any of the code samples on your machine how can MS ever prove that you saw the code? Your argument makes no sense whatsoever on the face of it because any clean room spec implementation would be impossible by that same token. The source code exists ergo it is possible that one of the clean room developers saw it. That's just absurd. Microsoft would have to prove that they saw the source code and used it as a reference, not the other way around.
Reply Share
Flag
Re: Great, (+1)
thegarbz 3 hours ago
Microsoft could allege that any reverse engineered code was derived from the original source code.
That's not how that works. APIs are not copyrightable, and thus the ability to copy their functionality is not something they can suddenly claim is infringing simply because someone could see how it worked in source code rather than reverse engineer it.
this could be an intentional act by Microsoft to damage various open source projects.
I think the 5G is getting to you. Best go burn down your local tower.
Reply Share
Flag
Re: Great, (+2)
tysonedwards 3 hours ago
Google v. Oracle would presently disagree with you. We are 13 days away from that being heard by the Supreme Court, so we aren’t too far away from a definitive answer on the matter.
Reply Share
Flag
Re: Great, (+1)
Aighearach 2 hours ago
Another temporally challenged analysis.
Is some country's mind control satellite malfunctioning, or what? What sort of morons don't understand tenses, but think they understand details?
Reply Share
Flag
Re: Great, (+1)
jabuzz 2 hours ago
Unless you happen to be Oracle who think API's are copyrightable.
Reply Share
Flag
Re: Great, (+1)
kbg 2 hours ago
That's not how that works. APIs are not copyrightable, and thus the ability to copy their functionality is not something they can suddenly claim is infringing simply because someone could see how it worked in source code rather than reverse engineer it.
Unfortunately reality doesn't agree with you: https://en.wikipedia.org/wiki/...
Reply Share
Flag
Re: Great, (+1)
sconeu 2 hours ago
That's not how that works. APIs are not copyrightable, and thus the ability to copy their functionality is not something they can suddenly claim is infringing simply because someone could see how it worked in source code rather than reverse engineer it.
Really? You might want to ask Oracle about that...
Reply Share
Flag
Re: Great, (+1)
segin an hour ago
the ability to copy their functionality is not something they can suddenly claim is infringing simply because someone could see how it worked in source code rather than reverse engineer it.
That's actually exactly how this works, at least in the US. In fact, this was one of the main points of the case Sega Enterprises Ltd. v. Accolade, Inc., 977 F. 2d 1510 (9th Cir. 1992)
Reply Share
Flag
Re: Great, (+3, Insightful)
SirSlud 3 hours ago
I seriously doubt MS gives a shit about Wine, they probably recognize it does their platform more good than harm - or has any meaningful effect on their bottom line at all. This is a company that long ago stopped putting all its eggs in how much money selling Windows licenses can make them. I expect rebuttals only from the folks who are in a spacetime bubble stuck at 20 years ago.
Reply Share
Flag
Re: Great, (+3, Insightful)
neilo_1701D 3 hours ago
Are you sure about that, this could end up being a poison pill. Microsoft could allege that any reverse engineered code was derived from the original source code. ... This significantly damages the ReactOS project, probably killing it dead.
And how does this happen, when the Windows 2000 source code leak didn't have these repercussions back in 2004?
Also, does Microsoft even care about ReactOS? It's a nice little project and all, but hardly a threat to Windows 10 or Azure.
Reply Share
Flag
Re: Great, (+1)
Voice of satan 2 hours ago
Exactly that. Codeweaver, for example, expressly states new hires must have no Microsoft source code experience. Their code MUST look different and be a clean room implementations. Else Microsoft could sue them and prove their code has been reverse engineered.
And Wine and DXVK are very important pieces of steam play which are very important to Linux gaming.
It will be harder to find developers "clean" of that knowledge.
Reply Share
Flag
Been there done that (+1)
williamyf an hour ago
The code of NT was leaked a few years/lustres ago. That did not spelled doom for reactos or wine, or a poison pill from redmond.
This leak will not be different
Reply Share
Flag
Re: Great,
RoseMersi an hour ago
Hey Man do u want to see me naked? Go to private broadcast for u and me, I want to fulfill all your sexual fantasies =>> https://is.gd/user9263
Reply Share
Flag
Re: Great, (+1)
julian67 39 minutes ago
Yeah Microsoft are *terrified* of ReactOS, an archaic & permanently alpha state OS used by 5 developers and their friend. Jesus, get a grip.
Reply Share
Flag
Re: Great, (+2)
jovius 4 hours ago
Until MS triumphantly finishes years of work for Windows 11, of which only 23% consists of hacks and internal APIs to not make Wine work.
Reply Share
Flag
Re: Great, (+1)
Jeremiah Cornelius 3 hours ago
Oh, no! Someone stole the golden turd!
Reply Share
Flag
Re: Great, (+1)
fustakrakich 3 hours ago
The owners were negligent, needs polishing
Reply Share
Flag
Re: Great, (+1)
johnsie 3 hours ago
Wine already works for most XP stuff. It's later versions of .NET thatthey struggle with. .NET Core should make a difference since it is multiplatform by design.
Reply Share
Flag
Re: Great, (+1)
Kisai 2 hours ago
Definitely not.
Just like the "Nintendo Leaks" , at best someone who isn't part of an emulator project can pick through it and identify the bits that cause problems and then slip that description under the door to someone working on the emulator. The same for Wine/ReactOS.
While it's certainly an interesting thing, it's also not really that valuable except to people looking for exploits. In which case as soon as it gets to someone who is actually knowledgeable and not just a bunch of script kiddie's, someone is inevitably going to recompile it in China and "Windows XP Chinese government monitors all your nonsense Edition" ends up supplanting pirate versions.
Reply Share
Flag
So, where are the GPL violations? (+4, Insightful)
nagora 4 hours ago
That's going to be interesting, isn't it?
Reply Share
Flag
Re: So, where are the GPL violations? (+1)
bobbied 3 hours ago
That's going to be interesting, isn't it?
Yup... I have a sneaking suspicion that there will be a significant issue discovered here... Which if it turns out to be true, then the mighty M$ may end up putting the source into the public domain and be done with it.
At which point, they will start rapidly rewriting all the code they can in their current products. It's OK, they can afford it I think.
Reply Share
Flag
Re: So, where are the GPL violations? (+1)
ClickOnThis 2 hours ago
That's going to be interesting, isn't it?
Yup... I have a sneaking suspicion that there will be a significant issue discovered here... Which if it turns out to be true, then the mighty M$ may end up putting the source into the public domain and be done with it.
Leaked or not, the code is still copyright. By somebody, if not by Microsoft. So no, I don't see this going into the public domain.
What I see as more likely is that MS will release what it can under a license that will protect its interests, even though the code is now visible. If MS has GPL code in its products, then it may (a) rewrite the offending code (as you suggested); or (b) welcome a showdown on the legal strength of the license. Companies in similar situations have opted for (a) up to now.
Reply Share
Flag
Re: So, where are the GPL violations? (+1)
OrangeTide 2 hours ago
Which if it turns out to be true, then the mighty M$ may end up putting the source into the public domain and be done with it.
It would mean that Microsoft would have to cease further distribution of Windows XP. That's probably not a big deal.
Potentially there are damages possible. That's complicated. I don't know of any examples where an GPL project successfully claimed damages for a violation. But I wouldn't be surprised if there were discreet settlements.
Reply Share
Flag
Many eyeballs out of MS have seen source, legally (+4, Insightful)
perpenso 3 hours ago
That's going to be interesting, isn't it?
Most likely, no, not at all. Researchers, professors and students, have had access to MS Windows (NT onward) source code for a long time. Microsoft grants access to certain researchers looking into things that also interests Microsoft. They have to keep the source secure but are free to publish their work. And Microsoft gets the right to incorporate their work if they care too.
In short many eyeballs have been on the Windows source code outside of Microsoft, and that's just the legal eyeballs.
Reply Share
Flag
Re: Many eyeballs out of MS have seen source, legal (+1)
nagora 35 minutes ago
That's going to be interesting, isn't it?
Most likely, no, not at all. Researchers, professors and students, have had access to MS Windows (NT onward) source code for a long time. Microsoft grants access to certain researchers looking into things that also interests Microsoft. They have to keep the source secure but are free to publish their work. And Microsoft gets the right to incorporate their work if they care too.
In short many eyeballs have been on the Windows source code outside of Microsoft, and that's just the legal eyeballs.
So, basically no one I would trust to tell the truth. Or indeed with any vested interest in telling the truth. Just report it and pocket the hush money.
Reply Share
Flag
Re: Many eyeballs out of MS have seen source, legal (+1)
perpenso 5 minutes ago
That's going to be interesting, isn't it?
Most likely, no, not at all. Researchers, professors and students, have had access to MS Windows (NT onward) source code for a long time. Microsoft grants access to certain researchers looking into things that also interests Microsoft. They have to keep the source secure but are free to publish their work. And Microsoft gets the right to incorporate their work if they care too.
In short many eyeballs have been on the Windows source code outside of Microsoft, and that's just the legal eyeballs.
So, basically no one I would trust to tell the truth. Or indeed with any vested interest in telling the truth. Just report it and pocket the hush money.
Well you could wait for the QAnon report on the source. :-)
Reply Share
Flag
Re: So, where are the GPL violations? (+1)
ArchieBunker 2 hours ago
Why would they bother when they could use BSD code? Didn't they already use it for ftp.exe back in the NT days?
Reply Share
Flag
Re: So, where are the GPL violations? (+1)
nagora 36 minutes ago
Why would they bother when they could use BSD code? Didn't they already use it for ftp.exe back in the NT days?
That's a fair point; it's easy to forget all those BSD mugs working away for the world's richest companies for free.
Reply Share
Flag
The gift that keeps on giving (+2)
OffTheLip 4 hours ago
that could spell a disaster for Microsoft because large chunks of Windows XP source code are still used in Windows 10
That explains a lot.
Reply Share
Flag
Re: The gift that keeps on giving (+1)
Luckyo 4 hours ago
Yeah, that explains the stable, functional parts that aren't directly linked to windows update and occasionally fuck your machine.
Reply Share
Flag
Re: The gift that keeps on giving (+3, Insightful)
WeatherServo9 4 hours ago
that could spell a disaster for Microsoft because large chunks of Windows XP source code are still used in Windows 10
That explains a lot.
If it ain't broke, don't fix it! Windows XP saw a lot of real world use over a number of years; sure, it had problems, but there's also probably a good amount of code essentially proven to be solid and reliable, so why wouldn't they want to leave well enough alone when possible?
Reply Share
Flag
Re: The gift that keeps on giving (+1)
jfdavis668 3 hours ago
Windows XP started out as a bug filled release with huge security holes. Took them years to find all the ways that it could be hacked and supply a patch. Now, it was better that the 95 based versions.
Reply Share
Flag
Re: The gift that keeps on giving (+2)
squiggleslash 2 hours ago
A huge number of Window's problems are likely directly linked to use of older code that hasn't been phased out. Windows having to reboot itself every time it does an update is a direct result of how it locks DLLs and other blocks of code. There are workarounds to try to minimize this in Windows at the moment, but the fact that Windows 10 cannot, without massive efforts on the part of the user to circumvent Microsoft's autoupdating process, have an uptime of more than a few days, should demonstrate that it's still completely fucked up.
Windows XP was an awful operating system. It was tolerated because it was slightly better than the piles of crap Microsoft had released before it, for the most part, but the major flaws in Windows today are directly traceable to decisions made long ago, and Microsoft's attempts to find workarounds for them without breaking backwards compatibility.
Reply Share
Flag
Re: The gift that keeps on giving (+1)
AmiMoJo 2 hours ago
XP was tolerated because there was no alternative for a lot of people. Mac OS only worked on Macs and Linux was pretty awful for non-techies in 2001.
Nowadays, in no small part due to many things being web based and cross platform frameworks making software more widely available, Linux is a great alternative as a desktop OS.
Reply Share
Flag
Re: The gift that keeps on giving (+1)
ClickOnThis 2 hours ago
that could spell a disaster for Microsoft because large chunks of Windows XP source code are still used in Windows 10
That explains a lot.
If it ain't broke, don't fix it! Windows XP saw a lot of real world use over a number of years; sure, it had problems, but there's also probably a good amount of code essentially proven to be solid and reliable, so why wouldn't they want to leave well enough alone when possible?
If Microsoft was relying on security-through-obscurity in this WXP code, and it is present in W10, then yes, it could spell disaster.
Making the code visible may in fact be what breaks it.
Reply Share
Flag
Re: The gift that keeps on giving (+1)
omnichad 2 hours ago
It would be awful if they were finally forced to fix these bugs.
Reply Share
Flag
It is broke, but can't fix it (+1)
raymorris 2 hours ago
One thing that has been important to Microsoft is backward compatibility - a Windows program I wrote 22 years ago still works. Contrast iOS and Android.
XP *is* broken, very. Yet Microsoft chooses not to fix it. Both for backward compatibility and because fixing things costs time and money in the short term.
Something we're dealing with right now is that while TLS 1.2 was released in 2008, Windows still uses 1.0 and 1.1 for important functionality. TLS 1.2 still isn't enabled in Windows by default, over a decade after 1.1 was broken. That's where a lot of the security issues with Windows come in - they are consistently 10-15 years behind on security because they don't want to change anything.
Reply Share
Flag
Re: It is broke, but can't fix it (+1)
jrbrtsn an hour ago
Based on some recent work I did with the Win32 API, I think Microsoft has a huge house of cards on their hands. The whole I/O subsystem looks bizarrely complex by Linux standards, and the TCP/IP implementation seems like an afterthought at best. If they have any sense they will put a BSD or Linux kernel under their graphical shell, and drop the steaming turd that is the NT kernel.
Reply Share
Flag
Re: The gift that keeps on giving (+2)
Merk42 an hour ago
This is Slashdot, Microsoft can do no right.
If Microsoft were to have completely rewritten Windows 10 from scratch, people here would complain it was "change for the sake of change" and therefore bad.
Reply Share
Flag
Re: The gift that keeps on giving (+1)
ArchieBunker 3 hours ago
Reading some comments elsewhere it seems this torrent was floating around in hacker circles for a long time and someone finally leaked it.
Reply Share
Flag
Re: The gift that keeps on giving (+1)
bobbied 3 hours ago
that could spell a disaster for Microsoft because large chunks of Windows XP source code are still used in Windows 10
That explains a lot.
Microsoft is a slave to legacy. They have to maintain compatibility above all else for as long as they possibly can. That means they keep the same code base that works for a LONG time.
Reply Share
Flag
Re: The gift that keeps on giving (+2)
TheDarkMaster 2 hours ago
"Microsoft is a slave to legacy. They have to maintain compatibility above all else for as long as they possibly can."
That's why Windows remains the dominant operating system on the market: Users have a very reasonable guarantee that their applications will continue to work.
Reply Share
Flag
Re: The gift that keeps on giving (+1)
iampiti an hour ago
Yup, I think it's a very positve feature of Windows. They strive to be reasonably compatible with previous versions and, thanks to that, you can run many binaries that are 20 years old or more.
I'm no expert but probably only IBM mainframes have a better track record.
Reply Share
Flag
I dunno, if the code works. (+2)
wiredog 3 hours ago
I'm currently working on a system that has 25+ year old C code way deep down inside. It works fine, all the bugs are well documented and dealt with, so why replace it?
Reply Share
Flag
Re: The gift that keeps on giving (+1)
iampiti an hour ago
Well, Windows is a huge project and you don't just throw all the code away and start from a clean sheet for every new version. A lot of time has gone by since Windows XP was last updated but I'm sure some parts of the code have seen little change since then
Reply Share
Flag
Wine, DOSBox, FreeDOS and ReactOS (+1)
jfdavis668 4 hours ago
Will suddenly improve.
Reply Share
Flag
Wine isn't going to touch this with a 10ft pole (+1)
Cid Highwind 4 hours ago
If Microsoft proprietary code turns up in Wine, they're proper fucked - criminal and civil liability to the tune of the GDP of the entire observable universe.
Reply Share
Flag
Re: Wine isn't going to touch this with a 10ft pole (+5, Interesting)
MikeDataLink 4 hours ago
If Microsoft proprietary code turns up in Wine, they're proper fucked - criminal and civil liability to the tune of the GDP of the entire observable universe.
That's not how this works. They'll use the source code to discover the API's so they can engineer software that talks to them.
Reply Share
Flag
Re: Wine isn't going to touch this with a 10ft pole (+1)
bill_mcgonigle 3 hours ago
This was basically settled with Compaq v. IBM. One team reverses & documents, one team implements, and a third team ("Chinese Wall") only talks to the other teams.
There can only be communication about how it works, no direct knowledge of code. As soon as one implementor sees the code, everything is destroyed.
I seem to recall Compaq had different access-controlled offices too. For WINE it might be more difficult as access control is harder online. One slip-up could ruin everything.
Reply Share
Flag
Re: Wine isn't going to touch this with a 10ft pole (+1)
MikeDataLink 3 hours ago
This was basically settled with Compaq v. IBM.
Nope. In that case they copied the code and made their own version of the BIOS. This isn't about copying the code, its about learning how to talk to the code.
Reply Share
Flag
Re: Wine isn't going to touch this with a 10ft pole
Anonymous Coward 3 hours ago
This is not about "learning how to talk to the code" - that's what you'd be doing if you were writing an application that wanted to make use of undocumented APIs.
What Wine is doing is re-implementing the APIs themselves so that existing applications can successfully make use of them, which is pretty much exactly the same as the Phoenix BIOS case described above.
Reply Share
Flag
Re: Wine isn't going to touch this with a 10ft pole (+1)
Rockoon 3 hours ago
That's not how this works. They'll use the source code to discover the API's so they can engineer software that talks to them.
You had me until the word "they"
Its inevitable. Dont be blind.
Reply Share
Flag
Re: Wine isn't going to touch this with a 10ft pole (+2)
Cid Highwind 3 hours ago
Windows code has leaked before (and sparked arguments on slashdot about what Wine should do with it before) their stance last time was they don't want contributions from anyone who touched it.
Reply Share
Flag
Re: Wine isn't going to touch this with a 10ft pole (+1)
orudge an hour ago
Wine has clean room guidelines (https://wiki.winehq.org/Clean_Room_Guidelines) which specifically forbid looking at Microsoft code (leaked or otherwise - e.g. Windows Research Kernel).
In many cases I suspect the code would not be all that useful anyway - some of Wine’s glitches and foibles arise simply because of differences between Linux/macOS and Windows that can’t easily be accommodated. And an unknown user who suddenly dumped a load of code without otherwise building up their experience with Wine and so on would be looked upon very suspiciously.
Reply Share
Flag
Could be a disaster for Wine development, rather (+5, Insightful)
mysidia 4 hours ago
Windows 10, and as for Open Source, this leak could become a boom for Wine development
If the Wine developers know what they are doing, they will steer clear from reading leaked source code.
Obtaining sudden unexplained knowledge from the sources could later result in allegations to having read and incorporated non-literally copied code and trade secrets that were from materials leaked illegally... Its toxic and dangerous to touch that stuff, unless Microsoft responds to the leak by releasing the code as open source to encourage that others identify bugs and submit fixes.
The more likely result however, is teams of investigators and lawyers going out to try and find where leaked code might have reached, and trying to get all misappropriated copies destroyed.
That... and Microsoft will now have an excuse to re-write a whole bunch of OS code.. perhaps rewriting the old C++ code in C# or Rust, or Javascript, or something...
Reply Share
Flag
Re: Could be a disaster for Wine development, rathe (+1)
dabadab 3 hours ago
Well, there's a tried and true method of executing this, as demonstrated by Phoenix Software with the IBM PC BIOS: one team looks at the code and writes a functional specification based on it and the other team (the actual Wine developers in this case) implement this specification.
Reply Share
Flag
Re: Could be a disaster for Wine development, rathe (+1)
sconeu 2 hours ago
The difference is that the PC BIOS was legally obtained, it was not a trade secret. IBM published the BIOS in the manual.
Reply Share
Flag
Re: Could be a disaster for Wine development, rathe (+1)
omnichad 2 hours ago
That wouldn't matter. You can't taint facts with copyright law. Sure, possessing/distributing the source code could be risky or even prosecuted, but work created from the derived spec would still be clear.
Reply Share
Flag
Re: Could be a disaster for Wine development, rathe (+1)
mysidia 43 minutes ago
but work created from the derived spec would still be clear.
Nope. Under the UTSA this would still be misappropriation of a trade secret a.k.a. Trade Secret infringement... this occurs generally when anyone improperly acquires a trade secret or improperly discloses or uses a trade secret.
Writing the spec based on the source code in the first place would itself be an act of trade secret infringement.
Then using the spec knowingly or with negligence or with having reason to know or even just accidentally using the spec that improperly disclosed a trade secret would be another act of trade secret infringement.
Reply Share
Flag
Re: Could be a disaster for Wine development, rathe (+1)
omnichad 31 minutes ago
The source code could certainly be a trade secret.
Calling documented bugs in the API a trade secret would require Microsoft to have to prove that the bugs were themselves a valuable secret.
Reply Share
Flag
Re: Could be a disaster for Wine development, rathe (+1)
mysidia 11 minutes ago
Microsoft to have to prove that the bugs were themselves a valuable secret.
Microsoft does not have to prove it. The commercial value in being able to create/re-create a competitive implementation would be evident in Wine's own existence. Mainly a huge burden of proof would fall to the Wine devs; all MS would need to show is pretty trivial, essentially that they kept the source code secret and took all the reasonable precautions to protect their secret, then the information allowing them to infer the 3rd party developers learned about the secrets through someone improperly obtaining and disclosing their source leak.
Calling documented bugs in the API a trade secret
Not "documented".. most APIs are Not publicly available APIs and are Internal for Microsoft's private use in the first place, and
the challenge for Wine developers is that the APIs contain numerous hacks and unexpected behaviors which
are Not published for the world to see. The value of having source code or actually accurate documentation is obviously enormous when it would come to attempting to re-create internal secret interfaces between programs and Microsoft utility libraries.
Reply Share
Flag
Re: Could be a disaster for Wine development, rath (+1)
fellip_nectar an hour ago
Easy to do with employees during a time when you could physically restrict access to the code at the workplace and be pretty damn sure no-one saw code they shouldn't have.
Not so much with a bunch of volunteers based all around the globe who access the code through the interwebs.
Reply Share
Flag
Re: Could be a disaster for Wine development, rathe (+1)
ZiggyZiggyZig 3 hours ago
Well I for one welcome our Javascript OS-rewriting overloads!
Reply Share
Flag
Re: Could be a disaster for Wine development, rathe (+2)
thegarbz 3 hours ago
Obtaining sudden unexplained knowledge from the sources could later result in allegations to having read and incorporated non-literally copied code and trade secrets that were from materials leaked illegally...
An act that isn't remotely illegal. You can't apply "trade secrets" to functionality implemented in an API. You can at best apply copyright to verbatim code.
Reply Share
Flag
Re: Could be a disaster for Wine development, rathe (+1)
flink 3 hours ago
Obtaining sudden unexplained knowledge from the sources could later result in allegations to having read and incorporated non-literally copied code and trade secrets that were from materials leaked illegally...
An act that isn't remotely illegal. You can't apply "trade secrets" to functionality implemented in an API. You can at best apply copyright to verbatim code.
If the reverse engineer even unknowingly relies on knowledge of the copyrighted source code to implement the open version of the API, it can be alleged that the implementation is now a derivative work. Even if the argument doesn't hold up at the end of the day, it will be enough to support a protracted trial that would bankrupt just about any free software project.
Any contributor to WINE should steer clear of these files, with the possible exception of header files, but those were probably available as part of SDKs anyway.
Reply Share
Flag
Re: Could be a disaster for Wine development, rathe (+1)
sconeu 2 hours ago
If the reverse engineer even unknowingly relies on knowledge of the copyrighted source code to implement the open version of the API, it can be alleged that the implementation is now a derivative work. Even if the argument doesn't hold up at the end of the day, it will be enough to support a protracted trial that would bankrupt just about any free software project.
See Oracle v. Google
Reply Share
Flag
Re: Could be a disaster for Wine development, rathe (+1)
geekmux 2 hours ago
Windows 10, and as for Open Source, this leak could become a boom for Wine development
If the Wine developers know what they are doing, they will steer clear from reading leaked source code.
Wait, Wine still exists? It actually lasted this long? Yeah, I'm sure it's seen massive improvement in the last 25 years. So has virtualization. No "dev work" needed. This is a rather weird one to keep alive.
I suddenly have this feeling that in the basement of Wine HQ, is a Fight Club full of developers...
Reply Share
Flag
Re: Could be a disaster for Wine development, rathe (+1)
iampiti an hour ago
Heh, you think they'll be ashamed of their code being exposed to the world and suddenly decide to rewrite huge parts of it in another language?
AFAIK Microsoft has already considered writing many low level parts of the OS in another language (I think I saw Rust mentioned somewhere). Also I guess some parts nowadays are written in C#.
Anyway, C++ is evolving reasonably fast these days (official releases of the standard every 3 years) and is adding many improvements. That negates somewhat the need to rewrite some parts in other languages.
Reply Share
Flag
Re: Could be a disaster for Wine development, rathe (+1)
stikves 31 minutes ago
Wine is stable enough to be okay at this point. They have already implemented most of the necessary APIs to run modern games, and even Microsoft's of Office suites.
But, just to be safe, they could implement some agreements for the future. For example, they could ask all code checking to have an acknowledgement of not looking at any existing Windows leaks.
Reply Share
Flag
Or it could be a disaster for WINE development (+1)
DarkOx 4 hours ago
Right now WINE not going "poof" do to copyright infringement action pretty much comes down to it being clean room. If any of this code ever slips its way into the project it might spell real trouble. Talk about 'viral'
Reply Share
Flag
Re: Or it could be a disaster for WINE development (+1)
OrangeTide 2 hours ago
Let's fork WINE. We'll have a version that runs XP perfectly and a version that doesn't get sued by Microsoft.
Reply Share
Flag
Who cares?
1s44c 4 hours ago
It's an obsolete version of a low quality OS family. The source code is probably only worth anything to wine developers, who are simply wasting their time, and security researchers who are looking for bugs that still exist in modern Windows.
Reply Share
Flag
Re: Who cares? (+1)
Gabest 3 hours ago
Windows 10 is XP with a new control panel. If you take out all the useless XAML/UWP based Windows Store non-sense, it's just XP.
Reply Share
Flag
Re: Who cares? (+1)
OrangeTide 2 hours ago
XP is good for running old games. Why would anyone run old games? Maybe you didn't beat them when they were new, people are busy you know.
Reply Share
Flag
Unrelated to Wine (+4, Informative)
Sun 4 hours ago
It's been a long while since I've programmed for Wine, but I doubt it changed any. It is not even the first leak.
Wine has a clear policy of not going near MS source code.
Reply Share
Flag
Boon (+1)
sethmeisterg 3 hours ago
Not boom.
Reply Share
Flag
Oh no! There's an outbreak of Windows XP! ... (+1)
Qbertino 3 hours ago
... Quick! Contain it, before it infects your computer! We're all gonna die!
Reply Share
Flag
What "disaster" (+1)
mi 3 hours ago
that could spell a disaster for Microsoft because large chunks of Windows XP source code are still used in Windows 10
What "disaster"? How could this possibly harm Microsoft?
No one is going to compete with them commercially based on this information. What harm is there in some geeks learning a few undocumented APIs? That they may now better understand, how something works — or implement their own app or widget better is good for Microsoft, as it makes their OS more attractive.
One could suspect, Microsoft have arranged for the leak deliberately — this way they shared the information without having to maintain the APIs...
Reply Share
Flag
Re: What "disaster" (+1)
k6mfw 3 hours ago
Microsoft have arranged for the leak deliberately
Kind of like a movie that is tanking at the box office, then somehow an unencrypted digital version is put into public files and gets huge headlines?
"Screenshot of source code" doesn't make sense to me. I've never seen source code but I expect it is a bloatware of text that goes on an on. And just a portion doesn't seem valuable because what other portions of the total code that is referenced or subroutine (if such a thing is still done?).
I still have three XP machines in use for personal stuff (internet, misc stuff, monitoring APRS activity). I ain't got time or skill to add "features" to my XP code.
Reply Share
Flag
Re: What "disaster" (+1)
DarkOx 3 hours ago
The disaster is there is a lot of code in Windows that goes back all the way to NT4 and maybe even before that. Not just things like cmd.exe but things that are running as "local_system" and listening on network sockets; like those print spooler vulnerabilities that were published earlier this year.
While people have no doubt fuzzed the crap out of windows that only reveals so much, and where it does turn you on to potential attack vector it does not always mean its clear or simple to turn it into something more than crashing a service. I am thinking about all those schannel bugs that nobody ever was able to turn in to RCE POCs. Keep in mind some of those are not patched on Windows 7 (out of support) and XP (out of support). There are still a good amount of win 7 out there though.
If you have the source you can feed it to a SAST tool and that might make it exactly clear what to do turn those into full RCEs attacks.
SAST Tools might also find a good number of potential new vectors that fuzzing has not.
Reply Share
Flag
NSAKey (+4, Interesting)
bill_mcgonigle 3 hours ago
Let's find out what the real story is behind NSAKey. Nobody believes Microsoft.
Reply Share
Flag
Load More
by TaboolaSponsored LinksYou May Like
Genius New Armored Shoes Taking Over US
Armored Shoes
Extra Rooms In Monterey Park Luxury Rehab Centers You May Not Be Able To Pass Up
Rehab | Search Ads
What are disease-modifying treatments for spinal muscular atrophy?
Mayo Clinic
Lucky! 23 Times Fans Married Their Celeb Crush
POPSUGAR
Submit Terms Privacy Feedback Non-mobile
follow us
Copyright © 2020 SlashdotMedia.All Rights Reserved.
×
Exercise Your Consumer Rights
Do Not Sell My Information
Opt out of campaigns and programs that require the sale or disclosure of information to our partners. View our Privacy Policy.
Submit Request
Opt Out of Targeted Advertising
Turn off online tracking by opting out of cookies and the transfer of data to third parties.
Submit Request
Exercise your consumer rights via other methods including:
By e-mail: [email protected]
By phone: 1-800-552-9000
Or by mail at:
Slashdot Media
PO Box 2452
La Jolla, CA 92038
Attention: Privacy Compliance
Slashdot
Genius New Armored Shoes Taking Over US
Armored Shoes
|
Sponsored
Extra Rooms In Monterey Park Luxury Rehab Centers You May Not Be Able To Pass Up
Rehab | Search Ads
|
Sponsored