David Plummer, a former Microsoft engineer, has recently opened up about his pivotal role in the development of Windows XP’s Product Activation system. As he reveals, he was the “primary author” responsible for the operating system’s side of this controversial feature, which included the notorious product key known as FCKGW. This key became infamous for its widespread use on pirated copies of the operating system, often seen scrawled on home-burnt CDs.
The Origins of FCKGW
Plummer recalls the technical intricacies involved in creating the product activation system. He explains, “I took their disc data and compressed and encrypted it several times. Rest assured it’s encrypted and even in the AI age no one has extracted it yet.” His approach was driven by a need for random data, leading him to utilize a precompressed binary image, a decision influenced by his youthful uncertainty regarding the reliability of CryptGenRand.
For those who attempted to use the FCKGW key on standard XP CDs, Plummer notes that it would not function as intended. “You didn’t have Bob in your bits,” he quips, indicating that the key was specifically tied to certain data configurations. However, for those savvy enough to download large ISO binaries or copy CDs in 1995, the combination of the key and a compatible disc could lead to a seemingly legitimate installation of Windows XP.
The Piracy Incident
Complicating matters for Microsoft, a piracy group known as Devils0wn leaked a complete Windows XP Pro Corporate ISO just five weeks prior to the official launch, along with the valid FCKGW key. The design of Windows Product Activation allowed for a bypass of the usual validation checks when a mathematically valid key was paired with the Volume Media data check, resulting in unauthorized installations.
As Plummer recounts, the situation escalated as pirates began embedding the key into images or simply writing it on CDs with a Sharpie. Speculating on the origins of the key, he suggests that it likely came from an OEM or hardware partner who received early access to the final media, allowing them to prepare for the launch. Names like Dell and Intel frequently emerge in discussions about this early access, as very few organizations had Volume License Keys (VLKs) at that time.
Microsoft’s Response
In response to the leak, Microsoft took measures to blacklist product IDs associated with the compromised keys in Service Pack 1. Service Pack 2 further intensified these efforts by blocking updates for installations using the FCKGW key. Nevertheless, Plummer points out that valid, un-leaked VLKs remained functional with Volume Media versions of XP for years following the incident.
Reflecting on the operational misstep, Plummer concludes, “The media and one of those keys left the building before the product even reached stores. Once both pieces were public, WPA’s hardware-binding never got a chance to run.” Interestingly, he mentions that he never encountered a key generator that effectively worked for Windows XP, while others speculate that the generators available at the time may have simply been selecting from a list of leaked Volume Media keys.
As the digital landscape of the early 2000s resembled a wild west of sorts, the story of the FCKGW key serves as a fascinating chapter in the history of software piracy and product activation. While many users may remember the key fondly, Plummer maintains a light-hearted detachment, claiming, “Not me, though. First time I’ve ever seen it in my life, guv. Honest.”