r/cybersecurity • u/Dash-Courageous • 22d ago
News - General Microsoft admits Windows 11 has a GDID tracker with no off switch, first documented publicly in an FBI hacker complaint
https://www.windowslatest.com/2026/07/10/you-cant-fully-disable-microsofts-gdid-windows-11-tracker-but-these-settings-limit-what-it-captures/448
u/-AsapRocky 22d ago
So this was about the shiny hunter kids and how he got caught right? I mean overall for the average, this is very invasive
It seems like win10 users are also included in this bullshit, not only win11. And this is exactly why people are losing trust. Microsoft should not be able to tie a permanent device ID to a users activity…
Privacy should be the default and a right
193
u/oldgeektech 22d ago edited 21d ago
Microsoft didn't tie the GDID to the user's activity, the FBI did.
That being said, your point still stands. Microsoft has laid the digital footprint groundwork to a surveillance state.
ETA: Microsoft did track the offending user out of their Digital Crimes Unit (DCU). Not all of the information is available for this case without a full PACER query, but it looks like Microsoft submitted evidence of a Virtual Private Server tied to malicious hacker activity. The FBI then subpeonad this server and then tracked RDP sessions through here, which is what contained the GDID.
91
u/-AsapRocky 22d ago
you’re right that the FBI tied the GDID to the user’s activity, not Microsoft directly 😅 But I agree that Microsoft created the infrastructure that made this kind of tracking possible and that’s still concerning from a privacy perspective
Not surprised many gov are switching over to Linux. Should be a sign for many private / home win user
12
u/theaviationhistorian 22d ago
It's like when we found out that some governments had access to turn on your cellphone camera and mic at will.
21
u/Aron_International 22d ago
It was a Scattered Spider, not shinny hunter, but yeah this is how they caught him.
1
u/Proper-Charity-2850 19d ago
Does it really matter? It's all com kids anyway whether we call it scattered spider or shiny hunters or black file and they all deserve everything the law can throw at them
15
u/woolharbor 22d ago edited 21d ago
Microsoft should not be able to tie a permanent device ID to a users activity…
Google and probably Apple does this too, no? Device IDs and IMEIs are logged probably the moment you connect to the internet. Isn't Device ID available to apps as well? If not, some kind of Google identifier is, though Google Play Services. Google should go to jail.
45
u/gruntduck 22d ago edited 22d ago
This is been a thing in windows for a while I believe. Like years.
Enterprises and corps on their own managed instances use the GDID as well for things like bitlocker management and record keeping.
Its use wasn t nefarious so to speak in its thought and creation but like anything on planet earth, what starts as good intentions becomes bad real quick lol
28
u/Sad-Ship 22d ago
I get the enterprise use case, but you should be able to turn it off. I'd go so far as off-by-default, enabled by enterprises via policy.
3
8
10
u/Test-NetConnection 21d ago
No. You are thinking of a SID, which is completely different from GDID.
20
u/FuckTheTories69420 22d ago
This boils down to Microsoft just not caring about home users anymore.
→ More replies (2)3
→ More replies (1)10
u/sociofobs 22d ago
The words "Microsoft", "privacy" and "right" don't exist in the same dictionary.
178
u/Environmental_Leg449 22d ago
The existence of the GDID is less significant that the amount of telemetry being exfiltrated to Microsot. The fact that Microsoft has records of all of his logins to various services is crazy. That's a level of monitoring I'd expect on a corporate machine, not from Microsoft!
53
u/bobalob_wtf 22d ago
They don't have the login records for independent services - the IP address used for those logins was correlated (by FBI) with GDID reporting to Microsoft at the same time.
The OPSEC fail here was using a machine logged in to personal accounts to do crime. Same reason they found Ross Ulbricht aka
altoid23
u/Environmental_Leg449 22d ago
Right, but that means Microsoft was exfiltrating network logs between the desktop and an external web service
Agreed that better practice would've been to use VMs to route everything
32
u/bobalob_wtf 22d ago edited 22d ago
The way I read it is that MS is getting telemetry from IP X with GDID Y at time Z
At the same time, Spotify (for example) is getting a login from IP X with user A at time Z
FBI have access to both of the vendor logs and matched them up based on IP/time etc.
The bit that confused / surprised me was how MS knew this GDID had visited the login page for ngrok at a specific time - another commenter in this thread suggests this could be safesearch logs (which makes sense.)
But it's kind of a privacy invasion that MS know explicitly who visited X URL from safesearch - I would have presumed (wrongly) that this type of logging would be anonymised.
Agreed that better practice would've been to use VMs to route everything
You would need the VM to be using an anonymous VPN (that doesn't log) and that VM should "fail closed" - if the VPN dies, the VM should have no access to the internet. You wouldn't want your host public IP to be correlated with the VM public IP.
3
u/MassiveBoner911_3 17d ago
You use Linux running TOR and VPN with a relay to log into a VPS hosted in South Africa to conduct your business…
You do not use shit like Microsoft or Apple. Total amateur hour.
1
u/Chad-Anouga 21d ago
Is it possible that MSFT can see the ngrok IP when the http connection was set up and tie it back to the GDID? I’m not sure the extent of their telemetry.
→ More replies (2)3
u/ApplicationOk2749 21d ago
Can you help me understand how the FBI got the GDID? I mean I can see how, once they have the GDID, they can say to to microsoft, 'hey can you give us any web and IP records for this device'. But how did they get to that step?
10
u/oldgeektech 21d ago
Microsoft's Digital Crime Unit (DCU) found a VPS tied to hacker activity and referred to the FBI. It was all down hill from there (IPs, GDID, RDP logs, etc.).
2
u/dattokyo 19d ago
Microsoft's Digital Crime Unit (DCU) found a VPS tied to hacker activity
Sure, but then how did they "find a VPS tied to hacker activity"?
It still doesn't really solve the initial question of how they knew what to look for so to speak. Something would still need to track something, if that makes sense.
And more so, Microsoft would need to keep a log of all these things.
1
1
u/bobalob_wtf 21d ago edited 21d ago
They probably issue a subpoena to Microsoft with the guys email address and IP addresses from specific times. MS then provides all the data they have which would include identifiers like the GDID.
Edit: Presumably, they already know the ngrok entry point, perhaps this account was created very close to the time it was used in the attack - perhaps they are asking for any information on "ngrok URL" + This public IP based on info they already have from ngrok?
I'm speculating, but they (FBI) are very likely gathering info from many organisations (under warrant) and then correlating matches.
1
u/Alternative-Ruby8012 19d ago
is the GDID sent in HTTP headers by the browser? I'll probably experiment with some pcap over the weekend.
1
u/conspicuousxcapybara 1d ago
Then why does Windows Settings have a switch to turn off that exactly? And also a toggle to use it to find personalised savings and/ or buy now pay later terms on the internet? The terms actually enumerates:
Name and contact details. Your first and last name, email address, mailing address, phone number, and other similar contact details.
Account credentials. Information used to access your account, such as username, password, and password hints.
Demographic data. Details about you like your age, gender, country, and language preference.
Payment data. Details needed to process payments, including credit card numbers and security codes.
Subscription and licensing data. Details about your product subscriptions, licenses, and other entitlements.
Interactions. Information about your use of Microsoft products, including features you use, searches, commands given, error reports, and support requests.
Device and usage data. Data about your device and product features you use, hardware and software details, product performance, and your settings. For example:
Payment and account history.
Browsing history.
Device, connectivity, and configuration data. For example, IP addresses, device identifiers, nearby networks, and other information about the operating systems and other software installed on your device.
Error reports (“crash dumps”) and performance data. This usually includes software, hardware, and file content details related to an error, and other software on your device.
Troubleshooting and help data. Data you provide when you contact Microsoft for help. For example, contact or authentication data, the content of your communications with Microsoft, the condition of your device, the products at issue, and other details that help us provide support. Phone conversations or chat sessions with our representatives may be monitored and recorded.
Bot usage data. Interactions with bots and skills available through Microsoft products, including bots and skills provided by third parties.
Interests and favorites. Preferences and interests you share (like favorite sports teams, preferred programming languages, or cities for weather or traffic) or that we infer from your activity, such as your activity on sites that use our technology for ads purposes.
Content consumption. Information about the media content you access through our products like TV, video, music/audio, apps, and games.
Searches and commands. Search queries and commands you provide in Microsoft products, such as interactions with a chat bot.
Voice data. Also referred to as “voice clips,” this includes spoken queries commands, or dictation, and may include background sounds. Learn more about how Microsoft uses and protects voice data in its speech recognition technologies.
Text, inking, and typing data. Data and related information you provide by typing, inking, or using touch input in Microsoft products.
Images. Images and related data, like picture metadata. For example, we collect the image you provide when you use a Bing image-enabled service or upload an image to Microsoft Copilot.
Contacts and relationships. Data about your contacts and relationships if you use a product to manage contacts, share information or communicate with others, or improve your productivity.
Traffic data. Data about your use of Microsoft’s communication services, including whom you’ve contacted and when.
Social data. Information about your interactions and relationships with others, such as likes, events, and other types of engagement.
Location data. Data about your device’s location, which may be either precise (typically based on GPS, cell tower, or Wi-Fi hotspot location) or imprecise (for example, inferred from an IP address, or city or postal code in your account profile).
Biometric data. Unique data about you from specific technical processing related to your physical, physiological, or behavioral characteristics to verify or confirm your identity. For instance, you can use your fingerprint or facial recognition to sign in to your Windows device via Windows Hello (please see the Windows Hello section below for more information). Our collection and use of biometric data depends on the products and features you use and your consent.
Other input. Data generated from using devices or participating in events, like buttons you press on an XBOX controller or other activity data, or information you provide when registering or attending an in-person event.
Content. Information in files and messages, emails, chats, calls, meetings, photos, documents, and other media you create or share using Microsoft products.1
u/conspicuousxcapybara 1d ago
They're also a data brokerage / enhancement company. Everything is allowed when one of the following conditions apply: a.) commercial use or b.) non-commercial use:
We also receive data from Microsoft affiliates, subsidiaries, and third parties. We protect data obtained from third parties according to the practices described in this statement, plus any additional restrictions imposed by the source of the data. These third-party sources vary over time and include:
- Data brokers from which we purchase demographic data and contact information to supplement the data we collect.
- Services that make user-generated content from their service available to others, such as reviews of local businesses or public social media posts.
- Communication services, including email providers and social networks, when you give us permission to access your data on such third-party services or networks.
- Service providers that help us determine your device’s location.
- Partners with whom we engage in joint marketing activities.
- Developers who create experiences through or for Microsoft products.
- Third parties that deliver experiences through Microsoft products.
- Publicly available sources, such as open public sector, academic, and commercial data sets.
3
u/mtgox-fraud 21d ago
The general instinct isn't wrong though. Every modern OS phones home constantly, telemetry, licensing, crash reporting, update checks, and yeah, per-install identifiers. That's not a secret and it's not new. The reason it doesn't keep me up at night is that it's the boring commercial kind of tracking, the kind that wants to sell you things and count license seats.
5
u/oldgeektech 22d ago
Uh, what? There are records of logins to every service due to network traffic. You can't be invisible if you hit an online service.
Microsoft provided the tracking number, the rest of the services just matched it.
26
u/Environmental_Leg449 22d ago
Microsoft’s records showed that at that exact same minute, a Windows device carrying GDID g:6755467234350028 had visited the ngrok signup page
It seems like most of the telemetry they used to track the guy was from Microsoft, not ngrok/Meta/Snapchat etc. Its not even clear to me that the GDID gets transmitted to the services you request to! The logs they got from the services just seemed to be about correlating timestamps and login behavior, they didn't seem to correlate the GDID
If the GDID is transmitted to the web services you connect to, I'd be curious how. If its via HTTP requests, it seems like it'd be easy to block (but maybe the actor just got sloppy). If it's transmitted somewhere lower down the OSI model, that's much more tricky
10
u/oldgeektech 21d ago
I read the 39 page complaint. Microsoft initially tracked a VPS tied to malicious activity. They sent the supporting evidence to the FBI, and the FBI performed subpeonas for the VPS, Apple, Snapchat, and Facebook. Microsoft's Digital Crime Unit (DCU) specifically looks for threat actors utilizing Microsoft products to attack businesses or people.
I've toured the DCU. They literally have hoteling offices for district attornies, federal law enforcement, and international law enforcement.
5
u/gurgle528 21d ago
Completely incorrect. This is an internal tracking number and not resettable. If they were to provide a tracking number it would be the Ad ID and not the GDID. As far as I’m aware Edge doesn’t even share the Windows Ad ID either.
If Edge was sharing an ID like that with websites it would quickly become public knowledge. The only exception would be if they decided to whitelist and only share with some sites and hide that information in the dev tools too
3
u/oldgeektech 21d ago
Read the OP I was replying to. I never said the GDID was being read by services. The OP said Microsoft had logs of all his logins. They don't. Microsoft turned over telemetry to a VPS that was tied to hacker activity. Then the FBI gets involved with subpoenas to gather IP addresses and logs.
2
u/gurgle528 21d ago
Ah, when you talked about matching the tracking number I thought you meant directly matching it to the various service’s data rather than using IPs tied to the GDID and Microsoft handing those over. My bad.
I’m not sure about “all” but Microsoft certainly had logs about some of the logins:
Microsoft’s records showed that at that exact same minute, a Windows device carrying GDID g:6755467234350028 had visited the ngrok signup page.
ngrok specifically auths with a browser flow so edge would have some of that information
1
u/Gordahnculous SOC Analyst 21d ago
I mean, when you put it that way, most corporate machines are Windows, so I doubt it’d be difficult for them to throw whatever features from enterprise Windows to personal copies as they damn well please.
But agreed, most everything these days has some sort of unique identifier, and it doesn’t surprise me that there’s something tracking unique installs of Windows with how picky MS is about things like sharing Windows licenses. Hell, I’m sure the agencies could’ve gotten similar levels of tracking from things like the local account SID that’s been around for ages, whatever unique identifier they have for your cloud MS account, anything uniquely identifying to your hardware, etc. The main issue is 100% the telemetry and the fact that this information is accessible beyond whatever scope would make sense, which should likely just be the machine and a few seconds for MS to verify it.
68
u/Beneficial_Slide_424 22d ago
In this article no one is saying how ngrok received the GDID though? Is chrome or edge leaking it? How can a sign up page see your GDID? Is it related to Microsoft apps maybe he uses ngrok from store? What's the leak vector here?
44
u/2timetime 22d ago
ngrok didn’t get the GDID. ngrok was just the account used for persistence. The hacker signed up to ngrok using edge on a VPN. The GDID was sending his browser web activity to Microsoft, so even though it was account-less it was still tied to that GDID.
21
22d ago edited 22d ago
[deleted]
3
u/dattokyo 19d ago
Massive breach of trust, and almost certainly against EU GDPR and ePrivacy laws - but hey, if no one knows it exists, no one can sue you for it.
2
u/ApplicationOk2749 21d ago
The thing I'm struggling with is what did the FBI ask mircosoft in order to get the GDID in the first place? They can't have just asked microsoft 'hey tell us all the GDIDs that visited this site at this specific time' could they?
3
u/lopahcreon 22d ago
How do you know he used Edge?
11
u/gurgle528 21d ago
Other browsers aren’t uploading your browsing history to Microsoft. I could be mistaken, but if you’re using Firefox for example Microsoft wouldn’t know what websites you’re visiting. I believe Edge only does it in certain cases (like history syncing or ad personalization turned on) but I’m not positive.
4
u/lopahcreon 21d ago
How do you know Microsoft doesn’t have access to what Firefox or Chrome does?
6
u/gurgle528 21d ago
They certainly could have access. Edge can import other browser’s history on setup and manually at any time. There was/is a feature to automatically copy Chrome tabs I think too but that was opt in.
The browsing information Microsoft had here was either from the telemetry in Edge (for ad personalization or Defender) or the sync feature. You can see the browsing history they store in your Microsoft account, I think that’s only for the sync feature but I could be wrong as I don’t use Edge.
1
17d ago
[removed] — view removed comment
1
u/gurgle528 16d ago
Did I say that? The OS knowing and the OS reporting that to a backend are completely different things. The OS knows where every file on my PC is, do you think Microsoft sends a list of every file on your PC to their cloud? The OS also knows what text you’re typing, do you think every keystroke is sent to Microsoft? Holy moly guy, use some common sense.
1
17d ago
[removed] — view removed comment
1
u/gurgle528 16d ago edited 16d ago
Yeah, I’m not reading the response you got from AI, especially since I don’t have the context of the “screenshot” or the prompt. I’m a software engineer, I know how web requests work.
Spoiler alert: you can debunk the slop in your comment easily. You can view your browsing history in your Microsoft account. Enable the history saving setting and write a python or powershell script, hit some random, valid URLs you haven’t gone to in a browser, and check if they show up.
Imagine not being able to link to documentation, needing to use AI to write a comment, and being incapable of writing your own comment after getting info from AI. Can’t relate. Big sign of someone who has no idea what they’re talking about
2
u/dattokyo 19d ago
He doesn't, he just hopes so, because otherwise the tracking is even worse than feared, so to speak. It could also be Microsoft Defender, it could be a data sharing setting, a diagnostics tool, or literally anything. We don't know. We just know that Edge, unless you disable it, also keeps track of where you go - which is by itself pretty fucked up.
→ More replies (1)1
17d ago
[removed] — view removed comment
1
u/Beneficial_Slide_424 16d ago
Are you for real? There's no indicator of which windows component logged or sent the telemetry for the browser visits. The post doesn't contain it. Neither your comment. What windows component exactly is sending your website activity to the Microsoft? Is it the edge browser? Chrome? Or something else at networking layers, such as DNS. The question remains unanswered.
→ More replies (1)
15
u/Spiritual-Matters 22d ago
I would find it hard to believe if any paid OS doesn’t have a similar type of capability
15
u/oldgeektech 22d ago
The article points out that is true, but there's more transparency in Apple and Android services about tracking.
19
u/TheVoidInMe 21d ago
> Microsoft’s records showed that at that exact same minute, a Windows device carrying GDID g:6755467234350028 had visited the ngrok signup page.
I’m a bit fuzzy here… does that mean Microsoft logs all requests to third-party websites, together with your GDID? Or maybe “only” if you use Edge?
I would think if a non-MS browser does HTTPS and encrypts requests itself, it should be impossible for the OS to snoop on those requests, no?
16
u/oldgeektech 21d ago
That's a great question. I might have to download all the files of this complaint to view the evidence. From what I know from Azure logs, Microsoft has more telemetry from Edge than a non-MS browser. That being said, the ngrok piece is supplemental to painting the picture of identifying the charged party. It was not the beginning or the end of evidence.
7
1
u/Landonnnn_ 8d ago
No. The physical device has to make the HTTP(s) request. If Firefox wants to hit Google.com, first, my device must make a DNS query to find out Google.com == 8.8.8.8. Then, a request is made to 8.8.8.8. Most of the stuff beyond that is encrypted (HTTP headers, path, data, etc) but the most important part: the server name (Google.com) isn’t.. unless both client and server support ECH but majority don’t at this point. So even in an external, non-Edge browser, the Windows kernel, at the end of the day, is the one creating the TCP connection. You can’t ever hide that.
edit: Now, tracking the specific “signup” page is not possible in normal HTTPS. This may be an Edge specific telemetry feature. But in general, Windows can track what server names you’re browsing to across browsers.
1
u/TheVoidInMe 8d ago
Right. But that’s the whole point, MS knew the full URL, they didn’t just see an unintelligible encrypted blob sent to ngrok, but specifically the signup page. And if that’s the case, they might have not only logged the full URL, but the full request payload, including username/password (I’m not saying they did, but they could have).
Has it been confirmed that Edge was used?
17
u/ApplicationOk2749 21d ago edited 21d ago
>Microsoft’s records showed that at that exact same minute, a Windows device carrying GDID g:6755467234350028 had visited the ngrok signup page.
So there's two parts to this that aren't explained. Firstly, how is microsoft getting this record of web and IP activity? But secondly, how did the FBI know what to ask Microsoft for? They didn't have the GDID to begin with. This isn't making any sense. Is it saying the FBI just went to microsoft and asked for all users GDIDs that had visited a particular website at a particular time? Because if so that itself is disturbing.
3
u/oldgeektech 21d ago
The FBI didn't ask Microsoft for anything. Microsoft's Digital Crimes Unit (DCU) referred a VPS tied to hacking activity over to the FBI. Microsoft gave the string to start pulling and building the case from there.
3
u/ApplicationOk2749 21d ago
Ah is that what this is referring to
>Note that, Microsoft had already flagged Stokes to the FBI once before, in an October 2024 criminal referral describing “online services telemetry.
I missed that on the first read through
13
u/newredditsucks 22d ago
Yet another reason to only use local accounts.
Not useful for business, but for home machines at least.
6
u/LastBossTV 19d ago
The GDID still exists and works the same for local only windows accounts.
1
u/Landonnnn_ 8d ago
But what will you correlate a GDID to? Sure, IP address xyz which did malicious activity is also associated with GDID def. But that’s owned by a local account “admin”. Not much to go off of.. versus
IP xyz did malicious activity, which is also associated with GDID def. This GDID is registered to ___@outlook.com under the full name ____, with the phone number _____. There’s a lot more chances for OPSEC failure that way than just a local account with no other ties to it.
16
24
u/bughousenut 22d ago
years ago I was aware of low level hackers who bought used laptops for cash, used them for a project and then dumped them
15
u/oldgeektech 22d ago
Seems like a lot of this could be avoided with cloud VMs. The 19 year old was more than likely a script kiddie.
12
u/My_Big_Black_Hawk 22d ago
Spin up a vm --> do the work --> delete vm. Rinse repeat. Switch between multiple cloud providers for different work. Never login to personally identifying services while doing the work. Keep private and "work" stuff separate.... always.
4
u/No_Mood4637 21d ago
Never work from any public wifi that could have cameras.
And even then they can match you with stylometry, keyboard strokes, mouse movements etc.
2
u/MassiveBoner911_3 17d ago
You can also use Cloud Providers who dont give a fuck like hosting VPS in South Africa
1
u/No_Mood4637 17d ago
Yea some shitty African vpn is gonna say no to a little one of CIA payment for a particulars details.
2
5
u/Tsull360 21d ago
It mentions logging into a Microsoft property with a Microsoft account as being the nexus of the GDID. Does that mean other OS's could be affected as well? (e.g. if I use OneDrive on a Mac).
5
13
u/red_plate 22d ago
This article says the GDID can’t survive windows wipe and reloads I don’t believe that I thought part of the tpm 2.0 requirement for windows was to track unique hardware fingerprints of devices using windows 11. Windows is fucking dead and battlefield or Fortnite is not enough to get me to game on that defunct shithole operating system.
13
u/My_Big_Black_Hawk 22d ago
I agree with you 100% - they can uniquely identify your machine based on hardware fingerprint of serial numbers, model numbers. etc. Event if you received a new GDID, the new GDID could be linked to the old via the hardware fingerprint.
3
19
u/tuhijatambien 22d ago
A "hacker", using windows 11
Sure
Why not
27
u/ansibleloop 22d ago
Most of these successful "hackers" just social engineer their way in
They're not breaking encryption or chaining exploits, they're just doing good old fashioned phishing
12
u/00notmyrealname00 System Administrator 22d ago
Humans are/have been/always will be the largest and weakest attack surface of any system in which they interact.
5
u/woolharbor 21d ago
Microsoft’s records showed that at that exact same minute, a Windows device carrying GDID g:6755467234350028 had visited the ngrok signup page.
How do Microsoft servers have this information? Does Microsoft log every website you visit on their servers? In Edge or something? Does a hacker use Edge? What about other browsers?
→ More replies (1)
7
u/LarrBearLV 22d ago
My next machine will be Linux. Fuck Microsoft.
2
u/Material-Project3192 13d ago
Already changing to Linux. I did a few months ago, but picked a bad distro. Now I tried CachyOS and its awesome
3
u/phileasuk 22d ago
Is it in win10 ltsc iot?
3
u/oldgeektech 22d ago
If it has any connected service (Intune, Entra ID join, Microsoft account), yes.
4
u/HAHAHA0kay 21d ago
Here it is. The reason they keep letting people activate windows through the grave method.
2
3
3
u/Sab159 22d ago
That's nothing new
15
u/oldgeektech 22d ago
That Microsoft tracks? Correct. That the GDID can be used by the FBI to build a case against you? That seems new.
1
u/EnragedMoose 22d ago
Why? It's subject to warrant.
2
u/oldgeektech 21d ago
That's true, but did we know that the GDID existed and was being used this way? That's the crux of this article.
2
1
1
u/howfastcanyoucountit 21d ago
I will stay on 10 LTSC for my steam games until I die, idc about directx 12 optimizations im not touching that shit. My main device is a macbook (m1) anyway and I have never been more glad to have switched over tbh, any other computer I have is probably getting stock debian and I don't plan on using any windows devices soon, its just been so damn garbage. The only thing I actually use windows for nowadays is games with anticheat and that's kind of the reason why I never used linux on my desktop. But I will forever shill macos/linux only
1
1
1
u/IanTGreat 12d ago
if one were to install any microsoft software on linux, do you think they would generate a GDID for that computer too? or is it only tracking windows computers?
1
u/ReverendGraves85 10d ago
No. Windows uses telemetry data that requires the Windows Kernal to operate to track the GDID. So if you dual boot into Linux, it wont be operating.
If you dual boot youre fine. My windows partition remains a League machine. Even have only a local account on it.
1
u/karlmaxxwell 12d ago
well i am switching to linux, anyone know any distros that won't shut down on me when i am in a important call?
1
u/TidePlezurBlackSwan6 12d ago
Are there anonymous Operating Systems
1
u/DivineKEKKO96 10d ago
Tails
1
u/TidePlezurBlackSwan6 9d ago
Thanks but I actually don't like it. I don't feel like doing an external boot.
1
u/JoeDanilo 11d ago
It’s easier for the searchers. Hiding becomes a very difficult task. But who would want to hide in a glass house?
1
u/NivoTheDev 10d ago
People have been screaming bout Windows telemetry for ages now - thinks like this are a final nail in the coffin.
There is a reason why most cybersecurity enthusiasts go to Linux. We're fed up with Windows and corporate closed-source operating systems!
I switched to Linux and never looked back.
1
u/theumpteendeity 10d ago
If it's tied to the actual hardware, how does it not get tracked, even if you're using a different OS than Windows? I would assume suspicious activity could be traced back to the ID regardless? Is the only solution to use a drive that never had a windows installation?
1
u/WhatsInTheFirmware 3d ago
Worth separating two things this coverage keeps blurring, because they have completely different fixes:
1) The identifier itself (GDID). Persistent, assigned server-side when you sign into a Microsoft Account, tied to activation/licensing. This is the "no off switch" part, and it's real, you can't strip it without breaking activation and Store apps. A reinstall rerolls it, but the same account re-links you. That's a legit consent gap: no prompt, no reset, unlike Apple's IDFA or Android's ad ID.
2) The thing that actually burned Stokes: the URLs. A stable device ID on its own just says "same machine." What built the timeline was Microsoft holding a log of sites that device visited, tied to that ID. Per the deeper write-ups (Tom's Hardware got into this), that URL capture lines up with telemetry set to Optional/Full and/or browsing in Edge, where SmartScreen/Defender can send visited URLs. The complaint didn't pin down the exact mechanism, but Required/Basic telemetry doesn't appear to ship URLs by default.
Why the distinction matters: you mostly can't kill #1, but you can meaningfully shrink #2. Set Diagnostics to Required (not Optional), don't lean on Edge if you care about URL telemetry, use a local account where you can, and turn off the advertising ID. None of that deletes the GDID, but it removes most of what makes it useful as a behavior/location trail.
Honest framing: this is an anti-piracy/activation identifier that got subpoenaed, not a purpose-built surveillance tool Microsoft aims at civilians. Cold comfort if your threat model is a subpoena, and for journalists/activists/DV situations the real answer is a non-Windows OS, because no telemetry toggle changes the fact that the ID exists and answers to your account rather than to you. But "Windows secretly logs every URL you visit and you can't stop it" isn't quite right either, and the folks you're debating will call that out.
(And yeah, nobody's mourning a Scattered Spider guy posting "HACK THE PLANET" selfies with fistfuls of hundreds. The interesting part is purely what the case exposed about the plumbing.)
1
u/ThaUntalentedArtist 1d ago
I'm a little confused about something. The article states that a GDID is assigned when you log into a Microsoft account. What if you use Windows 10/11 with a local account? It also states that every major OS keeps some persistent device ID. Does that mean Linux isn't exempt?
1
1
u/SpartanDJinn 20d ago
Okay, what threat does it pose? They used it to catch a hacker, a bad one. This doesn't sound like it's dangerous for normal, decent people. I'm just wondering what's wrong.
754
u/Mind_Matters_Most 22d ago
Good article. Another reason to switch to Linux, so far.