Microsoft Can Track Users via a Windows Device ID
1–10 of 170 posts
Re: Microsoft Can Track Users via a Windows Device ID
#2It's unclear what the mechanism is, but I'd wager their "telemetry" is constantly revealing your installation ID, your current IP, and domains that were recently resolved.
Re: Microsoft Can Track Users via a Windows Device ID
#3TLDR: Microsoft can (at least) correlate your Windows installation to all website domains you visit while using Windows. It's unclear what the mechanism is, but I'd wager their "telemetry" is constantly revealing your installation ID, your current IP, and domains that were recently resolved.
I feel like using wireshark to look at what's being sent back and forth from Windows telemetry, when using Edge, Chrome & etc should reveal what's being sent and recieved. Using MITM SSL spoofing should be able to intercept the packets.
Re: Microsoft Can Track Users via a Windows Device ID
#4TLDR: Microsoft can (at least) correlate your Windows installation to all website domains you visit while using Windows. It's unclear what the mechanism is, but I'd wager their "telemetry" is constantly revealing your installation ID, your current IP, and domains that were recently resolved.
The article links to this page, which was shared on HN yesterday. [1] I feel like using wireshark to look at what's being sent back and forth from Windows telemetry, when using Edge, Chrome & etc should reveal what's being sent and recieved. Using MITM SSL spoofing should be able to intercept the packets. [1] https://github.com/SmtimesIWndr/gdid-reversal
Re: Microsoft Can Track Users via a Windows Device ID
#5TLDR: Microsoft can (at least) correlate your Windows installation to all website domains you visit while using Windows. It's unclear what the mechanism is, but I'd wager their "telemetry" is constantly revealing your installation ID, your current IP, and domains that were recently resolved.
Reminds me of Google Safebrowsing.
Re: Microsoft Can Track Users via a Windows Device ID
#6Earlier quoted context omitted.
The article links to this page, which was shared on HN yesterday. [1] I feel like using wireshark to look at what's being sent back and forth from Windows telemetry, when using Edge, Chrome & etc should reveal what's being sent and recieved. Using MITM SSL spoofing should be able to intercept the packets. [1] https://github.com/SmtimesIWndr/gdid-reversal
I would be shocked if Microsoft was not using their own layer of certificate-pinning to stop people from doing that, and/or using another layer of encryption separate from the networking layer.
Re: Microsoft Can Track Users via a Windows Device ID
#7Re: Microsoft Can Track Users via a Windows Device ID
#8Fun fact, Microsoft Defender MAPS was previously named SpyNet.
https://en.wikipedia.org/wiki/Microsoft_Active_Protection_Se...
The GDID identifier seems software in nature though. They could be more aggressive and tie it to the baseboard's serial number the way some games do. Then the hardware is tracked throughout its entire lifecycle, not just per instance of Windows install.
Re: Microsoft Can Track Users via a Windows Device ID
#9Earlier quoted context omitted.
The article links to this page, which was shared on HN yesterday. [1] I feel like using wireshark to look at what's being sent back and forth from Windows telemetry, when using Edge, Chrome & etc should reveal what's being sent and recieved. Using MITM SSL spoofing should be able to intercept the packets. [1] https://github.com/SmtimesIWndr/gdid-reversal
I would be shocked if Microsoft was not using their own layer of certificate-pinning to stop people from doing that, and/or using another layer of encryption separate from the networking layer.