Live data from Hacker News

Microsoft Can Track Users via a Windows Device ID

pcmag.com

151–160 of 170 posts

Re: Microsoft Can Track Users via a Windows Device ID

#151
post #15

Earlier quoted context omitted.

Both systemd and dbus have a similar device id for Linux, which e.g. Chrome reads at startup: https://manpages.debian.org/trixie/systemd/machine-id.5.en.h... https://manpages.debian.org/trixie/dbus-bin/dbus-uuidgen.1.e...

I don't like the idea of a persistent id for my machine. Would there be any harm in rewriting the machine-id at every boot? Or just deleting it as part of the shutdown sequence?

Only side effect I ran into is that journalctl couldn't find the logs of a previous boot.

Re: Microsoft Can Track Users via a Windows Device ID

#152
post #15

Earlier quoted context omitted.

Both systemd and dbus have a similar device id for Linux, which e.g. Chrome reads at startup: https://manpages.debian.org/trixie/systemd/machine-id.5.en.h... https://manpages.debian.org/trixie/dbus-bin/dbus-uuidgen.1.e...

That's good to know, thank you. I'm been considering moving away from systemd, and certainly don't use Chrome. The number of things you need to try to keep track of merely _improve_ your privacy is maddening. The whole world seems to be against you.

As a sysadmin and a former enemy of systemd it's actually pretty good overall, simplifies a lot of things.

If the privacy reasons are driving you, see if you can find fixes to these issues without getting rid of systemd.

Re: Microsoft Can Track Users via a Windows Device ID

#153

The interesting part is not really the existence of a machine identifier. Almost every modern OS has some equivalent. The bigger question is the boundary: which components can access it, and when does a local identifier become a remote tracking identifier? A machine-id sitting on disk is very different from an OS vendor correlating it with network activity.

Yeah, this is what's glaringly missing from the article. Exactly how does Microsoft's device identifier get associated with the ngrok session (normally initiated via its closed-source CLI)? I can't tell from the article whether Microsoft is doing something underhanded to inject its device identifiers into network traffic, or whether the ngrok client software (again, closed-source!) grabbed the device identifier… and…

> Exactly how does Microsoft's device identifier get associated with the ngrok session

The article has a link to "39-page criminal complaint" PDF, and I'd summarize the prosecution's claims (from sections 21.e, 22, 26) as:

1. The ngrok client was downloaded onto hardware owned by the victims and used by the attacker.

2. The client was later discovered along with an ngrok auth token. (2x0b1363KPV35LCUuZCkJag0G84_2btDjSM5oY82TQuiLZvaz)

3. The ngrok auth data was linked to an ngrok account. (ac_2x0b16MSTJk4PvjLZMoqt4vOvZM)

4. Although a VPN was used by whomever created the ngrok account, the creation-time of the account correlates to Microsoft's telemetry, which indicates that the accused's computer was visiting ngrok sign-up pages.

Re: Microsoft Can Track Users via a Windows Device ID

#154

Related thread by some Massgrave.dev devs explaining some GDID mechanisms: https://x.com/massgravel/status/2074304593303892354

Convenience link for those who don't want to create a Twitter account to see more.

https://xcancel.com/massgravel/status/2074304593303892354

The sites' anti-bot measures seem unhappy with my current computer/location at this time, but hopefully it works for everyone else.

Re: Microsoft Can Track Users via a Windows Device ID

#155
post #133
post #9

Earlier quoted context omitted.

Only way to see what's going on is testing to see what's going on. Hopefully, someone who knows more about it than me can take a look at the packets and see what they contain.

I found this talk [0] and some of the slides suggest that Windows is, at least in some circumstances, packaging web-browsing data into telemetry. To lift examples from the slides, that includes page titles: "CorrelationGuid": "7da62b73-082f-4eb2-a370-135d0113e1dd", "EventInfo.Level": 2, "PageTitle": "SiSyPHuS AFUNKT - Search", "TabId": 830425073, "client_id": -7497793556371901000, "pop_sample": 100, "utc_flags": 1407…

What application is doing the sending and where is it being sent?

Re: Microsoft Can Track Users via a Windows Device ID

#156
post #49
post #40

Earlier quoted context omitted.

Have you heard of a website called facebook?

There was a time where the default assumption was functionality created tracking opportunities. Nowadays, it's more the opposite. Social media have always been on the forefront of monetizing data, but the same data in the hands of governments is used differently. My point is that the way you/we feel towards Facebook, the entire world is increasingly feeling about most, if not all, US tech. I know people who won't use…

It's interesting how you think of US tech currently being in a process of becoming a tool of state surveillance and oppression that Russia and China have, while the following exists:

* PRISM (est. 2007) spied on US citizens with the help from AT&T, Microsoft, Google, Apple, and etc.: https://en.wikipedia.org/wiki/PRISM

* SpyFiles (various years, ~2011) US/EU surveillance software: https://wikileaks.org/spyfiles/

* Facebook (est. 2004):

  - Helped Cambridge Analytica (~2013) to interfere with the elections: https://en.wikipedia.org/wiki/Facebook%E2%80%93Cambridge_Analytica_data_scandal

  - Bought Onavo (~2013) to spy on competition: https://en.wikipedia.org/wiki/Onavo

  - Manufactured consent to enable genocides in Ethiopia, Myanmar, and Gaza.
* Palantir (est. 2003): https://en.wikipedia.org/wiki/Palantir

* Microsoft GSP (~2003) to enable US government to find zero-days (now with Mythos): https://www.microsoft.com/en-us/securityengineering/gsp

Re: Microsoft Can Track Users via a Windows Device ID

#157
post #43

I guess we’ll see a Windows tool that sets your identifier to this suspect’s “g:6755467234350028” very soon (weird ID, by the way. 16-digits makes sense, but I would have expected it to be hexadecimal) Also, can anybody tell how “Microsoft had records showing that on May 12, 2025, at 19:21 UTC, the GDID associated with Stokes’ computer “accessed, among other ngrok pages, ' https://dashboard[.]ngrok.com/signup ,'” wor…

It's all parallel construction.

https://en.wikipedia.org/wiki/Parallel_construction

Re: Microsoft Can Track Users via a Windows Device ID

#158
post #144

Earlier quoted context omitted.

From the reply you're replying to: > 27. Microsoft records also indicate: a little more than three hours after the ngrok account was created, the user visited “[Company F].com” from the .168 proxy server.

This tells us nothing about whether non-Microsoft browsers are involved

Scary huh? What else aren't they telling us..

Re: Microsoft Can Track Users via a Windows Device ID

#159
post #156
post #49

Earlier quoted context omitted.

There was a time where the default assumption was functionality created tracking opportunities. Nowadays, it's more the opposite. Social media have always been on the forefront of monetizing data, but the same data in the hands of governments is used differently. My point is that the way you/we feel towards Facebook, the entire world is increasingly feeling about most, if not all, US tech. I know people who won't use…

It's interesting how you think of US tech currently being in a process of becoming a tool of state surveillance and oppression that Russia and China have, while the following exists: * PRISM (est. 2007) spied on US citizens with the help from AT&T, Microsoft, Google, Apple, and etc.: https://en.wikipedia.org/wiki/PRISM * SpyFiles (various years, ~2011) US/EU surveillance software: https://wikileaks.org/spyfiles/ * Fa…

It's one thing to spy on your population/users, it's another to spy on your clients.

You can go all authoritarian fascist if that's what floats your boat, but at least don't backstab people who buy shit from you.

Can't you be repressive and professional?!

Re: Microsoft Can Track Users via a Windows Device ID

#160
post #105

Earlier quoted context omitted.

Good question. My understand is that it was licensing: Hackers cloaked IP address -> VPN license -> Windows GDID -> Hacker's name.

From the reading of the document, I really don't think that's it. The suspects used phishing to get access to one company's servers, then used those servers to push software to other servers. It 100% reads that they enlisted Microsoft to correlate telemetry data with some known activities, backtracking from that. Barring specific additional data, this should be extraordinarily concerning. Repeatedly the documents cit…

Ngrok license not VPN license but yes, it’s correct as other posters have mentioned
Post reply on HN