Live data from Hacker News

Microsoft Can Track Users via a Windows Device ID

pcmag.com

161–170 of 170 posts

Re: Microsoft Can Track Users via a Windows Device ID

#161
post #153

Earlier quoted context omitted.

Yeah, this is what's glaringly missing from the article. Exactly how does Microsoft's device identifier get associated with the ngrok session (normally initiated via its closed-source CLI)? I can't tell from the article whether Microsoft is doing something underhanded to inject its device identifiers into network traffic, or whether the ngrok client software (again, closed-source!) grabbed the device identifier… and…

> Exactly how does Microsoft's device identifier get associated with the ngrok session The article has a link to "39-page criminal complaint" PDF, and I'd summarize the prosecution's claims (from sections 21.e, 22, 26) as: 1. The ngrok client was downloaded onto hardware owned by the victims and used by the attacker. 2. The client was later discovered along with an ngrok auth token. (2x0b1363KPV35LCUuZCkJag0G84_2btDj…

Thanks. (4) is the critical piece here.

Re: Microsoft Can Track Users via a Windows Device ID

#162
post #106

Earlier quoted context omitted.

> Microsoft literally logs all web requests Nope. That would be unbelievable but also very well known. It was a Windows software licensing matter, see my post above.

It's not unbelievable at all, and it is well-known. It's been publicized that Microsoft sends every URL you visit in Edge back to Microsoft servers, tied with all the IDs on the device: https://www.itpro.com/security/privacy/355029/microsoft-edge...

> Microsoft literally logs all web requests

> Microsoft sends every URL you visit in Edge back to Microsoft servers,

Not the same thing.

Re: Microsoft Can Track Users via a Windows Device ID

#163

Earlier quoted context omitted.

Yeah, this is what's glaringly missing from the article. Exactly how does Microsoft's device identifier get associated with the ngrok session (normally initiated via its closed-source CLI)? I can't tell from the article whether Microsoft is doing something underhanded to inject its device identifiers into network traffic, or whether the ngrok client software (again, closed-source!) grabbed the device identifier… and…

I work at ngrok, and this is not how our freemium plan works. Free plans limit based on usage alone, not on machine IDs.

Sure but you still know which connection belongs to which licensed customer which seems to be how this person was identified.

Re: Microsoft Can Track Users via a Windows Device ID

#164
post #43

I guess we’ll see a Windows tool that sets your identifier to this suspect’s “g:6755467234350028” very soon (weird ID, by the way. 16-digits makes sense, but I would have expected it to be hexadecimal) Also, can anybody tell how “Microsoft had records showing that on May 12, 2025, at 19:21 UTC, the GDID associated with Stokes’ computer “accessed, among other ngrok pages, ' https://dashboard[.]ngrok.com/signup ,'” wor…

It's all parallel construction. https://en.wikipedia.org/wiki/Parallel_construction

My suspicion as well. I don't see any crystal clear evidence for it, but I'm sure looking for it.

Re: Microsoft Can Track Users via a Windows Device ID

#165
post #159
post #156

Earlier quoted context omitted.

It's interesting how you think of US tech currently being in a process of becoming a tool of state surveillance and oppression that Russia and China have, while the following exists: * PRISM (est. 2007) spied on US citizens with the help from AT&T, Microsoft, Google, Apple, and etc.: https://en.wikipedia.org/wiki/PRISM * SpyFiles (various years, ~2011) US/EU surveillance software: https://wikileaks.org/spyfiles/ * Fa…

It's one thing to spy on your population/users, it's another to spy on your clients. You can go all authoritarian fascist if that's what floats your boat, but at least don't backstab people who buy shit from you. Can't you be repressive and professional?!

3 entries in the list above did exactly that more than a decade ago. My point is that the US tech is not in a process, they were at the frontier long before everyone else.

Re: Microsoft Can Track Users via a Windows Device ID

#166
post #162

Earlier quoted context omitted.

It's not unbelievable at all, and it is well-known. It's been publicized that Microsoft sends every URL you visit in Edge back to Microsoft servers, tied with all the IDs on the device: https://www.itpro.com/security/privacy/355029/microsoft-edge...

> Microsoft literally logs all web requests > Microsoft sends every URL you visit in Edge back to Microsoft servers, Not the same thing.

Explain how they differ, in a practical way that's relevant to this discussion?

Re: Microsoft Can Track Users via a Windows Device ID

#167
post #162

Earlier quoted context omitted.

> Microsoft literally logs all web requests > Microsoft sends every URL you visit in Edge back to Microsoft servers, Not the same thing.

Explain how they differ, in a practical way that's relevant to this discussion?

Request bodies and headers. You should be aware of this before you participate.

Re: Microsoft Can Track Users via a Windows Device ID

#168
post #154

Related thread by some Massgrave.dev devs explaining some GDID mechanisms: https://x.com/massgravel/status/2074304593303892354

Convenience link for those who don't want to create a Twitter account to see more. https://xcancel.com/massgravel/status/2074304593303892354 The sites' anti-bot measures seem unhappy with my current computer/location at this time, but hopefully it works for everyone else.

I can recommend the LibRedirect extension for doing this automatically: https://addons.mozilla.org/en-US/firefox/addon/libredirect/

(I don't use it for Twitter, because I find the 5s xcancel redirect more annoying than logging into Twitter. But I use it for Imgur and Tiktok, as Imgur straight up denies serving many VPN IPs, and Tiktok serves a really annoying captcha.)

Re: Microsoft Can Track Users via a Windows Device ID

#169
post #96

I assume this likely true for nearly all device manufactures. I assume all devices have some kind of unique ID that they use for tracking, whether they said so or not.

I'm more surprised that this already isn't a known fact. I wonder exactly how far into each device activity is being tracked.

It's down to the component level in many cases...

Re: Microsoft Can Track Users via a Windows Device ID

#170

Earlier quoted context omitted.

I don't like the idea of a persistent id for my machine. Would there be any harm in rewriting the machine-id at every boot? Or just deleting it as part of the shutdown sequence?

Only side effect I ran into is that journalctl couldn't find the logs of a previous boot.

wow... that implies that you can't use journalctl from a rescue environment to access the logs of the host system? Sounds like real genius design.
Post reply on HN