Earlier quoted context omitted.
How do we know? Does anyone check for things like this? Many, many apps read /etc/machine-id if you do a quick github search. Apps may have been silently correlating our activity for years without us knowing. We know DHCP, EFI, GNOME, popularity-contest and many other apps already use it. There are countless ways it could be used already that are hard to detect.
It should be noted that the "correct" usage of /etc/machine-id is that you use it in a way that doesn't allow cross-correlation between different applications by using a HMAC of the machine-id with an application-specific UUID instead of using it directly. systemd-id128 has a command line flag to do this for you. Whether everyone does that correctly, that's a different question. On the other hand, while developers sh…
GDID Windows – Cut the tracker that follows you even under VPN
81–90 of 106 posts
Re: GDID Windows – Cut the tracker that follows you even under VPN
#82(Kinda amazed they just didn’t to that instead)
Re: GDID Windows – Cut the tracker that follows you even under VPN
#83Earlier quoted context omitted.
How do we know? Does anyone check for things like this? Many, many apps read /etc/machine-id if you do a quick github search. Apps may have been silently correlating our activity for years without us knowing. We know DHCP, EFI, GNOME, popularity-contest and many other apps already use it. There are countless ways it could be used already that are hard to detect.
Basically all source is open. Eyes are plenty. Somebody would raise a stink. People can also notice things while monitoring their network via a number of tools like Wireshark, etc. All it takes is one person to notice and share their findings. It also helps that "Linux" isn't a monolith. One person's installation can be very different from another in terms of the software used. If one piece of software collects, that…
The number of new security bugs that e.g. LLM models have been finding lately, most of which are very old, are staggering.
Re: GDID Windows – Cut the tracker that follows you even under VPN
#84Or just use Linux.
Re: GDID Windows – Cut the tracker that follows you even under VPN
#85Earlier quoted context omitted.
It can still be correlated with past IDs by countless other methods in order to keep tracking you further.
But then you're using other methods, you're not using the ID as tracker. In fact if you just remove it, it eliminates this entire discussion.
If you use a different identifier to track changes in a GDID/machine-id/etc., that means you can continue tracking using mainly just the new machine-id, but you should always keep trying to correlate it with other things in case it changes.
Re: GDID Windows – Cut the tracker that follows you even under VPN
#86Earlier quoted context omitted.
> Microsoft has a list of IP addresses that has been used by a computer with a certain GDID, but FBI needs to get the GDID in the first place What they did was the opposite: ask Microsoft for GDIDs used by attacker-associated IPs within several 24-hour time periods during which attack-related activity took place. Windows pings Microsoft regularly with the GDID, establishing links between your GDID and any IP addresse…
Wait, so it would have, ironically, been safer to allow microsoft telemetry to bypass the VPN entirely and remain associated only with their home network, because it's the phone home to microsoft tunneled through the VPN that tied together all their IP addresses to a single microsoft account. The GDID itself is almost a red herring, as it could have been a session id or username or something only long lived enough to…
If they'd done their VPN/dirty work in a linux VM/container, with the VPN running in that, they'd have been fine.
Clean-them would have had their GDID on their normal ISP IP or equivalent, and Dirty-them would have had everything through the VPN from their no-telemetry dirty-host.
Re: GDID Windows – Cut the tracker that follows you even under VPN
#87Interesting, generally Microsoft bypasses the hosts file name resolution for various MSFT domains. Curious that these were not included (if it works, which I assume the mitigation does). https://petri.com/windows-10-ignoring-hosts-file-specific-na...
Windows falls back to the normal resolver in that case.
Re: GDID Windows – Cut the tracker that follows you even under VPN
#88People paint this as a bad thing but wouldn’t directly reporting the UUID from the DMI info be far worse? (Kinda amazed they just didn’t to that instead)
This GDID is essentially a similar concept though, but not as hardware tied, but is reported in telemetry.
Re: GDID Windows – Cut the tracker that follows you even under VPN
#89Earlier quoted context omitted.
Basically all source is open. Eyes are plenty. Somebody would raise a stink. People can also notice things while monitoring their network via a number of tools like Wireshark, etc. All it takes is one person to notice and share their findings. It also helps that "Linux" isn't a monolith. One person's installation can be very different from another in terms of the software used. If one piece of software collects, that…
I think it's a common misconception that just because source is available, people are actually looking at it properly. The number of new security bugs that e.g. LLM models have been finding lately, most of which are very old, are staggering.
However, by way of intentional code that goes against the interests of the user, which would be considered security issues with FOSS but not with proprietary codebases where the interests of the company come first, things should be better with FOSS.
The latter should also be more noticeable than the former. It's possible some of the former may not have run at all, neither accidentally nor intentionally. A bug can just stay dormant without ever surfacing in practice. The latter is there to be used.
The benefit of FOSS with respect to eyes is that those eyes are better aligned with the interests of users (since it's the users looking) than the eyes on closed-source code.
Re: GDID Windows – Cut the tracker that follows you even under VPN
#90Just stop already, you are in an abusive relationship. Get out. Remove windows. It's not your friend. It's your computer, you have options.