Live data from Hacker News

Microsoft confirms Windows GDID device identifier that cannot be disabled

ghacks.net

31–40 of 64 posts

Re: Microsoft confirms Windows GDID device identifier that cannot be disabled

#31
post #26

Earlier quoted context omitted.

Linux has the same kind of identifier at /etc/machine-id... readable by default by basically any application on the system.

Which is also well documented and trivially rotatable by anyone with root on the machine. How do you rotate the MS identifier?

https://github.com/gd03gd031/Windows-GDID-Changer

> well documented and trivially rotatable

Yes, but almost nobody does that or complains about it at all, even though applications may have been silently phoning it home for many years now.

Re: Microsoft confirms Windows GDID device identifier that cannot be disabled

#32

Earlier quoted context omitted.

Linux has the same kind of identifier at /etc/machine-id... readable by default by basically any application on the system.

...and that can be changed at-will.

same for the windows GDID

Re: Microsoft confirms Windows GDID device identifier that cannot be disabled

#33
post #5

How does the GDID compare to the UDID (Unique Device Identifier) and serial number in iOS; and the Apple Hardware UUID and serial number of Macs?

well, mostly the name. And the fact MS gave away GDID - IP mapping to the govt.

Is there any reason to think that the government couldn't force Apple to hand over the same data? They may or may not have taken over entire rooms at Apple (https://en.wikipedia.org/wiki/Room_641A) but you can bet they've at least got devices sitting on their network collecting data.

Re: Microsoft confirms Windows GDID device identifier that cannot be disabled

#34

Earlier quoted context omitted.

That's what hackers do in popular stories, right? In reality, most cybercriminsls just don't care that much (they usually use Tor browser, though). I mean they mostly use discord and telegram (both unencrypted). Serious "hackers" are usually state sponsored now, or members of mature groups.

They don't care, I would say they don't know. I saw an article where they analyzed the leaked IP addresses from a breach forum, and some of the top ten were Surfshark and iCloud Private relay.

>and some of the top ten were Surfshark and iCloud Private relay.

what's wrong with icloud private relay? It uses a 2-hop architecture so it's probably more private than any single-hop VPN.

Re: Microsoft confirms Windows GDID device identifier that cannot be disabled

#35
post #26

Earlier quoted context omitted.

Which is also well documented and trivially rotatable by anyone with root on the machine. How do you rotate the MS identifier?

https://github.com/gd03gd031/Windows-GDID-Changer > well documented and trivially rotatable Yes, but almost nobody does that or complains about it at all, even though applications may have been silently phoning it home for many years now.

>https://github.com/gd03gd031/Windows-GDID-Changer

sounds like you can rotate it, but it doesn't really matter because the registration/rotation process sends a bunch of static information to microsoft, which means they can re-correlate the the old id back to the new id.

Re: Microsoft confirms Windows GDID device identifier that cannot be disabled

#36

Earlier quoted context omitted.

"Old" people? How about the vast majority of the public, which is not represented on HN? Not to mention that one of the many major UI regressions in Windows is the removal of title bars from application windows, which is fundamental to this "trick." Try opening a PDF in Edge and also in Acrobat. Neither window has a title bar, and they are otherwise almost identical. You have to scrutinize the very few controls aroun…

Edge has less browser market share than Firefox right now, it's not the "vast majority."

I don’t believe that, there’s probably some missing data. Outside the techno echo chamber that HNers live in, most people use the defaults. I see people using adware browsers that were installed without their knowledge. Computers are just too complex for most people to notice details like what web browser they use.

Re: Microsoft confirms Windows GDID device identifier that cannot be disabled

#37
post #14

One more proof that Windows is malware.

Linux has the same kind of identifier at /etc/machine-id... readable by default by basically any application on the system.

This is a systemd identifier, not strictly speaking a "Linux" identifier.

In any case, an executable allowed to run on a host can trivially fingerprint the machine it is running on using a combination of hardware identifiers. Removing or rotating machine-id does not buy you any privacy against a malicious app.

What I find most surprising in this story is how careless these "hackers" were. You would think that people engaged in this type of activities would use throwaway devices running free operating systems and VMs, not personal devices logged into Snapchat and Facebook.

Re: Microsoft confirms Windows GDID device identifier that cannot be disabled

#38
post #10

How exactly does Microsoft link their gdid to a hotel booking? Hotels last I saw don't collect an obscure gdid... Did this victim use edge and sync their browser history or something perhaps?

Edge has a feature where it will periodically pull the bookmarks and browsing history from any other browsers you have installed, so they'll then get sent to Microsoft and associated with your Microsoft account. This was initially enabled by default without the user's consent, although I believe now you may have to opt into it if you do a fresh Windows install. I only realized this was a thing because one time my wor…

[dead]

Re: Microsoft confirms Windows GDID device identifier that cannot be disabled

#39
User nashashmi [1]:

  So this kid uses his home computer at his home, and they trace him down with 
  the IP address, and the IP address also makes a request for Windows Updates.
  And that narrows down the Device ID. The device id is now traced to this kid.
That seems more likely, I hope, than Edge/Windows secretly telemetering your GDID and every URL you visit to Redmond. It's a huge privacy hole still, but they can plausibly deny they set out to track you across the web using their OS.

[1] https://news.ycombinator.com/item?id=48815196#48818368

Re: Microsoft confirms Windows GDID device identifier that cannot be disabled

#40
post #10

How exactly does Microsoft link their gdid to a hotel booking? Hotels last I saw don't collect an obscure gdid... Did this victim use edge and sync their browser history or something perhaps?

Edge has a feature where it will periodically pull the bookmarks and browsing history from any other browsers you have installed, so they'll then get sent to Microsoft and associated with your Microsoft account. This was initially enabled by default without the user's consent, although I believe now you may have to opt into it if you do a fresh Windows install. I only realized this was a thing because one time my wor…

> so they'll then get sent to Microsoft and associated with your Microsoft account.

The import is entirely local, the "sent to Microsoft" bit is if you have Edge sync enabled. This is identical to Chrome importing your Firefox data and then syncing it back to Google. Except the Edge import was, by reports at the time, accidentally auto-enabled. But you'd still have to sign into Edge and enable sync.

Post reply on HN