Live data from Hacker News

Full Writeup of the Windows GDID

github.com

51–57 of 57 posts

Re: Full Writeup of the Windows GDID

#51
post #23

Earlier quoted context omitted.

What I'm more interested in is how/where the GDID is used . Imagine if e.g. Edge started sending your GDID as a header in every single web request.

When IE did this at the very beginning of the internet it was a real scandal. then verizon did it for (to?) mobile phones. I guess these things get normalized, people might say "those jerks" and then put it out of their mind.

There are, unfortunately, a lot of abuses people will tolerate in the name of convenience, especially if those abuses aren't readily apparent and affecting them directly at the time they learn about them.

The alternative is not running any proprietary tech. This would require people to give up a lot of convenience, build their own tech stack, make tools where none exist, etc. Doable for most on this forum I'd suspect, not really feasible for the population at large so the choice is even worse for them: be spied on, or abstain from using technology all together.

Its a captive audience, and why advocating for privacy is such a difficult, losing battle. People aren't going to stop using Windows because of this, so Microsoft has no incentive to do anything differently. Same goes for Meta, Google, Apple, etc.

Even for myself, I've gotten really lazy over the years and have traded quite a bit of my computing freedoms for the Apple device ecosystem's convenience factors. And that's the trap. When even the people who understand exactly what they're giving up still choose the golden handcuffs, the market has no incentive to change.

Re: Full Writeup of the Windows GDID

#52
post #30

Earlier quoted context omitted.

An MS account is not required for a GDID to be issued.

But without an MS accoutn it would not be connected to the browsing history

This is not true either; to Microsoft, every anonymous GDID is its own unique account on their servers.

Re: Full Writeup of the Windows GDID

#53

Couple questions: 1) Do we think this is actually how the FBI found this kid or is this simply what they're saying in order to keep some other tool hidden? 2) Is there a way to block or manually change the GDID from being revealed. If it's the browser leaking it, do all browsers leak it?

Complaint says "Cybersecurity researchers at Microsoft" found the kid and handed his name to FBI

Re: Full Writeup of the Windows GDID

#54

Earlier quoted context omitted.

Well, it's a darn good thing there is nothing like that over here on the Linux side. I'm pretty sure that if e.g. systemd attempted to generate a unique, persistent machine identifier during the installation process, it'd be shot down and patched off extremely quickly.

Linux does though? cat /etc/machine-id

[flagged]

Re: Full Writeup of the Windows GDID

#55

Earlier quoted context omitted.

What I'm more interested in is how/where the GDID is used . Imagine if e.g. Edge started sending your GDID as a header in every single web request.

In a sense it doesn't matter how the global ID is used now . The fact that it exists allows it to be used in ways like what you describe, either by a malicious (?) Microsoft itself or by a malicious third-party attacker. I'm familiar with these global IDs because I routinely used the Windows telemetry system as part of my work on the Windows core at Microsoft. We had strong policies on how and when we could access or…

Are there limits on what kinds of websites can request for a visitor's global ID information?

Must a website direct the user to log into their MS account before it is able to get a hold of the user's global ID information?

Re: Full Writeup of the Windows GDID

#56
post #23

Earlier quoted context omitted.

What I'm more interested in is how/where the GDID is used . Imagine if e.g. Edge started sending your GDID as a header in every single web request.

When IE did this at the very beginning of the internet it was a real scandal. then verizon did it for (to?) mobile phones. I guess these things get normalized, people might say "those jerks" and then put it out of their mind.

A typical phone operator records the data your phone sends to them on their servers. They're just lucky enough to have the absolutely unique ID of your phone number. Don't confuse this with something else. Microsoft and Google don't have the authority to create an ID for your computer unless they allow me to use that ID to make calls to your computer.

Re: Full Writeup of the Windows GDID

#57

Earlier quoted context omitted.

In a sense it doesn't matter how the global ID is used now . The fact that it exists allows it to be used in ways like what you describe, either by a malicious (?) Microsoft itself or by a malicious third-party attacker. I'm familiar with these global IDs because I routinely used the Windows telemetry system as part of my work on the Windows core at Microsoft. We had strong policies on how and when we could access or…

Are there limits on what kinds of websites can request for a visitor's global ID information? Must a website direct the user to log into their MS account before it is able to get a hold of the user's global ID information?

As far as I know, no browser for Windows allows sites to read the computer's telemetry global ID at all.
Post reply on HN