Live data from Hacker News

GDID Windows – Cut the tracker that follows you even under VPN

korben.info

51–60 of 106 posts

Re: GDID Windows – Cut the tracker that follows you even under VPN

#51
post #38
post #4

> Microsoft provided the FBI with the history of IP addresses tied to that specific GDID. This article, and most articles about this, doesn't explain where FBI got that GDID from. Ok, Microsoft has a list of IP addresses that has been used by a computer with a certain GDID, but FBI needs to get the GDID in the first place, and then try to bind that to a person. I found another article that explains the process a bit…

I'd take all of this with a cup of salt due to law enforcement's use of parallel construction in tech cases.

Wouldn't the evidence need to be presented to the defense for scrutiny, and if it turned out to be bunk, that would strongly hurt the state's case?

Re: GDID Windows – Cut the tracker that follows you even under VPN

#52

Earlier quoted context omitted.

I mean, there's a ton of unique identifiers on machines already tied to hardware and disks, but that must be a systemd thing since my Devuan machine does not have it. But given there's no cloud accounts on linux I would imagine it's trivially changed just like a NIC's MAC Also, seems unlikely it would be used for any single-signon with cloud services.

There are _some_ cloud accounts for linux such as Ubuntu One, which I would fear could have similar identification capabilities if ever forced by to do so by a 3-letter agency

Any sort of online service you're logged into is going to have your IP and account correlated with a timestamp. Dropbox, GDrive, and even your e-mail provider. While a device identifier might be more useful it's not like the lack a device ID will keep you from being tracked.

Re: GDID Windows – Cut the tracker that follows you even under VPN

#53

[flagged]

What Google was "caught" doing was exactly what it was doing in non-incognito mode already. Anyone expecting the websites you visit to know you're in private mode and to not log data is just lacking basic tech knowledge.

It is silly that Google had to explicitly state that in the disclaimer.

Re: GDID Windows – Cut the tracker that follows you even under VPN

#54
post #37
post #4

> Microsoft provided the FBI with the history of IP addresses tied to that specific GDID. This article, and most articles about this, doesn't explain where FBI got that GDID from. Ok, Microsoft has a list of IP addresses that has been used by a computer with a certain GDID, but FBI needs to get the GDID in the first place, and then try to bind that to a person. I found another article that explains the process a bit…

They didn’t. They went to ngrok and asked for all the data at the point of signup. They then looked to find the any of that data at the second site. In this case they had two identical data points - the GDID and the IP address.

What do you mean? The FBI could know that this VPN ip visited ngrok and then the retailer website, but how would it know that that ip was associated with the specific GDID unless microsoft was tracking (timestamp,website,gdid) tuples?

Re: GDID Windows – Cut the tracker that follows you even under VPN

#55
post #4

> Microsoft provided the FBI with the history of IP addresses tied to that specific GDID. This article, and most articles about this, doesn't explain where FBI got that GDID from. Ok, Microsoft has a list of IP addresses that has been used by a computer with a certain GDID, but FBI needs to get the GDID in the first place, and then try to bind that to a person. I found another article that explains the process a bit…

> Microsoft has a list of IP addresses that has been used by a computer with a certain GDID, but FBI needs to get the GDID in the first place

What they did was the opposite: ask Microsoft for GDIDs used by attacker-associated IPs within several 24-hour time periods during which attack-related activity took place. Windows pings Microsoft regularly with the GDID, establishing links between your GDID and any IP addresses you use. The IP logs from Microsoft and the VPS provider showed at least 10 instances where a single VPN IP accessed the attacker's VPS and also pinged Microsoft with at least one GDID within a 24-hour period. They found a constant GDID that all instances shared. This seems to have been the most damning GDID-related evidence in the DOJ complaint [1] and yet it wasn't mentioned in the article you linked (or any other articles about this I've seen pop up on HN). It includes the diagram from the complaint (page 18) that outlines this, but devoid of context. The ngrok stuff that the article focuses on was just the cherry on top and was discussed later in the complaint.

What also becomes clear when you read the complaint is that the GDID was just one piece of the puzzle and that they had plenty of other evidence. Attacker-associated IPs were used to access the suspect's Apple, Snapchat, and Facebook accounts, at least one of which was his actual residential IP, not a VPN IP. Once they had revealed the identity of the person who owned these accounts, they were able to all-but-confirm that this was in fact the attacker.

What remains unclear even after reading the complaint is how they were so sure that the GDID they obtained visited specific websites, but honestly, at that point, they were already drowning in evidence, so I don't know if it matters that much. It could be as simple as "he was signed into Edge with his Microsoft account and had sync enabled".

[1] https://www.justice.gov/usao-ndil/media/1450651/dl?inline

Re: GDID Windows – Cut the tracker that follows you even under VPN

#57

Earlier quoted context omitted.

I mean, there's a ton of unique identifiers on machines already tied to hardware and disks, but that must be a systemd thing since my Devuan machine does not have it. But given there's no cloud accounts on linux I would imagine it's trivially changed just like a NIC's MAC Also, seems unlikely it would be used for any single-signon with cloud services.

I'm guessing Devuan still has /var/lib/dbus/machine-id.

You're right. I have no idea what it's for, but I'm guessing for distinguishing between deployment images. I'm certainly not going to get too concerned about it.

The issue with the microsoft account was not unique IDs - tons of unique things on a machine.... it was a unique thing tied to an account and shipped to remote places.

Re: GDID Windows – Cut the tracker that follows you even under VPN

#58

Earlier quoted context omitted.

This seems like something that should be easy to confirm, but I haven't seen anyone do it. Do they keep a database of every website visit all Edge users make?

The question you should be asking is: why would Microsoft not do this?

GDPR compliance.

Not in the US, of course.

Re: GDID Windows – Cut the tracker that follows you even under VPN

#59
post #50

Earlier quoted context omitted.

/etc/machine-id also exists

But you don't have a service uploading it along with the URLs you visit, which is the creepy part. The ID itself can be useful for your own administration. And if such a service were to appear, it could easily be removed. Everything in Linux is optional, especially as long as you stick to open source.

How do we know? Does anyone check for things like this?

Many, many apps read /etc/machine-id if you do a quick github search.

Apps may have been silently correlating our activity for years without us knowing.

We know DHCP, EFI, GNOME, popularity-contest and many other apps already use it. There are countless ways it could be used already that are hard to detect.

Re: GDID Windows – Cut the tracker that follows you even under VPN

#60
post #4

> Microsoft provided the FBI with the history of IP addresses tied to that specific GDID. This article, and most articles about this, doesn't explain where FBI got that GDID from. Ok, Microsoft has a list of IP addresses that has been used by a computer with a certain GDID, but FBI needs to get the GDID in the first place, and then try to bind that to a person. I found another article that explains the process a bit…

None of this matters really.

This criminal mastermind got caught because he did everything but sign his name to the crimes while holding two pieces of government identification in presence of a notary.

The FBI did the bare minimum in terms of old-fashioned detective work, and correlated evidence from various sources.

The obsession with GDID is a complete nothing-burger and I'm tired of seeing it on the front page every other day.

Post reply on HN