Live data from Hacker News

GDID Windows – Cut the tracker that follows you even under VPN

korben.info

1–10 of 106 posts

Re: GDID Windows – Cut the tracker that follows you even under VPN

#3
Obvious workaround to get off windows and use Linux…

But do any popular linux distributions use an identifier? Ubuntu, Kali, Mint, Arch, etc?

It seems an attractive way for devs to work out telemetry. Awful in reality; but I imagine attractive.

Re: GDID Windows – Cut the tracker that follows you even under VPN

#4
> Microsoft provided the FBI with the history of IP addresses tied to that specific GDID.

This article, and most articles about this, doesn't explain where FBI got that GDID from. Ok, Microsoft has a list of IP addresses that has been used by a computer with a certain GDID, but FBI needs to get the GDID in the first place, and then try to bind that to a person.

I found another article that explains the process a bit better:

> Stokes got caught because he used the same Windows device for everything, and the GDID stitched all of it back together after the fact.

> Scattered Spider members phoned the jewelry retailer’s IT help desk from Google Voice numbers, posed as locked out employees, and talked support staff into resetting three accounts, two with administrator privileges. From there they installed a tunneling tool called ngrok to get past the retailer’s network defenses, moved roughly 77 gigabytes of data to Amazon cloud storage using ngrok [...]

> Investigators later subpoenaed ngrok and found the account used in the attack had been created on May 12, 2025, at 19:21 UTC from a VPN proxy IP address run by Tzulo, a hosting provider. The IP was a dead end. VPN proxies do that. But the GDID is built different.

> Microsoft’s records showed that at that exact same minute, a Windows device carrying GDID g:6755467234350028 had visited the ngrok signup page. Three hours later, the same GDID visited the retailer’s own website, through the same Tzulo proxy address used to set up the ngrok account. It gave the FBI a device, that don’t rotate the way VPN exit nodes do.

https://www.windowslatest.com/2026/07/10/you-cant-fully-disa...

Although this doesn't explain where Microsoft got that traffic data from. How do Microsoft know which sites a computer visit?

Re: GDID Windows – Cut the tracker that follows you even under VPN

#5

Obvious workaround to get off windows and use Linux… But do any popular linux distributions use an identifier? Ubuntu, Kali, Mint, Arch, etc? It seems an attractive way for devs to work out telemetry. Awful in reality; but I imagine attractive.

At least Debian and Ubuntu have /etc/machine-id, presumably easily changed - but it’s there.

Re: GDID Windows – Cut the tracker that follows you even under VPN

#7
post #5

Obvious workaround to get off windows and use Linux… But do any popular linux distributions use an identifier? Ubuntu, Kali, Mint, Arch, etc? It seems an attractive way for devs to work out telemetry. Awful in reality; but I imagine attractive.

At least Debian and Ubuntu have /etc/machine-id, presumably easily changed - but it’s there.

I think the difference is that, on Windows, there are background services that constantly ping Microsoft with the device ID. A device ID on its own is not really harmful if it's not exposed to the internet.

Re: GDID Windows – Cut the tracker that follows you even under VPN

#8
post #4

> Microsoft provided the FBI with the history of IP addresses tied to that specific GDID. This article, and most articles about this, doesn't explain where FBI got that GDID from. Ok, Microsoft has a list of IP addresses that has been used by a computer with a certain GDID, but FBI needs to get the GDID in the first place, and then try to bind that to a person. I found another article that explains the process a bit…

They make the default web browser on Windows, and that sends your browsing data if you don't disable its telemetry.

See https://news.ycombinator.com/item?id=48921595

Re: GDID Windows – Cut the tracker that follows you even under VPN

#9
post #5

Obvious workaround to get off windows and use Linux… But do any popular linux distributions use an identifier? Ubuntu, Kali, Mint, Arch, etc? It seems an attractive way for devs to work out telemetry. Awful in reality; but I imagine attractive.

At least Debian and Ubuntu have /etc/machine-id, presumably easily changed - but it’s there.

I mean, there's a ton of unique identifiers on machines already tied to hardware and disks, but that must be a systemd thing since my Devuan machine does not have it.

But given there's no cloud accounts on linux I would imagine it's trivially changed just like a NIC's MAC

Also, seems unlikely it would be used for any single-signon with cloud services.

Re: GDID Windows – Cut the tracker that follows you even under VPN

#10
post #4

> Microsoft provided the FBI with the history of IP addresses tied to that specific GDID. This article, and most articles about this, doesn't explain where FBI got that GDID from. Ok, Microsoft has a list of IP addresses that has been used by a computer with a certain GDID, but FBI needs to get the GDID in the first place, and then try to bind that to a person. I found another article that explains the process a bit…

They claim it was an ngrok account that was used to host an endpoint used in the compromise, tied to a microsoft account / gdid that was passed when ngrok software was downloaded from the "microsoft store".
Post reply on HN