Microsoft admits Windows 11 has a GDID tracker with no off switch, first documented publicly in an FBI hacker complaint (www.windowslatest.com)
from yogthos@lemmy.ml to privacy@lemmy.ml on 11 Jul 23:01
https://lemmy.ml/post/49929671

#privacy

threaded - newest

Maeve@kbin.earth on 11 Jul 23:19 next collapse

The complaint quotes a Microsoft representative describing the GDID as “a persistent, device-level identifier designed to uniquely identify an installation of a Windows operating system on a device, either a physical device (e.g., a mobile phone or laptop) or virtual machine, across certain Microsoft services and scenarios”

A Global Device ID (GDID) is a permanent, unique digital fingerprint that Microsoft automatically assigns to your computer when you install Windows or sign into a Microsoft account.

StellarExtract@lemmy.zip on 11 Jul 23:33 next collapse

Something this article glosses over is the fact that Microsoft knew all of the web URLs he was visiting. I don’t know if that’s because he was dumb enough to sign into Edge with his Microsoft account or if they were collecting that a different way, but the GDID wouldn’t have been nearly as useful without that info.

Daryl76679@lemmy.ml on 11 Jul 23:43 next collapse

And able to identify the specific accounts he was logging into. How are they able to do that?

Brkdncr@lemmy.world on 11 Jul 23:47 collapse

Edge can save passwords and creds, much like any credential manager.

FineCoatMummy@sh.itjust.works on 11 Jul 23:49 next collapse

IDK either. But so much is now like, ppl wanting privacy have to be right every time. The co’s wanting our data, only once! A single hidden backdoor siphon to our data and we didn’t protect ourself from it. A single telemetry that encodes every URL we visit. A single statistical way to fingerprint us.

That Sisyphus dude knows our pain.

hitmyspot@aussie.zone on 12 Jul 02:46 collapse

Which is why open source is important. Holes can be found and software telemetry can be avoided.

A lot of the telemetry is sold to people as being in their benefit. Monitor installed software for updates, location data for weather etc.

If the companies had to document the amount they collected in cash for each user based on ads and send it as a mk though report, it might be eye opening. The source if the cash would also be good. So did companies pay directly or dodgy intermediaries and data brokers.

blackwall@lemmy.world on 12 Jul 03:16 next collapse

I don’t think Microsoft recorded the URLs, just activity from a GDID and IP address at particular timestamps. The authorities would also have subpoenaed records from other accounts they knew were his e.g. Snapchat and Facebook. The GDID was just a way of assigning activity from his device to particular VPN endpoints at particular times. The point of the story is essentially that the GDID allowed them to track his device across multiple IP addresses. But this wouldn’t have been possible without at least some other pieces of the puzzle such as knowing which was his Microsoft account, or Facebook account etc. in the first place.

aurelar@lemmy.ml on 13 Jul 08:17 collapse

Read the federal complaint against Peter Stokes. Microsoft has a record of the URLs.

gila@hexbear.net on 12 Jul 06:01 collapse

IIRC that’s been a known function of Edge ever since its redesign around 5-6 years ago, regardless of whether you’re signed in all URLs go to Microsoft in plaintext

Daryl76679@lemmy.ml on 11 Jul 23:42 next collapse

Year of the Linux desktop anyone?

whatiswrongwithyou@lemmy.ml on 12 Jul 00:31 next collapse

The same user posted a thread in this comm about the Linux equivalent, device-id, which is possibly more problematic.

RichardNixos@lemmy.ml on 12 Jul 02:41 collapse
const_void@lemmy.ml on 12 Jul 00:39 next collapse

Seems like the answer is never. The masses are too addicted to PC games to give it up.

Hestia@hexbear.net on 12 Jul 01:23 next collapse

Linux is PC…

insurgentrat@hexbear.net on 12 Jul 01:26 collapse

Also you can play almost all games on linux

RedWizard@hexbear.net on 12 Jul 02:22 collapse

And in some cases they run better then on windows.

insurgentrat@hexbear.net on 12 Jul 03:35 collapse

true, although the opposite is also sometimes true. Really it’s mostly the same experience on a much less bloated OS that’s highly configurable.

FineCoatMummy@sh.itjust.works on 12 Jul 02:26 next collapse

I agree. But I think more to the other side of it. I worry that a vast influx, who don’t care about privacy and computing freedom, would make for huge market pressure to lock down Linux. Same way we see Windows, IOS, Android locked.

Game co’s, big tech, and others will demand it, if the masses flee to Linux. Today, most Linux users go nah, we want freedom more than your AAA game. If that changes, we could lose the very culture that resists locked down corporate controlled computing.

jtrek@startrek.website on 12 Jul 02:58 next collapse

It’s not the PC games keeping people so much. Proton solved a lot of that problem. It’s inertia.

Most people don’t care about things. They just don’t. Their brains just don’t have the juice.

geneva_convenience@lemmy.ml on 12 Jul 11:30 next collapse

A lot is professional software. Many people have one or two pieces of software they use a lot which doesn’t run on Linux.

shneancy@lemmy.world on 12 Jul 12:08 next collapse

i miss photoshop. not enough to boot into my windows partition, but it sure would be nifty if it would just work on linux. krita is decent but danggit, not the same

geneva_convenience@lemmy.ml on 12 Jul 13:03 next collapse

But if you were a professional photoshopper I’d imagine you wouldn’t work with Krita all day.

shneancy@lemmy.world on 13 Jul 07:50 collapse

as in i didn’t used to work with krita all day or i wouldn’t be working with krita all day now?

geneva_convenience@lemmy.ml on 13 Jul 10:49 collapse

You wouldn’t work with Krita all day right now

shneancy@lemmy.world on 13 Jul 17:16 collapse

well i used photoshop for a solid 8 years so i’d consider myself at the very least an advanced amateur

i don’t need it for work right now, but i used to

madthumbs@lemmy.world on 12 Jul 13:18 next collapse

It’s nifty on Windows where I can run all kinds of other professional productivity programs. I went back to Windows because Linux can’t deliver and likes to break on updates. -Someone that loves CLI and didn’t mind that about it.

Daryl76679@lemmy.ml on 12 Jul 20:51 collapse

You prefer Krita over GIMP for photoshopping tasks?

shneancy@lemmy.world on 13 Jul 07:59 collapse

i got both but decided to first learn krita as i like drawing more than image manipulation. though i’ll be needing to hop into gimp soon i feel, as krita’s text editing options are clunky at best

MunkysUnkEnz0@lemmy.world on 13 Jul 11:17 collapse

Dark room is another open source alternative.

shneancy@lemmy.world on 13 Jul 17:18 collapse

darkroom is the open source alternative to lightroom, both are vastly different from photoshop

jtrek@startrek.website on 12 Jul 14:47 next collapse

I don’t think that’s actually very many people. Not for their personal computers. Most people don’t run much more than a web browser, if they don’t play games.

geneva_convenience@lemmy.ml on 12 Jul 15:35 collapse

People tend to use the stuff they’re already used to. They could probably use Linux but if they buy a Laptop which has Windows preinstalled and they’re used to Windows it’s hard to get them to make the jump

jtrek@startrek.website on 12 Jul 16:58 collapse

Right. Inertia is the metaphor I used to express that idea.

mic_check_one_two@lemmy.dbzer0.com on 12 Jul 16:34 collapse

This is my issue. There are two specific pieces of software that only run on Windows. Even worse, there is one program that only runs on Mac. So in order to properly do my job, I need to maintain both a Windows laptop and a Mac. And ditching them is virtually impossible, because the Windows machine is used to control/configure a lot of gear, and the Mac program is an industry standard program that virtually every technician is expected to know.

NKBTN@feddit.uk on 12 Jul 15:14 collapse

The bigger problem is that most people just aren’t up for installing an OS themselves. I’ve certainly never had the chutzpah to replace Android, and I’m more tech savvy than most

jtrek@startrek.website on 12 Jul 17:01 collapse

100%. I think a lot about one of my friends when trying to think about that kind of user. Smart lady. Advanced degree. Has her life together. Would absolutely not want to try to install an OS. Wouldn’t even know how to start.

But I’m confident if I handed her a Linux laptop, she’d use it just the same as a Mac or Windows machine.

prole@lemmy.blahaj.zone on 12 Jul 15:02 collapse

Gaming hasn’t been an issue for years

mic_check_one_two@lemmy.dbzer0.com on 12 Jul 16:25 collapse

There are certain games that refuse to enable anticheat on Linux. So if you play one of those games, you’re forced to use Windows. But that isn’t Linux’s fault. It’s simply the game makers refusing to enable Linux support. Multiple game devs have even stated that it’s basically an “enable on Linux” checkbox on their end, but the publishers want that sweet kernel-level access on Windows.

iamtherealwalrus@lemmy.world on 12 Jul 09:58 collapse

I have tried over and over for 30 years now and every time I discover something is missing, something I’m not willing to give up. Today it was Google Drive. There are multiple solutions for Linux to mount Google Drive as a folder in the local filtersystem, none of them offer decent performance compared to the windows client. Every time I try Linux something like this comes up.

shneancy@lemmy.world on 12 Jul 12:06 collapse

could you elaborate on what you mean by “performance” of cloud storage? the speed of upload, download?

iamtherealwalrus@lemmy.world on 12 Jul 13:34 collapse

The time it takes to open and list a directory using Nautilus in GNOME desktop. It can take 5-10 seconds with a directory of 5 files, a lot longer if there are 50 files in a directory. And all the “solutions” I find on the web involve some kind of guesswork and tweaking settings left and right, hoping to somehow hit a magic combination that works.

[deleted] on 12 Jul 01:43 next collapse

.

M1ch431@slrpnk.net on 12 Jul 01:43 next collapse

Then there’s activation. Massgrave, the group behind Microsoft Activation Scripts, notes that Windows setup sends hardware info to Microsoft and gets identifiers back, the same tokens later used for Store access and licensing: “It’s impossible to prevent Windows from getting a GDID without breaking activation and UWP app[s].” Anyone who lost a license after swapping a motherboard has already met a smaller version of this.

I guess this is why people always said it was impossible to remove the watermark that appears when you are not activated, when it was rolled out many years ago.

Defeating the reasons for activation might’ve lead the more tech-savvy to figuring out the nature of the identifiers being sent for activation and seeing where else they are sent.

ramenshaman@lemmy.world on 12 Jul 02:39 next collapse

ELI5?

yogthos@lemmy.ml on 12 Jul 03:25 collapse

Imagine your computer has a secret ID number that Microsoft gives it when you sign in with your Microsoft account. This number is like a permanent nametag that your computer wears. Even if you use a VPN to hide your location, that nametag stays the same.

A hacker used a VPN to hide while breaking into a jewelry store’s computer system. But Microsoft helped the FBI find him because his computer’s secret nametag kept showing up everywhere he went online. They matched that nametag to his social media accounts and other stuff he did, and that’s how they caught him. Most people didn’t even know this secret nametag existed, and you can’t turn it off without breaking your computer.

ramenshaman@lemmy.world on 12 Jul 03:28 next collapse

Thanks! He should have used Linux

yogthos@lemmy.ml on 12 Jul 03:37 collapse

unfortunately lemmy.ml/post/49710604

ramenshaman@lemmy.world on 12 Jul 07:57 next collapse

I imagine there’s a distro that would work. Kali maybe?

yogthos@lemmy.ml on 12 Jul 15:29 collapse

yeah probably, and you can tweak any distro to rotate it too, just most people don’t realize it’s a thing in the first place

FudgyMcTubbs@lemmy.world on 12 Jul 13:22 collapse

I’m surprised they havent created some sort of software that changes your machine-id every 12 hours or something.

yogthos@lemmy.ml on 12 Jul 15:29 collapse

oh you can do that with linux, even with systemd, just takes a bit of tinkering

umbrella@lemmy.ml on 12 Jul 03:53 next collapse

how dumb can you be to use unhardened windows to hack valuable shit omg.

even if you didn’t know of this system (i didn’t) it’s well known windows scans for even the color of your underwear.

yogthos@lemmy.ml on 12 Jul 03:54 next collapse

also to login with edge on top of that

LarsIsCool@lemmy.world on 12 Jul 09:55 next collapse

didnt know Microsoft is a Charli XCX fan

shneancy@lemmy.world on 12 Jul 11:59 next collapse

the average lemmy user is much more tech literate than an average person

people really don’t know that kind of stuff. to many a computer is a computer, it has internet, and plays games… what’s an operating system?

Dpek@lemmy.zip on 12 Jul 13:31 next collapse

People cant figure out how to connect their idiotic tv (marketed as smart tv) to the streaming box

And others cant figure out how to turn the ac to cold and are “afraid of breaking it” bruh its a ac, the worst you can do is set a timer

waldfee@feddit.org on 12 Jul 14:31 collapse

In their defense the UIs on smart TVs are a load of bullshit though

Dpek@lemmy.zip on 12 Jul 20:51 collapse

Oh yeah thats why i didnt mention it still being in store mode

The remote has a button for selecting the input and the menu had 3 options: smart tv, tv and hdmi 3

umbrella@lemmy.ml on 12 Jul 19:44 collapse

damn, but even hackers capable of breaking into jewelery store systems?

like at this point the problem is extreme ignorance.

dieTasse@feddit.org on 12 Jul 13:01 collapse

I think we are too exposed to the movie-villains-geniuses. The reality is that most criminals are dumb.

MonkderVierte@lemmy.zip on 12 Jul 11:10 next collapse

They were logged in while using it for crime? That’s like posting about it on facebook.

yogthos@lemmy.ml on 12 Jul 15:44 collapse

basically

krolden@lemmy.ml on 12 Jul 16:05 collapse

Calling him a hacker is pretty generous if he let them catch him like this

brillotti@lemmy.world on 12 Jul 09:05 next collapse

Goym Device ID

BlackLaZoR@lemmy.world on 12 Jul 14:23 next collapse

Bog ID.

Current state: Happy

Owns: Nothing

ayyy@sh.itjust.works on 12 Jul 21:44 collapse

Can you explain the joke?

shortwavesurfer@lemmy.zip on 12 Jul 10:28 next collapse

This sounds so much like the snitch code from Thieves’ Emporium by Max Hernandez, written in 2014.

Or at least I believe it was 2014.

MonkderVierte@lemmy.zip on 12 Jul 11:07 next collapse

Don’t forget the unique identifier of Edge and Chrome.

Bieren@lemmy.today on 12 Jul 13:37 next collapse

Does MS track what you do in Edge and Windows, yes. Does Google track you in Crome and any app of theirs, yes. Does Apple track everything you do on their devices, yes. Does meta, twitter, all social media sites track the fuck out of you, also yes.

jjlinux@lemmy.zip on 12 Jul 14:09 next collapse

Does Linux track you? Does LibreWolf track you? Does GrapheneOS track you? Does Vanadium track you? Does SimpleX or Signal track you? Does…

Never mind, I think you get my point.

SocialistVibes01@lemmy.ml on 12 Jul 14:29 next collapse

Those idiots are so tiring, you’re wasting your time.

SocialistVibes01@lemmy.ml on 12 Jul 14:30 next collapse

Those idiots are so tiring, you’re wasting your time.

MasterBlaster@lemmy.world on 12 Jul 21:49 collapse

they generally give you the option to avoid tracking. now, whether they actually follow your desire is another issue.

prole@lemmy.blahaj.zone on 12 Jul 14:57 next collapse

Yes, all of that is true.

Were you building up to making a point, or…

yogthos@lemmy.ml on 12 Jul 15:28 collapse

tracking is a core function of pretty much all commercial software at this point

BlackLaZoR@lemmy.world on 12 Jul 14:21 next collapse

Hacker

Uses windows

He got what he fucking deserved

0_o7@lemmy.dbzer0.com on 12 Jul 15:09 next collapse

Okay, buy the thing to take note here is what tech companies can hide.

You know they’re tracking users but there are still things we’ll never find out unless they reveal it themselves or are made to reveal in indirectly.

BlackLaZoR@lemmy.world on 12 Jul 15:19 collapse

On the other hand, open source software has everything revealed by default. It has no dirty secrets to hide

Alfredo_DisguidoAlCazzo@reddthat.com on 13 Jul 07:06 collapse

Not only he uses windows, but a ms online account as well!!!

someone@lemmy.today on 12 Jul 17:07 next collapse

why would a hacker use windows?

orochi02@feddit.org on 13 Jul 08:13 next collapse

Probably bc its the most used os

Snapz@lemmy.world on 13 Jul 09:50 collapse

Enhance!!!

Aria@lemmygrad.ml on 12 Jul 17:33 next collapse

Smug Reddit-level takes left and right in this thread. The kid successfully hacked a website, you can assume he knows what he’s doing better than you and followed all the best practices short of not using Windows. They didn’t get his account from his Edge credential store. He probably used some Firefox-derivative. Tor browser if he was stupid. He probably “hardened” Windows every way he could think of, again, short of disconnecting from the internet. Windows simply does a good job of spying on you, that’s all it is.

There are even people in the thread recommending running Windows games on Linux as a way to avoid this surveillance. If you put Microsoft Flight Sim on your Linux computer, then that’s now a Windows computer. Microsoft owns that computer, same as the Windows one. If you install Nvidia drivers, Nvidia owns that computer, and the USA can ask Nvidia for your accounts and whereabouts instead of Microsoft. If you put Steam on your Linux computer, that’s now Steam’s computer and the USA can ask Steam.

There is no “safe” amount of malware.

chinaski@lemmy.ml on 12 Jul 19:31 next collapse

Why tor if he was stupid? I am stupid.

Aria@lemmygrad.ml on 12 Jul 20:25 collapse

The security of Tor is built on the assumption that one actor owning a majority of the nodes is improbable to the point of being written off as a non-concern. The tool has always been run and maintained by the USA government. When they opened access to the public, they owned the majority of the nodes, and with the amount of compute available to the NSA (look up the size of their official data-centres, add in their hacked bot-farms), it’s almost certain they still do. If it wasn’t their plan to always have supremacy, they aren’t doing their job. The purpose of Tor is to hide traffic from USA’s enemies. A few tens of thousands of private users is just reducing their power bill and painting targets on their own backs, not successfully hiding from the NSA.

chinaski@lemmy.ml on 12 Jul 22:06 collapse

I appreciate the explanation. If not Tor, for very obvious reasons you specified, what is the better alternative?

Aria@lemmygrad.ml on 13 Jul 11:52 collapse

There isn’t a 1-step perfect solution as far as I know. You can use Tor in combination with other technologies, and it’ll likely help you avoid a lot of surveillance, just not specifically the NSA. (Also keep in mind anyone/commercial actors can run Tor nodes with the intention of spying on Tor users. You need a lot of nodes to catch anyone, but I wouldn’t assume it never happens).

The main thing is to own your software and hardware, and disconnect what you don’t own from the internet. If you can’t meet those conditions, then it’s impossible no matter how vigilant and knowledgable you are.

My recommendations is to play your computer games on an offline computer via GOG purchases, or if you want Steam games, then just give up on securing that device. Have two networks. Have your secure computers for your general online tasks and chatting, and have the unsecure computer for interacting with DRM and services that lose a lot of functionality if the surveillance vectors are blocked.

Bad attempts at hardening often don’t work, and have the adverse effect of making you more unique for fingerprinting. It might be worth foregoing some hardening advice if you can think of workarounds the hostile actor might use, which you don’t know how to counter-act.

[deleted] on 13 Jul 07:45 collapse

.

mazzilius_marsti@lemmy.world on 13 Jul 05:42 next collapse

the fucked up thing is this GDID thing apparently also show up for VM. So that would mean any VM and even a Quebe?

Fuck microsoft

danielfm123@lemmy.zip on 13 Jul 09:40 collapse

We thought china was better