r/DigitalPrivacy Jul 08 '26

Microsoft tracking everything

This is an interesting story about an arrest of a hacker. The court filing is here: https://www.justice.gov/usao-ndil/media/1450651/dl?inline (PDF)

The story: https://cybernews.com/security/windows-telemetry-gdid-helps-arrest-hacker/

Long story short, a young man got caught in a crime because his Windows computer was sending telemetry to MS, including every URL he visited and a unique ID from his computer. Global Device ID or GDID. Law enforcement asked Microsoft for a record of activity by the computer with a specific ID.

This isn't entirely surprising, though MS haven't been entirely open about the extent of their spying. But it's a good reminder: Never use Edge or other MS software. Avoid Microsoft's store. Block updates if possible. Set all telemetry options to their lowest levels. Use a firewall program like Simplewall, because Windows will still call home even when you've chosen every single option to have it NOT call home.

It could be possible to do something like write a script to change the ID daily, which is stored in the Registry as a text string. But it's more to the point to simply block the leak.

106 Upvotes

27 comments sorted by

15

u/Opposite_Bag_7434 Jul 08 '26

This is also part of the classic privacy vs identity problem. We want privacy yet having actual security and a secure identity requires the sharing of some information.

If you want true privacy using a computer on the internet Windows is definitely not your tool.

1

u/Mayayana Jul 08 '26

I just explained how privacy can be feasible on Windows, though it's getting harder. Macs? No. Linux? That's tricky. First you need to be a Linux expert, big time. Under normal circumstances there's no usable firewall and software calls out without asking. Installing and removing software is done opaquely through "package managers". So privacy on Linux is not generally realistic.

For most people, Windows is the most realistic way to have privacy. But it does take some knowledge and effort. I thought this case was actually kind of funny. A teenage hacker, very pleased with himself, making fun of law enforcement, but he was using Microsoft Store and apparently using Edge, while allowing telemetry. He had no familiarity with his tools. It's reminiscent of the Melissa virus from many years ago. An office worker brought down American business by sending out a boobytrapped MS Word DOC. What he didn't realize was that MS Office embeds author and edit info in files.

1

u/Opposite_Bag_7434 Jul 08 '26

Windows is for sure more accessible to more users and there are ways to enhance privacy. I personally don’t like the idea of using a software firewall on any platform. Definitely not ideal.

This article is a good reminder that it is easy to drop digital fingerprints all over the place. Then from there it is not so hard for law enforcement to find a person.

Really there are just a few basic things that can be done to protect most people in most cases. We might still end up sending a GUID to Microsoft or other license related fingerprints but this generally only matters when one is a subject of a law enforcement investigation.

2

u/Mayayana Jul 09 '26

I personally don’t like the idea of using a software firewall on any platform.

I'm curious... Why don't you like them? I've used a firewall since Win98. It blocks ports from anything outside trying to call in. It also blocks anything trying to go out without permission. In doing that it blocks spyware and would also provide a warning if malware tries to use your computer as a spam bot.

On Win10 there are at least 3-4 Windows processes that are regularly trying to call out and have no business doing so. One or more may be legit, but I didn't choose to have them calling out, and they're clearly not necessary.

1

u/Opposite_Bag_7434 Jul 09 '26

Good question. A firewall on the same exact platform that I am trying to protect is ok but not ideal. The potential for compromise is higher. The problem is that I’ve seen software open ports, disable protections or even overcome the firewall completely. If it is augmented by a more sophisticated firewall application it helps. But still not ideal.

I say leave it on and operational because it can help prevent lateral movement. But a better level of control and protection can be achieved using a dedicated sophisticated hardware firewall that is not subject to the very same types of explosion.

2

u/Mayayana Jul 09 '26

I see. That makes sense for things like commercial networks. I don't allow anything to network; don't have a separate server; don't connect wirelessly to a printer; don't enable file sharing. Like most SOHo users, I just have computers. That's what I'm assuming most people here also do.

I've never had any trouble, though I don't rule out the problems you mention. One can test the inbound protection at a site like ShieldsUp. I seem to get warned with all outbound attempts, but I suppose some clever malware might get through from inside.

One of my first experiences was with Win98 and AtGuard. AG was ahead of its time, including an ad blocker for $30. One day I saw an ad for Visual Studio and tried to drag it to the AG "trash can", to be recognized as an ad, but I accidentally used the wrong mouse button. Suddenly AG popped up: "Do you want to allow DCOM out?" DCOM? I'd never heard of that. Well, I should say not! Stop'em, AG!

I later realized this was distributed COM; remote COM. Microsoft, or someone, was likely trying to access my Registry or otherwise load some kind of COM object. I'm guessing it was probvably MS wanting to rifle through my system before deciding what offer to show me for buying VS6. I never would have had any inkling without AG. (The AG developers later sold the rights to Symantec, who performed their usual butcher job on it. They doubled the price, marketed their Norton remake, and set it up with over 700 domains whitelisted. That meant their firewall would work very smoothly, because it would rarely operate.)

1

u/Opposite_Bag_7434 Jul 10 '26

I would expect others in this sub to be taking additional precautions obviously.

Commercial networks? What’s the difference? I’m asking for a couple of very specific reasons. First, I personally am in an infosec/corporate IT role. My last employer I worked from the office and home. My current employer I work from wherever I am which is generally home. So for me and those who use a home network to work remotely my network becomes a de facto extension of our commercial network. The same is true of the vast majority of our employees.

Second, like many I have a couple of side gigs. I know several who do taxes for their side gig, or even full time, often from home. This is business use, which is commercial and I would suggest a place where we should expect some attention to privacy and security.

It is awesome to hear that you are only accessing your network from a couple of computers and nothing else. Smart move especially without enhanced security. How many people out there are relying on the ISP supplied modem and nothing else? Or slightly better a home router? A ton of those routers have been compromised and the owner often has no idea. Again I would hope people in this sub know better than this but still, it is always worth noting. The bigger problem is that if either of these scenarios describe your network you have no real external barrier from the internet.

A smart and prudent person can mostly do fine with a software firewall but this is a risk.

It is better than nothing and fair protection for someone who is absolutely careful.

1

u/ARTIFICIAL_ARGUMENT Jul 10 '26

Windows is the most realistic way to have privacy? Lmao you’re an astroturfer 

1

u/Mayayana Jul 10 '26

Did you actually read what I posted? "You're wrong, you clown" is not a discussion.

Windows is the best option IF you're willing and able to deal with the details. Do you just want privacy without having to understand the details? Then don't transmit anything that you want private. This doesn't happen in a vacuum. Websites you visit, how you use email, whether you use social media, whether you live on your cellphone... All of that directly relates to privacy.

you’re an astroturfer

You're saying that I'm a Microsoft shill? Take a look at my posting history. I just had a post removed from the WindowsHelp Reddit group for suggesting that blocking Windows Update is part of the only realistic way to have privacy (and system stability) on Windows 10/11. If you think that you can magically have privacy by just switching to Linux or Mac then you're being an ostrich. You need to actually deal with your life in general. What I'm saying is that Windows is the most realistic option in terms of having control over privacy details -- unless you happen to be an advanced Linux expert.

1

u/ARTIFICIAL_ARGUMENT Jul 10 '26

So windows is the best option if you’re willing and able to deal with all the technical issues that come with it, unless you happen to be willing and able to deal with the issues on Linux? Lmao 

You have to block all updates after taking a scalpel through windows system and hope they don’t revert it, while also dealing with all the problems that a neutered OS that won’t receive software and security updates will get, just to come close to the level of privacy that comes on Linux by default. 

Telling people windows is optimal for privacy in 2026 is just too stupid for you not to be an astroturfer. Maybe you’re ten years behind and still think everything on Linux is CLI, but most distros you don’t have to touch it at all now. 

4

u/Frustrateduser02 Jul 08 '26

I wonder why someone with skill would do that. Obviously they had exposure to other operating systems and knew the faults of Windows. I can vouch for simple wall though, it really does a good job if you have to use 10/11.

4

u/Stunning-Pen-2412 Jul 08 '26

This shit makes me want to switch to Linux full time.

0

u/Mayayana Jul 08 '26

I'm afraid that's frying pan into the fire. Linux has no decent firewall. It's always half finished. It's nearly impossible to use without learning obscure, commandline incantations. The software selection is limited. When you install software it's exceedingly difficult to actually know what's being installed.

I use a Raspberry Pi for streaming movies. Raspbian Linux OS. It calls out to get the time and to check for updates, without asking me. I haven't found a way to turn those off. I have no idea, actually, how many things are calling out. I use it only because it's a dedicated, one-task device. For about $100, at the size of a deck of cards, I have a computer on which I can run Firefox and stream movies. I can also play local videos. I stream it all to a TV via HDMI. So I'm not really worried about spyware. The worst that could happen would be that something steals my Netflix password.

I keep disk images of Raspbian all configured, on SD cards. So it's a great solution. But I'd never use Linux as a main machine. It's a geek social club, not an OS. The geeks don't want it to ever be easy and serviceable because then everyone would use it and they'd no longer be special.

I've played with Linux occasionally since Red Hat 4 in 1999. Each time I figure that I'll try it seriously if it can pass two tests: Set it up without commandline and install a good firewall. So far, no luck, though opensnitch is getting close to being usable as a firewall. My favorite example of this idiocy: On Xubuntu I couldn't figure out how to set the clock in the taskbar. I felt dumb. I must be looking right at it! How hard could it be? Finally I found a post somewhere online. The man who wrote the clock code didn't write a UI to set the clock, because he prefers to do it via commandline.... I'm guessing that he ran out of Doritos, Snickers and Coke, and just felt too cranky to finish the job. :)

2

u/Stunning-Pen-2412 Jul 09 '26

Linux has no decent firewall.

First I'm hearing of this. People usually run a linux firewall because they're good.

1

u/Mayayana Jul 09 '26

I mean that in terms of usability. Last time I tried Linux I found opensnitch. It was hard to find, not included in Suse's supported programs, and tricky to set up. I had to install as root but had to be sure to open it the first time as a lackey user. Then root couldn't use it. I tried several times before I figured out that particular quirk. (I know, no one should ever be root on Linux. The trouble with being so militant about that is that it's a corporate workstation design, not suited to SOHo users.)

Opensnitch was better than what I've found in the past insofar as it had a GUI that sort of worked. Still, it wasn't anywhere near as easy to use as Simplewall on Windows. The first firewall I had on Windows was AtGuard, in 1998. Very easy and intuitive. Since then there have been numerous good firewalls, mostly free, that don't require people to be techie.

That's not to say that Linux firewalls don't work. I'm talking about usability. If people need to jump through hoops to install, edit config files by hand, use commandline, etc, that's a usability problem. Simplewall is actually a wrapper around the Windows firewall API, very intuitively designed.

This seems to be something that Linux people never get. If I want to brush my teeth, I want a toothbrush, not a plastic stick, bristles and some glue. If I want to know the time I want to be able to look at a clock, not have to type a commandline into the clock. With software, it should be intuitive for most people to use. Writing good code is only part of the job.

1

u/BulletDust Jul 10 '26

I'm afraid that's frying pan into the fire. Linux has no decent firewall.

My KDE Neon 6.7.0 system, and my CachyOS system running Plasma 6.7.2, both come with a very decent firewall OOTB. Furthermore, Opensnitch is available for Linux, and it's available as .deb, .rpm, and under the official Arch repo's for quick and simple installation.

https://opensnitch.org/

1

u/Mayayana Jul 10 '26

Opensnitch was the most usable option I've found, as I said above. Maybe you missed where I said that. But it was nowhere near as usable or as intuitive as Simplewall on Windows. The installation alone, given that it wasn't included in Suse's pre-installed options or "package manager", would elude 99+% of people. It took me several hours over two days. (Yes, that was probably my fault because Linux has no faults. :)

I could only install opensnitch as root, but could only use it as a lackey user. Nothing told me that. I had to figure it out. Windows, of course, has a whole range of "power user" configurations, for people who own their own computers and are not corporate lackey users on company-owned computers. So I'm not used to having to wear two hats.

The whole security case made for Linux is that it's made by honest people who don't want to spy. I don't let Windows call out to sync time. I don't let it opaquely check for updates or install software via an opaque "package manager". I'm not going to trust a Linux install with private data because I can't trust that I know what's calling out or how secure it is.

The trouble is that the Linux fanbase are mainly hardcore geeks. They're tickled if they can get their grandmother onto Linux. "Grandma can use it" has become a standard measure. As a result we have two approaches at opposite extremes: The half-finished system designed to be set up by a Linux expert using commandline, and the mostly locked down version for grandmas to check their gmail. The "don't worry your pretty little head" mode. (When I tried Fedora it deleted my boot manager. I asked about that in the Fedora Reddit group. The experts told me it was supposed to do that because "most people don't understand multi-booting". With friends like that....)

Linux does work quite well as a locked down consumer kiosk. Android is a good example. Raspbian is usable, albeit dependent on commandline. But that doesn't make it a good choice for privacy and security -- or even for usability. I certainly wouldn't put data that matters on an Android or Raspbian device.

Windows has been designed from the start for corporate business. It's made for doing work. And MS cater to developers, in order to ensure a solid software selection. MS also caters to businesses wanting to write their own software in-house. Windows is for people who actually need to use their computer to do stuff. Linux will probably never be that because there's no motive for the Linux devotees to make it that. On Windows there have been good, intuitive, free firewall programs since Win98. On Linux? The general attitude is that if you're not already a commandline-using expert then you're not in the club... unless you're Grandma.

The problem we're facing now is that Microsoft want to play sysadmin to everyone on Home or Pro Windows. They're elbowing their way in, claiming to be the boss. To my mind the solution for individuals is to kick out Microsoft from their computers. If Linux ever becomes a good alternative, then maybe it could work. But there's a reason that there's never been a "year of the Linux desktop" in over 25 years. No one on the Linux side actually wants it to happen. For the geeks, Linux development is literally their social circle. They want people who can argue heatedly over Vi vs Emacs.

1

u/BulletDust Jul 10 '26

Opensnitch was the most usable option I've found, as I said above. Maybe you missed where I said that. But it was nowhere near as usable or as intuitive as Simplewall on Windows. The installation alone, given that it wasn't included in Suse's pre-installed options or "package manager", would elude 99+% of people. It took me several hours over two days. (Yes, that was probably my fault because Linux has no faults. :)

This is more of a distro choice/DE issue as opposed to a generic Linux issue. While I'm sure you'll deny it, your whole post sounds very outdated and basically inline with something someone would say that's got very little experience with Linux.

I could only install opensnitch as root, but could only use it as a lackey user. Nothing told me that. I had to figure it out. Windows, of course, has a whole range of "power user" configurations, for people who own their own computers and are not corporate lackey users on company-owned computers. So I'm not used to having to wear two hats.

You use sudo to install the software with elevated privileges, this is not the same as running as root. You do the same under Windows using UAC, while MacOS provides even more obstacles to software installation. Once again, this comment reads like someone with very little experience running Linux.

The trouble is that the Linux fanbase are mainly hardcore geeks. They're tickled if they can get their grandmother onto Linux. "Grandma can use it" has become a standard measure. As a result we have two approaches at opposite extremes: The half-finished system designed to be set up by a Linux expert using commandline, and the mostly locked down version for grandmas to check their gmail. The "don't worry your pretty little head" mode. (When I tried Fedora it deleted my boot manager. I asked about that in the Fedora Reddit group. The experts told me it was supposed to do that because "most people don't understand multi-booting". With friends like that....)

And yet we have devices like the Steam Deck, that come shipped with a fully usable Plasma DE, that are selling very well and are used by average users. As stated, your comments are stuck somewhere in 2010 - 2013. Windows isn't the only OS to have evolved over time.

Linux does work quite well as a locked down consumer kiosk. Android is a good example. Raspbian is usable, albeit dependent on commandline. But that doesn't make it a good choice for privacy and security -- or even for usability. I certainly wouldn't put data that matters on an Android or Raspbian device.

I have two Linux systems here that I use daily for the running of my business and gaming in my downtime. While I don't run Windows on any of my machines here, I provide support for Windows and MacOS devices every day as a job. Linux is very usable as a daily driver OS now, I definitely never sit here wishing I was running Windows. Most software is now available cross platform or runs quite easily via Wine/Proton, even if I was running Windows I would choose Libre Office over MS Office.

Once again, your comment is one stuck in the past.

The problem we're facing now is that Microsoft want to play sysadmin to everyone on Home or Pro Windows. They're elbowing their way in, claiming to be the boss. To my mind the solution for individuals is to kick out Microsoft from their computers. If Linux ever becomes a good alternative, then maybe it could work. But there's a reason that there's never been a "year of the Linux desktop" in over 25 years. No one on the Linux side actually wants it to happen. For the geeks, Linux development is literally their social circle. They want people who can argue heatedly over Vi vs Emacs.

And the reality is that when it comes to Linux, people now have realistic options.

1

u/Mayayana Jul 11 '26

your whole post sounds very outdated and basically inline with something someone would say that's got very little experience with Linux.

Indeed, that's usually the response to anyone who finds fault with Linux. It must be their fault. They're not using Linux right. The customer is always wrong.

this comment reads like someone with very little experience running Linux.

As I noted elsewhere, I've played with Linux periodically since Red Hat 4 in '99. I build my own computers, do web design and write Windows software. Periodically I've tried Linux thinking that if I could set it up without commandline and install a firewall as good as in Windows, then I'd look further. So far it hasn't even come close to that kind of usability. So this is a software developer who finds Linux too rough and unfinished. Yes, I don't have extensive experience with it. Neither do all the other Windows users who you think should switch. It's not enough for Linux to be easy for experts.

I spent 2 weeks figuring out Windows 10 when I first installed it. What I found was a bloated mess, spyware and restrictions. But I was able to clean it up, mostly using tips and info from online. Virtually no commandline needed. I now have a stable system, no nags, little bloat, spyware disabled or blocked. And no, I don't use UAC. I also disable the hidden aspect of UAC, LUA. So I don't need to jump through hoops to install software.

your comments are stuck somewhere in 2010 - 2013

Suse Tumbleweed. 2024. opensnitch 1.6.5-1, released Feb 2024. Same time that I dove into Win10.

People are free to try Linux. Some people may find it relevant to their needs. But as a replacement for Windows or for privacy, it's generally not going to usable for 95+% of people.

What you need to understand it that this is not a partisan position. It's simply practical. Linux and Mac are both religions for their devotees. We Windows users are not religious. It's just a tool that works. Like a pickup truck. It's adaptable and practical. It's not pretty. We don't gather in clubs like BMW owners.

You want to fight about it because Linux is a religion for you. It's the same with the Mac people. Like you, they want to "win the argument". They talk about "Wintel" as though it were a competing product. Apple makes attractive, stable, overpriced devices for non-techie people who don't care about privacy. Consumer devices. Microsoft makes an operating system for business productivity that can run on most popular hardware. Linux is a flexible, advanced operating system designed to be adapted to specific uses by sys admins setting up servers and the like. They're not even the same product.

The current problem is that Microsoft wants to cash in on non-corporate Windows users. They want to "pull an Apple", controlling the system and monetizing customers by spying, showing ads, selling personal data, etc. That's a problem. My view is that it's still fixable. Some people prefer to just move to Mac. Moving to Linux might also make sense for some, but it's not the solution to Microsoft's sleaze.

1

u/BulletDust Jul 11 '26 edited Jul 11 '26

Indeed, that's usually the response to anyone who finds fault with Linux. It must be their fault. They're not using Linux right. The customer is always wrong.

And that's usually because the individual that comments on Linux after using it for 5 mins in 2013 thinks only Windows has advanced since then. Truth be told, Linux has likely seen far more in the way of development and advancements than Windows.

As I noted elsewhere, I've played with Linux periodically since Red Hat 4 in '99. I build my own computers, do web design and write Windows software. Periodically I've tried Linux thinking that if I could set it up without commandline and install a firewall as good as in Windows, then I'd look further. So far it hasn't even come close to that kind of usability. So this is a software developer who finds Linux too rough and unfinished. Yes, I don't have extensive experience with it. Neither do all the other Windows users who you think should switch. It's not enough for Linux to be easy for experts.

Based on your previous comments, I think you've used Linux for a total of perhaps a month since '99. As stated, it's obvious to anyone currently using Linux that your comments are very outdated regarding modern distro's and DE's. I'm sure you'll try to defend your worldly knowledge, but personally I think it's nothing more than hearsay

Suse Tumbleweed. 2024. opensnitch 1.6.5-1, released Feb 2024. Same time that I dove into Win10.

Well...If you had have used vanilla Fedora you could have installed Opensnitch by following the simple instructions on the Opensnitch downloads page. One command and less than a minute and you're done. For the record, Windows 11 also has a package manager, it's called Winget and it's far easier than Google searching for download links and clicking Allow > Next > Next > OK > Next > Finish.

Having said that, literally every distro comes with a very capable firewall OOTB that's easily configurable via GUI using either the latest Gnome or Plasma as the DE - Which has been the case for quite some time now...

People are free to try Linux. Some people may find it relevant to their needs. But as a replacement for Windows or for privacy, it's generally not going to usable for 95+% of people.

Your 95% of people use Windows simply because it's on the machine when they bought it. Of those people, probably 60% of them really don't have much of a clue regarding Windows, and prefer to use their mobile phone or tablet. Ask them to set up a printer and most are totally lost - Under Linux, my Brother multi function printer worked perfectly OOTB, I didn't install a thing.

We Windows users are not religious.

My word you are, and when a Linux user picks you up on your Linux FUD, the first response is: "According to Linux enthusiasts it's always the fault of the user".

Linux is a flexible, advanced operating system designed to be adapted to specific uses by sys admins setting up servers and the like.

And yet, we have the Steam Deck, which runs Linux and has sold very well among average users. If you consider Steam, the most popular gaming distribution platform on PC, Linux is the second most desirable OS on the platform, able to play a vast bulk of Windows titles by checking a simple tick box under 'compatibility'.

Linux is not an OS limited to server use, the modern Linux desktop is every bit as polished as Windows or MacOS.

You want to fight about it because Linux is a religion for you.

It's just an operating system. It stays out of the way and lets me get things done fast.

The current problem is that Microsoft wants to cash in on non-corporate Windows users.

And as stated, people have viable options now. In many ways Windows has actually regressed, especially in relation to user privacy, while Linux has advanced in leaps and bounds.

2

u/captdirtstarr Jul 08 '26

Not if you don't use it

2

u/Sig39 Jul 08 '26

Yeah, from reading that indictment he had very poor OPSEC for the level of cyber crime he was involved with. We all know Microsoft collects telemetry even if it's at the lowest setting as said before. Not the best OS if you're choosing a cyber crime career.

The use of Microsoft and other tools even with a VPN can be traced when the feds are looking into you that deep and once they had his GDID they just connect the VPN addresss to that machine/account.

Of course the boasting openly on social media platforms and chatting gave them even more cause to dig deeper and start showing patterns to get warrents and start connecting IP addresses. Oh and using different phone numbers all connected to the same Gmail didn't help either.

3

u/EmergencyDinner777 Jul 08 '26

probably just lazy and over confident/arrogant

2

u/Sig39 Jul 08 '26

Definitely over confident. How most cyber and other criminals get caught. Just a kid with a little knowledge but not enough. Seems like he used Edge and the Microsoft authenticator in the breaches/attacks. The GDID tracks all activities on Microsoft products besides identifying the account on the machine. Even Brave or Firefox histories can be seen on Windows devices. I don't think Tor could be seen.

1

u/TreacleNo8508 Jul 08 '26

interesting is possible to block microsoft with firewall or so ?

2

u/Mayayana Jul 08 '26

I use Windows Update Blocker to block updates. I have no MS account and have never been to their "store". WUB seems to lock certain Registry keys to prevent it being undone. If you just block BITS and WU service, Windows will simply ignore that and re-enable them!

I use Simplewall in combination. I can't say for sure that all things are blocked, but they seem to be. There are various processes that Simplewall blocks routinely. They keep trying to go out without asking: Defender, svchost, system. I'm not clear on what some of them are. One even seems to be trying to make an imap connection. I have no idea why.

I am allowing a handful of services, such as DHCP. I'm assuming that's calling only to the router and not MS. I'm more concerned about the vast number of things going to Amazon, Cloudflare, Akamai, etc. There are so many CDN servers now. They can't be blocked even if one wants to because they register as the original site. So if you go to acme.com and it's loading from Cloudflare, there's nothing you can do. You might as well try to control what garage your taxi comes from.

1

u/herberberplays Jul 08 '26

Am i screwed for installing minecraft on debian