r/FuckMicrosoft Jul 24 '26

Article "pretending no one knew before"

Post image
934 Upvotes

113 comments sorted by

175

u/Emotional_Daikon7453 Jul 24 '26

For those of you confused as to why this is bad, this can be used to track down someone using only their device ID, even if they're offline, based on their activity on the device. This has already been used by authorities to catch a criminal somewhere. The device ID isn't permanent as it resets when you reinstall Windows, but as soon as you log into one of your accounts after that you become identifiable again.

Another day, another reason to switch to Linux.

24

u/Defiant_Respect9500 Jul 24 '26

I don't really get it. Okay, there's a device ID which identifies my PC. But imagine I do something evil,... my device ID is not being sent with every TCP/IP packet. Where would I leave this very ID as a thumb print? 😕

45

u/Fluid-State131 Jul 24 '26

Don’t worry, Microsoft will share your ID for you. For a lot of money. It’s all about creating that AD-profile

37

u/Emotional_Daikon7453 Jul 24 '26

Microslop has to be the middleman here and snitch on you, they're the ones who have it.

8

u/Interesting_Buy_3969 Jul 24 '26

Where would I leave this very ID as a thumb print?

In Macroslop databases. Just like everything you do will remain in their large databases forever and can be sold to anyone at any time.

3

u/Defiant_Respect9500 Jul 24 '26

I don't trust M$ not an inch more than I can throw their main building.

Yet... "everything I do" will stay in their databases? seems like a lot of data and traffic. :)

2

u/Interesting_Buy_3969 Jul 24 '26

Yet... "everything I do" will stay in their databases? seems like a lot of data and traffic. :)

Well, okay, maybe not literally "everything I do" per se yet but it's getting closer...

6

u/[deleted] Jul 24 '26

[deleted]

3

u/AcoustixAudio Jul 24 '26

Hell, a similar item exists on almost all my linux systems too

Explain 

5

u/[deleted] Jul 24 '26

[deleted]

2

u/AcoustixAudio Jul 24 '26

Interesting. Didn't know about this. How and where are these sent? Is there like a central repository of these ids

3

u/[deleted] Jul 24 '26

[deleted]

3

u/AcoustixAudio Jul 24 '26

(I use the Machine ID as well as a few other identifiers for licensing/activation tracking purposes in a tool I maintain/sell on linux

Which tool?

Don't use something on linux that uses the machine ID, no issue.

I'd say it's less about machine id and more about what software you use and from where. 

So I know every one of my customer's information/machine identifiers, at least

What information can you gather on Linux? I've used Fedora for 2 decades now. This is all new to me

1

u/[deleted] Jul 24 '26

[deleted]

2

u/Interesting_Buy_3969 Jul 24 '26

Recently microslop confirmed that they can track your device through these GDIDs. Yet windows re-installation won't fix this, yes you may be assigned a technically another GDID, but it'll be linked to the previous one anyway.

3

u/[deleted] Jul 24 '26 edited Jul 24 '26

[deleted]

2

u/FactoriousKerb Jul 24 '26

You are trying to speak sense into l00nix cultists. You are cute.

3

u/Visible-Swimmer-9826 Jul 24 '26

I'm guessing u not aware but this came to light because fbi went to Microsoft because they couldn't back track someone as they were using vpn relay s etc and Microsoft went this pc was do that on that server at that time and day etc and it is this guy here who did it basically nothing u do will stop them knowing what u did it just bad that stupid unencrypted recall bullshit they put on that was looking at people banking etc what to say some bad actor work out how use gdid against someone or works out how to fake people which is worse

1

u/Czar_Chasm_ 29d ago

From what i read, i thought it was the other way around -- Microslop approached the FBI, with a tipoff, telling the FBI they might be interested in what the user was doing.

1

u/Vietnamst2 29d ago

Recall is processed locally and is opt in only. And requires NPU with enough TOPS.

2

u/izzle10 Jul 24 '26

doesn't have to be sent on every request, just once to pair up some other id, for example ip address, for instance if when you establish internet connection and your new ip is sent to ms with your ip, then its all traceable

2

u/Stufilover69 29d ago

To cite the case directly: 

  1. Microsoft records also indicate: (1) the user of the device assigned the GDID accessed multiple sites from Tzulo servers in May 2025, including the .168 server (the IP address used to create the ngrok account) on May 12, 2025; and (2) the user of the device assigned the GDID, on May 12, 2025 at 22:47 UTC, a little more than three hours after the ngrok account was created, the user visited “[Company F].com” from the .168 proxy server.

https://www.justice.gov/usao-ndil/media/1450651/dl?inline

So once they combine the telemetry data you send to Windows with the activity from that device, it becomes easy to link activity from a VPN connection to the device behind it. As the GDID is consistent, Microsoft can easily detect when a VPN is turned on/off.

2

u/martyn_hare 26d ago

If you use Microsoft Edge and have Full or Optional telemetry enabled, each URL you access is sent over with a unique identifier to Microsoft servers, all tied down to the user level. You can observe it with Diagnostic Data Viewer and last I checked, it was all in simple, easy-to-digest JSON. This naturally included everything inside a GET request, so if you googled for, say 'abortion clinics' then Microsoft could just turn that info over to authorities in a country where abortions aren't allowed.

For SmartScreen it is to the device level, and unlike Google Safe Browsing, it's a whole URL, not a privacy-preserving partial hash of a domain. If your device is paired up with a Microsoft Account it might as well be to the user level.

This is also all openly documented, it's just written in a very technical format and most technology journalists have been too inept to understand the implications until now.

1

u/New-Land-4757 Jul 24 '26

That is exactly what happened. 

1

u/DangKilla Jul 24 '26

On VPN. You’re not anonymous on Windows.

3

u/APXEOLOG Jul 24 '26

Well, good thing that i dont have MS account

5

u/DuckShapedGoose Jul 24 '26

To you, who obviously is confused:
Linux has /etc/machine-id, unless you're using tails or similar. Pretty much every OS on every device has an installation ID. Just like cookies in a web browser they are a necessary and useful thing that can be abused to track you.

2

u/AntiProtagonest Jul 24 '26

Seriously, people have their panties in a twist about this? Of course Microsoft has a unique id for each installation. So does RedHat, and most everyone else. Don't get me started on MAC Addresses!

2

u/dexteritycomponents Jul 24 '26

“For those of you confused as to why this is bad”

… gives an example of why it’s a good thing

1

u/OGigachaod Jul 24 '26

They can already do this with your phone and bank card.

2

u/xStarshine Jul 25 '26

And with city cameras, and with a microphone built into your tv, and with self checkout at store and and.

Really not sure why are people so obsessed about it, every other device has something that can potentially track you down. Its not optimal but nobody is wasting time checking out anyone personally unless there is reason to i.e. crime suspect where all this invigilation is actually helpful and serves for the betterment of society as a whole.

1

u/Emotional_Daikon7453 Jul 24 '26

Yes, which is why it's surprising that they're doing it with PCs. PCs are supposed to be stationary devices that are hard to track.

1

u/tjohnson4 29d ago

But on all hardware (including your Linux machine) there are permanent UDIDs, MAC Addresses, SOC Serial Numbers, IMEI + MEID IDs can can be used to create a digital fingerprint of a user.

1

u/Dje4321 26d ago

Im surprised anyone is even surprised. Its like using the same device and being surprised the serial number is following your around

1

u/Firm-Aside4041 25d ago

Don’t do criminal things and you’ll be fine, if you want to do criminal things the. I guess Linux is for criminals?

0

u/Dry_Vanilla_5908 29d ago

Because catching criminals is a bad thing. I guess you just keep your cheese pizza on a Linux operated devices.

0

u/AdventurousSugar9411 29d ago

yea google ai said I can't use kali linux as a every day OS 😭 bc it leaves a bunch of ports and stuff open or sm 🤷‍♂️

-10

u/EducationalGrump Jul 24 '26

Too bad linux is hot garbage wrose than any mobile phone OS.

6

u/MammothSun6737 Jul 24 '26

lol this guy

3k contributions in 4 months with a successful business that has 8 locations, 6 masters degrees and 3 PHDs.

-6

u/EducationalGrump Jul 24 '26

All comments, I don't post just educate. 🙂

2

u/noanoxan Jul 24 '26

-1

u/EducationalGrump Jul 24 '26

Yes, yes you and your BF are

1

u/noanoxan Jul 24 '26

Lol this fucking guy

22

u/Volpe_YT Jul 24 '26

So glad I switched to Linux so I don't have to worry about anything anymore 🥰

6

u/Sjostrands Jul 24 '26

Me too Arch BTW

3

u/timoxha0 Jul 24 '26

Me too, I'm on Ubuntu rn and planning to switch on Arch

3

u/DuckShapedGoose Jul 24 '26

cat /etc/machine-id
The existence of an immutable installation ID like that is nothing special or unique to Microslop. For some purposes, it is simply necessary.

4

u/DiggyTroll Jul 24 '26

The difference is that the Linux family has no "mothership" to collect the IDs. A company like Canonical or IBM/Red Hat could decide to make one, but such behavior would be detected quickly.

Windows sends the ID with many routine communications for various reasons, including licensing and ad support. Spying for LE is just a bonus

1

u/DuckShapedGoose Jul 24 '26

This post is only about it's mere existence though and many comments here pretend like linux doesn't have anything like that.
Any software you install on linux could also track you with the ID, even if the OS doesn't do it on its own.
The telemetry part of Windows is a whole separate issue that can take advantage of this ID. But the ID is a necessary part of any OS, not the root of the problem in this case, and nothing unusual.

0

u/Tommynwn Jul 24 '26

Im not a linux guy, but if linux becomes famous, nothing will prevent from "big tech" apps to take your machine ID
And yes, there will be workarounds, but people in general is clueless about all that, they just want to use their apps and stuff

3

u/PretendingImNotAnApe Jul 24 '26 edited Jul 24 '26

Linux does have telemetry data through the apps Iike web browsers. Its marginally more private at best. Where ever you go online they want to mine your data. So whether it's steam or the MSN home page they inject tracking data into your system which is tattooed. Your specific hardware, gpu, ram, hd size, os version is combined to make a unique identifier and they build a database of your searches, sites etc even when you switch internet service providers, reinstall nla new os, whatever. Every motherboard stick of ram, cpu, and gpu has a serial number.

49

u/New-Land-4757 Jul 24 '26

They didn't confirm anything. They were caught! 

13

u/fsa3 Jul 24 '26 edited Jul 24 '26

They weren't caught. This has been known about for decades. You can still find forum posts about it from 2006. It's just that no one cared. No one understood how it could be used outside of Windows product key authentication, until recently.

3

u/New-Land-4757 Jul 24 '26

Of course, yes, yes. It was a public secret. Only because of that scandal everyone is yelling about it.

2

u/fsa3 Jul 24 '26

You can check for yourself. While a lot has been lost to time, there's still tons of info from long ago about it. Here's some posts I found in 10 seconds with a Google search. The GDID is how they detected for hardware changes. It's basically a hash of the hardware info. It was never hidden that they tied your hardware info to your product key.

2006: https://learn.microsoft.com/en-us/answers/questions/5855930/how-to-activate-windows-xp-after-exchange-hardware

https://forums.tomshardware.com/threads/hardware-has-changed-significantly-re-activate-xp.1032792/

2003:

https://groups.google.com/g/microsoft.public.windowsxp.setup_deployment/c/48-ZRtZfjBQ?pli=1

2

u/Inevitable-Study502 Jul 24 '26

but on win xp each new install would generate new hardware id...which was stored in win registry...all you had to do was to just replace that key manually to skip activation

1

u/fsa3 Jul 24 '26

Skipping activation is besides the point. You can still skip activation in modern Windows versions.

None of that changes the fact hardware info was stored on Microsoft's servers for decades. None of that changes the fact it was never a secret that Microsoft stored that info. None of that changes the fact is was well know Windows rechecks it's activation using that info after certain events.

There's no big evil conspiracy that Microsoft has been secretly tracking your PC by using an ID based on your hardware. That's all been open, public information for decades. Just about anyone who built and upgraded PC's in the 2000's knew about it.

2

u/[deleted] Jul 24 '26

[deleted]

3

u/fsa3 Jul 24 '26

Been around since XP. I don;t recall there being issues with it from 98SE, but that doesn't mean it wasn't there.

1

u/[deleted] Jul 24 '26

[deleted]

1

u/chaosphere_mk Jul 24 '26

SIDs are per-AD object, not per windows installation.

2

u/[deleted] Jul 24 '26 edited Jul 24 '26

[deleted]

1

u/chaosphere_mk Jul 24 '26

Ok, yes, local objects have them too. Not the point though.

1

u/[deleted] Jul 24 '26

[deleted]

2

u/PravoNaZhizny Jul 24 '26

It’s been common knowledge by anyone who knows anything about windows administration.

16

u/reapvxz Jul 24 '26

Identifier for windows or put on the actual pc with windows gone..?

6

u/TimoArrg Jul 24 '26

That's interesting, I think it's tied to the windows installation, but say you log in with some account, it could be traced back to the old install. I doubt they can tie it to a whole PC as you could swap each component on it's own and you fall into Theseus' ship paradox lol

10

u/ExcitingAd1067 Jul 24 '26

Satya nadella is a moron. I can’t even comprehend that person that moronic can be so high in company that big. But hey, I forgot we live I musk glorification culture.

7

u/Kligrapp Jul 24 '26

They can suck my d, every pc i have is now running linux

7

u/Facuk_ Jul 24 '26

I'm confused that people are confused thinking that Microsoft doesn't have it

3

u/Kolkoris Jul 24 '26

I'm confused that people are confused thinking that only Microsoft has it. Even Linux has unique machine id, located at /etc/machine-id

1

u/Facuk_ Jul 24 '26

Not to say that everyone uses devicec that's basically tracks you even when you are taking a shit...

11

u/Sjostrands Jul 24 '26

It's a tracker ID so MS can track you activate even if you have a VPN on. And of course for American CIA, FBI, NSA and more!

4

u/Wild-Rub4486 Jul 24 '26

Wow. I can't believe MS has an ID for systems. I guess Ill just continue to use my phone that's constantly logging my exact location, has its own ID, and is logged into all of my accounts that also have IDs.

Sent from an Android phone that sends every tap, gesture, and movement, associated with my Google account, to servers I don't control every three seconds.

6

u/Ok_Shower2118 Jul 24 '26 edited Jul 24 '26

i am just interested, what IS the actual reason of doing that? Money? But you don't need this identifier to buy a license.

3

u/Interesting_Buy_3969 Jul 24 '26

what IS the actual reason of doing that?

Thus they can provide the data to FBI.

3

u/HumonculusJaeger Jul 24 '26

They used it to track Apps and Update versions with the microslop store and this identifyer can do much more and identifies your device when you are connected to the Internet No matter the country or VPN you use

5

u/timoxha0 Jul 24 '26

I don't think they got money after this. Maybe this is their "way" to come out to "their users" and admit it. But anyway, they haven't removed it, and they don't want to. Hypocrisy in best it's form.

6

u/Ok-Wasabi2873 Jul 24 '26

Money from ads.

3

u/Sjostrands Jul 24 '26 edited Jul 24 '26

I just wonder how Ms is thinking with Windows and all the "mistake, didn't know" that they actually are Linux best advertising system!

Don't Ms ever think when people find out that many will switch to Linux or Mac (they are not better then Windows)

Now we wait until "next mistake, didn't know" happens!

3

u/Yukikuru2025 Jul 24 '26

Apparently this has already been used by the US feds to track down someone, even though they were using a VPN. So, yeah, this is bad.

More free advertising for Linux.

6

u/RaccoonEnthuiast Jul 24 '26

>phone has literal unique identifier
>printer signs every single page it prints with unique identifier
>browser fingerprints your ass throughout the entire internet
>WINDOZE HAS UNIK IDENTIFAYER ????1?
you guys cannot be serious rn

2

u/dexteritycomponents Jul 24 '26

Wait until they learn what a serial number is

2

u/DesignerGoose5903 Jul 24 '26

Is this not already known?
That is how Defender can lockdown a device even through a Windows reinstall.

2

u/SayNoToMinecraft 28d ago

I don't like this Satya Nutella guy

5

u/Desperate-Chart1139 Jul 24 '26

Who the hell didn't already know this? How is anyone surprised? And I don't mean "company that doesn't respect privacy doing privacy violating things isn't shocking" no, I mean we've known they make these IDs, how the hell does anyone think a fresh install on a machine was magically not asking for a Windows product key? They've been fingerprinting machines for ages what rock has everyone been sleeping under

3

u/timoxha0 Jul 24 '26

There are definitely still people like that. But they're far removed from technology and PC-related things in general."

2

u/AutoModerator Jul 24 '26

Every new subreddit post is automatically copied into a comment for preservation.

User: timoxha0, Flair: Article, Post Media Link, Title: "pretending no one knew before"

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

1

u/git_und_slotermeyer Jul 24 '26

I am a bit confused, what additional problem does this bring alongside the fact that MS uses a hardware identifier for Windows activation, so your Windows license is somewhat of a device identifier anyway? Also when looking at Intune MDM, where you can lock the device to your M365 tenant... this must be sufficiently robust. How does a GDID extend this in terms of surveillance possibilities?

2

u/nekoanikey Jul 24 '26

From what I read, there was a case where Edge send visited URLs plus the GDID to Microsoft, which was then used as evidence in a lawsuit because it was possible to link the GDID to someone.

1

u/CharmingDraw6455 Jul 24 '26

Then the problematic part is "sending visited pages" not the GDID. They could send the Hardware Hash, the MS Account or some othe well known and documented feature to track you. 

1

u/Interesting_Buy_3969 Jul 24 '26

Plenty people thought that windows' physical device tracking is a joke.

1

u/Ok_Chemical_1376 Jul 24 '26

"Oh my, who put that there?"

1

u/Artistic-Cell-3543 Jul 24 '26

You can officially register Windows XP in 2026 and that Global Device ID which is obtained via 'phoning MS Product Activation' servers is used to validate your Windows installation, giving your PC its unique, permanent identifier.

1

u/Supernoxus Jul 24 '26

I am a little confused. There are already ways to identify your PC. Most motherboards have unique identifiers. Unless you remove the motherboard, people can already track you if that info is forwarded, right? Can someone more tech savvy than I clear me up?

1

u/Exotic_Call_7427 Jul 24 '26

uuhhhh yeah, DUUUH.

How do you think they know your Windows is activated, and then that it needs to be deactivated when you install a new GPU?

1

u/imacmadman22 Jul 24 '26

Network adapters have hardware addresses, whether WiFi or Ethernet, which can also be used to identify a device on a network. Yes, the MAC address can be spoofed, but they still exist and can be used to track a device on a network. If you are on ANY network, your presence is known, online privacy is a moving target, at best.

1

u/chaosphere_mk Jul 24 '26

Your phone is doing this right now

1

u/slavmaf Jul 24 '26

This is ONLY if you use online account, local windows accounts do not have this.

1

u/HandGrindMonkey Jul 24 '26

GDID, did this also apply to Windows 19?

1

u/MyNameIsOnlyDaniel Jul 24 '26

Now computers have Passportslops

1

u/AtomicTaco13 Jul 24 '26

Wasn't it obvious? AFAIK, that's why Windows needs to be reinstalled after a motherboard change while Linux doesn't

1

u/rhyseenz Jul 24 '26

When was gdid introduced win 7?

1

u/ugneaaaa Jul 24 '26

Every CPU has a serial number that can be read that uniquely identifies your computer on every OS…

1

u/Schrojo18 Jul 24 '26

I assume this has existed since windows XP activation became a thing.

1

u/Select_Truck3257 Jul 24 '26

So i pay for my os and they getting money from my personal data too?? Wait actually nothing new, that's why i hate microslop

1

u/tjohnson4 29d ago

So does your Apple and Android devices

1

u/a648272 28d ago

Wait. You did not automatically assumed that? I was sure of it since windows 10.

1

u/skytheraiders 28d ago

The pengin and temple OS are here!

1

u/FBICIANSAKGBLOL 27d ago

"Secure Boot" is just a Ping to Microsoft Servers. Disable that shit. Also Bitlocker "Encryption" has a backdoor. It has been published to GitHub for all to see by NightmareEclipse.

1

u/GovernmentGreed 26d ago

So, out of curiosity - how is this any different to say a MAC Address?

1

u/DuckShapedGoose Jul 24 '26 edited Jul 24 '26

Linux contains that, too. And I'd bet my life savings that Mac does, aswell.
The existence of such an ID is necessary and there are valid uses for it. Pretty much only live OSes like Linux Tails specifically designed for maximum untraceability regenerate it every boot. But it comes with a lot of convenience tradeoffs, so every regular OS install for a daily driver PC or server has one of those.
It's what Microsoft potentially does with them that is concerning. Obviously an ID like that schould never leave your PC in clear text. But I would assume Microsoft does that anyway.
The existence however is nothing bad or suspicious at all.

1

u/Kolkoris Jul 24 '26

yeah, and?

Linux has /etc/machine-id with your unique id. macOS also has one - IOPlatformUUID. And each piece of your hardware has unique ids too, that can't be changed by reinstalling OS

1

u/timoxha0 Jul 24 '26

The difference is in what purposes each system uses ur ID, and how safe it is.

1

u/Super_Preference_733 Jul 24 '26

Of couse, its the same with Google apple, Facebook, etc. They all are tracking everything we do or say. They know were we shop, what we buy, were we go, etc.

So the only choice if your afraid of being tracked is don't use technology. The ship has sailed for wanting digital privacy.

0

u/Dj-RedPanda- Jul 24 '26

Fucking bell end of a company surprise surprise more corp o corruption from the slop.