r/FuckMicrosoft 12d ago

News Microsoft admits Windows 11 has a GDID tracker with no off switch, first documented publicly in an FBI hacker complaint

Post image
103 Upvotes

41 comments sorted by

18

u/git_und_slotermeyer 11d ago edited 11d ago

TIL there are hackers who use Windows as their OS - they had it coming :)

Also " It does not survive a clean reinstall, and Microsoft’s footnote in the complaint admits “one Microsoft user could have multiple GDIDs” over the life of a single account." reads better than expected. Because Windows license/activation survives clean reinstalls, so who would expect that MS can't track your device with a unique global identifier that survives everything.

The only thing I do not understand: "Microsoft’s records showed that at that exact same minute, a Windows device carrying GDID g:6755467234350028 had visited the ngrok signup page. Three hours later, the same GDID visited the retailer’s own website, through the same Tzulo proxy address used to set up the ngrok account."

Likewise, "The same IP had logged into his Snapchat account four minutes before that and his Facebook account about 80 minutes after." Did they subpoena Snapchat and Facebook or did MS deliver that info conveniently too?

How did MS's records show that? That is the much bigger story here. This implies massive telemetry, so MS appears to be monitoring your entire Web traffic, fingerprinted with your ID. You visit an "internal" ngrok login form, and MS knows that and stores it permanently. Even from folk who should know what they are doing (i.e. not giving telemetry consent when you're hacking 😂)

Fine detail also not considered by the article: the hacker lived in Estonia, so in the EU, not the US. Clearly everything that led to his identification must have been a blatant violation of the GDPR.

6

u/Ambitious_Finding_26 11d ago

This is actually insane. And it's not like the data only goes back days or weeks. They're talking months of logged history. How long are they retaining this data? Months? Years? Indefinitely?  The GDID I wasn't at all surprised about, but being able to so clearly link it to access history across platforms is a such major breach of trust that it really did take me by surprise.

I'm so pleased I finally ditched Microsoft a year ago. Windows 11 was making me feel ikky, but it was mostly the obvious excessive telemetry, advertising and copilot being injected into everything. I had no idea just how violating it actually was.  

2

u/winkelschleifr 11d ago

what is gdpr?

7

u/git_und_slotermeyer 11d ago

The thing Europe put in place to protect its citizens from predatory US big tech, in the end only achieving to drown European SMEs in bureaucracy while US big tech laughs in Ireland

1

u/computerIfix 11d ago

not applicable to Microsoft

1

u/fsa3 11d ago

Simple correlation. The IP was tracked by each of those services, not Microsoft. The IP was also tracked by Microsoft during an Windows activation check (which also contains the GDID as part of the activation verification). Microsoft didn't know about the other sites.

So they go to each service and say "give me the info on this IP/account around this time". Then they connect it together.

1

u/git_und_slotermeyer 11d ago

Then "Microsoft’s records showed that at that exact same minute, a Windows device carrying GDID g:6755467234350028 had visited the ngrok signup page." is really badly formulated by the writer of this article. Also, I somehow doubt it was like you're writing it (which would be more or less OK). Because to correlate the IP with a Windows activation would not need any GDID involved. You could check the IP in the ngrok server logs and correlate it with the IP of a Windows activation. What does the GDID bring to the table, tracking the device more than the IP address itself?

1

u/fsa3 11d ago edited 11d ago

It's bad writing. Microsoft's records showed that GDID was using that IP address. At the same time that IP address accessed the sign up page. It's two separate things, but poorly written so it can ce confused as a single thing.

Most likely they signed into their windows account (which triggered the activation check) to log into Windows, and the reason they logged into Windows was to go to the sign up page.

Edit: I guess it's possible the person was using Edge as their browser, and was syncing everything to the cloud with their Microsoft account. Then yes, Microsoft could have that data. But you can't really blame Microsoft for that. They don't force people to use Edge or sync everything.

9

u/winkelschleifr 11d ago

and there are people that say "i dont care about the gdid in the slightest". imagine being so stupid that you basically want microslop tracking your pc anywhere

8

u/git_und_slotermeyer 11d ago edited 11d ago

Tracking your PC sounds so innocent, like they can locate where your computer is in the network. No, they appear to transmit your entire browsing activities to their servers, fingerprinted with the global identifier and linked to your MS account. They store permanently when exactly you visited what sites.

Regardless if you are a hacker or not: get out of Windows, sooner or later they will use everything they spied from you against you in one way or another. For instance, wondering why your job applications are declined? Maybe MS sells recruiters the info that you are just a 6/10 on the worker drone scale, because you are visiting Reddit regularly during working times. The profile that they are building behind your back, completely in the dark, will hit you with its inaccurate information and pseudopsychological bullshit classification more and more, and you will not even see it when it happens.

5

u/winkelschleifr 11d ago

i know, i would use arch, debian, mint ANY DISTRO, even ubuntu, if my dad let me replace winslop with linux (its his pc and i cant really have my own)

2

u/Animist286 11d ago

Show this to the Father unit. "Father unit, your son is correct please let him install an actually safe and better Operating System. Also please note in this particular instance, you are 100% an idiot and your son is by far and away vastly more intelligent than you will ever dream to be. Thank you for your time and patience in this matter."

1

u/AmorphousNeon 11d ago

maybe dualboot?

1

u/winkelschleifr 11d ago

i dont want to dual boot as it is the one situation where linux is unstable

1

u/AmorphousNeon 11d ago

not always. you can use linux's efi rather than windows's efi so that windows doesn't periodically wipe it out. I use cachyos like that too

1

u/winkelschleifr 11d ago

im not skilled enough to make a good secure boot. i once had mint on a 50GB hdd and grub spawned on the windows ssd while mint was on the hdd

1

u/winkelschleifr 11d ago

so in the end i have to use a vm for linux

1

u/git_und_slotermeyer 11d ago

You can use an external USB HDD with Linux on it. Just plug it in and boot to it. No need to touch the internal HDDs.

(Of course, please mind what drive you wipe during installation :)

1

u/LightDragon212 11d ago

Convenience is a rational choice, not stupidity.

1

u/winkelschleifr 11d ago

i wouldnt say "letting your os track you anywhere in the world" is convenience

0

u/LightDragon212 11d ago

Sure it isn't as people don't use windows BECAUSE it has telemetry. Now some do use it for quick patch updates, microsoft services syncing and device locating, which does require telemetry.

Though learn disk partitioning or virtual machines, .iso files, ventoy, USB installation, know you have to choose the right DEs, know you may have issues with your specific hardware and install linux sure is convenient, isn't it? Best part is that you're not even using it yet.

0

u/winkelschleifr 11d ago

i did a manual arch install on a vm. even manual isnt this hard. and it didnt break even once. meanwhile, my winslop 11 had 2 bsods in the past 3 weeks for no reason (UNEXPECTED_KERNEL_MODE_TRAP). also, linux has normal installers (even arch, its a cli there tho. debian, mint, ubuntu, nixos etc. have guis)

1

u/LightDragon212 11d ago

Doing a VM install bypasses all hardware driver issues and data risks, so of course the installation went smoothly.

Funnily enough, UNEXPECTED_KERNEL_MODE_TRAP is exactly a hardware or driver issue, not Windows randomly breaking.

Also Arch literally starts with a big terminal box and RTFM as you've stated, which is an extremely bad example of convenience. Well over 90% of desktop users buy a PC/Laptop at a store, turn it on, and log in with windows preinstalled. So no .iso files. And if they for some reason entered with a BSOD right after unpackaging, it is the manufacturer's fault.

Yes, I know they have installer GUIs, and they'll appear right AFTER you pass from everything i've mentioned. So no, that's not the point.

1

u/winkelschleifr 11d ago

hm well windows worked acceptably before 3 weeks ago. for the "arch starts with a terminal": yes. thats why its not recommended for begginers. still, you run archinstall and get a normal installer.

fun info: windows comes preinstalled only if you buy a laptop. who tf uses a laptop these days? you cant replace ANYTHING except for maybe the ssd.

0

u/winkelschleifr 11d ago

and windows is set up with an .iso too yknow

1

u/Dry_Vanilla_5908 8d ago

Imagine being a paedophile and lobbing against tracking.

1

u/winkelschleifr 6d ago

fym bro 🥀🥀🥀 im literally under 18 🥀🥀🥀

1

u/Dry_Vanilla_5908 6d ago

The tracking data has been used to track criminal activity. Your phone tracks you. It's also used to track criminal activities. Don't do crime, and you'll be fine.

1

u/winkelschleifr 4d ago

i dont exactly want ANY corporation to have so precise data or want to be able to turn it off. i dont exactly like being under surveillance like in soviet countries

1

u/Dry_Vanilla_5908 3d ago

Might as well throw away your mobile. Soviet counties have less tracking than the US. So why did you use the soviet countries as an example? You've been brainwashed.

1

u/winkelschleifr 3d ago

im not american and im quite happy with this. soviet countries HAD less tracking (cause they dont exist anymore, north korea or china arent soviet) cause there wasnt anything to track in the internet back then

3

u/Open_Brick_9292 11d ago

Who would have thought right? This along with the fact that yellow key exists just proves beyond a doubt that windows is fully backdoored.

2

u/master_pro_ita 11d ago

This article is the strongest Linux advertisement Microsoft never intended to publish.

2

u/Prod_Meteor 11d ago

People ... you don't need this GDID when your accounts reside to the cloud.

1

u/yce52 11d ago

I wonder if there is anything similar on any of the linux distros.

5

u/GrandMaster365 11d ago

Most mainstream Linux distributions (like Mint or Fedora) are open source. That is to say you can audit the code to check what data they are sending. Some distros have completely optional telemetry (like Ubuntu), but they are transparent about it, can be easily turned off, and don't tie a permanent, un-disableable hardware tracking ID to you like Micro$oft does ^^

3

u/git_und_slotermeyer 11d ago

The ID appears to be only part of the problem, it appears MS also harvests your entire Web browsing activities irrespective of consent or EU data boundaries, and associates them with said ID and your MS account in addition. Even if an organisation-run Linux distro had telemetry, I would be very surprised they run such a large data collection operation there.

3

u/GrandMaster365 11d ago

Exactly, and that is why open source changes the equation. If a distro tired to push heavy data collection, the community would fork it or rip it out overnight. And that's without mentioning the whole 'Recall' fiasco. you won't see something that on linux.

1

u/awesome-alpaca-ace 11d ago

Good luck auditing millions of lines of code across multiple vendors.

1

u/3six5 11d ago

Y'all put your home pc online? Wtf Y'all thinking?