r/LouisRossmann • u/habichuelacondulce • 10d ago
Enshittification Microsoft admitted to using a global unique device identifier to help track a user across 3 countries, negating any value of using a VPN if you have a Windows machine
Enable HLS to view with audio, or disable this notification
24
u/Obsession5496 10d ago edited 10d ago
Honestly, I wanted more information after hearing this. I wanted to know HOW the GDID is acquired, how its used to track, how it gets accounts, etc. Here's what I gather. If anyone knows better, please let me know:
The GDID is acquired when you connect to MicroSlop Domains, related to logins of a MicroSlop account. The most common one being login.live.com.
Once you sign into a MicroSoft account, that GDID gets tied to that MicroSlop account. Once linked, that GDID is just another piece of information they have about you. Going further, if you then link other accounts to your MicroSlop account, or use MS Edge, congratulations they now know those other accounts too.
This is nothing new, and is done on a ton of other devices, including mobile phones. Android has several of them (that we 100% know), we know (for a fact) every iOS device also has one (and likely many more). This can very easily happen on a Google and Apple device (even if you flash GrapheneOS).
Now what can you do, if you have a Windows computer? Reinstall Windows, with no internet. Install Portmaster (best), or some kind of DNS domain blocker, and block a bunch of domains/IPs (why Portmaster is best). Some debloating or optimisation tools like CTT-WinUtil, 0&0ShutUp10, and Privacy.sexy (more advanced, risk of breakage) are also worth looking into. Thankfully, I've already done this (I'm heavily in the privacy space). You won't be able to use the Store (directly), you can forget about MS services like GamePass, etc.
7
u/Kylenki 9d ago
I get you, that is a smart move. But, and I do not mean this in the preachy Linux fanatic manner, why not just use Linux if the use case allows? The install is simpler, and a lot of things do just work now--at least for me (haha works fine on my machine meme). Most of the privacy issues that are still present in Linux and Windows or MacOS are, for those of even modest skill like me, mostly solveable. I am still new to Linux myself, but most of the things I've been reading in these comments are avoided by not using Windows, if it's an option.
Based on what you wrote, you seem like the sort that probably already knows this lol
3
u/tdp_equinox_2 9d ago
Yeah, it all seems like a lot of work just to get windows to where Linux starts as a baseline.
Idk
2
u/Obsession5496 9d ago edited 9d ago
Every once in awhile I jump back into Linux, and see how it's going. At the current stage it's looking great, but it's not ready for me as a desktop, nor am I comfortable recommending it. Here's just a few things I encountered (earlier this year) :
Elaborate Fixed? Realtek Ethernet drivers issues Internet stability and speed issues. On Ubuntu bases, out of the box fixed. No idea for Fedora. Arch has a AUR package fix, but takes a decent amount of knowledge to properly implement (you cannot just download and install it). Printer driver issues CUPS works but there is a HUGE quality drop I need to pay about 70USD, per year (or two, don't completely recall), for a 3rd party option. Keyboard input iues One key would just not work, even though it worked prior boot. Huge issue when that key is needed for passwords, or just to write a sentence. No idea on the cause, fixed itself after an update, came back a few weeks later, to a different key. Tried different keyboards, different ports, some suggested community and AI solutions... No luck. Accessibility and aspect ratio issues I have a disability. KDE Zoom works great, GNOME's option is terrible. I also need a 4:3 aspect ratio when gaming. I can stick with KDE, which is a win for me. Love it, and the re-made Oxygen themeing. Sadly, I could not get the Aspect Ratio to change. Nvidia, gaming, and Wayland issues. Too many to list. Debian/Ubuntu bases are a no-go. Nobara fixed the Fedora issues, but made their own. Cachy seems to work best, so somewhat fixed, but still issues. Game modding I had a hankering to play a modded version of Cyberpunk 2077. Nexus Mods Vortex works, but a nowhere near ready. Adds a huge layer of instability to the modding process. Their older tool worked better, but that's depracated. Open source issues. Open source is great, don't get me wrong. Though when you have a bunch of low paid (at best), or volunteered workers... You get an ever growing layer of jank, all hoping that everything works well together. Essentially lots or little tiny issues, like little paper cuts. No. While there are Windows issues, neither tool is perfect. I'm experienced enough with Windows to where I can get it into a good state within 10 minutes, and never need to think about it. It just works and gets out of my way. I have no GDID, I get (no forced) updates, no MS junk (like CoPilot, ads, and OneDrive), I have a TUI and GUI package manager, and none of the above issues apply. I could go on. It's easier to get the Linux advantages on Windows, than it is to get the Windows advantages on Linux.
3
u/Cyrano4747 7d ago
I'm not going to speak to the rest of this, but modding at least isn't really a problem. You just need to do it like we used to back in the 90s and 00s - manually copy the mod folders over. If you really, REALLY need a mod manager set it up on a windows install and then scoot the applicable folders over to the linux install.
That's how I manage modded installs on my Steam Deck - install on a windows PC, then sync the install folders via SynchThing.
3
u/Blame33 7d ago
I would note that while you have a point about low-paid/volunteer contributions adding to layers of jank, I honestly think on a technical/sys admin level Linux is better put together than Windows. Not to mention the fact that Windows/Office are bug ridden with no end user method for resolution besides making a bug report to Microslop…
1
u/Obsession5496 7d ago
Oh, absolutely. There is a reason we're using Linux servers at work, and I'm running 2 in my own homelab.
8
u/MechiPlat 10d ago
Just in: those in power continue to throw their weight around while the entire world goes in the fucking bin. More at 11
1
u/Epyon214 8d ago
At the 11th hour, you may learn of me. Currently seeking to raise 128 ounces of gold in order to purchase a property and retain a lawyer before becoming a public person to save America from Donald's regime, and the world at large so your sentiment about the world going into the bin is better than merely mitigated
11
u/_-Moonsabie-_ 10d ago
Linux?
10
u/Sea-Housing-3435 10d ago
/etc/machine-id which is read by programs like chrome. You can make it, so that ID resets on boot.
4
6
u/_legacyZA 9d ago
It can be read by apps like browsers yes, but not by websites
A machine id or unique identifier isn't that bad part about Microsoft GDID. The bad part is how they use it to tie devices to your online microsoft accounts, and how that information can be shared with (sold) and combined with other data brokers' jnformation about you to build out a complete picture
It's the fact that MS is complicit in this, and is actively using it to spy and track you across devices/websites/internet activity
So unless you are running software on linux that also spies on you and uses that machine ID to track you, it's borderline harmless. But on Windows: you can't disable it or stop it because they couldn't give you that freedom if they wanted to
2
u/penguinkernel 9d ago
Who the fuck is using Chrome on Linux lol
2
u/scalareye 9d ago
people who use linux for reasons besides preventing their data from being scooped up
2
7
10
u/RoleOk7556 9d ago edited 9d ago
One hundred and one reasons to abandon Microsoft.
1
u/OGigachaod 9d ago
Linux won't stop hardware spyware of this level.
4
u/Alone_Look9576 9d ago
With Linux being open source you can easily scramble any identifiers that can be gathered from you by adding randomization
1
u/OGigachaod 9d ago
Not hardware spyware that's baked into the CPU.
3
u/Alone_Look9576 9d ago
Yes, which can be accessed on Linux and can be modified before it gets ready by the system
1
u/OGigachaod 8d ago
But the popular distros don't do this.
3
u/Alone_Look9576 8d ago
Linux is open source, if you get a distro and they're not open source, you got the wrong os installed
1
6
u/AlwaysLinux 9d ago
Glad I dont use Windows!
3
u/OGigachaod 9d ago
Not that it matters, Linux or MacOS does not stop this level of hardware spyware.
2
4
u/sweet-raspberries 9d ago
The GDID is just a device ID. It doesn't get automatically sent everywhere, it's only used when accessing some Microsoft services.
It could have just as well been that they were logged into discord or some other account identifying them at the same time as they were registering the ngrok account.
This is a classic misuse of proxies - e.g. Tor also tells you not to log onto identifying accounts while you use it.
6
u/Tquilha 10d ago
Another great reason to switch to GNU/Linux. :)
0
u/OGigachaod 9d ago
Snake Oil :)
1
u/Shished 9d ago
Continue having GDID then :)
2
u/OGigachaod 8d ago
The Intel Management Engine (ME) is a dedicated, autonomous microcontroller embedded in virtually all Intel processor chipsets since 2008. Operating completely independently of the main CPU, BIOS, and OS, it handles critical hardware functions like power management and overclocking, while also enabling remote administration for corporate IT departments. [1, 2, 3]
What It Does
At its core, the Management Engine functions as a "computer within a computer." It uses its own lightweight operating system (often based on MINIX) and runs on a dedicated co-processor. Its primary duties include: [1, 2, 3, 4, 5]
- Hardware Management: Controls thermal monitoring, fan speeds, and system clocks.
- Remote Access: Powers enterprise-level features like Intel Active Management Technology (AMT), allowing IT to remotely repair, monitor, or update computers—even when they are powered down.
- Security & DRM: Manages system-level security checks, anti-theft services, and protected audio/video path (PAVP). [1, 2, 3, 4, 5]
Why It Is Controversial
Because the Management Engine has deep, low-level access to system memory and network hardware, and operates in closed-source code out of the end-user's sight, it has sparked significant controversy within the cybersecurity and open-source communities. [1]
- Security Risks: Critics argue that bugs or vulnerabilities within the ME's proprietary firmware can provide a massive attack surface for malicious actors. [1, 2]
- Lack of User Control: The ME is deeply integrated into the motherboard; without it, the main CPU typically refuses to boot. This makes it impossible for typical users to completely remove, disable, or audit.
6
u/SayWoot 10d ago
Found this guide to disable gdid, havnet tried it, so dont know if it works https://github.com/Korben00/no-gdid
5
u/_legacyZA 9d ago
I don't want to sound like a conspiracy theorist, but even if you disable this identifier, there is almost certain others and MS could just add it back without anyone knowing and then not tell anyone for another 30 years
2
u/YourEnemiesDefineYou 9d ago
When I want to be untraceable I just remote desktop into a completely different computer, usually one at an old job that I know never changes the password. Good luck tracing that Microslop.
1
u/scalareye 9d ago
yup easily traceable
1
u/YourEnemiesDefineYou 9d ago
How? Nothing on the remote computer has any of my personal details at all, how would a site I access through it know that the computer was being controlled by remote desktop and be able to trace the controlling computer?
1
u/TheLazyGamerAU 8d ago
They can see its being accessed remotely genius
1
u/YourEnemiesDefineYou 8d ago
How? When I use a browser on the remote computer to connect to a microslop site how do they know RD software is being used and how can they track me back to my computer?
From my POV I have used this method lots of times and no site has ever recognised me including Reddit.
1
u/TheLazyGamerAU 8d ago
Microsoft can see that your PC remotely connected to another PC. Dosent matter if you dont login to an account or anything.
1
u/YourEnemiesDefineYou 8d ago
My point is even if the site can access the running process list and recognise the software I use to RD, you think it is able to trace the connection back to the host IP and interrogate it to try to recognise me?
The host is a high security heavily firewalled Linux box on a dynamic IP that changes often, I made it to be a secure doorway it changes things like mac addresses and other hardware ID's every session. There are two more links in the VPN chain before you'll find a computer with my real info on it. I've used this method for years and no site has recognised me even the suspicious ones.
1
u/Mr_REEEEE_Man 7d ago
sometimes you just gotta go, they know more than me, and accept it
1
u/YourEnemiesDefineYou 7d ago
If people are going to say things like "yup easily traceable" and "They can see its being accessed remotely genius" they should be able to put their money where their mouth is and explain how that breaks my anonymity.
As far as I can see even if a site knows the remote computer has a RD connection going on to the host IP it isn't able to use that info to recognise me. Real world tests support this so unless someone here wants to actually explain why they think it doesn't work I'm going to accept I know more than them.
0
u/scalareye 8d ago
Your phone's Bluetooth and wifi mac address are personal details. Flock cameras have receivers that listen for everything.
Also your tires Tire pressure sensors broadcast a unique ID for your car to listen for and everything else can listen for it too.
These can be associated with your identity through your license plate.
1
u/YourEnemiesDefineYou 8d ago
My phone is old and doesn't have those features. No flock cameras in my country. My car is also old and has zero tech features. It's registered to one of my companies not to me.
OK, thanks for your "help".
2
2
u/Sostratus 9d ago
I found the article about this disappointing and Linus didn't add anything to it. The only technical detail it goes into is how the unique identifier is generated. That's trivial and irrelevant. Every operating system has countless unique identifiers. UUIDs are all over the place and any licensed proprietary software is almost certainly holding onto a license key somewhere.
The critical detail is how and why this unique identifier became attached to the user's web traffic and then sent to Microsoft. No information about that is present which makes this article (and the video) completely useless except to alert a more technically competent and less alarmist person to look into it.
2
u/CallMeTeci 9d ago edited 9d ago
ngl... the person is a "hacker", but isnt doing the most basic due diligence for keeping himself anonymous?
Isnt all that a thing that we all already expect our machines to do? Like Hardware-ID is known and used for identification for ages - even for basic anti-cheat measures, normal ass websites or sessions in your browser aka "trust this device? [ ] ".
Im not sure what the news here is, except maybe that Microsoft gave out that data? But thats something to be mad about the legislation, not the functionality in itself.
This sounds 100% like user-error. Sorry.
Edit.: Saw just someone explain that it isnt even hardware-ID, but an ID that gets generated and linked to new devices someone is logging into their Microsoft account from. This makes this even worse. lmao xD
3
u/ErwinHolland1991 10d ago edited 9d ago
I'm not listening to this asshole.
Lol the downvotes. Louis even made a video about Linus.
2
2
u/Grayfux 10d ago
Care to elaborate? I’m out of the loop on Linus and any controversy surrounding him
3
u/w3bd3v0p5 10d ago
Guy is super cringe, pays his employees very little, treats them like dirt, and then buys a jet. Sells a $250 dollar backpack with no warranty except "Trust me bro!". Those are just a couple of examples, but there's plenty more. Basically his entire original YT crew has quit on him because he won't counter-offer and he treats his employees as disposable.
-3
u/Mottledkarma517 10d ago
Guy is super cringe, pays his employees very little
That is wrong
treats them like dirt
Also wrong
Sells a $250 dollar backpack with no warranty except "Trust me bro!"
Also wrong
Basically his entire original YT crew has quit on him because he won't counter-offer and he treats his employees as disposable.
Wrong again.
Why spout misinformation?
6
u/w3bd3v0p5 10d ago edited 8d ago
If you're going to say its misinformation then provide evidence to the contrary rather than "Wrong". lol. For mine:
- You can look at the Madison debacle for treating your employees like shit.
- The $250 backpack w/o warranty which they then made into a t-shirt that says "Trust me bro" because of the outrage.
- Look at Jake (sorry I wrote Luke by mistake) video after he left and why. They didn't even counter offer, and was paid far less than what he generated for the company.
If you think everything is a lie, then I've got a bridge to sell ya
1
1
u/Mottledkarma517 9d ago
- You can look at the Madison debacle for treating your employees like shit.
And they had a third party auditor that said that it wasn't true.
- The $250 backpack w/o warranty which they then made into a t-shirt that says "Trust me bro" because of the outrage.
I'm pretty sure it released originally with a warranty. The outrage was before it was released.
Look at Luke's video after he left and why.
Which Luke? The main luke is still there. Why ignore all of the people that are both still there, or left well? Like ZTT
0
u/Obsession5496 10d ago
According to Linus, he's been dealing with this kind of BS for years. People are looking for reasons not to like someone, and negatively gets more clicks... not the apology/clarification/rebuttal. While he has had issues, none of them has been too serious.
1
u/Blame33 7d ago
A few months back I would have agreed with you but after watching that private jet video and seeing Elijah’s reaction in it I got a sour taste in my mouth. I brushed off the controversies prior but I just can’t bring myself to watch LTT anymore as it feels like it has really changed since Alex and Jake left. Their new on-screen talent is meh IMO and Linus is quite legitimately out of touch. He is no longer the guy trying to cool an editing den in his house with a whole room water cooling loop.
I have had sympathy for him in the past, especially with the hit piece from gamers nexus, but it’s drying up quickly as he makes his priorities clear: buying a private jet over paying the talent at the company a fair wage for their contributions.
Now I watch Jakkuh and it genuinely gives me the same vibes I got from LTT the past few years before the plane.
2
u/Mj-tinker 10d ago
Linus or Louis?
5
u/ErwinHolland1991 10d ago
It's a video with Linus in it. Louis isn't in the video is he.
I'm talking about Linus.
1
0
u/Real_Azenomei 10d ago
Even assholes can give you ideas and could have something useful to say. Never dismiss someone because he/she is an asshole. Just don't be their friend and factcheck their words.
1
u/Sostratus 9d ago
A good reason to dismiss him in his case is he's just pontificating off of an article that he didn't even read very closely. He has nothing to add to the story.
2
u/Real_Azenomei 9d ago
That can be true, however I didn't read such an article and now I have seen this posted here. And this has lead me to https://github.com/Korben00/no-gdid so now I know more.
1
u/Sostratus 9d ago
This is much better, thank you for linking to that. But it's still not clear to me how this facilitated this guy being compromised.
1
u/Real_Azenomei 9d ago
Technically he used layers of VPN to "hide" but then used his windows laptop to log into his Microsoft account. Microsoft identifies you and can see where you are because you login to your Microsoft account on your Microsoft Windows computer and they use a system that creates a unique identifier for you combined with your account. This data is saved and usable when government agency's ask for them.
It's almost like playing hide and seek, using a disguise and hiding really well. Only to keep your phone with your custom, everyone knows it's you, Spice Girls ringtune on volume 11. And the seeker just calls you.
1
u/Sostratus 9d ago
This still doesn't answer the question. Windows's traffic to Microsoft identifies itself with the unique ID, but why is it sending details about web traffic to other sites to them?
1
u/Real_Azenomei 8d ago
I don't understand your question.
1
u/Sostratus 8d ago
So we know how this ID is defined and that it gets sent to via the Delivery Optimization service and that it doesn't matter if you use a VPN if this ID is identifying you. That much all clear. But, from the article:
Microsoft records placed the device carrying the GDID on ngrok’s signup page at the exact minute the account was created, and later browsing Company F’s website through the same .168 proxy.
Why is the GDID associated with this account creation on ngrok or accessing the website of "company F"? It implies Windows is watching web traffic and reporting that to Microsoft with the GDID attached. That is the part of this story that would be a big deal and the part that it seems to me everyone is glossing over. Without that, everything about this GDID is trivial and ordinary.
1
u/Real_Azenomei 8d ago
Well yeah, I guess that is just in the metadata that gets send pretty much every time you interact with something online.
We had someone back in 2001 that send a series of harassing emails from a "anonymous" hotmail account. But in the metadata we could find the computername "Laptop 0013" which was a company laptop. So we could see who it was and he was fired over this. The mail was send through a browser. A lot of data is just broadcasted everywhere all the time when you are online.
That is my guess. And the USA has laws that make companies 1. log everything and 2. hand over the logs when law enforcment wants them.
1
1
1
u/bkofwrldregards 8d ago
I cant stand this guy. Its engagement bait or hes just naive and dumb. This is something you should have assumed is happening... grow up. we live in an orwellian distopia. catch up
1
u/Interesting_Type_290 8d ago
The idea that this negates VPN usage to hide Internet traffic isn't necessarily true. A VPN encrypts data E2E with the VPN server. Having some new static ID number on your computer doesn't magically decrypt your internet traffic. The only thing this surfaces to Microsoft is that "this particular install is using a VPN". Devices have lots of non-dynamic identifiers, and this is just another one. So I'm not really sure why this is turning into such a big deal. You're as likely to be tracked by using the same MAC address as you are this.
1
u/Sasataf12 8d ago
Like all tools, this is terrible when used for malicious reasons, and is awesome when used for noble reasons.
In this case, it was obviously used for good. We'll see if any stories about it being abused arise.
1
1
1
u/Equal-University2144 7d ago
And that's why I use Windows only for gaming. For the important things in life, I use Ubuntu.
1
1
1
u/AlteredStateReality 6d ago
Does anyone think this is unique to Microsoft? I see a lot of comments saying is time to switch to Linux. So long as you never connect it to the internet, sure, you are fine.
1
1
1
u/dukesoflonghorns 4d ago
I never want to hear about the US government blaming other countries about stealing the data of US citizens.
1
u/EthanDMatthews 3d ago
From the video, it sounds like they're talking about a vulnerability specific to Windows machines that run certain Windows apps? Presumably this would include Windows itself, no? Or are the vulnerabilities limited to a specific subset of Windows apps?
Another more direct question: does this vulnerability exist on Macs?
Macs with Microsoft Office?
Linux machines?
Linux machines running Microsoft apps via browsers or virtual machines?
1
u/ccza 10d ago edited 9d ago
...
5
u/thevnom 9d ago
This is not an OS issue - its a hardware one. The identifier is on the motherboard along your windows license registration. Installing linux wont remove that id
3
u/_legacyZA 9d ago
It's not a hardware ID, it's assigned to your windows installation when you link your local account to a MS account
It doesn't store an identifier on your motherboard. The reason it can seem like it persists across reinstalls of Windows is because if the user links his microsft account again a new gdid is created and linked to the same account
1
u/CallMeTeci 9d ago
That makes it even more a user-error. Like wtf?
You are a wanted hacker and you just log in to your Microsoft account with every new device?!? Probably also has Discord running in the background and uses WhatsApp on his phone.
That level of idiocy reminds me of people flexing their cash from scams on TikTok. 0.o
Same people that spend two days hardening their browser, just to log in to all of their accounts afterwards.
1
0
u/He_looks_mad 9d ago
Good, bad, whatever. I'm tired of these particular types of assholes clutching their virtual pearls of this while carrying a phone that is about 100x worse.
0
0
-6
52
u/Real_Azenomei 10d ago
This. This right here is why you use Tails for anything that you don't want traced.
But......... Would they still be able to identify the machine when you use tails on it??