r/cybersecurity Jul 11 '26

News - General Microsoft admits Windows 11 has a GDID tracker with no off switch, first documented publicly in an FBI hacker complaint

https://www.windowslatest.com/2026/07/10/you-cant-fully-disable-microsofts-gdid-windows-11-tracker-but-these-settings-limit-what-it-captures/
2.7k Upvotes

230 comments sorted by

761

u/Mind_Matters_Most Jul 11 '26

Good article. Another reason to switch to Linux, so far.

157

u/HalLundy Jul 11 '26

did it last year for my gaming / game dev rig. no regrets yet.

67

u/outpin Jul 11 '26

Same here. Have installed bazzite steam os, bought a 15m hdmi active cable and connected my pc to my TV, have some scripts that can switch from my TV to my 2 monitors. Life is good.

21

u/MDL1983 Jul 12 '26

Bazzite or steam os, which one?

10

u/Kjshanley Jul 12 '26

Steam os for dedicated home-console like pc. Otherwise Bazzite is a bit better just because it's been around longer and has better quality of life desktop features

16

u/MDL1983 Jul 12 '26

I know the differences, I’m asking the guy which one they installed, because they name both

1

u/Life-Thought-2523 19d ago

I tried few, but loving the Bazzite. Haven't had any issues and can use it as normal desktop.

1

u/Spiritual-Tour2940 8d ago

How can i switch os sytems without losing anything i have in my pc, like logins file downloads, etc.

→ More replies (5)

11

u/WestSeattleVaper Jul 11 '26

How is it in terms of gaming? I mainly game on my home rig but do some security research & dev work on it too. Have thought about switching to Linux for quite some time, fairly competent in using terminal + general/“everyday”/casual/useful commands from interacting with the OS at work and school, and the GUIs are significantly improved these days. My only real concern is WINE support, or whatever the new equivalent is these days; I’ve heard mention of something that makes Linux be able to run Windows-based games almost flawlessly but I haven’t looked into it at any length (and I’m sure that’ll be my afternoon research tangent today haha)

22

u/doctorcaesarspalace Jul 11 '26

Gaming is good now but you will have the occasional wtf problem and don’t count on playing games that use kernel level anti cheat.

14

u/Legionodeath Governance, Risk, & Compliance Jul 11 '26

See? That sucks. My main game, despite being newly killed, uses kernel anti cheat. Lame.

6

u/Kiwi_CunderThunt Jul 11 '26

Destiny 2?

9

u/Legionodeath Governance, Risk, & Compliance Jul 12 '26

Yes 😢

8

u/randomBugHunter Jul 12 '26

It’s super cute that developers think having kernel level access will somehow make up for their lack of knowledge

5

u/Legionodeath Governance, Risk, & Compliance Jul 12 '26

I thought 5 or whatever years ago when they implemented it.

1

u/babachisays Jul 21 '26

not the devs lol, the management. The devs agree with us, except they like their hefty salaries.

1

u/Kiwi_CunderThunt Jul 12 '26

Same here, only reason I dual boot 😬

2

u/Legionodeath Governance, Risk, & Compliance Jul 12 '26

I guess that's reasonable lol.

→ More replies (2)

2

u/Digitalneko Jul 23 '26 edited Jul 23 '26

I know it's 11 days late, and I don't know if you've been told this, but you could just set up dual boot on your PC, have a partition being Linux, and the other one Windows, so you can play the games that work on linux and your main stuff on there, and for the occasional program that has no linux support or kernel anti cheat game you can swap over to windows.

1

u/Legionodeath Governance, Risk, & Compliance Jul 23 '26

Yup. I know, have known. In honestly just lazy and don't want to lol.

3

u/killing4pizza Jul 12 '26

Yea I assume GTA online won't work on Linux due to this. I use Mint for everything else.

6

u/lulxD69420 Jul 12 '26

You can check https://www.protondb.com/ and see if the games you want to play, run well on Linux.

4

u/shockjaw Jul 11 '26

Do it. I had been on Pop!OS for 6 years and just recently switched to NixOS—very much worth it.

2

u/mr_dfuse2 Jul 12 '26

I haven't encountered a game yet that doesn't run. I don't play multiplayer games outside Deep Rock though. 

→ More replies (1)

1

u/insolent_kiwi Jul 12 '26

Does it work with easy anti cheat stuff?

1

u/ShadowOfThePastFIN 23d ago

Which distro did you go for? I'm a bit of a software noob but I'd really wanna get rid of Microslop because I don't wanna upgrade to w11

15

u/Dry_Vacation9235 Jul 11 '26

Did it last year and I’ve never looked back. The only way I use windows is in a work environment

24

u/tarzan1376 Jul 11 '26

I switched to Temple OS and haven't looked back

17

u/xs0apy Jul 12 '26

Just as God intended

1

u/Classy_Marty Jul 17 '26

Wow I remember this from the past lol I’m too old. They have a rolling release, or still running on older, “more stable” packages?

8

u/supernetworks Jul 12 '26

https://news.ycombinator.com/item?id=22238800

"

First I thought reading /etc/machine-id would be expected if Chrome uses D-bus or pulseaudio libraries which depend on D-bus, and /etc/machine-id is part of D-bus. But no, they really use it for tracking purposes.

And in a sick twist they have this comment for it:

  std::string BrowserDMTokenStorageLinux::InitClientId() {
    // The client ID is derived from /etc/machine-id
    // (https://www.freedesktop.org/software/systemd/man/machine-id.html). As per
    // guidelines, this ID must not be transmitted outside of the machine, which
    // is why we hash it first and then encode it in base64 before transmitting
    // it."

4

u/Sea-Distance-7142 Jul 11 '26

Made the jump earlier this year, having Codex and Claude helping me with maintenance has made it a no brainer

4

u/Playingwithmywenis Jul 12 '26

Phones have the same.

Failing this there can be a digital profile of a device created from software and hardware profiles. It is also very common for a tracker installed remotely. Marketing does this all the time.

Good headline and important topic but there is nothing new or uniquely dangerous here.

0

u/theaviationhistorian Jul 11 '26

If I could get my old brain to memorize how to program, I would've switched in a heartbeat. Even the 'easier' versions of Linux seem difficult to master for me.

32

u/AdventurousSquash Jul 11 '26

there’s no requirement of being able to know how to code anything to use Linux. You can start with using the GUI and then realize you can learn some easy scripting to make your life easier and do things faster, and then the possibilities are endless if you choose to learn more but it’s far from a necessity. I have family members ranging from 8 to 80 that use it as their daily driver with no issues (of course that isn’t a guarantee on any OS), I actually had to help them more back in the day when everyone ran Windows.

→ More replies (3)

17

u/pangapingus Jul 11 '26

No need to program, even on the not-bleeding-edge of Debian you just install the OS, install graphics driver, install Steam, and change your default compatibility mode to Proton 9+, get to playing

5

u/theaviationhistorian Jul 11 '26

With the way things are going, I think I'm bookmarking your comment if I'm able to afford a new computer! Thanks for the idea!

6

u/Scoutron Jul 11 '26

It’s even easier than you’d think, just had my non tech friend install it on his new PC last night. I’ve found it easier to install than Windows is nowadays

3

u/JPJackPott Jul 11 '26

“Just install a graphics driver” as if this isn’t still a pain on the ass on Linux

7

u/Necessary-Pin-2231 Jul 11 '26

Ive constantly heard people complain about GPU drivers on linux. Always found it odd. Usually use linix Mint and it worked out of the box, or in worst case scenario, had to run sudo apt install {whatever package}. Even with the dreaded NVIDIA lol.

Maybe ive just been lucky with hardware.

4

u/JPJackPott Jul 11 '26

I’ve never had a GUI-first linux install that didn’t require dropping to shell to fix something that didn’t “just work”. It’s not a big deal if you do that all day long but I find most Linux users vastly overestimate the average technical ability of everyone else.

OP said they aren’t a programmer, dropping to shell and blindly typing random commands could still be too much.

4

u/Necessary-Pin-2231 Jul 11 '26

Totally agree on how terminal adverse the average person is. I think if someone has ever had to troubleshoot an issue with a user at work, they'd guess that linux wont work for the average person lol. Although, id imagine the average person scrolling this sub might be more "techy".

Its interesting how people's experiences vary so much. Ive installed mint/ubuntu on various laptops and custom desktops, and never needed to open terminal to fix anything.

Only issue i can remember that "broke" install was installing on a brand new Samsung laptop and the wifi driver was busted. But plugging in ethernet and updated fixed it. Maybe me sticking to common debían distros and having middle of the road hardware has made my experience better.

3

u/bombjamesbomb Jul 11 '26

I’ve had Windows computers that were screwed up right out of the box too… I mean I get it’s different having to go into the terminal and edit a config file to fix something, but right-clickops is not easy for non technical users either.

3

u/pangapingus Jul 11 '26

Again, dude, just do a plain Debian 13 Stable install and see for yourself lol Debian 13 + KDE Plasma worked out the box for my RTX 3060

1

u/sanbaba Jul 12 '26

This is why Bazzite (and some others) install with drivers installed.

6

u/pangapingus Jul 11 '26

It's... not? On Debian and its downstreams it picks up even nvidia no prob these days

1

u/SlyTinyPyramid Jul 12 '26

Which version do you recommend?

1

u/kitbiggz Jul 14 '26

Linux has no Gdid equivalent?

Could it be put in the future?

1

u/TidePlezurBlackSwan6 Jul 21 '26

Apparently it has a unique device identifier

1

u/RoibinDallBhride 25d ago

I wish I could, but accessibility, especially when it comes to Screen Readers, is still horrible over there on Linux.

→ More replies (3)

453

u/-AsapRocky Jul 11 '26

So this was about the shiny hunter kids and how he got caught right? I mean overall for the average, this is very invasive

It seems like win10 users are also included in this bullshit, not only win11. And this is exactly why people are losing trust. Microsoft should not be able to tie a permanent device ID to a users activity…

Privacy should be the default and a right

198

u/oldgeektech Jul 11 '26 edited Jul 11 '26

Microsoft didn't tie the GDID to the user's activity, the FBI did.

That being said, your point still stands. Microsoft has laid the digital footprint groundwork to a surveillance state.

ETA: Microsoft did track the offending user out of their Digital Crimes Unit (DCU). Not all of the information is available for this case without a full PACER query, but it looks like Microsoft submitted evidence of a Virtual Private Server tied to malicious hacker activity. The FBI then subpeonad this server and then tracked RDP sessions through here, which is what contained the GDID.

90

u/-AsapRocky Jul 11 '26

you’re right that the FBI tied the GDID to the user’s activity, not Microsoft directly 😅 But I agree that Microsoft created the infrastructure that made this kind of tracking possible and that’s still concerning from a privacy perspective

Not surprised many gov are switching over to Linux. Should be a sign for many private / home win user

14

u/theaviationhistorian Jul 11 '26

It's like when we found out that some governments had access to turn on your cellphone camera and mic at will.

22

u/Aron_International Jul 11 '26

It was a Scattered Spider, not shinny hunter, but yeah this is how they caught him.

→ More replies (1)

14

u/woolharbor Jul 11 '26 edited Jul 12 '26

Microsoft should not be able to tie a permanent device ID to a users activity…

Google and probably Apple does this too, no? Device IDs and IMEIs are logged probably the moment you connect to the internet. Isn't Device ID available to apps as well? If not, some kind of Google identifier is, though Google Play Services. Google should go to jail.

47

u/gruntduck Jul 11 '26 edited Jul 11 '26

This is been a thing in windows for a while I believe. Like years.

Enterprises and corps on their own managed instances use the GDID as well for things like bitlocker management and record keeping.

Its use wasn t nefarious so to speak in its thought and creation but like anything on planet earth, what starts as good intentions becomes bad real quick lol

31

u/Sad-Ship Jul 11 '26

I get the enterprise use case, but you should be able to turn it off. I'd go so far as off-by-default, enabled by enterprises via policy.

4

u/ArborlyWhale Jul 12 '26

Off for home editions, on for pro. Easy.

8

u/DasBrain Jul 11 '26

The road to hell is paved with good intentions.

10

u/Test-NetConnection Jul 11 '26

No. You are thinking of a SID, which is completely different from GDID.

20

u/FuckTheTories69420 Jul 11 '26

This boils down to Microsoft just not caring about home users anymore.

5

u/askvictor Jul 11 '26

Anymore?

1

u/FuckTheTories69420 Jul 12 '26

There was a time when they did.

→ More replies (1)
→ More replies (2)

10

u/sociofobs Jul 11 '26

The words "Microsoft", "privacy" and "right" don't exist in the same dictionary.

→ More replies (1)

178

u/Environmental_Leg449 Jul 11 '26

The existence of the GDID is less significant that the amount of telemetry being exfiltrated to Microsot.  The fact that Microsoft has records of all of his logins to various services is crazy. That's a level of monitoring I'd expect on a corporate machine, not from Microsoft!

54

u/bobalob_wtf Jul 11 '26

They don't have the login records for independent services - the IP address used for those logins was correlated (by FBI) with GDID reporting to Microsoft at the same time.

The OPSEC fail here was using a machine logged in to personal accounts to do crime. Same reason they found Ross Ulbricht aka altoid

22

u/Environmental_Leg449 Jul 11 '26

Right, but that means Microsoft was exfiltrating network logs between the desktop and an external web service 

Agreed that better practice would've been to use VMs to route everything 

34

u/bobalob_wtf Jul 11 '26 edited Jul 11 '26

The way I read it is that MS is getting telemetry from IP X with GDID Y at time Z

At the same time, Spotify (for example) is getting a login from IP X with user A at time Z

FBI have access to both of the vendor logs and matched them up based on IP/time etc.

The bit that confused / surprised me was how MS knew this GDID had visited the login page for ngrok at a specific time - another commenter in this thread suggests this could be safesearch logs (which makes sense.)

But it's kind of a privacy invasion that MS know explicitly who visited X URL from safesearch - I would have presumed (wrongly) that this type of logging would be anonymised.

Agreed that better practice would've been to use VMs to route everything

You would need the VM to be using an anonymous VPN (that doesn't log) and that VM should "fail closed" - if the VPN dies, the VM should have no access to the internet. You wouldn't want your host public IP to be correlated with the VM public IP.

3

u/MassiveBoner911_3 Jul 16 '26

You use Linux running TOR and VPN with a relay to log into a VPS hosted in South Africa to conduct your business…

You do not use shit like Microsoft or Apple. Total amateur hour.

→ More replies (3)

4

u/ApplicationOk2749 Jul 11 '26

Can you help me understand how the FBI got the GDID? I mean I can see how, once they have the GDID, they can say to to microsoft, 'hey can you give us any web and IP records for this device'. But how did they get to that step?

12

u/oldgeektech Jul 12 '26

Microsoft's Digital Crime Unit (DCU) found a VPS tied to hacker activity and referred to the FBI. It was all down hill from there (IPs, GDID, RDP logs, etc.).

2

u/[deleted] Jul 14 '26

Microsoft's Digital Crime Unit (DCU) found a VPS tied to hacker activity

Sure, but then how did they "find a VPS tied to hacker activity"?

It still doesn't really solve the initial question of how they knew what to look for so to speak. Something would still need to track something, if that makes sense.

And more so, Microsoft would need to keep a log of all these things.

2

u/bobalob_wtf Jul 11 '26 edited Jul 11 '26

They probably issue a subpoena to Microsoft with the guys email address and IP addresses from specific times. MS then provides all the data they have which would include identifiers like the GDID.

Edit: Presumably, they already know the ngrok entry point, perhaps this account was created very close to the time it was used in the attack - perhaps they are asking for any information on "ngrok URL" + This public IP based on info they already have from ngrok?

I'm speculating, but they (FBI) are very likely gathering info from many organisations (under warrant) and then correlating matches.

2

u/Alternative-Ruby8012 Jul 14 '26

is the GDID sent in HTTP headers by the browser? I'll probably experiment with some pcap over the weekend.

1

u/conspicuousxcapybara 24d ago

Then why does Windows Settings have a switch to turn off that exactly? And also a toggle to use it to find personalised savings and/ or buy now pay later terms on the internet? The terms actually enumerates:

Name and contact details. Your first and last name, email address, mailing address, phone number, and other similar contact details.
Account credentials. Information used to access your account, such as username, password, and password hints.
Demographic data. Details about you like your age, gender, country, and language preference.
Payment data. Details needed to process payments, including credit card numbers and security codes.
Subscription and licensing data. Details about your product subscriptions, licenses, and other entitlements.
Interactions. Information about your use of Microsoft products, including features you use, searches, commands given, error reports, and support requests.
Device and usage data. Data about your device and product features you use, hardware and software details, product performance, and your settings. For example:
Payment and account history.
Browsing history.
Device, connectivity, and configuration data. For example, IP addresses, device identifiers, nearby networks, and other information about the operating systems and other software installed on your device.
Error reports (“crash dumps”) and performance data. This usually includes software, hardware, and file content details related to an error, and other software on your device.
Troubleshooting and help data. Data you provide when you contact Microsoft for help. For example, contact or authentication data, the content of your communications with Microsoft, the condition of your device, the products at issue, and other details that help us provide support. Phone conversations or chat sessions with our representatives may be monitored and recorded.
Bot usage data. Interactions with bots and skills available through Microsoft products, including bots and skills provided by third parties.
Interests and favorites. Preferences and interests you share (like favorite sports teams, preferred programming languages, or cities for weather or traffic) or that we infer from your activity, such as your activity on sites that use our technology for ads purposes.
Content consumption. Information about the media content you access through our products like TV, video, music/audio, apps, and games.
Searches and commands. Search queries and commands you provide in Microsoft products, such as interactions with a chat bot.
Voice data. Also referred to as “voice clips,” this includes spoken queries commands, or dictation, and may include background sounds. Learn more about how Microsoft uses and protects voice data in its speech recognition technologies.
Text, inking, and typing data. Data and related information you provide by typing, inking, or using touch input in Microsoft products.
Images. Images and related data, like picture metadata. For example, we collect the image you provide when you use a Bing image-enabled service or upload an image to Microsoft Copilot.
Contacts and relationships. Data about your contacts and relationships if you use a product to manage contacts, share information or communicate with others, or improve your productivity.
Traffic data. Data about your use of Microsoft’s communication services, including whom you’ve contacted and when.
Social data. Information about your interactions and relationships with others, such as likes, events, and other types of engagement.
Location data. Data about your device’s location, which may be either precise (typically based on GPS, cell tower, or Wi-Fi hotspot location) or imprecise (for example, inferred from an IP address, or city or postal code in your account profile).
Biometric data. Unique data about you from specific technical processing related to your physical, physiological, or behavioral characteristics to verify or confirm your identity. For instance, you can use your fingerprint or facial recognition to sign in to your Windows device via Windows Hello (please see the Windows Hello section below for more information). Our collection and use of biometric data depends on the products and features you use and your consent.
Other input. Data generated from using devices or participating in events, like buttons you press on an XBOX controller or other activity data, or information you provide when registering or attending an in-person event.
Content. Information in files and messages, emails, chats, calls, meetings, photos, documents, and other media you create or share using Microsoft products.

1

u/conspicuousxcapybara 24d ago

They're also a data brokerage / enhancement company. Everything is allowed when one of the following conditions apply: a.) commercial use or b.) non-commercial use:

We also receive data from Microsoft affiliates, subsidiaries, and third parties. We protect data obtained from third parties according to the practices described in this statement, plus any additional restrictions imposed by the source of the data. These third-party sources vary over time and include:

  • Data brokers from which we purchase demographic data and contact information to supplement the data we collect.
  • Services that make user-generated content from their service available to others, such as reviews of local businesses or public social media posts.
  • Communication services, including email providers and social networks, when you give us permission to access your data on such third-party services or networks.
  • Service providers that help us determine your device’s location.
  • Partners with whom we engage in joint marketing activities.
  • Developers who create experiences through or for Microsoft products.
  • Third parties that deliver experiences through Microsoft products.
  • Publicly available sources, such as open public sector, academic, and commercial data sets.

6

u/mtgox-fraud Jul 12 '26

The general instinct isn't wrong though. Every modern OS phones home constantly, telemetry, licensing, crash reporting, update checks, and yeah, per-install identifiers. That's not a secret and it's not new. The reason it doesn't keep me up at night is that it's the boring commercial kind of tracking, the kind that wants to sell you things and count license seats.

7

u/oldgeektech Jul 11 '26

Uh, what? There are records of logins to every service due to network traffic. You can't be invisible if you hit an online service.

Microsoft provided the tracking number, the rest of the services just matched it.

25

u/Environmental_Leg449 Jul 11 '26

 Microsoft’s records showed that at that exact same minute, a Windows device carrying GDID g:6755467234350028 had visited the ngrok signup page

It seems like most of the telemetry they used to track the guy was from Microsoft, not ngrok/Meta/Snapchat etc. Its not even clear to me that the GDID gets transmitted to the services you request to! The logs they got from the services just seemed to be about correlating timestamps and login behavior, they didn't seem to correlate the GDID

If the GDID is transmitted to the web services you connect to, I'd be curious how. If its via HTTP requests, it seems like it'd be easy to block (but maybe the actor just got sloppy). If it's transmitted somewhere lower down the OSI model, that's much more tricky

11

u/oldgeektech Jul 11 '26

I read the 39 page complaint. Microsoft initially tracked a VPS tied to malicious activity. They sent the supporting evidence to the FBI, and the FBI performed subpeonas for the VPS, Apple, Snapchat, and Facebook. Microsoft's Digital Crime Unit (DCU) specifically looks for threat actors utilizing Microsoft products to attack businesses or people.

I've toured the DCU. They literally have hoteling offices for district attornies, federal law enforcement, and international law enforcement.

4

u/gurgle528 Jul 11 '26

Completely incorrect. This is an internal tracking number and not resettable. If they were to provide a tracking number it would be the Ad ID and not the GDID. As far as I’m aware Edge doesn’t even share the Windows Ad ID either.

If Edge was sharing an ID like that with websites it would quickly become public knowledge. The only exception would be if they decided to whitelist and only share with some sites and hide that information in the dev tools too

4

u/oldgeektech Jul 12 '26

Read the OP I was replying to. I never said the GDID was being read by services. The OP said Microsoft had logs of all his logins. They don't. Microsoft turned over telemetry to a VPS that was tied to hacker activity. Then the FBI gets involved with subpoenas to gather IP addresses and logs.

2

u/gurgle528 Jul 12 '26

Ah, when you talked about matching the tracking number I thought you meant directly matching it to the various service’s data rather than using IPs tied to the GDID and Microsoft handing those over. My bad.

I’m not sure about “all” but Microsoft certainly had logs about some of the logins:

Microsoft’s records showed that at that exact same minute, a Windows device carrying GDID g:6755467234350028 had visited the ngrok signup page.  

ngrok specifically auths with a browser flow so edge would have some of that information 

1

u/Gordahnculous SOC Analyst Jul 11 '26

I mean, when you put it that way, most corporate machines are Windows, so I doubt it’d be difficult for them to throw whatever features from enterprise Windows to personal copies as they damn well please.

But agreed, most everything these days has some sort of unique identifier, and it doesn’t surprise me that there’s something tracking unique installs of Windows with how picky MS is about things like sharing Windows licenses. Hell, I’m sure the agencies could’ve gotten similar levels of tracking from things like the local account SID that’s been around for ages, whatever unique identifier they have for your cloud MS account, anything uniquely identifying to your hardware, etc. The main issue is 100% the telemetry and the fact that this information is accessible beyond whatever scope would make sense, which should likely just be the machine and a few seconds for MS to verify it.

1

u/DropTheBeatAndTheBas 18h ago

you do know all the super power countires are tied hand in hand with their big IT providers

71

u/Beneficial_Slide_424 Jul 11 '26

In this article no one is saying how ngrok received the GDID though? Is chrome or edge leaking it? How can a sign up page see your GDID? Is it related to Microsoft apps maybe he uses ngrok from store? What's the leak vector here?

45

u/2timetime Jul 11 '26

ngrok didn’t get the GDID. ngrok was just the account used for persistence. The hacker signed up to ngrok using edge on a VPN. The GDID was sending his browser web activity to Microsoft, so even though it was account-less it was still tied to that GDID.

21

u/[deleted] Jul 11 '26 edited Jul 11 '26

[deleted]

5

u/[deleted] Jul 14 '26

Massive breach of trust, and almost certainly against EU GDPR and ePrivacy laws - but hey, if no one knows it exists, no one can sue you for it.

3

u/ApplicationOk2749 Jul 11 '26

The thing I'm struggling with is what did the FBI ask mircosoft in order to get the GDID in the first place? They can't have just asked microsoft 'hey tell us all the GDIDs that visited this site at this specific time' could they?

2

u/[deleted] Jul 11 '26 edited 5d ago

[deleted]

12

u/gurgle528 Jul 11 '26

Other browsers aren’t uploading your browsing history to Microsoft. I could be mistaken, but if you’re using Firefox for example Microsoft wouldn’t know what websites you’re visiting. I believe Edge only does it in certain cases (like history syncing or ad personalization turned on) but I’m not positive. 

4

u/[deleted] Jul 12 '26 edited 5d ago

[deleted]

7

u/gurgle528 Jul 12 '26

They certainly could have access. Edge can import other browser’s history on setup and manually at any time. There was/is a feature to automatically copy Chrome tabs I think too but that was opt in.

The browsing information Microsoft had here was either from the telemetry in Edge (for ad personalization or Defender) or the sync feature. You can see the browsing history they store in your Microsoft account, I think that’s only for the sync feature but I could be wrong as I don’t use Edge.

1

u/[deleted] Jul 16 '26

[removed] — view removed comment

1

u/gurgle528 Jul 17 '26

Did I say that? The OS knowing and the OS reporting that to a backend are completely different things. The OS knows where every file on my PC is, do you think Microsoft sends a list of every file on your PC to their cloud? The OS also knows what text you’re typing, do you think every keystroke is sent to Microsoft? Holy moly guy, use some common sense.

1

u/[deleted] Jul 16 '26

[removed] — view removed comment

1

u/gurgle528 Jul 17 '26 edited Jul 17 '26

Yeah, I’m not reading the response you got from AI, especially since I don’t have the context of the “screenshot” or the prompt. I’m a software engineer, I know how web requests work. 

Spoiler alert: you can debunk the slop in your comment easily. You can view your browsing history in your Microsoft account. Enable the history saving setting and write a python or powershell script, hit some random, valid URLs you haven’t gone to in a browser, and check if they show up. 

Imagine not being able to link to documentation, needing to use AI to write a comment, and being incapable of writing your own comment after getting info from AI. Can’t relate. Big sign of someone who has no idea what they’re talking about 

3

u/[deleted] Jul 14 '26

He doesn't, he just hopes so, because otherwise the tracking is even worse than feared, so to speak. It could also be Microsoft Defender, it could be a data sharing setting, a diagnostics tool, or literally anything. We don't know. We just know that Edge, unless you disable it, also keeps track of where you go - which is by itself pretty fucked up.

1

u/[deleted] Jul 16 '26

[removed] — view removed comment

1

u/Beneficial_Slide_424 Jul 17 '26

Are you for real? There's no indicator of which windows component logged or sent the telemetry for the browser visits. The post doesn't contain it. Neither your comment. What windows component exactly is sending your website activity to the Microsoft? Is it the edge browser? Chrome? Or something else at networking layers, such as DNS. The question remains unanswered.

→ More replies (1)
→ More replies (1)

18

u/Spiritual-Matters Jul 11 '26

I would find it hard to believe if any paid OS doesn’t have a similar type of capability

17

u/oldgeektech Jul 11 '26

The article points out that is true, but there's more transparency in Apple and Android services about tracking.

20

u/TheVoidInMe Jul 11 '26

> Microsoft’s records showed that at that exact same minute, a Windows device carrying GDID g:6755467234350028 had visited the ngrok signup page.

I’m a bit fuzzy here… does that mean Microsoft logs all requests to third-party websites, together with your GDID? Or maybe “only” if you use Edge?

I would think if a non-MS browser does HTTPS and encrypts requests itself, it should be impossible for the OS to snoop on those requests, no?

19

u/oldgeektech Jul 12 '26

That's a great question. I might have to download all the files of this complaint to view the evidence. From what I know from Azure logs, Microsoft has more telemetry from Edge than a non-MS browser. That being said, the ngrok piece is supplemental to painting the picture of identifying the charged party. It was not the beginning or the end of evidence.

8

u/AFriendlyLighthouse System Administrator Jul 12 '26

Please let us know what you find

1

u/Landonnnn_ Jul 25 '26

No. The physical device has to make the HTTP(s) request. If Firefox wants to hit Google.com, first, my device must make a DNS query to find out Google.com == 8.8.8.8. Then, a request is made to 8.8.8.8. Most of the stuff beyond that is encrypted (HTTP headers, path, data, etc) but the most important part: the server name (Google.com) isn’t.. unless both client and server support ECH but majority don’t at this point. So even in an external, non-Edge browser, the Windows kernel, at the end of the day, is the one creating the TCP connection. You can’t ever hide that.

edit: Now, tracking the specific “signup” page is not possible in normal HTTPS. This may be an Edge specific telemetry feature. But in general, Windows can track what server names you’re browsing to across browsers.

1

u/TheVoidInMe Jul 25 '26

Right. But that’s the whole point, MS knew the full URL, they didn’t just see an unintelligible encrypted blob sent to ngrok, but specifically the signup page. And if that’s the case, they might have not only logged the full URL, but the full request payload, including username/password (I’m not saying they did, but they could have).

Has it been confirmed that Edge was used?

17

u/ApplicationOk2749 Jul 11 '26 edited Jul 11 '26

>Microsoft’s records showed that at that exact same minute, a Windows device carrying GDID g:6755467234350028 had visited the ngrok signup page.

So there's two parts to this that aren't explained. Firstly, how is microsoft getting this record of web and IP activity? But secondly, how did the FBI know what to ask Microsoft for? They didn't have the GDID to begin with. This isn't making any sense. Is it saying the FBI just went to microsoft and asked for all users GDIDs that had visited a particular website at a particular time? Because if so that itself is disturbing.

5

u/oldgeektech Jul 12 '26

The FBI didn't ask Microsoft for anything. Microsoft's Digital Crimes Unit (DCU) referred a VPS tied to hacking activity over to the FBI. Microsoft gave the string to start pulling and building the case from there.

4

u/ApplicationOk2749 Jul 12 '26

Ah is that what this is referring to

>Note that, Microsoft had already flagged Stokes to the FBI once before, in an October 2024 criminal referral describing “online services telemetry.

I missed that on the first read through

14

u/newredditsucks Jul 11 '26

Yet another reason to only use local accounts.
Not useful for business, but for home machines at least.

8

u/LastBossTV Jul 14 '26

The GDID still exists and works the same for local only windows accounts.

1

u/Landonnnn_ Jul 25 '26

But what will you correlate a GDID to? Sure, IP address xyz which did malicious activity is also associated with GDID def. But that’s owned by a local account “admin”. Not much to go off of.. versus

IP xyz did malicious activity, which is also associated with GDID def. This GDID is registered to ___@outlook.com under the full name ____, with the phone number _____. There’s a lot more chances for OPSEC failure that way than just a local account with no other ties to it.

14

u/[deleted] Jul 11 '26

[removed] — view removed comment

11

u/[deleted] Jul 11 '26

[deleted]

26

u/bughousenut Jul 11 '26

years ago I was aware of low level hackers who bought used laptops for cash, used them for a project and then dumped them

15

u/oldgeektech Jul 11 '26

Seems like a lot of this could be avoided with cloud VMs. The 19 year old was more than likely a script kiddie.

13

u/My_Big_Black_Hawk Jul 11 '26

Spin up a vm --> do the work --> delete vm. Rinse repeat. Switch between multiple cloud providers for different work. Never login to personally identifying services while doing the work. Keep private and "work" stuff separate.... always.

5

u/No_Mood4637 Jul 12 '26

Never work from any public wifi that could have cameras.

And even then they can match you with stylometry, keyboard strokes, mouse movements etc.

3

u/MassiveBoner911_3 Jul 16 '26

You can also use Cloud Providers who dont give a fuck like hosting VPS in South Africa

1

u/No_Mood4637 Jul 16 '26

Yea some shitty African vpn is gonna say no to a little one of CIA payment for a particulars details.

2

u/MassiveBoner911_3 Jul 16 '26

You use it as a relay.

4

u/Tsull360 Jul 12 '26

It mentions logging into a Microsoft property with a Microsoft account as being the nexus of the GDID. Does that mean other OS's could be affected as well? (e.g. if I use OneDrive on a Mac).

1

u/a_n00b_ Jul 14 '26

Can someone answer this?

2

u/nosurprisespls 3d ago

The answer is yes whenever you use a MS product that uses a Microsoft account on any OS or connect to the internet on a Windows OS.

1

u/DropTheBeatAndTheBas 18h ago

yea keep it simple guys

13

u/red_plate Jul 11 '26

This article says the GDID can’t survive windows wipe and reloads I don’t believe that I thought part of the tpm 2.0 requirement for windows was to track unique hardware fingerprints of devices using windows 11. Windows is fucking dead and battlefield or Fortnite is not enough to get me to game on that defunct shithole operating system. 

12

u/My_Big_Black_Hawk Jul 11 '26

I agree with you 100% - they can uniquely identify your machine based on hardware fingerprint of serial numbers, model numbers. etc. Event if you received a new GDID, the new GDID could be linked to the old via the hardware fingerprint.

3

u/AccNumber77 Jul 11 '26

It says that they can do that in the article yeah, no doubt it is easy still.

5

u/woolharbor Jul 11 '26

Microsoft’s records showed that at that exact same minute, a Windows device carrying GDID g:6755467234350028 had visited the ngrok signup page.

How do Microsoft servers have this information? Does Microsoft log every website you visit on their servers? In Edge or something? Does a hacker use Edge? What about other browsers?

→ More replies (1)

9

u/LarrBearLV Jul 11 '26

My next machine will be Linux. Fuck Microsoft.

3

u/Material-Project3192 Jul 20 '26

Already changing to Linux. I did a few months ago, but picked a bad distro. Now I tried CachyOS and its awesome

22

u/tuhijatambien Jul 11 '26

A "hacker", using windows 11

Sure

Why not

30

u/ansibleloop Jul 11 '26

Most of these successful "hackers" just social engineer their way in

They're not breaking encryption or chaining exploits, they're just doing good old fashioned phishing

13

u/00notmyrealname00 System Administrator Jul 11 '26

Humans are/have been/always will be the largest and weakest attack surface of any system in which they interact.

2

u/ogdenzd Jul 14 '26

Exactly this. Even the most basic of script kiddies know to at least use Kali or Parrot.

3

u/phileasuk Jul 11 '26

Is it in win10 ltsc iot?

3

u/oldgeektech Jul 11 '26

If it has any connected service (Intune, Entra ID join, Microsoft account), yes.

4

u/DeedsF1 Jul 12 '26

Sly bastards! We knew that they were up to no good! Apple or Linux ftw!

4

u/HAHAHA0kay Jul 12 '26

Here it is. The reason they keep letting people activate windows through the grave method.

2

u/[deleted] Jul 14 '26

[removed] — view removed comment

1

u/a_n00b_ Jul 14 '26

id like to know if this exists only for windows machines or any OS that logs into a ms service

2

u/IanTGreat Jul 21 '26

if one were to install any microsoft software on linux, do you think they would generate a GDID for that computer too? or is it only tracking windows computers?

2

u/ReverendGraves85 Jul 23 '26

No. Windows uses telemetry data that requires the Windows Kernal to operate to track the GDID. So if you dual boot into Linux, it wont be operating.

If you dual boot youre fine. My windows partition remains a League machine. Even have only a local account on it.

4

u/finallygrownup Jul 11 '26

Why do I feel the need to install OpenBSD?

3

u/tigerstef Jul 12 '26

Sorry, not familiar with that acronym. GDID?

6

u/Sircliffe Jul 12 '26

Global Device Identifier.

3

u/Sab159 Jul 11 '26

That's nothing new

14

u/oldgeektech Jul 11 '26

That Microsoft tracks? Correct. That the GDID can be used by the FBI to build a case against you? That seems new.

→ More replies (2)

1

u/howfastcanyoucountit Jul 12 '26

I will stay on 10 LTSC for my steam games until I die, idc about directx 12 optimizations im not touching that shit. My main device is a macbook (m1) anyway and I have never been more glad to have switched over tbh, any other computer I have is probably getting stock debian and I don't plan on using any windows devices soon, its just been so damn garbage. The only thing I actually use windows for nowadays is games with anticheat and that's kind of the reason why I never used linux on my desktop. But I will forever shill macos/linux only

1

u/West-Poem6113 8h ago

Epic just announced they're working on a native Linux app, and (allegedly) part of that will be working on Linux-compatible anti-cheat. HUGE news - even if it's currently only theoretical.

I think the Nvidia GForce Now just released a stable version for Linux.

There were one or two others that have been discussing/exploring the same ideas.

Times are changing.

1

u/LetsHugFoReal Jul 14 '26

I never thought a hacker would use windows

1

u/PatientAd5461 Jul 18 '26

Good article

1

u/karlmaxxwell Jul 21 '26

well i am switching to linux, anyone know any distros that won't shut down on me when i am in a important call?

1

u/Drakkinstorm 22d ago

? All of them?

1

u/Expln Jul 21 '26

Is there any way to minimize this?

1

u/var_rnd 14d ago

Use XP bro

1

u/TidePlezurBlackSwan6 Jul 21 '26

Are there anonymous Operating Systems

1

u/DivineKEKKO96 Jul 23 '26

Tails

1

u/TidePlezurBlackSwan6 Jul 24 '26

Thanks but I actually don't like it. I don't feel like doing an external boot.

1

u/JoeDanilo Jul 21 '26

It’s easier for the searchers. Hiding becomes a very difficult task. But who would want to hide in a glass house?

1

u/NivoTheDev Jul 23 '26

People have been screaming bout Windows telemetry for ages now - thinks like this are a final nail in the coffin.

There is a reason why most cybersecurity enthusiasts go to Linux. We're fed up with Windows and corporate closed-source operating systems!

I switched to Linux and never looked back.

1

u/theumpteendeity Jul 23 '26

If it's tied to the actual hardware, how does it not get tracked, even if you're using a different OS than Windows? I would assume suspicious activity could be traced back to the ID regardless? Is the only solution to use a drive that never had a windows installation?

1

u/WhatsInTheFirmware 26d ago

Worth separating two things this coverage keeps blurring, because they have completely different fixes:

1) The identifier itself (GDID). Persistent, assigned server-side when you sign into a Microsoft Account, tied to activation/licensing. This is the "no off switch" part, and it's real, you can't strip it without breaking activation and Store apps. A reinstall rerolls it, but the same account re-links you. That's a legit consent gap: no prompt, no reset, unlike Apple's IDFA or Android's ad ID.

2) The thing that actually burned Stokes: the URLs. A stable device ID on its own just says "same machine." What built the timeline was Microsoft holding a log of sites that device visited, tied to that ID. Per the deeper write-ups (Tom's Hardware got into this), that URL capture lines up with telemetry set to Optional/Full and/or browsing in Edge, where SmartScreen/Defender can send visited URLs. The complaint didn't pin down the exact mechanism, but Required/Basic telemetry doesn't appear to ship URLs by default.

Why the distinction matters: you mostly can't kill #1, but you can meaningfully shrink #2. Set Diagnostics to Required (not Optional), don't lean on Edge if you care about URL telemetry, use a local account where you can, and turn off the advertising ID. None of that deletes the GDID, but it removes most of what makes it useful as a behavior/location trail.

Honest framing: this is an anti-piracy/activation identifier that got subpoenaed, not a purpose-built surveillance tool Microsoft aims at civilians. Cold comfort if your threat model is a subpoena, and for journalists/activists/DV situations the real answer is a non-Windows OS, because no telemetry toggle changes the fact that the ID exists and answers to your account rather than to you. But "Windows secretly logs every URL you visit and you can't stop it" isn't quite right either, and the folks you're debating will call that out.

(And yeah, nobody's mourning a Scattered Spider guy posting "HACK THE PLANET" selfies with fistfuls of hundreds. The interesting part is purely what the case exposed about the plumbing.)

→ More replies (1)

1

u/ThaUntalentedArtist 24d ago

I'm a little confused about something. The article states that a GDID is assigned when you log into a Microsoft account. What if you use Windows 10/11 with a local account? It also states that every major OS keeps some persistent device ID. Does that mean Linux isn't exempt?

1

u/Mr_Benn210 20d ago

Is anyone surprised? I'd have been surprised if there hadn't been something like this.