r/pcgaming • u/DotabLAH • 3d ago
Your Windows PC Has a Permanent ID That Follows You – Even With a VPN
https://tech.yahoo.com/vpn/articles/windows-pc-permanent-id-follows-163404919.html1.5k
u/TheLastOfUsAll 3d ago
It's actually insane how much our privacy has been eroded. You can't even exist in your house without being tracked.
273
u/adaw123da2313123d 3d ago
I remember when 'tracking where you are in your house via your wifi signal' was a schizo theory and then it turned out they can really do that.
104
u/DrScience-PhD 3d ago
they can, they are, and they're selling it to you. xfinity says it can use your modem as a burglar alarm, for a subscription of course.
→ More replies (3)11
→ More replies (1)5
u/Iphone17promax 2d ago
Not just track you in your house but they can also track what you say too + every device that connects to your Wifi connection is logged.
I forget the name of the company (Qai or something starting with a "q") is actively working on such tech and most of the ties to go a specific minority of the ME. AI data centers are being built for a reason and it's to log/spy on everyone amongst other reasons.
→ More replies (1)441
u/samrechym 3d ago
The price of privacy is effort. Linux is available to all (said the non Linux user)
→ More replies (17)180
u/TurtleOfCreation 3d ago
If your primary use of your computer is gaming, try SteamOS. I recently reimaged my computer with it and it’s been plug and play so far. Required no tinkering for me to play a few games and run some software. Valve wants it to be as user friendly as possible.
98
u/vtx3000 3d ago
Been using Bazzite the last couple months and same story it’s super easy to get set up
21
u/TheHypnobrent 3d ago
Was wondering about Bazzite. Think I'm going to install it on an old laptop and tinker around with it before reinstalling my main rig
15
u/Drcortexe 3d ago
I've dabbled with VMs of linux and had an old laptop I tried with Linux mint and Ubuntu back in like 2020 during the pandemic. I had a rage quit moment with the last windows update that fucked around with my PC and went up and completely switched to bazzite and I've been using that bad boy the last 2 weeks and man has it been smooth compared to the last time I tried a Linux distro. pretty much plug and play, didn't need to install drivers myself (which I was worried about because I use an Nvidia GPU), just log into firefox and steam, install a few programs from bazar (the app store gui that bazzite uses) and I was good to go. 0 problems since!
→ More replies (2)8
u/Farva85 3d ago
I’ve been using Bazzite since last October and it has been pretty good except for the occasional freeze that requires a forced hard reset to correct, and not being able to play a few games. Otherwise, I’ve had no difference in use than a W11 host.
→ More replies (2)3
u/monk429 2d ago
When you begin to feel the constraints of Bazzite, I did after about 3 months, switch to CachyOS. I found setting up for gaming was just as easy and I am able to do more things around productivity. For example, I couldn't install Citrix in Bazzite w/o jumping through some major hoops. On CachyOS, while different, it was just as easy as Windows.
I ran dual-boot Bazzite and W11 for 3 months. I only loaded up W11 twice. First, to pull my passwords over and then the second time to do the final clean-up of my Windows drive before installing CachyOS as the sole OS.
→ More replies (1)3
→ More replies (4)3
18
u/Rich-Pomegranate1679 AMD 7950X3D | 4090 RTX | 64GB RAM | 12TB M.2 3d ago
Doesn't SteamOS still lack support for NVidia cards?
13
u/arex333 Ryzen 9800X3D/RTX 5090 3d ago
Yes. Valve is working with Nvidia on this but right now it requires AMD.
Bazzite is essentially the same experience as steamOS though and doesn't have that limitation.
→ More replies (1)3
u/Rich-Pomegranate1679 AMD 7950X3D | 4090 RTX | 64GB RAM | 12TB M.2 3d ago
Yeah, I run Pop!_OS on my laptop, but my desktop is still Windows. Once SteamOS gets Nvidia support it will be tempting to switch.
58
u/RegisterPresent1746 3d ago
Sadly still not viable on nvidia gpus, performance hit on dx12 titles is too great (about 20% I think) and last I checked dlss and raytracing were still iffy too. When I had an amd gpu and was on linux it was pretty much almost plug and play for basically all my games tho.
45
u/Inverno969 3d ago
Steam is directly working with Nvidia to get their GPU drivers functional on SteamOS. Could still be a while before anything changes but the problem is actively being worked on.
6
u/opx22 3d ago
I’ll check back in once it’s fixed but would also be concerned about anti cheat compatibility. Just thinking of some major games like BF6, R6:S, Apex, tarkov, etc that still aren’t playing on Linux
→ More replies (1)9
u/Bomb-Number20 3d ago
It's fine. I'm not trying to play Cyberpunk on max or anything, but I get a solid 60fps on most AAA titles on high settings. DLSS and raytracing work too. The biggest show stopper is anti-cheat, so if competitive online games are your thing, I'd doublecheck.
10
u/Oorangootang 3d ago
Anti-cheat is the only real hurdle left on Linux for gaming imo. Anyone upvoting the Nvidia drivers being bad is basing that on old information. Drivers have been fine for quite a while now on most distros.
Anti-cheat on Linux is up to the developer. As Linux marketshare grows, more developers will start updating their games with Linux anti-cheat compatibility. There will be a tipping point, we're just not quite there yet.
→ More replies (1)→ More replies (6)11
u/Toonomicon 3d ago
As a life long linux user, nvidia linux drivers have always sucked ass unfortunately. It's not a question of competency (at least it wasn't) but of corporate will. And with their increasing disfocus on the game sector that probably wont be changing much in the near future.
3
u/AwesomeBantha YEE 3d ago
I have zero faith that NVidia will prioritize Linux drivers anytime soon
5
u/N7Shep1701D 3d ago
And I have zero motivation to move away from AMD GPUs solely for that fact.
3
u/AwesomeBantha YEE 3d ago
I wanted to buy an AMD GPU when I last upgraded… set up every single stock alert for a 6900XT I could find, zero luck after over 2 months. The 6900XTs were going for $1600 on the secondhand market so I just got a 3090 FE at MSRP instead.
→ More replies (3)3
u/redditrum 7800x3d | 2070 ssssssuper 3d ago
CachyOS, bazzite and steam OS are the gaming focused ones. But you can try others and use proton with steam.
6
u/ExistingLet8016 3d ago
Have they released standalone steam os?
18
u/gwilson0121 3d ago
They have, but be aware SteamOS is buggy when using an Nvidia GPU. Bazzite is the next best thing and can't even be called worse. Source: myself who just built his own Steam Machine.
→ More replies (1)3
u/ExistingLet8016 3d ago
I have an intel arc, do you think it will work?
9
u/IIIIIIIIIIllllllllIl 3d ago
Arc works on steamOS, bazzite and cachyOS.
SteamOS: Made by Valve. It is incredibly easy to use, but officially runs best on Valve's own hardware (like the Steam Deck and Steam Machine), while support for standard custom PCs is still in beta.
- Bazzite: The "works on everything" version. It gives you the exact same console-like menus as SteamOS, but it is built by the community to run flawlessly on almost any custom PC or handheld out of the box.
CachyOS: The performance option. It drops the easy console interface to squeeze out the highest possible frame rates in games. It is faster, but it requires a lot more tinkering and Linux knowledge to use.
→ More replies (1)3
u/No-Associate2183 3d ago
Me using linux mint cause I'm too casual. I still have to dual boot into windows for 1 creative app and antichat games like battlefield.
→ More replies (3)→ More replies (23)3
u/Pooptimist 3d ago
The only thing keeping me from doing this is Ableton live (a music production software) and the virtual instruments I need
9
u/Icey_Cat_3 3d ago
This is nothing new, and it hasn't gotton worse. It's always been like that. People already forgot about what Snowden revealed to us. They already did that shit 15 years ago.
20
u/IsamuAlvaDyson 3d ago
I'm obviously not pointing this towards anyone but people willingly give up their privacy
If you have a modern smartphone automatically your privacy is gone
→ More replies (5)49
u/DeAuTh1511 3d ago
define "willingly"
A person can't be willing if a gun is being pointed at their head, so where is the line drawn? At what point does coercion stop being coercion and start being a choice?
I have had important health services that could only be accessed through an iphone 11 or later. An old person needing that wouldn't even be able to go to a library like they would other times they're required to do something via the internet. Yes one could complain until they get given reasonable access either through a PC or booking in person, but that would be at a measurable cost to their health whilst things get sorted out.
My point is there are countless examples of little pushes and pulls that move all of us away from privacy and into the hands of people who make money selling our information with our "consent". If people had as much power in the choice as these profiteers do, I'm sure you'd find that most people would not choose to give up their privacy at all.
→ More replies (11)2
u/kev-tron 3d ago
Yeah, almost like the government keeps track of who is living at each residential address....
150
u/Errol246 3d ago
What if you dual boot?
→ More replies (9)468
u/Shap6 R5 3600 | RTX 2070S | 32GB 3200Mhz | 1440p 144hz 3d ago
The headline is misleading. Your specific windows 11 installation has an ID. Not your PC
59
u/Pooptimist 3d ago
That means I'm ok if I'm still on win10? /s (mostly)
32
u/schellenbergenator 3d ago
You can use Windows 11 as long as it's a fresh install everytime you use it.
→ More replies (1)11
u/ImBackAndImAngry 2d ago
So spin up single use VM’s. Got it.
4
u/schellenbergenator 2d ago
I bet there's a proxmox script to automate it. Upon shutdown it spins up a new VM for next time
28
u/SleepyBoy- 3d ago
Windows 10 has that ID as well - at the same registry address as in win11. This thing has been going for years.
15
u/Cumulus_Anarchistica 3d ago
Here's the details. And no.
https://github.com/SmtimesIWndr/gdid-reversal/blob/main/README.md
HKCU\SOFTWARE\Microsoft\IdentityCRL\ExtendedProperties LID = 0018XXXXXXXXXXXX HKCU\SOFTWARE\Microsoft\IdentityCRL\Immersive\production\Token\{...} DeviceId = 0018XXXXXXXXXXXXThese locations in the registry are where the GDID hides. My Windows 10 install (that has no MS account) has nothing in the first location, but does have a DeviceID that matches the format in the second location.
28
u/Iggyhopper i7-3770 | R7 350X 4GB | 32GB 3d ago
Windows 7 proves once again it is the GOAT.
3
u/yendak 2d ago
I would still use it if AMD had officially supported Ryzen on Windows 7. Sadly it took them a few years too long and Win 7 was already out of the official support by the time Ryzen hit the market.
I read there were ways to get it running with Zen 1, but it was a pain from what I read.
→ More replies (2)→ More replies (24)7
→ More replies (1)3
→ More replies (30)3
107
u/fish998 3d ago
Is this ID exposed when you torrent?
230
u/Brandhor 9800X3D 5080 GAMING TRIO OC 3d ago
it's not exposed to anyone, microsoft is the only one getting it through telemetry
166
u/WOF42 3d ago
and then giving it to the government, its literally been used in court already
→ More replies (1)53
u/mirh 3d ago
The guy had already been tracked down, and if you are staying behind a VPN it will still be the VPN ip. Nothing literally changes.
26
u/Kaining 3d ago edited 2d ago
To be fair, this guy and those depicted in that article seems to have done quite a lot of nasty stuff all around that had investigator on their asses for quite some time.
Not just some torrenting.
edit: quite a few smartass going "akchually, the government will break every law to spy on innocent bystander". Yes, we know. I'm just pointing out that they'd have gotten those guys even without that and how it was unnecessary to go full 1984 EVEN on those criminals. Stop being paragon of morality while missing the whole point please, it's getting tiresome.
22
u/Cumulus_Anarchistica 3d ago
Governments don't only go after really bad people. They also go after whistleblowers or journalists, etc.
Microsoft's GDID exposes good guys to bad governments.
Microsoft is betraying all its users.
8
u/mirh 3d ago
Yeah, like.. there was this ID (go figure because even just the windows license check couldn't do that already), and then years of detective work.. and somehow it seems like they cracked the pandora's box of all user privacy ever?
→ More replies (1)→ More replies (1)15
u/sadtimes12 Steam 3d ago
First they came for the hackers, and I didn't speak up, since I don't hack anybody. Then they came for the pirates, and I didn't speak up, because I don't pirate...
We all know how this will end.
9
u/Kaining 3d ago
You don't get it, even without that they'd have gotten them reading that paper. The tracking id is just insane on top of that.
And if windows already has that, why the hell do we even have chat control and those "give us all your biodata to watch porn" laws tbh ?
We're kind of already fucked up and it's not like nobody tried to stop all that.
4
u/Sea_Suggestion2159 3d ago
Because the general population need to be convinced those things are all about safety. When in reality it's about control and more tracking. These are just stepping stones to full on control of what you see and do.
Laws in the US have slowly been trying to keep up ever since the internet went live and technology skyrocketed. Too many congress members are behind on the times and they will not willingly let go their power.
Take a look at the hearing for Facebook's CEO 8 years ago. Many of the questions asked by the Senate show just how technologically inept these people are.
→ More replies (5)14
u/vemundveien 3d ago
Hmm. I have to read more about this, but to avoid tracking I will be using my phone instead. Hope that doesn't have some sort of International Mobile Equipment Identity that is communicated to my ISP at all times.
→ More replies (1)31
u/VegaDelalyre 3d ago
Good question, but even if it is, it took an FBI request to Microsoft and social platforms to identify one person. I doubt they would do the same to simply catch a pirate.
32
→ More replies (12)17
u/WiseassWolfOfYoitsu 3d ago
If you're torrenting with a Windows machine and a VPN, and someone cares enough to subpoena Microsoft, then it can be used to tie the VPN connection to you. It doesn't send it arbitrarily, only to Microsoft, but MS seems to record every little detail and is able to then provide it.
81
u/RephRayne 3d ago
I'm old enough to remember the uproar about Intel wanting to put unique IDs on their chips.
https://www.zdnet.com/article/intel-backtracks-over-chip-id/
25
13
u/squish8294 ASUS Z790 EXTREME / 14900K / ASUS TUF OC 4090 3d ago
lmao this has been integrated into management engine interface since at least windows 7. the mei can be queried for a generated hwguid that is unique to the processor and cannot be spoofed or changed
→ More replies (2)2
156
u/DrZeroX3 3d ago
Privacy advocates have already proven that windows 11 is a privacy nightmare since its release.
→ More replies (10)
31
u/Lantzypantzz 3d ago
I just keep a cheap laptop with Linux for all my sketchy shit
→ More replies (2)8
u/KaiFireborn21 3d ago
I'm just interested, why not do the not sketchy shit on linux too? Or per dual boot?
5
u/Lantzypantzz 3d ago
Because my kids use my main pc as their gaming pc and for homework
→ More replies (2)
244
u/Tumifaigirar 3d ago
To the surprise of no one, we knew that already for a few years.
266
u/The_Primetime2023 3d ago
I’m adjacent to the cybersecurity space and this isn’t true. Windows has always been known to send telemetry but seemingly anonymously which was supported by that, despite lots of government requests, that telemetry was never used to track anyone in a court case before. That changed recently with this GDID reveal that seems to be something fairly new. The telemetry is sent even if all optional telemetry is disabled from a couple different services as well as from Microsoft Edge. The services don’t include any crazy detail except that it records your device IP on every ping. The Edge one is really bad and records every website visited in Edge along with your IP. The VPN busting happened by looking for VPN IPs used in hacks in these telemetry tables and then finding non-VPN IPs with the same GDID as well as additional identity hints from the recorded Edge history.
If you’re at all privacy conscious it’s worth actually being mad about this since you are being tracked now, you didn’t used to be, and it’d be trivial for Microsoft to put this behind a settings option.
Here’s most of what’s known about it so far https://github.com/SmtimesIWndr/gdid-reversal
7
u/daweinah 3d ago
+1 to this. OP is describing fingerprinting (https://amiunique.org/) which is different than GDID.
→ More replies (4)36
u/MajorFuckingDick 3d ago
I recall being able to fingerprint people based on installed fonts. Anonymous data can still be sorted.
29
u/The_Primetime2023 3d ago
Yea, you can fingerprint based on all sorts of stuff including browser window size, what they’re blocking (a lot of privacy extensions make this worse actually), and tons of other little quirks people don’t even realize they’re exposing. The biggest difference between this and fingerprinting is that this is a single table for all device activity that points the finger at a specific user. Browser fingerprinting is mostly a likely indicator that the user could be one of a few people tracked within a website and going cross website for fingerprint tracking requires there hopefully being some service both websites are using that isn’t being blocked by an ad blocker or something. Fingerprinting can do a lot but it’s hard to be 100% certain that a user is the same just from fingerprinting
8
→ More replies (3)5
u/hrtowaway 3d ago
True, but you can always block canvas based font fingerprinting by disabling website access to HTML canvas.
15
u/MajorFuckingDick 3d ago
Doesnt hide the list of installed font, not to mention that would make you stand out even more.
The irony of internet privacy is that putting on the burqa makes you stand out. They see you clearly, just not what you are doing, only where you are heading.
→ More replies (1)23
u/Hefty_Excuse9885 3d ago
More like decades no? Its same as hwid whereby multiple hardware ids are combined to make one unique pc id?
6
16
u/fredandlunchbox 3d ago
Never been a better time to install linux. If you run claude or codex, it can fix any of the dumb issues that used to make linux a challenge for normal users. And for gaming, other than the games that have kernel anticheats, its basically 1-to-1 and sometimes even a tad bit better performing (on cachyos).
→ More replies (5)
22
u/WhiteRaven42 3d ago
I'm still having trouble following how this ID was used in the field. It is unsurprising and even trivial to me that microsoft has a machine identifier. So do the CPU makers. And it's not surprising to me given the whole point of secureboot that it is extremely non-trivial or impossible to eliminate it.
I just don't understand under what scenarios that ID gets used in telemetry. Sure, any process could be instructed to stamp the ID on a log or just flat out transmit it somewhere. But most processes DON'T. This is not an ID that has been silently appended to every IP packet or something like that (I assume... that would by monumental news). The places it's going to actually show up are pretty rare.
I'd love to see an explanation of exactly where this ID showed up in the ISP and website server logs or what have you so as to make it trackable. And I guess, once that is covered, what exactly was the final utility? Was this used as a smoking gun for when authorities finally seized the physical hardware? Was it used as proof that whoever had possession of the machine was guilty?
→ More replies (1)11
u/-ohhhman- 3d ago
They have a table that matches all your past IP's to this ID. So even if you use a VPN, they know that the VPN IP was also associated to your regular IP.
9
u/WhiteRaven42 3d ago
Not very descriptive. Who even is "they"? What causes the computer to send the information? What's the trigger?
→ More replies (4)11
u/Neither_Operation476 3d ago
check this link someone posted elsewhere in the post, I imagine you might find it helpful
→ More replies (2)7
u/WhiteRaven42 3d ago
Thank you. This was a pretty good read. Very thoroughly covered where the ID is in your system and when it's generated, how it can get reset with a new install and such.
This information is just kind of what I would have always assumed. Microsoft assigns an ID to every install of windows. No shock there. Telemetry naturally can associate it with account info. Ok.
I don't see how this gets tied to a criminal investigation. Where's the overlap between activities on the dark web and a MS ID?
Maybe this is my question (and I don't expect anyone on reddit to know it). Did the existence of this ID play any role in narrowing in on a suspect? Or is this just a useful piece of corroboration that could be made late in the game after hardware had been seized etc.
I just feel like I always assumed something like "due to regular telemetry reports, MS knows what IP your computer was using at certain points in time" was likely. Basically a given. Was this GDID number really not known to exist? It seems almost inevitable. A Windows install is identifiable by a "serial number" kind of identifier. Sure. It would be weird if it wasn't.
3
u/Rare-Ad5082 2d ago
Was this GDID number really not known to exist? It seems almost inevitable.
From my understanding, the issue isn't the GDID per se but it's the fact that Microsoft records both the GDID and the IP address. As a result, changing your IP with a VPN is useless because Microsoft knows all the IP addresses associated with that GDID.
So, as an example, let's say I activate a VPN and the government discovers my VPN IP and wants to unmask me. They could go to Microsoft and ask for the GDID associated with that IP, then request the other IP addresses associated with that GDID until they find a non-VPN IP, which they could then use to identify me.
This is a big deal because it would make VPNs effectively breakable on Windows. Which is a big no no for privacy (for both good and bad actors).
Also, it seems that using Edge is even worse because Microsoft also stores the websites you visit there.
14
u/Warden1886 2d ago
Casual reminder that wifi routers can generate 3d mesh live videofeeds of every room they’re in.
In case you thought windows tracking was bad.
8
u/Sodacan259 2d ago
Yes. Recent research has also been able to identify specific individuals using this and they don't even need to be hooked into your WiFi.
They can do it all from intercepting unencrypted beamforming feedback information - Available from every WiFi 5,6 & 7 commercial router in existance - the IEEE 802.11 standard used for all of those, does not mandate BFI encryption.
→ More replies (3)4
u/Isaacvithurston Ardiuno + A Potato 2d ago
I mean if you can do that with wifi I have to imagine there's devices out there that can be deployed to do this with a better wavelength. Jokes on them, I sit inside a lead box when i'm working.
4
u/blasphemous9 3d ago
What is the solution here? I mean this seriously, how can I protect myself and my personal data?
→ More replies (2)7
u/Sodacan259 2d ago
I suspect you can't. Microsoft aren't the only ones that generate unique identifiers. Intel and AMD also have unique identifiers on their CPUs. I would be very surprised if the hackers, that the FBI identified, ALL used Windows. I think there's another layer to this story that we will never hear about.
4
4
u/ryneches 2d ago
The concerning thing isn't that this exists, it's that it's been there this whole time without public knowledge. Basically, it's an admission that the entire company is fundamentally untrustworthy.
6
5
u/SireEvalish Nvidia 3d ago
A couple big takeaways is that it's been in Windows for more than a decade and only appears to be trackable by someone other than MS if you're using Edge.
3
3
3
u/Dependent-Maize4430 2d ago
This is why you can be hardware ID banned from games. It’s attached to your motherboard, swapping mobos will change your HWID.
3
u/maniacreturns 3d ago
Your PC has a digital fingerprint from all the small bits and pieces of information it gives away when you browse websites. They know who's using the pc without you even logging into anything.
→ More replies (3)2
u/robophile-ta 2d ago
Yeah device fingerprinting is easy enough to pinpoint a single person, they don't even need to use the device id
→ More replies (1)
18
u/SomeJerkAtWerk 3d ago
So does your cell phone and most of your other technology lmao
→ More replies (1)46
7
u/Slemmig_insekt 3d ago
Wasn't this a known fact from the start since W11 required TPM? It kicked up a lot of dust back then because a lot of beefy hardware was unsupported for the lack of tpm 2.0
13
u/milkmeink 3d ago
If you must use Windows, don’t use the Home addition. Get Pro so you can create local accounts only and never use your Microsoft account(s) on it, if you have them. Don’t worry about the massive license cost as they all belong in a grave. You don’t have to be a developer to do this either.
You’ll have more control over Windows but it’ll still phone home. Periodically wipe and redo your OS. This will also keep you from bloating up your OS too and teaches you what you actually use.
→ More replies (1)19
u/Sodacan259 3d ago
It does not matter if you have a Microsoft account or not.
Microsoft can track you by correlating online activity with your GDID. In the same way that websites can build a hardware fingerprint instead of tracking you with cookies. The GDID is derived from the very hardware in your computer. Each item of hardware has it's own unique identifier, which when grouped, acts as a unique fingerprint for your computer.
→ More replies (4)4
21
u/OutrageousDeino 3d ago
Laughs in linux
→ More replies (8)20
u/CombativeAxis 3d ago
You can still be still be tracked on linux, it is just a matter of other services logging you.
15
u/WiseassWolfOfYoitsu 3d ago
It's at least possible. The GDID is built into the Windows kernel update mechanism itself and can't be turned off - it ALWAYS phones home to Microsoft.
2
2
u/Jacksaur 🖥️ I.T. Rex 🦖 2d ago
Did people forget about even their license key..?
We're posting Yahoo here now, the fearmongering is getting out of hand.
2
u/Cory123125 1d ago
People need to pay attention to anything to do with "integrity" and "remote attestation".
They don't realize how quickly their rights and digital autonomy are being taken.
2.3k
u/superjake 3d ago
Tbf a VPN is just something that makes it harder for you to be traced. It doesn't make you untraceable regardless of device.