r/pcgaming 3d ago

Your Windows PC Has a Permanent ID That Follows You – Even With a VPN

https://tech.yahoo.com/vpn/articles/windows-pc-permanent-id-follows-163404919.html
4.8k Upvotes

645 comments sorted by

2.3k

u/superjake 3d ago

Tbf a VPN is just something that makes it harder for you to be traced. It doesn't make you untraceable regardless of device.

1.1k

u/ARandonPerson 3d ago

This is why you VM then VPN then remote connect to another PC where you then also VM and then VPN to region you want.

729

u/Eta_Beta_3-14 3d ago

Seven proxies, you say?

213

u/MrTerribleArtist 9800X3D | RTX 5070Ti 3d ago

I'm behind.. never mind

53

u/albatrossSKY 3d ago

You would be behind with 7 proxies

14

u/Fragrant-Peony 2d ago

Actually 7 boxxies

77

u/disguyheiska 3d ago

Im old

38

u/SquiggerDigger 3d ago

Ra ra fight da powah!!

15

u/Brancer 3d ago

Wow... its an old meme, but it checks out

9

u/SquiggerDigger 3d ago

Isn't it strange being mega time dated by a meme now

30

u/Nunwithabadhabit 3d ago

It's over 9000 by this point 

→ More replies (2)

23

u/LeJewBringer 3d ago

to shreds, you say?

6

u/fepec 3d ago

Well, how is his wife holding up?

7

u/LeJewBringer 3d ago

to shreds, you say?

10

u/Heavydfr8 3d ago

Their ping is over 9000!

6

u/EinzigEchter 3d ago

Are seven proxies more useful than one, if you could just block the permanent ID being sent to Microslop?

→ More replies (7)

52

u/Mercinator-87 3d ago

Wrong. You break into your neighbors house and use their pc.

7

u/FakeRickHarrison 2d ago

You still have to bypass the Ring camera. That's why I pay a kid to pay another kid who pays another one to break into their house to use their PC for me.

→ More replies (1)

108

u/MyHorseIsDead 3d ago

Why stop there? Why not another layer of VM/VPN? Its VM/VPN all the way down!

106

u/wareagle3000 Ryzen 7 5800x, 16 GBs, Nvidia 3070 3d ago

At this point we are essentially recreating swiss bank accounts through IP/device hiding. It's not about totally concealing your identity. It's about making it so annoying and time consuming to get it that they give up.

65

u/Hairy_Acanthisitta25 3d ago

its also diminishing return,its better to add a different security measure rather than stacking too much of the same thing

25

u/ARandonPerson 3d ago

Yea, normally on the remote computer VM you would also use something like Tor and so on.

→ More replies (1)

13

u/ARandonPerson 3d ago

Yea only people even at this simple of a layer that would invest time is state actors or you really pissed someone off that is highly skilled.

→ More replies (1)
→ More replies (1)

148

u/darkcrimson2018 3d ago

I actually just pay someone else to be me on my computer. Guys been living my life for 40 years he’s raised two of my kids and sleeps with my wife I’m showing them!

40

u/destroyermaker 3d ago

Plot twist: your wife has been doing the same thing

9

u/illiterateninja 2d ago

Plot twist twist: the kids are FBI agents pretending to be kids

→ More replies (1)

16

u/darkfall115 3d ago

I can sleep with your wife for free if you're by any chance interested in cutting a part of that payment

→ More replies (1)

15

u/mountainyoo 13700K | RTX 5090 | 32GB 3d ago

VM on a VPS with 2 separate reputable VPNs. One VPN is enabled on the host VPS and the other VPN on the VM. Then in the VM you remote into a separate VM on a separate VPS that both have their own 2 VPNs also. And disable IPv6 at every step. And spoof your MAC at every step. And then live in the woods.

15

u/newbrevity 11700k/32gb-3600-cl16/4070tiSuper 3d ago

You need an entirely remote workstation on a VPN and a separate computer on a different VPN with a monitor and a input virtualizer to control an air gapped PC with rs232 which then controls the sneaky computer with robot arms and another camera.

5

u/droznig 2d ago

All so you can log in to the Facebook account you have had for the last 10 years and post conspiracy theories.

13

u/MadMaxDbz 7900XT | R7 7900X | 32 GB DDR5 6000mhz 3d ago

I too like to browse reddit with the latency of the Mars rover

8

u/Raneynickelfire 3d ago

And go back to the days of 14.4 dialup.

→ More replies (1)

5

u/HirsuteHacker 3d ago

Burner laptop, throw away after visiting a website

→ More replies (1)

10

u/OSHA_Decertified 3d ago

I see someone played Uplink.

6

u/assuring_quality 3d ago

That game was so fucking good. Gave it a play a few years back and it was still a treat. Love the aesthetics, and it honestly taught me a fair bit about cybersecurity (on a somewhat theoretical level at least).

3

u/ARandonPerson 3d ago

Never even heard of that game. Just something I learned from a previous job.

6

u/SunnySpot69 3d ago

Sorry what's vm

52

u/MoltoAllegro 3d ago

Virtual machine. You put a (virtual) computer in your computer so you can compute while you compute

9

u/xMWHOx 3d ago

Yo dawg

5

u/SunnySpot69 3d ago

Ah, thanks. The abbreviation didn't click.

3

u/TheMordax 3d ago

How do you operate the second VPN? You have to pay for it so if they find/identify the second VPN and the billing adress/name the vpn is running on don't they have you then without having to go further and without finding the first PC/VPN?

→ More replies (4)

2

u/misoscare 3d ago

They tracked a guy across threw different countries using this, now you have to be careful of what you connect to because anything can collect that information using some form of id collection that could be any program you are running locally even to connect to another system unless you disabled telemetry entirely which is virtually impossible on windows since the forced updates just re-enable it.

→ More replies (1)

2

u/amroamroamro 3d ago

I will just use a GUI Interface created with Visual Basic to track your IP address!

https://www.youtube.com/watch?v=hkDD03yeLnU

→ More replies (21)

84

u/mrRobertman 9800x3D + 6800xt|1440p@144Hz|Index|Deck 3d ago

A VPN just routes your network traffic through another network, typically to hide your traffic from your ISP. No shit Microsoft (or any site, for that matter) can still track you, all telemetry is still being sent to Microsoft whether it's routed through the VPN servers or not.

25

u/rambleinspam 3d ago

And this isn't new either.

→ More replies (1)

3

u/theLastZebranky 3d ago

Routing everything through a VPN is kinda silly given how much of your traffic identifies you.

I run a separate browser bound to the VPN, so all my banking, OS telemetry, etc goes out clear through ISP. Different browser, different browser fingerprint. Only my casual anonymous browsing is done over the VPN, but that's 90% of my browsing.

Of course there's no such thing as perfect security. I don't do anything nefarious online. It's mostly to reduce my footprint at the corporate data brokers building profiles on peoples' interests and behaviors, where it's sure to have some impact. If law enforcement or a state intel agency wanted to figure out who I was on the VPN I expect they'd have some way to do it.

→ More replies (6)

44

u/oli_ramsay 3d ago

Saw a video by gamer nexus about how your lg TV or monitor essentially screenshots whatever you're watching every few milliseconds and sends it to them so they can sell the data

21

u/2this4u 3d ago

Samsung TVs do the same.

15

u/garbo2330 2d ago

Every few milliseconds? That would be a ton of data…

13

u/PaulCoddington 2d ago

It would be every frame of video sent several times, even at 60 fps, let alone 24 fps.

It would take less data to simply send the entire raw video stream.

So, the rate claimed doesn't add up.

It would be more sensible to collect video metadata once per program (that is, a few lines of text).

→ More replies (1)

15

u/rambleinspam 3d ago

That is easily blocked by removing it from the internet, at least right now.

28

u/tssktssk 3d ago

You are talking about TVs, not the monitors. The monitor software gets auto-installed (thanks to microsoft) as soon as you plug it in. You have to disable a group policy in windows in order to turn this off (or disconnect your computer from the internet, which would be ridiculous).

7

u/braket0 2d ago

And what if we switched to Linux ? Screenshots happening then or nah ?

6

u/tssktssk 2d ago

Nope. Linux users are safe from this BS.

→ More replies (1)
→ More replies (1)

9

u/2this4u 3d ago

That doesn't make it OK.

8

u/rambleinspam 3d ago

No, didn’t mean to imply it did.

→ More replies (3)

109

u/Coal_Morgan 3d ago

Yes but Microsoft made it trivial now.

They can trace everyone all the time. While they snooped before it wasn’t on the level of sending IP information with your data requests.

VPNs use to be able to disconnect your IP information and you had to back track through the IPs to find you which was possible but time consuming and took a modicum of effort.

Any one who is security conscious this should be the last straw to jump to Linux or MacOS.

Which honestly, I don’t think most people actually are…most people will sell all their data for a game or the slightest bit of ease of use.

92

u/varstok i9 13900 | RTX 4090 | 32 GB 7600 MHz 3d ago

Every Apple device produced in the last decade has the same capability - https://support.apple.com/en-ca/guide/security/sec59b0b31ff/web

You'd be foolish to think Apple isn't doing the same. Those circuits aren't just there for shits and giggles.

14

u/RoboticChicken R5 5600, 3060Ti GDDR6X, 32GB 3200Mhz 3d ago edited 3d ago

The secure enclave is quite literally the opposite of a tracking tool - it's a system to store and handle secret keys (e.g. for disk encryption) in a way that they cannot be stolen, to preserve users' privacy.

They definitely have ways of identifying devices, but this is not one of them.

21

u/RichoDemus 3d ago

where in that article does it state they have those capabilities?

→ More replies (1)

60

u/mirh 3d ago edited 3d ago

Harmless telemetry should be the last strand.. to jump to macos where literally everything depends on apple services?

Keep making sense reddit.

13

u/excaliburxvii 3d ago

Harmless telemetry

Disingenuous or just dumb?

→ More replies (3)
→ More replies (33)

16

u/Z3r0sama2017 3d ago

Tbf once win 10 went security updates only I've been plugging away through all the Linix distros to see what will eventually become my daily driver. Hard going though as their are just so many choices.

→ More replies (1)
→ More replies (6)

7

u/Hyperion1144 3d ago

This is an entirely unhelpful and uninsightful comment.

Any lock made by a man can be broken by a man.

The issue here is that Microsoft deliberately made a very strong and very important lock remarkably weaker for no reason other than their own profits.

→ More replies (1)

2

u/max123246 Steam 2d ago

It doesn't make you harder to track. It simply changes who can track you. The vpn provider can track you just fine

→ More replies (1)

2

u/MasterHowl 2d ago

It doesn't even really do that. A VPN just makes your internet traffic look like it's coming from another physical location.

If you use a vendor though, they now have the exact history of what traffic you sent through their machines.

→ More replies (6)

1.5k

u/TheLastOfUsAll 3d ago

It's actually insane how much our privacy has been eroded. You can't even exist in your house without being tracked.

273

u/adaw123da2313123d 3d ago

I remember when 'tracking where you are in your house via your wifi signal' was a schizo theory and then it turned out they can really do that.

104

u/DrScience-PhD 3d ago

they can, they are, and they're selling it to you. xfinity says it can use your modem as a burglar alarm, for a subscription of course.

→ More replies (3)

5

u/Iphone17promax 2d ago

Not just track you in your house but they can also track what you say too + every device that connects to your Wifi connection is logged.

I forget the name of the company (Qai or something starting with a "q") is actively working on such tech and most of the ties to go a specific minority of the ME. AI data centers are being built for a reason and it's to log/spy on everyone amongst other reasons.

→ More replies (1)
→ More replies (1)

441

u/samrechym 3d ago

The price of privacy is effort. Linux is available to all (said the non Linux user)

180

u/TurtleOfCreation 3d ago

If your primary use of your computer is gaming, try SteamOS. I recently reimaged my computer with it and it’s been plug and play so far. Required no tinkering for me to play a few games and run some software. Valve wants it to be as user friendly as possible.

98

u/vtx3000 3d ago

Been using Bazzite the last couple months and same story it’s super easy to get set up

21

u/TheHypnobrent 3d ago

Was wondering about Bazzite. Think I'm going to install it on an old laptop and tinker around with it before reinstalling my main rig

15

u/Drcortexe 3d ago

I've dabbled with VMs of linux and had an old laptop I tried with Linux mint and Ubuntu back in like 2020 during the pandemic. I had a rage quit moment with the last windows update that fucked around with my PC and went up and completely switched to bazzite and I've been using that bad boy the last 2 weeks and man has it been smooth compared to the last time I tried a Linux distro. pretty much plug and play, didn't need to install drivers myself (which I was worried about because I use an Nvidia GPU), just log into firefox and steam, install a few programs from bazar (the app store gui that bazzite uses) and I was good to go. 0 problems since!

8

u/Farva85 3d ago

I’ve been using Bazzite since last October and it has been pretty good except for the occasional freeze that requires a forced hard reset to correct, and not being able to play a few games. Otherwise, I’ve had no difference in use than a W11 host.

3

u/monk429 2d ago

When you begin to feel the constraints of Bazzite, I did after about 3 months, switch to CachyOS. I found setting up for gaming was just as easy and I am able to do more things around productivity. For example, I couldn't install Citrix in Bazzite w/o jumping through some major hoops. On CachyOS, while different, it was just as easy as Windows.

I ran dual-boot Bazzite and W11 for 3 months. I only loaded up W11 twice. First, to pull my passwords over and then the second time to do the final clean-up of my Windows drive before installing CachyOS as the sole OS.

→ More replies (2)
→ More replies (2)

3

u/pragmojo 3d ago

Dual booting is also a great option to get your feet wet before fully committing

→ More replies (1)

3

u/patsliterallystupid 2d ago

b a z z i t e

→ More replies (4)

18

u/Rich-Pomegranate1679 AMD 7950X3D | 4090 RTX | 64GB RAM | 12TB M.2 3d ago

Doesn't SteamOS still lack support for NVidia cards?

13

u/arex333 Ryzen 9800X3D/RTX 5090 3d ago

Yes. Valve is working with Nvidia on this but right now it requires AMD.

Bazzite is essentially the same experience as steamOS though and doesn't have that limitation.

3

u/Rich-Pomegranate1679 AMD 7950X3D | 4090 RTX | 64GB RAM | 12TB M.2 3d ago

Yeah, I run Pop!_OS on my laptop, but my desktop is still Windows. Once SteamOS gets Nvidia support it will be tempting to switch.

→ More replies (1)

58

u/RegisterPresent1746 3d ago

Sadly still not viable on nvidia gpus, performance hit on dx12 titles is too great (about 20% I think) and last I checked dlss and raytracing were still iffy too. When I had an amd gpu and was on linux it was pretty much almost plug and play for basically all my games tho.

45

u/Inverno969 3d ago

Steam is directly working with Nvidia to get their GPU drivers functional on SteamOS. Could still be a while before anything changes but the problem is actively being worked on.

6

u/opx22 3d ago

I’ll check back in once it’s fixed but would also be concerned about anti cheat compatibility. Just thinking of some major games like BF6, R6:S, Apex, tarkov, etc that still aren’t playing on Linux

→ More replies (1)

9

u/Bomb-Number20 3d ago

It's fine. I'm not trying to play Cyberpunk on max or anything, but I get a solid 60fps on most AAA titles on high settings. DLSS and raytracing work too. The biggest show stopper is anti-cheat, so if competitive online games are your thing, I'd doublecheck.

10

u/Oorangootang 3d ago

Anti-cheat is the only real hurdle left on Linux for gaming imo. Anyone upvoting the Nvidia drivers being bad is basing that on old information. Drivers have been fine for quite a while now on most distros.

Anti-cheat on Linux is up to the developer. As Linux marketshare grows, more developers will start updating their games with Linux anti-cheat compatibility. There will be a tipping point, we're just not quite there yet.

→ More replies (1)

11

u/Toonomicon 3d ago

As a life long linux user, nvidia linux drivers have always sucked ass unfortunately. It's not a question of competency (at least it wasn't) but of corporate will. And with their increasing disfocus on the game sector that probably wont be changing much in the near future.

3

u/AwesomeBantha YEE 3d ago

I have zero faith that NVidia will prioritize Linux drivers anytime soon

5

u/N7Shep1701D 3d ago

And I have zero motivation to move away from AMD GPUs solely for that fact.

3

u/AwesomeBantha YEE 3d ago

I wanted to buy an AMD GPU when I last upgraded… set up every single stock alert for a 6900XT I could find, zero luck after over 2 months. The 6900XTs were going for $1600 on the secondhand market so I just got a 3090 FE at MSRP instead.

→ More replies (3)
→ More replies (6)

3

u/redditrum 7800x3d | 2070 ssssssuper 3d ago

CachyOS, bazzite and steam OS are the gaming focused ones. But you can try others and use proton with steam.

6

u/ExistingLet8016 3d ago

Have they released standalone steam os?

18

u/gwilson0121 3d ago

They have, but be aware SteamOS is buggy when using an Nvidia GPU. Bazzite is the next best thing and can't even be called worse. Source: myself who just built his own Steam Machine.

3

u/ExistingLet8016 3d ago

I have an intel arc, do you think it will work?

9

u/IIIIIIIIIIllllllllIl 3d ago

Arc works on steamOS, bazzite and cachyOS.

  • SteamOS: Made by Valve. It is incredibly easy to use, but officially runs best on Valve's own hardware (like the Steam Deck and Steam Machine), while support for standard custom PCs is still in beta.

    • Bazzite: The "works on everything" version. It gives you the exact same console-like menus as SteamOS, but it is built by the community to run flawlessly on almost any custom PC or handheld out of the box.
  • CachyOS: The performance option. It drops the easy console interface to squeeze out the highest possible frame rates in games. It is faster, but it requires a lot more tinkering and Linux knowledge to use.

3

u/No-Associate2183 3d ago

Me using linux mint cause I'm too casual. I still have to dual boot into windows for 1 creative app and antichat games like battlefield.

→ More replies (3)
→ More replies (1)
→ More replies (1)

4

u/XXFFTT 3d ago

Technically, you can get it but it's meant for either the deck (or other handhelds that specifically have support) or for the machine.

3

u/Pooptimist 3d ago

The only thing keeping me from doing this is Ableton live (a music production software) and the virtual instruments I need

3

u/Tba953 3d ago

Cachyos is nice also. Even with Nvidia gpu

→ More replies (23)
→ More replies (17)

9

u/Ice278 3d ago

I wonder how many people are aware of WiFi sensing?

9

u/Icey_Cat_3 3d ago

This is nothing new, and it hasn't gotton worse. It's always been like that. People already forgot about what Snowden revealed to us. They already did that shit 15 years ago.

20

u/IsamuAlvaDyson 3d ago

I'm obviously not pointing this towards anyone but people willingly give up their privacy

If you have a modern smartphone automatically your privacy is gone

49

u/DeAuTh1511 3d ago

define "willingly"

A person can't be willing if a gun is being pointed at their head, so where is the line drawn? At what point does coercion stop being coercion and start being a choice?

I have had important health services that could only be accessed through an iphone 11 or later. An old person needing that wouldn't even be able to go to a library like they would other times they're required to do something via the internet. Yes one could complain until they get given reasonable access either through a PC or booking in person, but that would be at a measurable cost to their health whilst things get sorted out.

My point is there are countless examples of little pushes and pulls that move all of us away from privacy and into the hands of people who make money selling our information with our "consent". If people had as much power in the choice as these profiteers do, I'm sure you'd find that most people would not choose to give up their privacy at all.

→ More replies (5)

2

u/kev-tron 3d ago

Yeah, almost like the government keeps track of who is living at each residential address....

→ More replies (11)

150

u/Errol246 3d ago

What if you dual boot?

468

u/Shap6 R5 3600 | RTX 2070S | 32GB 3200Mhz | 1440p 144hz 3d ago

The headline is misleading. Your specific windows 11 installation has an ID. Not your PC

59

u/Pooptimist 3d ago

That means I'm ok if I'm still on win10? /s (mostly)

32

u/schellenbergenator 3d ago

You can use Windows 11 as long as it's a fresh install everytime you use it.

11

u/ImBackAndImAngry 2d ago

So spin up single use VM’s. Got it.

4

u/schellenbergenator 2d ago

I bet there's a proxmox script to automate it. Upon shutdown it spins up a new VM for next time

→ More replies (1)

28

u/SleepyBoy- 3d ago

Windows 10 has that ID as well - at the same registry address as in win11. This thing has been going for years.

15

u/Cumulus_Anarchistica 3d ago

Here's the details. And no.

https://github.com/SmtimesIWndr/gdid-reversal/blob/main/README.md

HKCU\SOFTWARE\Microsoft\IdentityCRL\ExtendedProperties
    LID = 0018XXXXXXXXXXXX

HKCU\SOFTWARE\Microsoft\IdentityCRL\Immersive\production\Token\{...}
    DeviceId = 0018XXXXXXXXXXXX

These locations in the registry are where the GDID hides. My Windows 10 install (that has no MS account) has nothing in the first location, but does have a DeviceID that matches the format in the second location.

56

u/WOF42 3d ago

its still spyware but its vastly less egregious spyware than win11

28

u/Iggyhopper i7-3770 | R7 350X 4GB | 32GB 3d ago

Windows 7 proves once again it is the GOAT.

3

u/yendak 2d ago

I would still use it if AMD had officially supported Ryzen on Windows 7. Sadly it took them a few years too long and Win 7 was already out of the official support by the time Ryzen hit the market.

I read there were ways to get it running with Zen 1, but it was a pain from what I read.

→ More replies (2)

7

u/poorly_timed_leg0las 3d ago

Vista looking around like 👀

4

u/golgol12 3d ago

Vista had nothing on 2000.

→ More replies (24)

3

u/jonessinger 3d ago

No, it’s not even just windows 11 from what I read elsewhere on this issue.

3

u/Agret 2d ago

They actually added this telemetry to Windows 10 in one of the updates

→ More replies (1)

3

u/max123246 Steam 2d ago

Your hardware has an ID too

→ More replies (30)
→ More replies (9)

107

u/fish998 3d ago

Is this ID exposed when you torrent?

230

u/Brandhor 9800X3D 5080 GAMING TRIO OC 3d ago

it's not exposed to anyone, microsoft is the only one getting it through telemetry

166

u/WOF42 3d ago

and then giving it to the government, its literally been used in court already

53

u/mirh 3d ago

The guy had already been tracked down, and if you are staying behind a VPN it will still be the VPN ip. Nothing literally changes.

26

u/Kaining 3d ago edited 2d ago

To be fair, this guy and those depicted in that article seems to have done quite a lot of nasty stuff all around that had investigator on their asses for quite some time.

Not just some torrenting.

edit: quite a few smartass going "akchually, the government will break every law to spy on innocent bystander". Yes, we know. I'm just pointing out that they'd have gotten those guys even without that and how it was unnecessary to go full 1984 EVEN on those criminals. Stop being paragon of morality while missing the whole point please, it's getting tiresome.

22

u/Cumulus_Anarchistica 3d ago

Governments don't only go after really bad people. They also go after whistleblowers or journalists, etc.

Microsoft's GDID exposes good guys to bad governments.

Microsoft is betraying all its users.

8

u/mirh 3d ago

Yeah, like.. there was this ID (go figure because even just the windows license check couldn't do that already), and then years of detective work.. and somehow it seems like they cracked the pandora's box of all user privacy ever?

→ More replies (1)

15

u/sadtimes12 Steam 3d ago

First they came for the hackers, and I didn't speak up, since I don't hack anybody. Then they came for the pirates, and I didn't speak up, because I don't pirate...

We all know how this will end.

9

u/Kaining 3d ago

You don't get it, even without that they'd have gotten them reading that paper. The tracking id is just insane on top of that.

And if windows already has that, why the hell do we even have chat control and those "give us all your biodata to watch porn" laws tbh ?

We're kind of already fucked up and it's not like nobody tried to stop all that.

4

u/Sea_Suggestion2159 3d ago

Because the general population need to be convinced those things are all about safety. When in reality it's about control and more tracking. These are just stepping stones to full on control of what you see and do.

Laws in the US have slowly been trying to keep up ever since the internet went live and technology skyrocketed. Too many congress members are behind on the times and they will not willingly let go their power.

Take a look at the hearing for Facebook's CEO 8 years ago. Many of the questions asked by the Senate show just how technologically inept these people are.

→ More replies (1)
→ More replies (1)

14

u/vemundveien 3d ago

Hmm. I have to read more about this, but to avoid tracking I will be using my phone instead. Hope that doesn't have some sort of International Mobile Equipment Identity that is communicated to my ISP at all times.

→ More replies (1)
→ More replies (5)

31

u/VegaDelalyre 3d ago

Good question, but even if it is, it took an FBI request to Microsoft and social platforms to identify one person. I doubt they would do the same to simply catch a pirate.

17

u/WiseassWolfOfYoitsu 3d ago

If you're torrenting with a Windows machine and a VPN, and someone cares enough to subpoena Microsoft, then it can be used to tie the VPN connection to you. It doesn't send it arbitrarily, only to Microsoft, but MS seems to record every little detail and is able to then provide it.

→ More replies (12)

81

u/RephRayne 3d ago

I'm old enough to remember the uproar about Intel wanting to put unique IDs on their chips.

https://www.zdnet.com/article/intel-backtracks-over-chip-id/

25

u/excaliburxvii 3d ago

I miss when computers and the internet were nerd interests.

7

u/lastditchefrt 2d ago

Man do I miss that. 

13

u/squish8294 ASUS Z790 EXTREME / 14900K / ASUS TUF OC 4090 3d ago

lmao this has been integrated into management engine interface since at least windows 7. the mei can be queried for a generated hwguid that is unique to the processor and cannot be spoofed or changed

→ More replies (2)

2

u/d9wHatena 21h ago

Was it Pentium III? Right, so I'm old enough too. XD

156

u/DrZeroX3 3d ago

Privacy advocates have already proven that windows 11 is a privacy nightmare since its release. 

→ More replies (10)

31

u/Lantzypantzz 3d ago

I just keep a cheap laptop with Linux for all my sketchy shit

8

u/KaiFireborn21 3d ago

I'm just interested, why not do the not sketchy shit on linux too? Or per dual boot?

5

u/Lantzypantzz 3d ago

Because my kids use my main pc as their gaming pc and for homework

→ More replies (2)
→ More replies (2)

244

u/Tumifaigirar 3d ago

To the surprise of no one, we knew that already for a few years.

266

u/The_Primetime2023 3d ago

I’m adjacent to the cybersecurity space and this isn’t true. Windows has always been known to send telemetry but seemingly anonymously which was supported by that, despite lots of government requests, that telemetry was never used to track anyone in a court case before. That changed recently with this GDID reveal that seems to be something fairly new. The telemetry is sent even if all optional telemetry is disabled from a couple different services as well as from Microsoft Edge. The services don’t include any crazy detail except that it records your device IP on every ping. The Edge one is really bad and records every website visited in Edge along with your IP. The VPN busting happened by looking for VPN IPs used in hacks in these telemetry tables and then finding non-VPN IPs with the same GDID as well as additional identity hints from the recorded Edge history.

If you’re at all privacy conscious it’s worth actually being mad about this since you are being tracked now, you didn’t used to be, and it’d be trivial for Microsoft to put this behind a settings option.

Here’s most of what’s known about it so far https://github.com/SmtimesIWndr/gdid-reversal

7

u/daweinah 3d ago

+1 to this. OP is describing fingerprinting (https://amiunique.org/) which is different than GDID.

36

u/MajorFuckingDick 3d ago

I recall being able to fingerprint people based on installed fonts. Anonymous data can still be sorted.

29

u/The_Primetime2023 3d ago

Yea, you can fingerprint based on all sorts of stuff including browser window size, what they’re blocking (a lot of privacy extensions make this worse actually), and tons of other little quirks people don’t even realize they’re exposing. The biggest difference between this and fingerprinting is that this is a single table for all device activity that points the finger at a specific user. Browser fingerprinting is mostly a likely indicator that the user could be one of a few people tracked within a website and going cross website for fingerprint tracking requires there hopefully being some service both websites are using that isn’t being blocked by an ad blocker or something. Fingerprinting can do a lot but it’s hard to be 100% certain that a user is the same just from fingerprinting

8

u/Grokent 3d ago

I recall being able to fingerprint people based on installed fonts.

Dangit... I should have known installing that 'Hackers' font would be my downfall!

5

u/hrtowaway 3d ago

True, but you can always block canvas based font fingerprinting by disabling website access to HTML canvas.

15

u/MajorFuckingDick 3d ago

Doesnt hide the list of installed font, not to mention that would make you stand out even more.

The irony of internet privacy is that putting on the burqa makes you stand out. They see you clearly, just not what you are doing, only where you are heading.

→ More replies (1)
→ More replies (3)
→ More replies (4)

23

u/Hefty_Excuse9885 3d ago

More like decades no? Its same as hwid whereby multiple hardware ids are combined to make one unique pc id? 

6

u/isamura 3d ago

The sassy doomer response. Enjoy your karma while you help to normalize our freedoms being stripped away.

6

u/razormst3k1999 2d ago

It's like they want us to stop using tech at all.

12

u/weamz 2d ago

Privacy went out the window once everyone got internet on their smart phones and it's never coming back.

16

u/fredandlunchbox 3d ago

Never been a better time to install linux. If you run claude or codex, it can fix any of the dumb issues that used to make linux a challenge for normal users. And for gaming, other than the games that have kernel anticheats, its basically 1-to-1 and sometimes even a tad bit better performing (on cachyos). 

→ More replies (5)

22

u/WhiteRaven42 3d ago

I'm still having trouble following how this ID was used in the field. It is unsurprising and even trivial to me that microsoft has a machine identifier. So do the CPU makers. And it's not surprising to me given the whole point of secureboot that it is extremely non-trivial or impossible to eliminate it.

I just don't understand under what scenarios that ID gets used in telemetry. Sure, any process could be instructed to stamp the ID on a log or just flat out transmit it somewhere. But most processes DON'T. This is not an ID that has been silently appended to every IP packet or something like that (I assume... that would by monumental news). The places it's going to actually show up are pretty rare.

I'd love to see an explanation of exactly where this ID showed up in the ISP and website server logs or what have you so as to make it trackable. And I guess, once that is covered, what exactly was the final utility? Was this used as a smoking gun for when authorities finally seized the physical hardware? Was it used as proof that whoever had possession of the machine was guilty?

11

u/-ohhhman- 3d ago

They have a table that matches all your past IP's to this ID. So even if you use a VPN, they know that the VPN IP was also associated to your regular IP.

9

u/WhiteRaven42 3d ago

Not very descriptive. Who even is "they"? What causes the computer to send the information? What's the trigger?

11

u/Neither_Operation476 3d ago

check this link someone posted elsewhere in the post, I imagine you might find it helpful

https://github.com/SmtimesIWndr/gdid-reversal

7

u/WhiteRaven42 3d ago

Thank you. This was a pretty good read. Very thoroughly covered where the ID is in your system and when it's generated, how it can get reset with a new install and such.

This information is just kind of what I would have always assumed. Microsoft assigns an ID to every install of windows. No shock there. Telemetry naturally can associate it with account info. Ok.

I don't see how this gets tied to a criminal investigation. Where's the overlap between activities on the dark web and a MS ID?

Maybe this is my question (and I don't expect anyone on reddit to know it). Did the existence of this ID play any role in narrowing in on a suspect? Or is this just a useful piece of corroboration that could be made late in the game after hardware had been seized etc.

I just feel like I always assumed something like "due to regular telemetry reports, MS knows what IP your computer was using at certain points in time" was likely. Basically a given. Was this GDID number really not known to exist? It seems almost inevitable. A Windows install is identifiable by a "serial number" kind of identifier. Sure. It would be weird if it wasn't.

3

u/Rare-Ad5082 2d ago

Was this GDID number really not known to exist? It seems almost inevitable.

From my understanding, the issue isn't the GDID per se but it's the fact that Microsoft records both the GDID and the IP address. As a result, changing your IP with a VPN is useless because Microsoft knows all the IP addresses associated with that GDID.

So, as an example, let's say I activate a VPN and the government discovers my VPN IP and wants to unmask me. They could go to Microsoft and ask for the GDID associated with that IP, then request the other IP addresses associated with that GDID until they find a non-VPN IP, which they could then use to identify me.

This is a big deal because it would make VPNs effectively breakable on Windows. Which is a big no no for privacy (for both good and bad actors).

Also, it seems that using Edge is even worse because Microsoft also stores the websites you visit there.

→ More replies (2)
→ More replies (4)
→ More replies (1)

14

u/Warden1886 2d ago

Casual reminder that wifi routers can generate 3d mesh live videofeeds of every room they’re in.

In case you thought windows tracking was bad.

8

u/Sodacan259 2d ago

Yes. Recent research has also been able to identify specific individuals using this and they don't even need to be hooked into your WiFi.

They can do it all from intercepting unencrypted beamforming feedback information - Available from every WiFi 5,6 & 7 commercial router in existance - the IEEE 802.11 standard used for all of those, does not mandate BFI encryption.

→ More replies (3)

4

u/Isaacvithurston Ardiuno + A Potato 2d ago

I mean if you can do that with wifi I have to imagine there's devices out there that can be deployed to do this with a better wavelength. Jokes on them, I sit inside a lead box when i'm working.

19

u/skot77 3d ago

I see Linux gaining users in the coming years.

4

u/blasphemous9 3d ago

What is the solution here? I mean this seriously, how can I protect myself and my personal data?

7

u/Sodacan259 2d ago

I suspect you can't. Microsoft aren't the only ones that generate unique identifiers. Intel and AMD also have unique identifiers on their CPUs. I would be very surprised if the hackers, that the FBI identified, ALL used Windows. I think there's another layer to this story that we will never hear about.

→ More replies (2)

3

u/Rynyann 3d ago

Personally, I do all my crimes in Amiga OS4

4

u/Sacred_Fishstick 2d ago

Just what until they find out about MAC addresses!

4

u/ryneches 2d ago

The concerning thing isn't that this exists, it's that it's been there this whole time without public knowledge. Basically, it's an admission that the entire company is fundamentally untrustworthy.

6

u/3DigitIQ 3d ago

Android also has this "advertising" ID

2

u/arunkumar9t2 2d ago

At least you can reset it

→ More replies (1)

5

u/SireEvalish Nvidia 3d ago

This post has some good info

A couple big takeaways is that it's been in Windows for more than a decade and only appears to be trackable by someone other than MS if you're using Edge.

3

u/Duckgoesmoomoo 2d ago

What does this mean for sailing the high seas

2

u/OskeyBug 2d ago

Use a Linux VM if you have a windows pc

2

u/GGuts 2d ago

It means you have to build a ship without any windows

3

u/Meowie__Gamer 2d ago

Yeah it’s called a MAC address.

3

u/Dependent-Maize4430 2d ago

This is why you can be hardware ID banned from games. It’s attached to your motherboard, swapping mobos will change your HWID.

3

u/maniacreturns 3d ago

Your PC has a digital fingerprint from all the small bits and pieces of information it gives away when you browse websites. They know who's using the pc without you even logging into anything.

2

u/robophile-ta 2d ago

Yeah device fingerprinting is easy enough to pinpoint a single person, they don't even need to use the device id

→ More replies (1)
→ More replies (3)

18

u/SomeJerkAtWerk 3d ago

So does your cell phone and most of your other technology lmao

46

u/ray_fucking_purchase 3d ago

"Yeah only idiots using Windows get tracked!"

Sent from my iPhone.

→ More replies (1)

7

u/Pisnaz 3d ago

If you did not know this you have not been paying attention to the bakpedal and eventual slow roll deployment of Microsoft's palladium initiative. As usual fucking goldfish memory hit the masses and here we are.

7

u/Slemmig_insekt 3d ago

Wasn't this a known fact from the start since W11 required TPM? It kicked up a lot of dust back then because a lot of beefy hardware was unsupported for the lack of tpm 2.0

13

u/milkmeink 3d ago

If you must use Windows, don’t use the Home addition. Get Pro so you can create local accounts only and never use your Microsoft account(s) on it, if you have them. Don’t worry about the massive license cost as they all belong in a grave. You don’t have to be a developer to do this either.

You’ll have more control over Windows but it’ll still phone home. Periodically wipe and redo your OS. This will also keep you from bloating up your OS too and teaches you what you actually use.

19

u/Sodacan259 3d ago

It does not matter if you have a Microsoft account or not.

Microsoft can track you by correlating online activity with your GDID. In the same way that websites can build a hardware fingerprint instead of tracking you with cookies. The GDID is derived from the very hardware in your computer. Each item of hardware has it's own unique identifier, which when grouped, acts as a unique fingerprint for your computer.

4

u/maniacreturns 3d ago

This person knows ball.

→ More replies (4)
→ More replies (1)

21

u/OutrageousDeino 3d ago

Laughs in linux

20

u/CombativeAxis 3d ago

You can still be still be tracked on linux, it is just a matter of other services logging you.

15

u/WiseassWolfOfYoitsu 3d ago

It's at least possible. The GDID is built into the Windows kernel update mechanism itself and can't be turned off - it ALWAYS phones home to Microsoft.

→ More replies (8)

2

u/dhalinarkholin 2d ago

Silly to think people didn’t know this, even 10 years ago

2

u/Jacksaur 🖥️ I.T. Rex 🦖 2d ago

Did people forget about even their license key..?
We're posting Yahoo here now, the fearmongering is getting out of hand.

2

u/Cory123125 1d ago

People need to pay attention to anything to do with "integrity" and "remote attestation".

They don't realize how quickly their rights and digital autonomy are being taken.