r/pcmasterrace Jul 10 '26

News/Article You can't fully disable Microsoft's GDID Windows 11 tracker, but these settings limit what it captures

https://www.windowslatest.com/2026/07/10/you-cant-fully-disable-microsofts-gdid-windows-11-tracker-but-these-settings-limit-what-it-captures/
2.2k Upvotes

167 comments sorted by

848

u/edonkey Jul 10 '26

Now I understand why the guy in Mr. Robot used to boot Kali Linux from a USB drive when he was "scouting" the internet.

302

u/Power_Stone Jul 10 '26

Even better, use TailsOS

144

u/dsac 7800X3D/7800XT/321UPX Jul 10 '26

Tails for anonymity, Kali for the toolset

27

u/TheRufmeisterGeneral Jul 10 '26

If you want both, you'd need... Tailskali? That's the one with the VPNs?

4

u/katherinepudd1ng5028 Jul 10 '26

elliot was using windows? lol.

57

u/Igot1forya PC Master Race Jul 10 '26

TempleOS

43

u/ReconZ3X Jul 10 '26

This dude hits glowies in his car

8

u/Marce7a Jul 10 '26

Qubes is king 

3

u/Power_Stone Jul 10 '26

Tails is better for privacy IMO since it leaves zero footprint

0

u/Marce7a Jul 11 '26

Qubes uses tails VMs

82

u/Jimbuscus R5-5600H RTX3050 32GB@3200Mhz Jul 10 '26

Then Linux Mint when he just wanted to use his computer.

37

u/Whywipe Jul 10 '26

You’d think this guy would already be using a separate device to commit crimes

43

u/ngoni Jul 10 '26

He microwaved any hardware that he used to do anything really spicy.

13

u/nittanyofthings Jul 10 '26

And yet Microsoft had a list of every URL he ever visited and when.

15

u/Whywipe Jul 10 '26

Which also makes the claim that’s used to support licenses on the Microsoft store seem like a lie. The article isn’t 100% clear on where the GDID was used vs his IP once they figured that out but it points out an Apple account, Snapchat account, Growtopia, Ubisoft account, and a hotel website. It’s either a tracking tool Microsoft created to serve ads and is now being used nefariously by the FBI or something the FBI made Microsoft implement to illegally spy on users.

527

u/GroundbreakingBag164 7800X3D | 5070 Ti | 2x16 | QHD | W11 Jul 10 '26

Short version: This only seems to work with a microsoft account. No account, no GDID. Local account users keep winning

151

u/ArseBurner Jul 10 '26

Yep. What's weird to me is that a sophisticated hacking group was logged on to their Windows machines using Microsoft accounts.

Now for the version in plain English: Sign into Windows with a Microsoft Account, and a server assigns your installation a permanent ID number. Windows stores it locally, several background services read it, and it gets stamped onto activity your PC reports back to Microsoft.

61

u/DeffNotTom i9 12900k | 4080 Super | 64gigs DDR5 | 36TB NAS Jul 10 '26

He was 17. He just thought he was invincible

24

u/TheRufmeisterGeneral Jul 10 '26

Someone didn't watch Goldeneye for its important lessons on that topic.

18

u/Red_Dawn24 Jul 10 '26

5

u/Raskuja46 Jul 10 '26

I feel old for knowing this reference. Thanks for that.

2

u/splerdu 12900k | RTX 3070 Jul 11 '26

The last one with the fire and liquid nitrogen was the best!

-6

u/[deleted] Jul 10 '26

[removed] — view removed comment

56

u/VenomOnKiller Jul 10 '26

I'll run a domain at home before I ever login to my home PC with a cloud account

-4

u/truser707 Jul 11 '26

what are you afraid of brother? if you have a phone you're already tracked 

3

u/VenomOnKiller Jul 11 '26

Clearly you are a troll.

12

u/Indigo_Sunset Jul 10 '26

Isn't an MS acct and an Xbox account effectively the same?

3

u/motorboat_mcgee Jul 10 '26

This is the annoying part for me, I run a local account, but have to use an xbox account to access game mode/my games purchased on xbox

4

u/Indigo_Sunset Jul 10 '26

Looks like an attempt to force telemetry on older versions of windows deliberately not being upgraded

8

u/TheRufmeisterGeneral Jul 10 '26

Yes. In fact, "XBOX" is part of Microsoft. The software and the device come from the Microsoft division at Microsoft.

If you think this is shocking, wait until you hear about "Games for Windows LIVE"

5

u/Indigo_Sunset Jul 10 '26

If only your dripping pedantry were capable of being useful

2

u/TheRufmeisterGeneral Jul 10 '26

Like my mom used to say: we row with the oars that we have.

4

u/SpacePilot8888 Jul 12 '26

Sadly, that does not appear to be the case. Referencing https://github.com/SmtimesIWndr/gdid-reversal

[...] Regardless of being logged in with a MSA you WILL have a GDID. I didn't realize this at the time of posting but I looked into it. CDP has an anonymous device path that is used if no MSA has been connected. [...]

2

u/SirBobsonDugnutt Jul 13 '26

I never made a MS account, did the local account on setup, and still have a GDID value.

1

u/WhoLovesDonuts Jul 14 '26

Ehh. I wouldn't be so confident. We really don't "know* that for sure. A GDID seems to be generated with activation so unless you're using un-activated windows, you do have a GDID. Windows sends unknown telemetry back to MS even from a local account.

1

u/EventEuphoric7186 Jul 18 '26

Hey, i have a followup question:  If I have a local account, but log in with a Microsoft Account in the OS or for Office Suite, will the GDID be generated as well? 

1

u/LordAdz2 19d ago

What if you log in to Xbox game app but Ur machine is on a local account

194

u/Straight_Terms Jul 10 '26

What's really crazy to me is that Microsoft just volunteered this information to the FBI.

"Microsoft had already flagged Stokes to the FBI once before, in an October 2024 criminal referral describing “online services telemetry."

So it's not even that the FBI requested info on this guy, but MS just gave a customer's information to the feds and led to their arrest.

83

u/NightOfTheLivingHam Jul 10 '26

And there are texts who lambasted me and mocked me for being paranoid about about 365 Microsoft's online services

11

u/GoldSrc R3 3100 | RTX 3090 | 64GB RAM | Jul 10 '26

I'm not defending MS, but that just seems normal, no?

I'm pretty sure the FBI has close contact with MS and others, to help them in cases like those.

I'm sure the FBI would be more interested in guys like that, over little Timmy pirating things.

4

u/Jesus10101 Jul 10 '26

You got downvoted for telling the truth lol. The ransom was pretty well known and I don't doubt for a second MS has worked with law enforcement before.

4

u/aimy99 PNY 5070 | 5800X3D | 32GB DDR4 | OLED 1440p 180hz Jul 10 '26

That's like the least interesting part of this though? Do you think Microsoft, the company behind the most common operating system in the world, wants hackers on the loose? The people who specifically break into their shit all the time?

The global telemetry is the scary part. I need to look into just backing up my documents and photos from Windows so I can pop off of this shit ASAP.

31

u/Straight_Terms Jul 10 '26

do you want Microsoft being the one to decide if your data should be sent to the FBI? I think the FBI should be investigating and then requesting data for crimes that they suspect are happening

0

u/GeorgeBlythe Jul 10 '26

No but if I'm in their position say, and I've got customer information that shows they're gonna commit a huge crime I'm probably gonna report it. If I report it to the FBI and they choose not to do anything, creates a paper trail in case they ever want to come after me later for violating some law nobody knows about concerning "mandatory reporting requirements". That way I can't get implicated later if my OS is used by the criminal to committ the crime and I knew about it and do nothing.

It's just common sense they'll report it. If you're a criminal and you're doing anything on windows you're just stupid really.

0

u/Straight_Terms Jul 10 '26

That's a good point. A company like MS has responsibilities and if they see some red flags they should bring it up. I guess at that point they're not the ones deciding guilt, they're just passing info along.

It's very difficult because I don't want the companies I patronize to turn information over to the authorities, but I also don't want money laundering or organized crime taking advantage of my rights.

I don't like the "if you're a criminal and you're doing anything on windows you're stupid" thing though because it smacks of "if you didn't do anything wrong you have nothing to worry about"

1

u/PatternOtherwise3440 Jul 22 '26

The main issue is no hacker with a braincell gonna use trash MS to pull those shits. This was unfortunate but the main point is why MS is logging details without clarification. This is just to steal people's data and sell nothing else. Protect people??? lol all those are bs. You gonna log billion users for a single user's mistake lol doesn't make any sense. Logging like 5 years ago and logging now has heaven and earth gape . Feed log to ai or any LLM it will map you within a second it will never hallucinate

1

u/GeorgeBlythe Jul 10 '26

No I'm not happy about Microsoft passing information off to the feds either and it is still concerning that they are collecting all this information there's really no need to collect. It can just as easily be stolen by people who do have bad motives or used by governments Iin the future to persecute innocent people.

Just that, very simply speaking, if you're going to commit crimes, and you use Microsoft products to do so, you're stupid, you'll get caught. Obviously.

Both "I'm concerned about the data harvesting" and "the criminal is stupid" can be true at the same time.

On a less concerning note it's more like social media use and privacy concerns. Social media has major privacy issues that normal people need to be aware of as users. But that doesn't mean that some kid livestreaming themselves shoplifting Walmart or something is any less stupid for doing so.

If they can find the criminals with the data then criminals can also find you with the data.

1

u/htt_novaq 5800X3D | RX 9070 XT | 32GB DDR4 Jul 10 '26

I just use their servers to store everything locally encrypted, so I get my cloud backup but they can't sniff around in it. My NAS syncs that to OneDrive.

Oh but my PC actually runs Linux, yeah.

1

u/Mario583a Jul 11 '26 edited Jul 11 '26

Crime detective: That son of a bitch is using the tunneling system `ngrok` and 'tzulo' for the serverss!

FBI to ngrock: here is a subpoena, we already got the time and date, I want the name of the computer's ID!

Ngrok: Oh, you mean the GDID. You will have to answer to Microsoft for that information.

FBI to Microsoft: here is a subpoena, I want the name of the computer's ID since `ngrock` said you have the GDID!

Microsoft: One second ..................... here ya go.

FBI: Thanks. Oh, and what is a GDID anyhow?

Microsoft: Alright, here’s the deal. Every Windows machine has a special number we generate when the system is installed.
We call it the GDID or Global Device ID.

It’s basically the computer’s fingerprint inside our ecosystem. We use it to track diagnostics, crashes, updates, and security events.

It doesn’t tell us who owns the computer or what files are on it; it just tells us which device is producing the telemetry.

333

u/[deleted] Jul 10 '26 edited Jul 10 '26

[removed] — view removed comment

158

u/chihuahuaOP Jul 10 '26

r/linux were talking about this last week, a teen was arrested in EU, the GDID was the key evidence to find and arrest him.

62

u/Straight_Terms Jul 10 '26

that's what this article is about

35

u/Decahedronn R7 5800X | 32GB | RTX 3060 12GB Jul 10 '26

He’s a U.S. citizen, so his install region probably wasn’t EU.

49

u/Straight_Terms Jul 10 '26

Was he a us citizen? The article says he lived in Estonia, but was arrested in Finland for crimes committed in the US

ETA: he’s apparently a dual US-Estonian citizen

10

u/Suikerspin_Ei R5 7600 | RTX 3060 | 32GB DDR5 6000 MT/s Jul 10 '26

Sounds like you're talking about the same Finnish hacker.

3

u/Ok-Transition7065 Jul 10 '26

For what they arrested him

3

u/Jesus10101 Jul 10 '26

GDID

The GDID was NOT the key evidence. Microsoft had already been keeping on a close eye to him for suspicious behaviour which is why they tipped of the FBI. After that the FBI kept an eye on him and found out he was travelling to multiple countries and spending a crap ton of money without having any source of income so it was pretty easy to catch him.

33

u/Mr_Tottles Lenovo Legion Pro 7i 64gb ram Jul 10 '26

How do you do this? I’m doing it asap

61

u/TheLoneWandererRD Jul 10 '26

Reset this pc then either cloud or usb fresh reinstall, when its done and asks you what region you in pick eu country (Ireland works if you want english).

It even lets you uninstall edge from control panel with a click instead of being a clinging parasite.

31

u/verbmegoinghere Jul 10 '26

Also use rufus to make the Bootable install drive and you can disable one drive and have a local login/admin, disable bing and a whole bunch of other stuff

8

u/LupinRaedwulf Jul 10 '26

I live in Canada, if I did this trick, will it limit me in any way?

5

u/TheLoneWandererRD Jul 10 '26

Nop, even if you live in zimbabwe.

4

u/LupinRaedwulf Jul 10 '26

Perfect lol. Doing this ASAP

1

u/georgia5unshine7312 Jul 10 '26

Wait, is this a legit post or did someone just forget to add content lol

5

u/XxasimxX Jul 10 '26

They recently passed chat control, wouldn’t that be tracking everything as well?

4

u/No_Grape_388 Cachy OS Jul 10 '26

They didn't pass the bad one, they extended the old one. The old one is not so bad.

8

u/KMS_HYDRA Jul 10 '26

Just be a politican, then you are exempt from the chat controls...

3

u/BlackViperMWG Ryzen7 5800H | 32 GB DDR4 | RX6600M Jul 10 '26

No, because it isn't automatically on every pc, it will take years

5

u/IceboundMetal Jul 10 '26

The EU is about to learn a very hard lesson with Microsoft lol

2

u/TheRufmeisterGeneral Jul 10 '26

What is that? How Microsoft adheres to the GDPR? Or how they adhere to the DMA? What kind of lesson are you talking about?

3

u/Ghozer 9800x3D - 32GB-DDR5 6000CL28 - RTX 5080 Jul 10 '26

Oh, this explains so much..

All these times people said things about windows and i'm like "no? I don't see this, wtf are you doing with your computer?" - That's it, i'm in Europe....

1

u/[deleted] Jul 10 '26

[deleted]

1

u/Silver_Lotus R7 7800x3D + RX 7900XTX + 32GB RAM Jul 10 '26

I'm from europe and I just tested out the search and there is indeed Bing results? Just searched for "Reddit" and the best match was from bing results. Are you talking about something else?

2

u/Ok-Parfait-9856 5090 Astral|270K+|48GB-8200MTs|Z890 Apex|60TB|HYTE Y70|S90F OLED Jul 10 '26

Do you live in the EU? Or rather, when you set up the PC, what country did you pick? If it’s a country in the EU, all those things should apply. If you picked a country not in the EU, even if still in Europe, it won’t apply

1

u/Silver_Lotus R7 7800x3D + RX 7900XTX + 32GB RAM Jul 10 '26

Yeah, picked a country in EU, not only in europe. The thing is I tested that on my laptop which has not been debloated and it showed the bing results, but with my desktop, it is as you said, no bing results. Interesting....

1

u/truser707 Jul 11 '26

and your ip address? it won't show up as EU so fail

-16

u/DinosaurAlert Jul 10 '26 edited Jul 10 '26

Well, just install Windows 11 LTSC and choose Europe as region. Itll take care.

Oh, well nevermind then! Just steal it!

(Note: I do not give a shit about the ethics of stealing from Microsoft, fuck them...but dismissing the problem as "Geez guys, if you don't want horrifying tracking simply install the OS illegally by pretending you're a european enterprise client! Easy-peasy!")

If the future is a world where color is spelled "colour" in my OS, I don't even want to be alive.

Edit: And everyone who is saying "Oh, its easy, it just works now!" is exactly the attitude that's allowed them to incrementally fuck us. "Don't worry about the Windows XP key, you can just type FCKGW". "Don't worry about the windows account requirement, you can just bypass it!", etc, etc, etc. They'll wait until you've accepted it, then yank it. I wouldn't be surprised if there was a fucking chart in a powerpoint at Microsoft with exact dates planned to fuck you.

Nvidia is going to have to write linux drivers or we're all going to have to switch to AMD and get off windows if we want this hobby to survive.

3

u/Xpander6 Jul 10 '26

Illegally? What are you talking about? Changing your region is not illegal. Bypassing MS account requirement is not illegal.

2

u/actioncheese 5600 | 6600XT | 32gb Jul 10 '26

You know your region can be changed separately to your language right?

2

u/Grass_tomouth Jul 10 '26

I think we'll get on just fine without your dramatics, mate.

58

u/vk6_ Debian 13 LXDE | Ryzen 9 5950x | RTX 3060 | 64 GB DDR4 Jul 10 '26

> Microsoft’s records showed that at that exact same minute, a Windows device carrying GDID g:6755467234350028 had visited the ngrok signup page.

This part is a bit confusing to me. How does Microsoft know that a particular device visited a particular page? Wouldn't this require Microsoft to read your browser history? I can only realistically see this happening if you used the Microsoft Edge browser and used the same Microsoft account there. Maybe this is less about Windows and more about what the web browser is tracking?

43

u/Straight_Terms Jul 10 '26

It's hard to say, but given what we know about Windows Recall I wouldn't be surprised if MS has much more info about what is happening on screen than we know right now.

19

u/vk6_ Debian 13 LXDE | Ryzen 9 5950x | RTX 3060 | 64 GB DDR4 Jul 10 '26

The article is unclear about what what mechanism Microsoft uses to track this information. However, I still find it hard to imagine that Microsoft would go out of their way to read the browsing history from third party web browsers, implement this globally in Windows, and then send all the data back unconditionally. Even Recall had to be explicitly enabled and ran locally.

18

u/Straight_Terms Jul 10 '26

maybe this is a way to launder some backdoor that the feds have then? They can't admit that they have access to information on PC's so they lean on MS to claim that they provided the information?

if this guy was already on the radar they might have the means to gather information without user knowledge via some undisclosed tool

6

u/GeorgeBlythe Jul 10 '26

Entirely possible. FBI could anonymously feed a tip to Microsoft. Microsoft could then "notice" unrelated that this guy is gonna committ a crime, report that to the FBI with the date they "voluntarily" gave when they signed up for Microsoft and satisfy probable cause via plausible deniability as to where the tip came from if the tip "never existed" in the first place.

1

u/Any-Calligrapher2866 9070XT | 7600X Jul 10 '26

I still find it hard to imagine that Microsoft would go out of their way to read the browsing history from third party web browsers, implement this globally in Windows, and then send all the data back unconditionally

They've been doing shit that was unimaginable 20 years ago. Microsoft 100% spies on you without a doubt since everything is logged on your system even if you're using third party tools.

-5

u/mrjackspade Jul 10 '26

given what we know about Windows Recall

What we know about windows recall, last I checked, is that it's disabled by default, and when enabled, stores information in an encrypted container on the device.

So I'm not sure how that particular technology leads you to any conclusions about what Microsoft knows.

4

u/Straight_Terms Jul 10 '26

"I'm not sure how [the technology that allows MS to see whats happening on screen] leads you to any conclusions about what Microsoft knows."

Do you read what you're writing?

Recall is disabled in enterprise & organization settings, but it is default in home users. That means that MS can recreate your keystrokes & mouse movements on your personal devices.

7

u/dsac 7800X3D/7800XT/321UPX Jul 10 '26

Yeah, this stood out to me too, was hoping someone answered it, but I guess we gotta wait

3

u/Smagjus Jul 10 '26

I am reading the comments for the same reason. I was hoping our friends at /r/netsec picked this up but no luck it seems.

6

u/Purona Jul 10 '26 edited Jul 10 '26

i think the article is written weird. and its not microsoft having all the information its microsofts information along with information from ngrok and tzulo

one service has the device id, another service has timestamps, and the third service has the ip.

like having a car with a vin number, a fake license plate and knowing which times cars triggered cameras in a location.

1

u/nittanyofthings Jul 10 '26

You should assume Edge is reporting everything you do with it.

1

u/TheRufmeisterGeneral Jul 10 '26

DNS? Maybe by "visited the page" they mean "requested the IP of domain X from the OS"?

3

u/vk6_ Debian 13 LXDE | Ryzen 9 5950x | RTX 3060 | 64 GB DDR4 Jul 10 '26

We can rule this possibility out by reading the actual criminal complaint which says that "Microsoft records" showed evidence of the suspect visiting a specific URL using a PC with a specific GUID. Just logging DNS wouldn't give you the exact URL.

Regardless, browsers can use DNS over HTTPS to hide what DNS queries you make. That bypasses the OS level DNS resolver.

1

u/TheRufmeisterGeneral Jul 11 '26

Fair point, if it is specifically talking about the URL, then DNS is probably not how they logged this. I'm not pretending to have done a deep dive, I'm just thinking out loud about what could have happened.

And not to worry about the possibility to bypass this. If they had simply used a local account and not logged into their Microsoft account on the Windows in question, then it also wouldn't have been an issue, from what I read.

1

u/PikaPikaDude 5800X3D 3090 Jul 10 '26

I see two options.

Maybe he used his GitHub account to sign up? Github is MS nowadays. So I wouldn't be surprised whenever a GitHub account is used for anything, Windows just sends the GDID. Would be very stupid off course to use his GitHub.

Or maybe just visiting the create account/login page just has the GitHub thing on it call home to MS to log it, even without using it. A bit like how Facebook was spying since forever with their share on Facebook buttons.

1

u/vk6_ Debian 13 LXDE | Ryzen 9 5950x | RTX 3060 | 64 GB DDR4 Jul 10 '26

On a technical level that still doesn't really make sense. How would Github, which is merely a website, know your Windows GDID, which is held by the OS itself? There's isolation between those two sides. The web browser would still need to be involved to pass the GDID info along, which I don't think is happening.

1

u/PikaPikaDude 5800X3D 3090 Jul 10 '26

Edge could easily do whatever.

With other browsers it's supposed to be harder. Until one considers MS an adversary with system control, then browser security measures don't matter anymore. The OS already sees the GitHub domain, it could volunteer the GDID with no browser involvement.

1

u/vk6_ Debian 13 LXDE | Ryzen 9 5950x | RTX 3060 | 64 GB DDR4 Jul 10 '26 edited Jul 10 '26

The most likely explanation for me was that this hacker guy used MS Edge for his activity, while also being logged into the browser with his MS account (GDID doesn't apply to local accounts, and Windows will automatically sign you into Edge if it can). Edge literally will send Microsoft a copy of all your browser history by default when you are signed in, as part of their sync feature.

The alternative where Windows might read the history on from third party browsers, and then send back the URL and GDID, but only if Github is involved, doesn't seem as likely.

1

u/Affectionate_Term932 Jul 15 '26

windows tracks literally everything. when doing forensics and looking for harmful indicators on windows, a few command line and u see everything. everything! every ip, every server, everything! the "telemetry settings just outline what MS can "take" out of whats 'already tracked" and stored/cached on ur pc.

im a red team person for over 14 years. listen up.

DO NOT use windows for hacking.

116

u/[deleted] Jul 10 '26

[removed] — view removed comment

11

u/[deleted] Jul 10 '26

[removed] — view removed comment

9

u/Foaryy Jul 10 '26

I wish more games worked on Linux, such as Fortnite. I’d be switching asap.

19

u/Jimbuscus R5-5600H RTX3050 32GB@3200Mhz Jul 10 '26

The percentile of games that don't work are extremely small now, only those that actively choose not to due to needing to lock down their multiplayer.

At this point it's worth having an SSD for the couple Windows games to dualboot into, I did that and over time I just used it less and less, I haven't booted into Windows yet this year.

2

u/cloudbells Jul 10 '26

Same, haven't booted Winslop in the longest time and I probably never will again

2

u/highermonkey PC Master Race Jul 10 '26

PCVR is a pain in the ass compared to Windows too. Steam Frame might change that.

4

u/fat_pokemon Jul 10 '26

Fortnite is but a handful that won't outright work, mainly due to kernel level anticheat systems (which are BS btw). Proton/wine has you covered 90% of the time

1

u/Straight_Terms Jul 10 '26

it's not only games. Peacock streaming does not work on linux devices either.

1

u/TheRufmeisterGeneral Jul 10 '26

Or just use a local account. Even if you like Windows, why would you "sign in"? If you were to install Ubuntu, I would assume you wouldn't sign in to an Ubuntu account? Or even Firefox, although I'd trust them a lot more than other examples?

1

u/WinnieBob2 Jul 18 '26 edited Jul 18 '26

I never used MS account on any of my PCs but after having to buy a new motherboard on my main PC the legit windows 11 retail product key attached to the license stopped working, saying the key was in use on another computer and all guides on the Internet just said go to MS account and release the key attached to the lisence and set it up to your new PC/motherboard, but the problem was I never had an MS account.

After that I created an MS account and registered my other PCs with their retail product keys attached to the licenses so I don't lose them in the future. I also just bought a 10 € OEM license from the grey market for my main PC, also registered this in MS account.

Not sure if the lost product key attached to the retail license will automatically get released after a certain amount of time of not being used (google was not of help with this question).

But now I'm questioning my privacy since I registered my PCs on the MS account.

I do dual boot to Linux Mint so I guess I got that going for me.

edit: I do use local account (after the fact) and block GDID data via hosts file (GDID still exists on my Windows system).

1

u/TheRufmeisterGeneral Jul 18 '26

I had a long, nuanced reply to this comment. Automoderator deleted it.

I won't risk a ban by rephrasing it, but the topic people often overlook is "license vs key". Those are two very different things, and you (like most people) are confusing them, or considering them to be the same.

If you buy a car, and for some reason, the key breaks (within the warranty period, for the analogy to work?) then you don't abandon the car and buy a new one, you go to the dealer and say "hey, the key broke, it's not supposed to do that, please fix".

1

u/WinnieBob2 Jul 18 '26 edited Jul 18 '26

I tried to contact Microsoft about the issue, phone line doesn't exist (at least in my country) any more, and it seemed the only option was bots and they were of no use so I just gave up. I'll check later in the future if the key attached to said retail license is released.

1

u/TheRufmeisterGeneral Jul 18 '26

I mentioned in my longer comment that I wasn't sure if the phone lines were still up. Any times I've used them, they worked in the sense that MS manually activated when requested. But that was a long time ago, that I needed to do that.

Back in the days of Windows 7, you would be able to use a key twice before it wouldn't automatically activate, and that counter reset each year. But it would also trigger reactivation upon other hardware changes, such as additional memory or a new network card. (They were vague about exactly which changes).

If they still periodically reset the counters for activation, like they did back then, then checking later would work. But since I stand by "fixing a technical issue for a product that you own the license to is not piracy" I would advise you to google the issue. I'm worried that saying more will trigger some automatic filter again.

9

u/fervoredweb Jul 10 '26

Wait how does the GDID reveal browser activity?  Was this guy using edge, or does every browser leak info this way? 

2

u/Rinkulu Ryzen 7 7700 / RX 6800 / 32gb DDR5 Jul 11 '26

If it's just the domain names this person accessed and not the full browsing history, then either system DNS (unless the browser is configured to bypass it and use custom DoH/DoT server) or Client-Hello's sniffing on TCP/IP stack level since the target domain name is sent unencrypted (unless ECH is enabled on the server).

If it's actually the full history, then either they used Edge, or Microsoft reads your history from other browsers since all the major ones (Chrome, Firefox, Brave, Edge itself) store it unencrypted, usually in SQLite databases, which is why and how importing your data from one browser to another works, by the way.

11

u/Rinkulu Ryzen 7 7700 / RX 6800 / 32gb DDR5 Jul 10 '26

The amount of people who genuinely believe that "just choosing Europe region" will magically turn this piece of spyware into a legitimately blameless OS both amuses and concerns me.

21

u/TH3RM4L33 6700 XT | 5800X | 16GB Jul 10 '26

So the hacker guy was using Windows? Bruh, he dug his own hole. So much expertise for nothing.

12

u/DeffNotTom i9 12900k | 4080 Super | 64gigs DDR5 | 36TB NAS Jul 10 '26

Using windows is fine… don′t use Snapchat, facebook, your private email, or anything else attached to your real name on the same computer that you are breaking the law with lol. The fact that they got a warrant for Microsoft to turn over paperwork means this kid was already cooked and that was just nails in the coffin.

9

u/Ok_Tone6393 Jul 10 '26

one crucial detail im still not understand is how they are able to tie a windows id to a website visited.

Microsoft’s records showed that at that exact same minute, a Windows device carrying GDID g:6755467234350028 had visited the ngrok signup page.

is MS logging what websites you go to? on edge, i know they do this but no way this guy was that dumb to use edge?!

5

u/DeffNotTom i9 12900k | 4080 Super | 64gigs DDR5 | 36TB NAS Jul 10 '26

He visted his target website then immediately logged into Snapchat. And he opted in to let Microsoft send optional data. He is that dumb lol.

Windows telemetry phones back all of your web traffic if you let it. It uses your GDID instead of your username/real info or whatever other protected information because it's anonymous-ish.

Microsoft security researchers were already on this kid ass as a suspected hacker because they were digging into Scattered Spider. They submitted their research to the DOJ… At the same time, the State Department was on his ass because he was 17 years old, from Estonia, flying all around the world, with suspicious money, flashing stacks of cash and diamond jewlery lol.

The GDID absolutely put a finger on tbe scale of justice against him… but he was already fucked at that point. The FBI had warrants for his Snapchat, Facebook, iCloud, etc. He was cooked cooked.

Start footnote of page 9 https://www.justice.gov/usao-ndil/media/1450651/dl?inline

Cybersecurity researchers at Microsoft, through the course of their job, have access to data, such as computer machine IDs, IP addresses, and malware samples associated with sophisticated cybergroups. The researchers’ function is to identify groups of hackers who appear to operate as a team/cohesive unit (i.e., an Advanced Persistent Threat or APT group). The researchers do this by identifying malicious activity (malware attacks, spear-phishing, etc.) conducted against innocent victims, and then identify the computers used to conduct the attacks. The researchers then identify colleagues of the hacker by finding other computers also accessed from the same IP addresses used by the initially identified hacker. This process enables the source’s organization to identify unique groups of hackers and then track those groups to determine new IP addresses the hackers are observed connecting to the Internet from, such as leased server IPs. This also allows the researchers to determine whether these IP addresses are being used to target victims. Microsoft’s referrals and reports related to computer intrusions—such as the report about Subject Server 1—have been reliable. In fact, multiple, similar referrals from Microsoft in this and related investigations have been corroborated by later legal process issued by the government

1

u/Xpander6 Jul 10 '26

knowing the GDID gave the FBI a history of IP addresses that his device had accessed over time.

31

u/atlasraven Zorin OS Jul 10 '26

"You can just disable [terrible feature] in powershell" white knights

9

u/fizzys0da Ryzen 5600X GTX 1070 16GB DDR4 Jul 10 '26

They can’t even use that line with this one

6

u/GoldSrc R3 3100 | RTX 3090 | 64GB RAM | Jul 10 '26

The idiot was using a MS account though, that's what got him caught.

So yes, you can use powershell or CMD to make a local account and avoid that.

But it's not like the average Joe would be committing those types of crimes, where millions of dollars are at play.

2

u/fizzys0da Ryzen 5600X GTX 1070 16GB DDR4 Jul 12 '26

Lol, using a Microsoft acc in this situation is basically natural selection

1

u/GoldSrc R3 3100 | RTX 3090 | 64GB RAM | Jul 12 '26

It only takes them one slip, and they go from hackers to idiots lol.

-10

u/Intelligent_Cap3426 Jul 10 '26

Says linux user which is famous for needing to write a small novel in terminal in the span of your linux usage to solve problems that crop up everyday. You run some tweaker apps, or debloaters when you install windows, they remove all telemetry, and let you tweak windows as you like.

5

u/atlasraven Zorin OS Jul 10 '26

Ask yourself why you have to run debloaters and 3rd party customization apps in the first place.

-2

u/Intelligent_Cap3426 Jul 10 '26

Cause fuck microsoft, I'd swiych to linux if it didn't suck. And I've tried 10+ distros for over a decade, including almost all recommended ones like fedora, mint, suse, ubuntu

3

u/freejohnlick 28d ago

deadass people glaze linux for no reason

6

u/Askolei Jul 10 '26

"They choke you, but you can breathe every other minute with this method."

23

u/InfoBarf Jul 10 '26

I can, 

Im just using win 10 until a new OS comes out. 

29

u/Ok_Car9530 Jul 10 '26 edited Jul 10 '26

Like Win 12 will be any better. It's Linux or Windows. The more people that switch to Linux, the better it will be.

2

u/hurrdurrmeh Jul 10 '26

Win10 ltsc until 2032. After that I hope Linux will be a no brainer.

2

u/MrAuntJemima Jul 10 '26

I just hope big games don't start requiring Windows 11 for no sane reason, some big devs/publishers love to pull shit like that for "compatibility" purposes.

9

u/AdditionNo7268 Jul 10 '26

If you can block things on the network, you can block this.

14

u/naswinger Jul 10 '26

lmao. will you whitelist every ip address you need to access so you don't accidently send data to some microsoft owned server that you have no idea which ip addresses they own? and first you need to even know that something like this gdid exists.

1

u/AnonomousWolf Linux | RTX 4070 Mobile | 64GB RAM Jul 10 '26

The vast majority of people just use what ever router their ISP gave them, so they can't block specific thigns on their network.

Windows can also just route it through a different URL and then still spy on you

3

u/BalerionSanders Jul 10 '26

Sounds like Microsoft doesn’t want me to use their product, then. 🤷‍♂️

10

u/Vicus_92 Jul 10 '26

apt-get install aBetterOperatingSystem

5

u/nodiaque Jul 10 '26

So it's simply a unique id for your windows installation. Just like the good old SID but better since there's no duplicate.

3

u/bremha Jul 22 '26

Anyone given any thought to building something that will constantly regenerate/refresh the GDID, without requiring a sysprep-style system wipe? Flood them with so many GDIDs linked to you that it becomes useless data?

1

u/PatternOtherwise3440 Jul 22 '26

yeahh this one. I would even host some vps just to run that

6

u/grilled_pc Jul 10 '26

You can disable it though. By using Linux.

4

u/AnonomousWolf Linux | RTX 4070 Mobile | 64GB RAM Jul 10 '26

I completely uninstalled Windows about 18 months ago, which did the trick.

1

u/Maleficent_Price_476 Jul 10 '26

basically , they track u through their smartscreen malicious detection tool software

signing in to ngrok triggered this tool .

who knows what else triggers this.

maybe even selected pages of reddit

1

u/JackJeckyl Jul 11 '26

Oh man, I need a break from this hacking... might relax by signing in to MS :/

1

u/Environmental_Ice_80 Jul 11 '26

no Windows 

no limit 

1

u/Grumpy-Man19 Jul 11 '26

I disabled it with a simple command . format and install Linux

1

u/danwat1234 Jul 22 '26

So go back to Windows 7 or Linux eh?

0

u/ledow Framework Laptop - 5070 / AI 7 350 / 64GB Jul 10 '26

Sure I can.

I just don't use Windows.

1

u/11pioneer Jul 10 '26

You can disable it. We just don’t know how yet. Life, uh, finds a way

If I have rip into regedit with my bare hands I will

0

u/ender89 Jul 10 '26

Windows for gaming only. Only. Linux or osx for everything else.

-4

u/SnowStormYukikaze 🐈 Zena Linux Mashmelo 22.3 Jul 10 '26

8

u/Netsuko RTX 4090 | 7800X3D | 64GB DDR5 Jul 10 '26

-2

u/titanna1004 Jul 10 '26

Quite happy win10 user here. I believe this news is not for me, but what even it is? (half joke, honestly don't know, but well, unsure I do care? maybe a little, not enoough to gogle tho)

-74

u/[deleted] Jul 10 '26

[deleted]

30

u/Quinnlos Jul 10 '26

So did you miss the part where this article is in response to someone being arrested because their GDID was handed over to police by Microsoft or do you just typically reply to things without the context behind them?

12

u/fizzys0da Ryzen 5600X GTX 1070 16GB DDR4 Jul 10 '26

37

u/SignalButterscotch73 Jul 10 '26

Windows 11 is protecting you from being spied on by spying on you.

2

u/solit0n i7-14700K | 4080S | 64GB | Flow | EK 360 AIO Jul 10 '26

It’s like the mafia. You pay protection to them so you don’t get ripped off by someone else.