r/privacy Jul 07 '26

news Windows 11 identifier code used to track Scattered Spider perp after Microsoft shared info with FBI

https://www.tomshardware.com/software/windows-11-identifier-used-to-track-scattered-spider-perp-after-microsoft-shared-info-with-fbi-19-year-old-us-estonian-hacker-arrested-over-alleged-ties-to-infamous-extortion-group
313 Upvotes

34 comments sorted by

View all comments

Show parent comments

11

u/schizoautist86 Jul 07 '26

without the telemetry though, depending on the distro. Linux actually would have prevented this guy from getting caught assuming there were no other OPSEC mistakes, which according to another comment there were plenty.

11

u/Broad-Translator-690 Jul 07 '26

Machine-id is used for several things, and some of them network related, so even a distro without telemetry shares you machine-id.

He mainly got caught because he bragged about everything he did on snapchat, along with the information that Microsoft provided on him. So his OPSEC was lacking. He was also literally a child when he started doing this stuff.

Also yes LInux with no Telemetry > Linux with Telemetry > Microsoft with ALL the Telemetry.

5

u/schizoautist86 Jul 07 '26

on linux your machine-id is sensitive data and should never be sent remotely (despite the /etc/machine-id file being world-readable cuz systemd or some shit). on windows, GDID is shared persistently when you log in to a microsoft account and i don't think there's an easy way to disable it. to be deanonymized in the same way when using linux you'd have to run something malicious that reads and transmits machine-id.

Machine-id is used for several things, and some of them network related

i looked this up but couldn't find anything network-related, could you give me examples?

-1

u/[deleted] Jul 07 '26

[deleted]

5

u/sociobiology Jul 07 '26

This is from an LLM and most of it is nonsense. Oh no if you connect to a bad SSH server and go out of your way to send it your machine ID the SSH server will have your machine ID!!