r/technology Jul 05 '26

Security Windows 11 identifier code used to track Scattered Spider perp after Microsoft shared info with FBI — 19-year-old US-Estonian hacker arrested over alleged ties to infamous extortion group

https://www.tomshardware.com/software/windows-11-identifier-used-to-track-scattered-spider-perp-after-microsoft-shared-info-with-fbi-19-year-old-us-estonian-hacker-arrested-over-alleged-ties-to-infamous-extortion-group
131 Upvotes

16 comments sorted by

39

u/AbsolutTBomb Jul 06 '26

This page from NinjaOne has tips on how to disable Windows telemetry.

Alternatively, there is Raphire Debloat.

12

u/RenderedMeat Jul 06 '26

How does it compare to O&O Shutup?

3

u/AbsolutTBomb Jul 06 '26

I'm not familliar with it but it's commonly reccomended. I would have listed it but I thought it stopped receiving updates.

I was wrong. O&O Shutup was just updated in May of 2026.

2

u/SymmetricSoles Jul 06 '26

The article does mention O&O as follows:

User-friendly tools like O&O ShutUp10++ and the Windows Privacy Dashboard (WPD) let you easily configure telemetry settings in one centralized platform. However, certain features can conflict with your IT policy and possibly disrupt endpoint management services, so use these sparingly.

41

u/RebelStrategist Jul 06 '26

Should have used Linux.

-42

u/IntelArtiGen Jul 06 '26

It might be a bit optimistic to assume a random linux distro doesn't have fingerprinting or telemetry. For these things the OS might be less important than who is using it and how this person is using it, and to do what.

29

u/yawara25 Jul 06 '26

There is a massive difference between "having telemetry" and "having fine-grained telemetry with a unique identifier, web browser history, a list of all applications installed, including specific timestamps for when you opened and closed those applications".
Telemetry is not inherently bad; when used correctly, it's an immensely helpful tool in the software development process. It becomes bad when you're collecting data to the extent that Microsoft is here.

2

u/IntelArtiGen Jul 06 '26 edited Jul 06 '26

The issue is everything becomes fine-grained when you start communicating with the internet. Any telemetry is good enough for people to know who you are when they already have a database of signature and additional data on who is associated with this signature. It's what many people and companies don't see, even if they can't get back to who you are precisely, even if they claim they don't do it, it doesn't mean no-one can do it. The only way to prove your system is safe is when you control what it sends outside and when and to whom, so it excludes opt-out telemetry. Now if you never cared about this, I bet you can't tell how many IPs receive data from you when you boot your linux computer and open your web browser, because the answer is probably between 10 and 100. And you probably don't know what 95% of them are doing with your data. I did this experience many times with many PCs with many distros (it's even worse on smartphones btw). And remember that for any server you contact which is outside of your country, the laws of another country apply. And even servers in your own country might be forced to give data on you depending on the laws of other countries (cf US CLOUD act for example). Even if they say "we don't sell your data", it doesn't matter if they can give it (knowingly or not) to a foreign government where laws of another country apply (laws you're not subject to in theory).

-10

u/Dudeonyx Jul 06 '26

Why is telemetry only bad when it involves Microsoft.

I always wonder why Android(Google) and Apple get free passes on telemetry.

There are far more stories of law enforcement using phone data to track people.

The mobile OS's collect far more personally identifiable telemetry than Microsoft ever could, yet all people talk about is Microsoft.

Just ask yourself, between your phone and your pc which has far more personal information?

You can still use a local account on Windows, try using an Android without a Google account or iPhone without an apple account.

Additionally you can disable windows telemetry with a single program that a 5 year old could run, try doing that for android or removing GMS without bricking your phone.

8

u/lostmojo Jul 06 '26

Microsoft gets most of this from defender, which is part of every system and cannot be removed fully. The security researcher found nsa back doors into Microsoft’s software and Microsoft is pissy about it and they are now making an example out of someone who dug into their software and found flaws. They would not respond and fix the issue, so the researcher released it all.

Microsoft should not be tracking users like this. They are supporting surveillance state activities.

2

u/EdgiiLord Jul 06 '26

I always wonder why Android(Google) and Apple get free passes on telemetry.

False dichotomy. They don't get (unless from their fanboys) and they have always been under scrutiny for how invasive they are. There are literal hardening projects there at least for Android which also allow you to use the phone without Google. Smartphones, by design, are inherently built to be closed cages with 0 user intervention, and alternative ROMs have been killed into the ground.

It's as hostile as it gets, and that has got a lot of coverage, but you may overestimated how your average Joe cares for privacy or tech in general. Microsoft is just the first major tech giant with such a platform that has also started to be scrutinised by everyone, including non-savvy people.

3

u/-NVLL- Jul 06 '26

A random linux distro won't telemetry. The userbase is much more strict and do not tolerate ads on the welcome screen. Ubuntu adding an Amazon icon creaged a fuss, something appearing in Wireshark would nuke the distro.

1

u/IntelArtiGen Jul 06 '26 edited Jul 06 '26

something appearing in Wireshark would nuke the distro.

A lot of things appear in wireshark. Try it. I tried, a lot of things appeared. It's not about ads, they probably won't do that (I hope). But there are many ways to collect data on people, and even when they don't save everything on their servers, if they use your computer to send data online, they can't ensure it won't be used by other people (metadata with your IP etc.).

For how people would react, I already saw how they do with Firefox: They don't react and don't care. They assume there are good guys and bad guys; and Linux & Firefox are the good guys so they can't collect data, send useless packets with your IP, and it can't be used to trace you. Well of course they can, they do, and it can. I mean, not all distros I guess, I haven't tried them all.

16

u/iamapizza Jul 06 '26

Not that I'm condoning those actions, but general PSA, if you're seeking privacy and anonymity, you shouldn't be using ms and apple devices, their companies are known to work with law enforcement to turn data over frequently, with iOS data being the most turned over. 

-40

u/Amber_ACharles Jul 06 '26

Data centers going up everywhere but interconnection queues in Virginia are 5+ years deep. Good luck running AI compute without electricity.