5 ms·
GDID Windows – Cut the tracker that follows you even under VPN
https://www.windowslatest.com/2026/07/10/you-cant-fully-disable-microsofts-gdid-windows-11-tracker-but-these-settings-limit-what-it-captures/ https://www.windowslatest.com/2026/07/10/you-cant-fully-disa...
- deleted 2mo ago[deleted]
- SV_BubbleTime 2mo agoObvious workaround to get off windows and use Linux… But do any popular linux distributions use an identifier? Ubuntu, Kali, Mint, Arch, etc? It seems an attractive way for devs to work out telemetry. Awful in reality; but I imagine attractive.
- moepstar 2mo agoAt least Debian and Ubuntu have /etc/machine-id, presumably easily changed - but it’s there.
- NotPractical 2mo agoI think the difference is that, on Windows, there are background services that constantly ping Microsoft with the device ID. A device ID on its own is not really harmful if it's not exposed to the internet.
- Terr_ 2mo agoRight, the danger here isn't stable unique data itself--there's already plenty of that--but the OS "telemetry" which steals [0] it and reports to Big-Brother along with too much other betraying information. Every site you visit, every program you run, the serial numbers of all your hardware, etc. Even if the GDID were totally absent, it would still be a correlate-able privacy nightmare. Ultimately there's no informed consent here: The average consumer is disbelieving and surprised if you tell them what kinds of stuff Microsoft has/can put into a dossier. Nobody thinks: "Ah, Edge on a fresh Windows install, I'm glad Microsoft knows every site I visit, and can tell I'm a friend with someone because we use the same bluetooth speaker." [0] It seems wrong to use the verb "leaks" when it's so obviously intentional.
- capitainenemo 2mo agoI mean, there's a ton of unique identifiers on machines already tied to hardware and disks, but that must be a systemd thing since my Devuan machine does not have it. But given there's no cloud accounts on linux I would imagine it's trivially changed just like a NIC's MAC Also, seems unlikely it would be used for any single-signon with cloud services.
- NotHereNotThere 2mo agoThere are _some_ cloud accounts for linux such as Ubuntu One, which I would fear could have similar identification capabilities if ever forced by to do so by a 3-letter agency
- giantrobot 2mo agoAny sort of online service you're logged into is going to have your IP and account correlated with a timestamp. Dropbox, GDrive, and even your e-mail provider. While a device identifier might be more useful it's not like the lack a device ID will keep you from being tracked.
- oasisaimlessly 2mo agoI'm guessing Devuan still has /var/lib/dbus/machine-id.
- 2b3a51 2mo agoTIL. /var/lib/dbus/machine-id Exists on Slackware64 15.0 but /etc/machine-id Does not.
- capitainenemo 2mo agoYou're right. I have no idea what it's for, but I'm guessing for distinguishing between deployment images. I'm certainly not going to get too concerned about it. The issue with the microsoft account was not unique IDs - tons of unique things on a machine.... it was a unique thing tied to an account and shipped to remote places.
- sorenjan 2mo ago> Microsoft provided the FBI with the history of IP addresses tied to that specific GDID. This article, and most articles about this, doesn't explain where FBI got that GDID from. Ok, Microsoft has a list of IP addresses that has been used by a computer with a certain GDID, but FBI needs to get the GDID in the first place, and then try to bind that to a person. I found another article that explains the process a bit better: > Stokes got caught because he used the same Windows device for everything, and the GDID stitched all of it back together after the fact. > Scattered Spider members phoned the jewelry retailer’s IT help desk from Google Voice numbers, posed as locked out employees, and talked support staff into resetting three accounts, two with administrator privileges. From there they installed a tunneling tool called ngrok to get past the retailer’s network defenses, moved roughly 77 gigabytes of data to Amazon cloud storage using ngrok [...] > Investigators later subpoenaed ngrok and found the account used in the attack had been created on May 12, 2025, at 19:21 UTC from a VPN proxy IP address run by Tzulo, a hosting provider. The IP was a dead end. VPN proxies do that. But the GDID is built different. > Microsoft’s records showed that at that exact same minute, a Windows device carrying GDID g:6755467234350028 had visited the ngrok signup page. Three hours later, the same GDID visited the retailer’s own website, through the same Tzulo proxy address used to set up the ngrok account. It gave the FBI a device, that don’t rotate the way VPN exit nodes do. https://www.windowslatest.com/2026/07/10/you-cant-fully-disable-microsofts-gdid-windows-11-tracker-but-these-settings-limit-what-it-captures/ https://www.windowslatest.com/2026/07/10/you-cant-fully-disa... Although this doesn't explain where Microsoft got that traffic data from. How do Microsoft know which sites a computer visit?
- crtasm 2mo agoThey make the default web browser on Windows, and that sends your browsing data if you don't disable its telemetry. See https://news.ycombinator.com/item?id=48921595 https://news.ycombinator.com/item?id=48921595
- sorenjan 2mo agoThis seems like something that should be easy to confirm, but I haven't seen anyone do it. Do they keep a database of every website visit all Edge users make?
- int0x29 2mo agoI have a sneaking suspicion that that ID can be deleted either with a specific service not running or with Windows powered off.
- nickphx 2mo agoit is generated from identifiers on device by a remote microsoft system where it is stored ..
- int0x29 2mo agoBut it is regenerated by reinstalling. So I suspect that its less fingerprint based and more of an in disk IDs thing. Which goes back to if you clear the right things while the system is not running you might be able to change it
- pndy 2mo agoI won't be surprised if MS patches workarounds quickly and won't shed a word on the whole situation. Or worse, pulls the "this helps fighting evil hackers" reasoning.
- Razengan 2mo agowow.. How is this not a bigger deal
- Terr_ 2mo agoI think it's likely that Microsoft is running a process to correlate "new" GDIDs to old ones, ex: "Oh look, this one has almost all the serial numbers of components and attached-devices as that other one, it's probably the same computer with a fresh install, let's make a note of that..."
- aucisson_masque 2mo agoBut I've got nothing to hide
- Terr_ 2mo ago(Aware/assuming you're being sarcastic.) I've always felt that statement reveals a serious lack of imagination, or at least a failure to apply it to the question.
- codedokode 2mo agoThey do not need this, they require you to create a Microsoft account to use your own computer (currently without a phone number, passport and selfie but that will probably change in the future).
- 0x1d7 2mo agoInteresting, generally Microsoft bypasses the hosts file name resolution for various MSFT domains. Curious that these were not included (if it works, which I assume the mitigation does). https://petri.com/windows-10-ignoring-hosts-file-specific-name-resolution/ https://petri.com/windows-10-ignoring-hosts-file-specific-na...
- Quarrel 2mo agoFWIW, YogaDNS stops these bypasses if you tick a settings box ("Block plain DNS over TCP from System Resolver"). Or use similar DNS forcing techniques against port 53. Windows falls back to the normal resolver in that case.
- illithid0 2mo agoIf you care about privacy, you simply cannot use Windows. Microsoft has made it clear over the last decade (if not longer) that they have a vested interest in compromising your ability to use software without exploiting and monetizing data about your usage. Microsoft is a post-privacy corporation. Eventually, we really have to stop acting so shocked about this sort of thing from them.
- Xotic007 2mo ago[dead]
- ck2 2mo agothis is a Windows 11 thing only? when LTSC exists why are people using W11 ?
- antisthenes 2mo agoWindows 10 LTSC IOT will be the last Windows I ever use. As I grow older, I simply do not have the patience or the will to do all these workarounds and tweaks to my OS to turn it from a piece of barely-working corporate spyware into something that I can call a productive tool. It also seems like interacting with the OS is on its way out anyway, as most people essentially interact with computers via the browser (essentially a different sandboxed OS altogether), whether on desktop or mobile device.
- pudgywalsh 2mo agoI agree, tracking data via unique identifiers is evil incarnate, unless it's Google or VC-backed adtech doing it, because how else will they make money having architected their entire businesses around it.
- inventor7777 2mo agoI cannot believe people tolerate this kind of behavior from such a large company with a huge market. It does make me wonder if people would react differently if Linux or Apple did the same thing.
- pudgywalsh 2mo agoBetter start believing it; Google Chrome has a 71% market share.
- jolmg 2mo agoIt's not one homogeneous people reacting to different OSes. It's different people, and they react differently when somebody else's OS does something vs when their OS does something. Windows users don't care or feel locked in because it's the only OS they've known and they depend on it. Linux users expect this type of behavior from Windows, but they can't do more than switching themselves which they already have. Were Linux to do something similar, you remove the offending piece of software.
- gruez 2mo ago>Every finding here was reproduced on a real Windows 11 Pro VM (build 26200). Nothing is theoretical. See docs/technical-writeup.md for the evidence, tagged by confidence level. That's sounds nice and all, but everything about it, from "Nothing is theoretical" to "evidence, tagged by confidence level" goes out the window when you find claude as one of the commit authors, and the content is clearly copy pasted output from claude with very little editing. Worse yet, one of the sources he cites is also clearly AI output. I'm not even against the use of AI here. I would rather see it clearly say either "this is what claude found after I told it to investigate" or "yes this is generated by claude, but I independently verified each of the points myself".
- 20after4 2mo agoValid points, not sure why you were down-voted.
- nekusar 2mo agoSo, uhh, fuck windows and use Linux if you value your security and privacy?
- Nevin1901 2mo agoOr just use Linux.
- altcognito 2mo agoThat's exactly the advice at the end.
- ranger_danger 2mo ago/etc/machine-id also exists
- sudonem 2mo agoAnd it’s easily altered.
- ranger_danger 2mo agoIt can still be correlated with past IDs by countless other methods in order to keep tracking you further.
- kvuj 2mo agoBut then you're using other methods, you're not using the ID as tracker. In fact if you just remove it, it eliminates this entire discussion.
- ranger_danger 2mo agoThe trick is to combine it all, which is what MS is doing. For example your MS account stores any GDIDs that you've logged in with. If you use a different identifier to track changes in a GDID/machine-id/etc., that means you can continue tracking using mainly just the new machine-id, but you should always keep trying to correlate it with other things in case it changes.
- jolmg 2mo agoBut you don't have a service uploading it along with the URLs you visit, which is the creepy part. The ID itself can be useful for your own administration. And if such a service were to appear, it could easily be removed. Everything in Linux is optional, especially as long as you stick to open source.
- pudgywalsh 2mo ago[flagged]
- brookst 2mo agoNot a fan of whaddaboutism. It’s much easier to switch browsers than operating systems, especially if you have apps that require windows. Besides, there is no obligation to be equally outraged about all things.
- pudgywalsh 2mo ago[flagged]
- MrNeon 2mo agoWhat Google was "caught" doing was exactly what it was doing in non-incognito mode already. Anyone expecting the websites you visit to know you're in private mode and to not log data is just lacking basic tech knowledge. It is silly that Google had to explicitly state that in the disclaimer.
- Dylan16807 2mo agoIt's reasonably detectible. And it wasn't about "websites" logging you in general, it was about Google in particular logging you, the same company that was making the misleading privacy promises. They deserved the slap over it. And it required a bit more than basic tech knowledge to understand what was misleading, it was a real problem.
- MrNeon 2mo ago"Now you can browse privately, and other people who use this device won’t see your activity. However, downloads and bookmarks will be saved." Can you tell me how the original Incognito mode disclaimer was misleading? Even if it is detectable it shouldn't be detected, why would I want websites to act differently when I'm in private mode? And if it did block Google's services from capturing the same data as they capture in non-private mode it would act as a sort of ad blocker, why should that be a function of private mode?
- codedokode 2mo agoStopped using Windows in Windows 7 era, never regretted.
- BobbyTables2 2mo agoPeople paint this as a bad thing but wouldn’t directly reporting the UUID from the DMI info be far worse? (Kinda amazed they just didn’t to that instead)
- Quarrel 2mo agoIt would be about as bad, although nothing, AFAIK, actually systematically sends it as telemetry. This GDID is essentially a similar concept though, but not as hardware tied, but is reported in telemetry.
- imglorp 2mo agoEven if you fix this one, how do you know if you got all of them? How do you know they won't add more another time in some quiet patch? Just stop already, you are in an abusive relationship. Get out. Remove windows. It's not your friend. It's your computer, you have options.
- MallocVoidstar 2mo agoArticle tells you to paste > $lid=(Get-ItemProperty 'HKCU:SOFTWAREMicrosoftIdentityCRLExtendedProperties').LID which obviously does not work because it has all the slashes removed. Article author apparently didn't bother to proofread anything.
- Cold_Miserable 2mo agoGet-ItemProperty : Cannot find path 'HKCU:\SOFTWAREMicrosoftIdentityCRLExtendedProperties' because it does not exist. At line:1 char:7 I guess I'm good then.
- d3Xt3r 2mo agoYou're missing all the backslashes, so of course it doesn't exist.