5 ms·
Deletes all instances of Microsoft's GDID and prevents minting of new ones
- hypfer 2mo agoWouldn't it make more sense to instead use the same GDID on thousands of hosts? Or a random GDID on each read? No GDID sounds like it sticks out a lot more.
- jmclnx 2mo agoOr recreate it on every boot :) For example, it you are paranoid about Linux's /var/lib/dbus/machine-id file you can easily use dbus-uuidgen(1) to re-create it on shutdown.
- happosai 2mo agoTrying to make windows work differently than what Microsoft wants is a losing proposition. It would make more sense just not use windows to begin with.
- ziiinq 2mo ago[dead]
- userbinator 2mo agoVibe-coding a sufficiently compatible replacement seems increasingly possible. ReactOS and WINE can either get on board, or if they still try their IP pearl-clutching, I suspect they'll be replaced by something else. Bonus points for using Copilot to do it.
- GoblinSlayer 2mo agoI wonder what will happen if Copilot just recalls all windows code from memory.
- isdononthephone 2mo ago[flagged]
- gruez 2mo ago>Why not create a new HN account for every post? Your profile: >created: 1 day ago
- isdononthephone 2mo ago[flagged]
- tomhow 2mo agoIt's so notable how people who try to attack HN often have very little idea of its character. HN has not been heavily frequented by startup founders hunting VC money for at least 15 years.
- Melatonic 2mo agoOr just have the option of any of these Same GDID would pollute the data for Microsoft if enough people did it. Which would also incentivise a fix or another way to differentiate. Random GDID would likely be the most "security through obscurity" approach but still allow tracking per "session" or whatever time period it changed in. No GDID could stick out more and if enough people did it also incentivise a fix. Hard to say which is best but I also like another persons suggestion of random GDID assigned at boot. Or maybe no GDID by default with the option to spoof a random GDID manually
- cyanydeez 2mo agowhile it'd be nice for your paranoia to believe this id key is used for surveillance, it's more likely they just use the same type of finger printing that browsers use. There's zero way to onion.route your internet connection information, unless you plan to go nowhere and do nothing. Sure, it's worth to highlight privacy-potential-invasions, but the idea that you'll some how escape notice by changing the gdid is short sighted navel gazing.
- dvtkrlbs 2mo agoThere is literally court documents showing this was used by surveilling in at least one case. How that is paranoia
- dgellow 2mo agoCould you share more context and details?
- amiga386 2mo agohttps://www.windowslatest.com/2026/07/10/you-cant-fully-disable-microsofts-gdid-windows-11-tracker-but-these-settings-limit-what-it-captures/ https://www.windowslatest.com/2026/07/10/you-cant-fully-disa...
- future10se 2mo agoYou might've missed this recent story where the FBI was able to identify an alleged teenage member of the Scattered Spider hacking group using the Microsoft GDID, and made an arrest: https://news.ycombinator.com/item?id=48815196 https://news.ycombinator.com/item?id=48815196 https://news.ycombinator.com/item?id=48920338 https://news.ycombinator.com/item?id=48920338
- dgellow 2mo agoThanks! I did miss it
- 2mo ago
- LoganDark 2mo agoWindows has a hardcoded list of Microsoft domain names that entirely bypass the hosts file. I see nothing about this, so I would assume there is no countermeasure here. Curiously, this approach appears to have been tested as working anyway.
- jasonjayr 2mo agoIs there anyone maintaining a canonical list of such domains and hosts? This would be useful to add as firewall rules on a router upstream of any windows hosts, or to a pihole.
- LoganDark 2mo agoHere's one from a couple years back: https://petri.com/windows-10-ignoring-hosts-file-specific-name-resolution/ https://petri.com/windows-10-ignoring-hosts-file-specific-na... AFAICT it has not changed.
- vetrom 2mo agoRun say a linux firewall vm with PCI nic passthrough and give the host windows machine a virtio-pci/TAP interface as its network access is one countermeasure off the top of my head I can think of.
- exceptione 2mo agoAgreed, running it inside a vm is how you would treat any other malware. Why pci passtrough instead of a regular virtio network driver though?
- vetrom 2mo agoI'm imagining a situation where you need to run windows on the host, but you do not want windows itself arbitrating network access -- so you pass through the real NIC to the vm, and route through the vm with a virtio (I think TAP is actually the only option host-side though but still) NIC.
- exceptione 2mo ago> Court reporting in 2026 established that Microsoft held a GDID-to-URL/time/IP association in one investigation. Afaik, this is illegal under GDPR, as an IP has been classified as a personal identifier.
- john_chungus1 2mo ago[dead]
- buzer 2mo agoStoring IP address itself is not illegal. The questions are: 1) what is the legal basis for storing it and if that's proper or not (e.g. legitimate interest requires balancing test) 2) if proper GDPR Article 13 notice was given and it covers that processing 3) if all Article 5 principals are being followed in regards to it (e.g. data minimization, retention period etc.) 4) if Microsoft had legal basis to transfer the data to police (they probably did, that's not high bar to clear)
- exceptione 2mo ago> Storing IP address itself is not illegal True, but associating that with a device the user owns (not Microsoft) would require a very real justification like you mentioned, and I precluded that there is no legitimate interest here. caveat: IANAL.
- userbinator 2mo ago"The mutation path", "the fully lab-validated line. Other accepted builds warn.", "Status can still inspect", "command, verdict, exit code", "device-identity rehydrate sources", "the network gate", "real-shaped PUID"? WTF. That was extremely difficult to read. I'm assuming it's LLMese (I've had less trouble with reading the writing of ESL'ers), but one of the strangest dialects of it I've ever seen. It has the flavour of article-spun SEO spam and those shady fake research papers with "tortured phrases". What causes this obfuscated writing style?
- andersa 2mo agoI like to call this style of writing "advanced technical claudish"
- mlinhares 2mo agoI use claude and codex to write nearly all my code today but i can't accept using it to write prose. I still handwrite every single document I have to write and have them review and propose changes, i feel like if i can't put my own ideas into words for people (and claude) to work on i've completely lost it.
- azalemeth 2mo ago> What causes this obfuscated writing style? Claude without an editor having worked too long on its own project.
- nullsanity 2mo ago
- nixosbestos 2mo agoFun story, when my ex and I split a few years ago, I wiped all connections of my Microsoft account to the machine I built him. Last week, when I logged into my Microsoft account, I had an extra machine with a funny name. Checking some logs, sure enough that was the hostname he gave that machine. Realized what had happened, refreshed the page, and it was gone. The URL parameter for these devices in the Microsoft Account page is the GDID. So the Microsoft Account page showed me a GDID of a device I unlinked ~4 years ago. (And I'm slightly obsessive, I check on my Google/Microsoft account every other month.) Gooood job Microsoft.
- Melatonic 2mo agoYou sure it wasn't one of the other UID numbers that have been in use longer ?
- deleted 1mo ago[deleted]
- nixosbestos 1mo agoYes? It's the fucking GDID. Anyone could've just looked and confirmed it. It's the GDID format; it's not a GUID; I'm not stupid. EDIT: god, shocking, crazy, hard for this site to imagine but, I spent 10 whole seconds looking at my account, click on a device, looked at the URL. It's clearly a hex-encoded GDID. https://account.microsoft.com/devices/device?deviceId=global[001880098F23FCDB] https://account.microsoft.com/devices/device?deviceId=global... `001880098F23FCDB` but sure, I'm the idiot here. I MEAN HOLY FUCK ITS LITERALLY THE GLOBAL DEVICE ID IN THE URL, IN THE EXACT FORMAT OF A 'GDID', BUT WHAT DO I KNOW? And yes, it's totally normal for my Microsoft account to show me a machine named 'pelinore', registered to my account, when I literally don't know the first fucking thing about DnD, and I have specific machine naming convention that would never include 'pelinore' /s.
- cadamsdotcom 2mo agoSharing in the hope it helps even one person on the fence to convert. C. 2012 I swore never to use Windows again, and I've managed it! It is possible - macOS is really good (you'll have to unlearn your muscle memory of the Ctrl key) and Linux gaming has come a long way. If using Windows professionally, consider installing it in a VM on your mac or linux box, then asking your agent to set up scripts that remote to to it (eg. via ssh) and do the required tasks (builds, headless test-runs etc) - remotely. Offtopic for the GDID thing; but couldn't be more on topic if you think the market shouldn't tolerate GDIDs and such things.
- Retr0id 2mo ago> you'll have to unlearn your muscle memory of the Ctrl key There is another option, which is to use Karabiner to revert to PC-like shortcuts. Learning the mac way is probably better if you plan to use mac exclusively, but I was triple-wielding macos+windows+linux for a period and I wanted my muscle memory to work across all of them.
- Melatonic 2mo agoAren't a lot kg the mac ones just Command plus the same button ? My brain has learned pretty well to code switch between OS at this point. It's actually really too bad MacOS doesn't have some of the windows key shortcuts like "windows key + arrow key". Would be super useful.
- WalterGR 2mo ago> It's actually really too bad MacOS doesn't have some of the windows key shortcuts like "windows key + arrow key". Would be super useful. Right this way, sir/madam: “Mac window tiling icons & keyboard shortcuts” https://support.apple.com/guide/mac-help/mac-window-tiling-icons-keyboard-shortcuts-mchl9674d0b0/mac https://support.apple.com/guide/mac-help/mac-window-tiling-i...
- Melatonic 2mo ago
- isdononthephone 2mo ago[flagged]
- IronWolve 2mo ago<Gov AI> this user keeps hitting our instances with no GDID, better look into it.
- Melatonic 2mo agoBetter yet - reply with the same GDID of the machine doing the scanning :-D
- monster_truck 2mo agoThis is slop (derogatory) It's missing quite a few things. Not exactly a ringing endorsement for claude
- WalterGR 2mo agoI’ll bite. What is it missing?
- monster_truck 2mo agoYou can tracelog CDP, passport, delivery optimization, and countless other services if you're interested.
- VCFundedGenYer 2mo agoFYI this contains major red flags. Degrading the MS sign in and other features is not sustainable. If you truly want to get away from GDID and all the other Windows nonsense, start using Linux Mint.