Microsoft admits Windows 11 has a GDID tracker with no off switch, first documented publicly in an FBI hacker complaint
Microsoft admits Windows 11 has a GDID tracker with no off switch, first documented publicly in an FBI hacker complaint
GDID is the persistent Windows ID that helped FBI trace a Scattered Spider hacker despite VPNs. Here's how it works and how to limit it.Abhijith M B (Windows Latest)
like this

Maeve
in reply to ☆ Yσɠƚԋσʂ ☆ • • •StellarExtract
in reply to ☆ Yσɠƚԋσʂ ☆ • • •like this
TVA likes this.
Daryl76679
in reply to StellarExtract • • •like this
TVA likes this.
Brkdncr
in reply to Daryl76679 • • •like this
TVA likes this.
FineCoatMummy
in reply to StellarExtract • • •IDK either. But so much is now like, ppl wanting privacy have to be right every time. The co's wanting our data, only once! A single hidden backdoor siphon to our data and we didn't protect ourself from it. A single telemetry that encodes every URL we visit. A single statistical way to fingerprint us.
That Sisyphus dude knows our pain.
blackwall
in reply to StellarExtract • • •aurelar
in reply to blackwall • • •gila [any, any]
in reply to StellarExtract • • •Daryl76679
in reply to ☆ Yσɠƚԋσʂ ☆ • • •like this
TVA likes this.
whatiswrongwithyou
in reply to Daryl76679 • • •RichardNixos
in reply to whatiswrongwithyou • • •const_void
in reply to Daryl76679 • • •Hestia [she/her, fae/faer]
in reply to const_void • • •insurgentrat [she/her, it/its]
in reply to Hestia [she/her, fae/faer] • • •RedWizard [he/him, comrade/them]
in reply to insurgentrat [she/her, it/its] • • •insurgentrat [she/her, it/its]
in reply to RedWizard [he/him, comrade/them] • • •FineCoatMummy
in reply to const_void • • •I agree. But I think more to the other side of it. I worry that a vast influx, who don't care about privacy and computing freedom, would make for huge market pressure to lock down Linux. Same way we see Windows, IOS, Android locked.
Game co's, big tech, and others will demand it, if the masses flee to Linux. Today, most Linux users go nah, we want freedom more than your AAA game. If that changes, we could lose the very culture that resists locked down corporate controlled computing.
prole
in reply to const_void • • •mic_check_one_two
in reply to prole • • •iamtherealwalrus
in reply to Daryl76679 • • •shneancy
in reply to iamtherealwalrus • • •iamtherealwalrus
in reply to shneancy • • •And all the "solutions" I find on the web involve some kind of guesswork and tweaking settings left and right, hoping to somehow hit a magic combination that works.
Michael
in reply to ☆ Yσɠƚԋσʂ ☆ • • •I guess this is why people always said it was impossible to remove the watermark that appears when you are not activated, when it was rolled out many years ago.
Defeating the reasons for activation might've lead the more tech-savvy to figuring out the nature of the identifiers being sent for activation and seeing where else they are sent.
ramenshaman
in reply to ☆ Yσɠƚԋσʂ ☆ • • •☆ Yσɠƚԋσʂ ☆
in reply to ramenshaman • • •Imagine your computer has a secret ID number that Microsoft gives it when you sign in with your Microsoft account. This number is like a permanent nametag that your computer wears. Even if you use a VPN to hide your location, that nametag stays the same.
A hacker used a VPN to hide while breaking into a jewelry store's computer system. But Microsoft helped the FBI find him because his computer's secret nametag kept showing up everywhere he went online. They matched that nametag to his social media accounts and other stuff he did, and that's how they caught him. Most people didn't even know this secret nametag existed, and you can't turn it off without breaking your computer.
ramenshaman
in reply to ☆ Yσɠƚԋσʂ ☆ • • •☆ Yσɠƚԋσʂ ☆
in reply to ramenshaman • • •ramenshaman
in reply to ☆ Yσɠƚԋσʂ ☆ • • •☆ Yσɠƚԋσʂ ☆
in reply to ramenshaman • • •FudgyMcTubbs
in reply to ☆ Yσɠƚԋσʂ ☆ • • •☆ Yσɠƚԋσʂ ☆
in reply to FudgyMcTubbs • • •☂️-
in reply to ☆ Yσɠƚԋσʂ ☆ • • •how dumb can you be to use unhardened windows to hack valuable shit omg.
even if you didn't know of this system (i didn't) it's well known windows scans for even the color of your underwear.
☆ Yσɠƚԋσʂ ☆
in reply to ☂️- • • •LarsIsCool
in reply to ☂️- • • •shneancy
in reply to ☂️- • • •the average lemmy user is much more tech literate than an average person
people really don't know that kind of stuff. to many a computer is a computer, it has internet, and plays games... what's an operating system?
Dpek
in reply to shneancy • • •People cant figure out how to connect their idiotic tv (marketed as smart tv) to the streaming box
And others cant figure out how to turn the ac to cold and are "afraid of breaking it" bruh its a ac, the worst you can do is set a timer
Holla
in reply to Dpek • • •Dpek
in reply to Holla • • •Oh yeah thats why i didnt mention it still being in store mode
The remote has a button for selecting the input and the menu had 3 options: smart tv, tv and hdmi 3
☂️-
in reply to shneancy • • •damn, but even hackers capable of breaking into jewelery store systems?
like at this point the problem is extreme ignorance.
dieTasse
in reply to ☂️- • • •MonkderVierte
in reply to ☆ Yσɠƚԋσʂ ☆ • • •☆ Yσɠƚԋσʂ ☆
in reply to MonkderVierte • • •krolden
in reply to ☆ Yσɠƚԋσʂ ☆ • • •brillotti
in reply to ☆ Yσɠƚԋσʂ ☆ • • •BlackLaZoR
in reply to brillotti • • •Bog ID.
Current state: Happy
Owns: Nothing
ayyy
in reply to brillotti • • •shortwavesurfer
in reply to ☆ Yσɠƚԋσʂ ☆ • • •This sounds so much like the snitch code from Thieves' Emporium by Max Hernandez, written in 2014.
Or at least I believe it was 2014.
MonkderVierte
in reply to ☆ Yσɠƚԋσʂ ☆ • • •Bieren
in reply to ☆ Yσɠƚԋσʂ ☆ • • •youmaynotknow
in reply to Bieren • • •Does Linux track you? Does LibreWolf track you? Does GrapheneOS track you? Does Vanadium track you? Does SimpleX or Signal track you? Does...
Never mind, I think you get my point.
SocialistVibes01
in reply to youmaynotknow • • •SocialistVibes01
in reply to youmaynotknow • • •MasterBlaster
in reply to youmaynotknow • • •prole
in reply to Bieren • • •Yes, all of that is true.
Were you building up to making a point, or...
☆ Yσɠƚԋσʂ ☆
in reply to Bieren • • •BlackLaZoR
in reply to ☆ Yσɠƚԋσʂ ☆ • • •He got what he fucking deserved
0_o7
in reply to BlackLaZoR • • •Okay, buy the thing to take note here is what tech companies can hide.
You know they're tracking users but there are still things we'll never find out unless they reveal it themselves or are made to reveal in indirectly.
BlackLaZoR
in reply to 0_o7 • • •Alfredo_DisguidoAlCazzo
in reply to BlackLaZoR • • •someone
in reply to ☆ Yσɠƚԋσʂ ☆ • • •Shrouded0603
in reply to someone • • •Snapz
in reply to someone • • •Aria
in reply to ☆ Yσɠƚԋσʂ ☆ • • •Smug Reddit-level takes left and right in this thread. The kid successfully hacked a website, you can assume he knows what he's doing better than you and followed all the best practices short of not using Windows. They didn't get his account from his Edge credential store. He probably used some Firefox-derivative. Tor browser if he was stupid. He probably "hardened" Windows every way he could think of, again, short of disconnecting from the internet. Windows simply does a good job of spying on you, that's all it is.
There are even people in the thread recommending running Windows games on Linux as a way to avoid this surveillance. If you put Microsoft Flight Sim on your Linux computer, then that's now a Windows computer. Microsoft owns that computer, same as the Windows one. If you install Nvidia drivers, Nvidia owns that computer, and the USA can ask Nvidia for your accounts and whereabouts instead of Microsoft. If you put Steam on your Linux computer, that's now Steam's computer and the USA can ask Steam.
There is no "safe" amount of malware.
chinaski
in reply to Aria • • •Aria
in reply to chinaski • • •chinaski
in reply to Aria • • •Aria
in reply to chinaski • • •There isn't a 1-step perfect solution as far as I know. You can use Tor in combination with other technologies, and it'll likely help you avoid a lot of surveillance, just not specifically the NSA. (Also keep in mind anyone/commercial actors can run Tor nodes with the intention of spying on Tor users. You need a lot of nodes to catch anyone, but I wouldn't assume it never happens).
The main thing is to own your software and hardware, and disconnect what you don't own from the internet. If you can't meet those conditions, then it's impossible no matter how vigilant and knowledgable you are.
My recommendations is to play your computer games on an offline computer via GOG purchases, or if you want Steam games, then just give up on securing that device. Have two networks. Have your secure computers for your general online tasks and chatting, and have the unsecure computer for interacting with DRM and services that lose a lot of functionality if the surveillance vectors are blocked.
Bad attempts at hardening often don't work, and have the adverse effect of making you
... Show more...There isn't a 1-step perfect solution as far as I know. You can use Tor in combination with other technologies, and it'll likely help you avoid a lot of surveillance, just not specifically the NSA. (Also keep in mind anyone/commercial actors can run Tor nodes with the intention of spying on Tor users. You need a lot of nodes to catch anyone, but I wouldn't assume it never happens).
The main thing is to own your software and hardware, and disconnect what you don't own from the internet. If you can't meet those conditions, then it's impossible no matter how vigilant and knowledgable you are.
My recommendations is to play your computer games on an offline computer via GOG purchases, or if you want Steam games, then just give up on securing that device. Have two networks. Have your secure computers for your general online tasks and chatting, and have the unsecure computer for interacting with DRM and services that lose a lot of functionality if the surveillance vectors are blocked.
Bad attempts at hardening often don't work, and have the adverse effect of making you more unique for fingerprinting. It might be worth foregoing some hardening advice if you can think of workarounds the hostile actor might use, which you don't know how to counter-act.
NauticalNoodle
in reply to Aria • • •mazzilius_marsti
in reply to ☆ Yσɠƚԋσʂ ☆ • • •the fucked up thing is this GDID thing apparently also show up for VM. So that would mean any VM and even a Quebe?
Fuck microsoft
danielfm123
in reply to ☆ Yσɠƚԋσʂ ☆ • • •https://aussie.zone/u/BigBoyShuanzee
in reply to ☆ Yσɠƚԋσʂ ☆ • • •My company is moving to Windows 11, I had one of my service desk teammates tell me that for an IT support person I'm very critical of change
Before Windows 11 I was critical of change because every change came with no new training for my team and a giant email to the company explaining very lazily about the changes and with the same text at the end of every email.. "Any problems call the service desk".
Now we've lost active directory.. Now I'm in a position where an incredibly incompetent IT security have restricted our access to intune and Entra and then the business wants me to still perform my daily duties as normal.
Upside is that same IT security is getting removed in the next few weeks.
Probably to be replaced by someone else even worse.
I just want to learn how to use Entra and Intune..
Everything Microsoft touches turns to shit.
Active directory just worked.. It was built when people at Microsoft actually knew how the operating system worked.. None of those people are still at Microsoft..
BlackVenom
in reply to • • •If you enjoyed how AD worked, you'll love how I tune and AAD don't.
And the workarounds for them... Like local management... Only get harder.
Good luck.