Skip to main content


in reply to jcrabapple

2023 hacking? 19-year-old cyber criminal?

i'm not a math genius, but it sounds like this person was a child at the time.

microsoft, spying on children and tracking them around the internet? creepy!

in reply to jcrabapple

amateurs. who doesn't wipe and reinstall their windows install at least yearly? Who can trust all the cruft and metadata that gets built up in the backrooms of your hard drive. yeech.
in reply to jcrabapple

Lesson of the story?
- Don't committ cyber crime, especially not over your home internet connection
- Don't login with personal accounts to a work PC (especially if it runs Windows)
in reply to jcrabapple

Remember the moral of the story kids : always hack on linux
in reply to jcrabapple

Which in essence means. Microsoft holds the key to a lot of criminals from child abusers to drug and human trafickers. But the choose to back down here?

Or rather the FBI know it could cat awhile breed of other assholes if they would only care enough.

In best case MS would have never done that in order to protect users but well in this day and age and especially with that Zeitgeist in the US right now, they will certainly not walk back on that GDID.

Even if they EU tries

in reply to jcrabapple

I can't believe I'm that person now, but; yet another reason to go Linux
in reply to jcrabapple

@gvwilson the story doesn’t quite say directly, but I think the implication is that when he turned on the VPN, the GDID was sent back to Microsoft via windows update, and thus they log everyone’s unique device ID associated with every IP address (and thus every location) it has ever had? without parsing this closely it kinda sounds like the browser just sends your GDID to everybody as part of every request, or at least sent it to ngrok as part of signup, which I don’t think is true
in reply to jcrabapple

Meh. Microsoft, like all other big companies, will respond to legal process. Given that Microsoft's recent operating systems basically require you to log in to their cloud at startup, this is not particularly surprising to me.

And if motivated to pursue a threat actor who is actively harming their customers, Microsoft can tell a great deal about users. As can Google, or FB/Meta. I always said that if just two of those companies decided to find someone responsible for something, they probably could if they shared information.

in reply to jcrabapple

"Experienced cyber-criminal" used *and trusted* Windows?? Was he stupid?
in reply to jcrabapple

I'm a bit concerned that it looks like systemd wants to do this as well in its own way.
in reply to jcrabapple

Now replace „cyber criminal“ with „dissident“.

With this level of permanent surveillance western democracies have become a hoax.

in reply to jcrabapple

This prompted me to have a very nerdy project morning on my Nobara PC. I don't do the criminal stuff this kid did, but like hell I'm going to assume that this isn't being abused.

So I randomed my machine ID, randomed my MAC address, setup a cron to clear old journal files that don't match my current machine ID, got SSH recovery setup in case I nuked my plasma shell, and everything is running so far.

Nobara Linux. :linux: