15 comments

[ 3.4 ms ] story [ 35.7 ms ] thread
one thing this doesn't touch on that I am curious about is how was browsing history, etc, correlated to the GDID?
Wasn't this the GUID (Globally Unique Identifier) of early 00s Windows? When did it change to GDID? Are they the same?
this is why Microsoft is pushing so hard for Microsoft accounts at install
For those like me who were not abreast of this issue: the FBI was able to arrest some kid who hacked/is alleged to have hacked a jewellery retailer through a VPN. They were able to track the hacker via the user's GDID, which is a stable identifier unaffected by VPN usage.

This surveillance is certainly going to expand in scope as age verification comes into widespread usage. Personally I see little legitimate use case for this telemetry. It seems only useful for the purposes of tracking users for law enforcement or targeted advertising purposes.

How a Windows device's global ID is generated may be new info in the public sphere, but the fact that the global ID exists is not a secret. This format of device ID has been in Windows since the initial release of Windows 10 in 2015, when it was introduced as part of Windows' current telemetry subsystem. To see your device's global ID, open Windows Feedback Hub, then go to Feedback Hub Settings and look under Device Information.
> The court record itself says a reinstall produces a new GDID

That's a half truth if I ever saw one. Telemetry also includes the hardware hash (which does use SMBIOS serial number, CPUID, TPM identifiers, etc.) and that one survives OS reinstalls and even hardware swaps. It is the underlying id used for things like Autopilot (the equivalent to Apple's remote MDM lock).

Can promise you a re-install does nothing for your privacy. Plenty of IDs are embedded in the hardware.
So can you change/spoof your GDID easily?
is there a mac equivalent to the windows GDID?
AI-generated "research" once more. How can anyone call it full writeup?

As someone pointed out in the X argument comments, this is unconfirmed and most likely NOT how the actual GDID being sent to microsofts servers looks like.

1. The GDID that most closely resembles the one mentioned in the DOJ indictment of Stokes is found inside the registry key Computer\HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\IrisService\IrisActionCreatives, which starts with the "g:" prefix and is explicitly called GLOBALDEVICEID. This keys holds cached json response from microsoft servers and this is clear as night and day what value microsoft servers consider a "GDID"

2. According to the research, a Microsoft account is required. No, it's not necessary. Whether or whether you are not logged into your Microsoft device, GDID is being filled in. Did AI forget to check that?

3. How can author claim this is full writeup of GDID, when you did not verify whether the value your AI found, is the one being sent along with telemetry network requests? Author did not even verify whether he found the right thing

I also verified the value computed as suggested by the repository's creator and it is different from the value discovered inside the Iris registry key that begins with "g:".

Summary: The value author of repo claims is a GDID, is not the same value as saved on microsoft servers.

Aside from the writeup, how stupid must one be to commit cybercrimes from a Windows 11 computer full of spyware?
Couple questions:

1) Do we think this is actually how the FBI found this kid or is this simply what they're saying in order to keep some other tool hidden?

2) Is there a way to block or manually change the GDID from being revealed. If it's the browser leaking it, do all browsers leak it?

Complaint says "Cybersecurity researchers at Microsoft" found the kid and handed his name to FBI