This was a fun article to read. Yes Windows is more surveillance software than Android or Apple are - the article makes that case well at the end when talking about how tracking is more explicit and can be turned off on those.
But I'm struck with how dumb, or just lacking in paranoia, this seemingly successful and rich hacker is. First of all he's using Windows. Excuse me? Second he used that device to log into personal stuff like Snapchat and Facebook. And he posted a picture of himself at a hotel that they tracked.
I'm no hacker, but if I were, I'd treat devices as disposable surgical gloves, and I wouldn't touch Windows.
> Yes Windows is more surveillance software than Android or Apple are
this is cheap
> There’s no consent screen. A GDID gets assigned when you sign into a Microsoft Account. Apple’s advertising identifier needs an App Tracking Transparency prompt and a visible reset; Android’s works the same way. GDID has neither, and a Windows reinstall only gets you a new number Microsoft can still get back to the same account.
You can opt out of "some" tracking. But that is all. You have an advertising ID, a Chrome/Safari ID, an IMEI etc.
>Microsoft’s records showed that at that exact same minute, a Windows device carrying GDID g:6755467234350028 had visited the ngrok signup page. Three hours later, the same GDID visited the retailer’s own website, through the same Tzulo proxy address used to set up the ngrok account.
Can someone explain the mechanism through which Windows sends this information to Microsoft? Did the hacker use Edge, which communicated the web history + the GDID of the user to Microsoft, or is Windows snooping on browsers besides Edge and sending the web history to Microsoft, or is Windows bundling a summary of all connections open and sending it to Microsoft?
> Note that, Microsoft had already flagged Stokes to the FBI once before, in an October 2024 criminal referral describing “online services telemetry.”
I don’t like the idea of Microsoft taking it upon themselves to proactively report what their customers are doing to law enforcement. I guess this makes it unwise to use Windows to i.e. look for information on where to get an abortion if you live in a red state.
the GDID seems like a tertiary issue barely worth mention, like ok a hw identifier exists in web browsing logs that microsoft somehow has the entirety of??
8 comments
[ 3.4 ms ] story [ 30.1 ms ] threadBut I'm struck with how dumb, or just lacking in paranoia, this seemingly successful and rich hacker is. First of all he's using Windows. Excuse me? Second he used that device to log into personal stuff like Snapchat and Facebook. And he posted a picture of himself at a hotel that they tracked.
I'm no hacker, but if I were, I'd treat devices as disposable surgical gloves, and I wouldn't touch Windows.
this is cheap
> There’s no consent screen. A GDID gets assigned when you sign into a Microsoft Account. Apple’s advertising identifier needs an App Tracking Transparency prompt and a visible reset; Android’s works the same way. GDID has neither, and a Windows reinstall only gets you a new number Microsoft can still get back to the same account.
You can opt out of "some" tracking. But that is all. You have an advertising ID, a Chrome/Safari ID, an IMEI etc.
Did the hacker not disable telemetry? Was he using Microsoft Edge? Or is it just a GDID->IP mapping combined with network activity?
It is obvious that Microsoft has an identifier for my device. They enforce license activation.
The problem is that they’re tracking user activity and associating it with this ID, even for a user who, one would assume, rejected all telemetry.
Can they do this in devices owned by companies and governments that are configured with strict no telemetry and no cloud services policies?
Can someone explain the mechanism through which Windows sends this information to Microsoft? Did the hacker use Edge, which communicated the web history + the GDID of the user to Microsoft, or is Windows snooping on browsers besides Edge and sending the web history to Microsoft, or is Windows bundling a summary of all connections open and sending it to Microsoft?
I don’t like the idea of Microsoft taking it upon themselves to proactively report what their customers are doing to law enforcement. I guess this makes it unwise to use Windows to i.e. look for information on where to get an abortion if you live in a red state.
Full Writeup of the Windows GDID
https://news.ycombinator.com/item?id=48811081
Microsoft Can Track Users via a Windows Device ID
https://news.ycombinator.com/item?id=48815196