36 comments

[ 0.24 ms ] story [ 17.7 ms ] thread
(comment deleted)
Obvious workaround to get off windows and use Linux…

But do any popular linux distributions use an identifier? Ubuntu, Kali, Mint, Arch, etc?

It seems an attractive way for devs to work out telemetry. Awful in reality; but I imagine attractive.

> Microsoft provided the FBI with the history of IP addresses tied to that specific GDID.

This article, and most articles about this, doesn't explain where FBI got that GDID from. Ok, Microsoft has a list of IP addresses that has been used by a computer with a certain GDID, but FBI needs to get the GDID in the first place, and then try to bind that to a person.

I found another article that explains the process a bit better:

> Stokes got caught because he used the same Windows device for everything, and the GDID stitched all of it back together after the fact.

> Scattered Spider members phoned the jewelry retailer’s IT help desk from Google Voice numbers, posed as locked out employees, and talked support staff into resetting three accounts, two with administrator privileges. From there they installed a tunneling tool called ngrok to get past the retailer’s network defenses, moved roughly 77 gigabytes of data to Amazon cloud storage using ngrok [...]

> Investigators later subpoenaed ngrok and found the account used in the attack had been created on May 12, 2025, at 19:21 UTC from a VPN proxy IP address run by Tzulo, a hosting provider. The IP was a dead end. VPN proxies do that. But the GDID is built different.

> Microsoft’s records showed that at that exact same minute, a Windows device carrying GDID g:6755467234350028 had visited the ngrok signup page. Three hours later, the same GDID visited the retailer’s own website, through the same Tzulo proxy address used to set up the ngrok account. It gave the FBI a device, that don’t rotate the way VPN exit nodes do.

https://www.windowslatest.com/2026/07/10/you-cant-fully-disa...

Although this doesn't explain where Microsoft got that traffic data from. How do Microsoft know which sites a computer visit?

I'd take all of this with a cup of salt due to law enforcement's use of parallel construction in tech cases.
> Microsoft has a list of IP addresses that has been used by a computer with a certain GDID, but FBI needs to get the GDID in the first place

What they did was the opposite: ask Microsoft for GDIDs used by attacker-associated IPs within several 24-hour time periods during which attack-related activity took place. Windows pings Microsoft regularly with the GDID, establishing links between your GDID and any IP addresses you use. The IP logs from Microsoft and the VPS provider showed at least 10 instances where a single VPN IP accessed the attacker's VPS and also pinged Microsoft with at least one GDID within a 24-hour period. They found a constant GDID that all instances shared. This seems to have been the most damning GDID-related evidence in the DOJ complaint [1] and yet it wasn't mentioned in the article you linked (or any other articles about this I've seen pop up on HN). It includes the diagram from the complaint (page 18) that outlines this, but devoid of context. The ngrok stuff that the article focuses on was just the cherry on top and was discussed later in the complaint.

What also becomes clear when you read the complaint is that the GDID was just one piece of the puzzle and that they had plenty of other evidence. Attacker-associated IPs were used to access the suspect's Apple, Snapchat, and Facebook accounts, at least one of which was his actual residential IP, not a VPN IP. Once they had revealed the identity of the person who owned these accounts, they were able to all-but-confirm that this was in fact the attacker.

What remains unclear even after reading the complaint is how they were so sure that the GDID they obtained visited specific websites, but honestly, at that point, they were already drowning in evidence, so I don't know if it matters that much. It could be as simple as "he was signed into Edge with his Microsoft account and had sync enabled".

[1] https://www.justice.gov/usao-ndil/media/1450651/dl?inline

None of this matters really.

This criminal mastermind got caught because he did everything but sign his name to the crimes while holding two pieces of government identification in presence of a notary.

The FBI did the bare minimum in terms of old-fashioned detective work, and correlated evidence from various sources.

The obsession with GDID is a complete nothing-burger and I'm tired of seeing it on the front page every other day.

Thanks, I've added that link to the toptext above.

Edit: actually there have been a few threads about this - the link you mentioned was submitted in the second of these:

Microsoft confirms Windows GDID device identifier that cannot be disabled - https://news.ycombinator.com/item?id=48920338 - July 2026 (60 comments)

Microsoft admits Windows 11 has a GDID tracker with no off switch - https://news.ycombinator.com/item?id=48872561 - July 2026 (15 comments)

Windows GDID Changer - https://news.ycombinator.com/item?id=48818707 - July 2026 (4 comments)

Full Writeup of the Windows GDID - https://news.ycombinator.com/item?id=48811081 - July 2026 (49 comments)

Microsoft GDID telemetry includes full browsing and gaming history - https://news.ycombinator.com/item?id=48787239 - July 2026 (6 comments)

I have a sneaking suspicion that that ID can be deleted either with a specific service not running or with Windows powered off.
I won't be surprised if MS patches workarounds quickly and won't shed a word on the whole situation. Or worse, pulls the "this helps fighting evil hackers" reasoning.
wow.. How is this not a bigger deal
I think it's likely that Microsoft is running a process to correlate "new" GDIDs to old ones, ex:

"Oh look, this one has almost all the serial numbers of components and attached-devices as that other one, it's probably the same computer with a fresh install, let's make a note of that..."

They do not need this, they require you to create a Microsoft account to use your own computer (currently without a phone number, passport and selfie but that will probably change in the future).
Interesting, generally Microsoft bypasses the hosts file name resolution for various MSFT domains. Curious that these were not included (if it works, which I assume the mitigation does).

https://petri.com/windows-10-ignoring-hosts-file-specific-na...

FWIW, YogaDNS stops these bypasses if you tick a settings box ("Block plain DNS over TCP from System Resolver"). Or use similar DNS forcing techniques against port 53.

Windows falls back to the normal resolver in that case.

If you care about privacy, you simply cannot use Windows. Microsoft has made it clear over the last decade (if not longer) that they have a vested interest in compromising your ability to use software without exploiting and monetizing data about your usage.

Microsoft is a post-privacy corporation. Eventually, we really have to stop acting so shocked about this sort of thing from them.

this is a Windows 11 thing only?

when LTSC exists why are people using W11 ?

Windows 10 LTSC IOT will be the last Windows I ever use.

As I grow older, I simply do not have the patience or the will to do all these workarounds and tweaks to my OS to turn it from a piece of barely-working corporate spyware into something that I can call a productive tool.

It also seems like interacting with the OS is on its way out anyway, as most people essentially interact with computers via the browser (essentially a different sandboxed OS altogether), whether on desktop or mobile device.

I agree, tracking data via unique identifiers is evil incarnate, unless it's Google or VC-backed adtech doing it, because how else will they make money having architected their entire businesses around it.
I cannot believe people tolerate this kind of behavior from such a large company with a huge market.

It does make me wonder if people would react differently if Linux or Apple did the same thing.

It's not one homogeneous people reacting to different OSes. It's different people, and they react differently when somebody else's OS does something vs when their OS does something. Windows users don't care or feel locked in because it's the only OS they've known and they depend on it. Linux users expect this type of behavior from Windows, but they can't do more than switching themselves which they already have. Were Linux to do something similar, you remove the offending piece of software.
>Every finding here was reproduced on a real Windows 11 Pro VM (build 26200). Nothing is theoretical. See docs/technical-writeup.md for the evidence, tagged by confidence level.

That's sounds nice and all, but everything about it, from "Nothing is theoretical" to "evidence, tagged by confidence level" goes out the window when you find claude as one of the commit authors, and the content is clearly copy pasted output from claude with very little editing. Worse yet, one of the sources he cites is also clearly AI output.

I'm not even against the use of AI here. I would rather see it clearly say either "this is what claude found after I told it to investigate" or "yes this is generated by claude, but I independently verified each of the points myself".

Valid points, not sure why you were down-voted.
So, uhh, fuck windows and use Linux if you value your security and privacy?
Or just use Linux.
That's exactly the advice at the end.
Exactly , windows should be used for gaming. :D
Or don't commit fraud worth millions of dollars using your personal Windows machine.
Stopped using Windows in Windows 7 era, never regretted.
People paint this as a bad thing but wouldn’t directly reporting the UUID from the DMI info be far worse?

(Kinda amazed they just didn’t to that instead)

Even if you fix this one, how do you know if you got all of them? How do you know they won't add more another time in some quiet patch?

Just stop already, you are in an abusive relationship. Get out. Remove windows. It's not your friend. It's your computer, you have options.

Article tells you to paste

> $lid=(Get-ItemProperty 'HKCU:SOFTWAREMicrosoftIdentityCRLExtendedProperties').LID

which obviously does not work because it has all the slashes removed. Article author apparently didn't bother to proofread anything.

Get-ItemProperty : Cannot find path 'HKCU:\SOFTWAREMicrosoftIdentityCRLExtendedProperties' because it does not exist. At line:1 char:7

I guess I'm good then.