893
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
this post was submitted on 13 Jul 2026
893 points (100.0% liked)
Technology
86515 readers
3062 users here now
This is a most excellent place for technology news and articles.
Our Rules
- Follow the lemmy.world rules.
- Only tech related news or articles.
- Be excellent to each other!
- Mod approved content bots can post up to 10 articles per day.
- Threads asking for personal tech support may be deleted.
- Politics threads may be removed.
- No memes allowed as posts, OK to post as comments.
- Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
- Check for duplicates before posting, duplicates may be removed
- Accounts 7 days and younger will have their posts automatically removed.
Approved Bots
founded 3 years ago
MODERATORS
There's a very easy trick to defeat this: use Linux.
No you don't understand... I've spent the last 30 years investing in increasingly awful software companies to create "industry standards" and leaving these companies behind would require me to change and learn!!!
I talked with the women i'm working with where we print our price lists about changing from adobe to something else and she told me it would be a bad idea since it would make both of our work much more buggy and time consuming with more chances of the end result being worse. So i'll keep using indesing and the adobe suite for now but i did switch from sketchup to blender for 3D modeling and it's a bit challenging and more messy then i'm used to but i get better rendering results from what i tried so far.
As long as you can export to the same format, it shouldn't matter from the print shop's perspective, no? They just see the same file they would've always seen.
The way we work together is by exchanging full fresh indesing pakages that contain the main indd, the idml, a pdf, the links folder and the fonts folder so that we always have everything we need.
Sorry if this is a dumb question, I don't know anything about graphics design, just about the technology behind it.
Why do you send all these things as separate files? Is just a rasterised or vector export of the project not enough?
Sounds like the design world really needs a standardised container format that can contain all these separate things otherwise.
So many issues with the world boils down to that last part, people refusing to change and learn. I never understood it, I've always loved change and learning. I've seen so many people go from having that same openness to only caring about keeping everything the same and never learning, it's really disturbing. Some are like that from a very early age, others fall into it at any other part of their lives and it's never a good thing IMO.
At some point you just have to leave the software behind. That time is now!
Even worse!
Admitting that I was not always doing the most sensible thing, at all times! That I was actually doing really stupid things, for a long time!
I ... I can't make mistakes... no ... reality is wrong!
Realizing you're making mistakes and continuing anyway is the problem.
Yes, I'm trying to be hyperbolically facetious, to illustrate that.
If your system uses systemd, it has an etc/machine-id, which is used for a lot of different things. And changing it will break a lot of stuff, probably until you reboot. I guess you could write something to randomly shuffle it every time you reboot? But it is the go-to way for lots of programs (including browsers) to identify themselves. Which means (unless you have done the work to scramble your machine ID) you can be tracked on Linux as well.
The difference is that Linux isn't sending telemetry to some central entity associating that ID to an IP.
This article is super vague about this as well. How does Microsoft not only have the GDID->IP link, but they have Web history as well? Are they just exposing all this through advertising telemetry?
Fucking gross. And if you know of anything on Linux exposing/transmitting the machine-id, please do let everyone know because nothing should. Anything that does should be considered malware.
It's not just Windows tracking your web browsing history. GPU drivers do it too. Source: https://www.neowin.net/news/intel-windows-driver-to-now-collect-user-telemetry-data-like-website-categories-by-default/
..on Windows. if you explicitly install their malware and agree to data sharing.
I should have clarified, but yes it's the windows GPU drivers. Though even on Linux, it's hard to know what the proprietary GPU drivers do, but from what I read they don't collect telemetry by default. Luckily Nvidia is developing official open source drivers now so we won't have to worry about these things.
Also note that for the Windows Nvidia drivers, it's fairly annoying to disable all telemetry. It's not just an option in the installer. You have to use unofficial third party tools.
That's wild. Shit like this makes me distrust proprietary drivers
I distrust proprietary anything at this point
i think i remember hearing the dbus machine-id being read by google chrome on linux. it could be used for privacy violation with proprietary software, though i personally consider linux machines with chrome or equivalent software installed compromised.
My interpretation was that they had an IP that they suspected was the perp's home network, and subpoena'd some major platforms to confirm beyond a shadow of a doubt. Given the perp's sloppiness in using the same machine for both personal and illicit computing activities, they could even have some network traffic in the capture to indicate which platforms they should subpoena
Or if we want to be more conspiracy-minded, maybe they installed a trojan on his computer and this is the parallel evidence trail that law enforcement created so they don't have to admit to hacking the hackers
Or he used Edge, so Microsoft just has all his browsing data.
Another user said they think machine-id is readable by the browser. This is absolutely true, machine-id is working as described when it is read by any web browser.
So Linux isn’t sending your unique id to a central entity that can associate it with your ip, it’s sending your unique id to any entity you browse to that can then associate it with your ip.
If you're really worried about that, just change it every time you boot or something. There's a kernel parameter to change it.
There is not a parameter to automatically change it every time the system boots, that solution doesn’t work for machines that don’t reboot often and it breaks stuff in systemd as volunteered by many people talking about it online and as verified by me two weeks ago when I tried that.
I never said there was. There is however a kernel parameter to change the machine id, which I did say.
What you said was that if a person was actually worried about it there is a kernel parameter to change it.
My reply was not intended to refute what you said but instead to illustrate how that approach doesn’t solve the problem of tracking and is not a workable solution for many systems and users.
I made that reply to help you and any reader understand the depth and breadth of the problem, not to start a fight.
It's intended to be read by applications on the system. That's like its whole purpose. If you know of any browsers sending it or otherwise making it available without hashing it with an application key first, that would be a problem.
Yes as I said it’s working as intended. The point of machine id is to id a machine.
A better solution would be to not rely on the various programs to hash the unique id and instead have the host read it, hash it and provide the hash to the program that asked.
Your claim was that Linux was "sending your unique id to any entity you browse" which is misleading at best.
machine-idshould never be transmitted and if it is, that software should be considered spyware.That doesn't solve anything, really. There's plenty of ways to fingerprint a machine that doesn't involve the
machine-id.Machine-id is read as plaintext by programs and transmitted as plaintext by programs.
Hashing the unique id from the host side as opposed to trusting programs to read it and act in a way the user understands and deems appropriate is a much better method of handling calls to identify the equipment than just letting programs read your standardized unique id.
And the above would literally solve something, it would keep programs from just walking directly across the mat tee posing to get a unique id and force them to do some kind of jetpack backflip routine that, when presented to a court, is much more tenuous.
[citation needed]
Anything that does that is spyware and if you're aware of anything that does this you should be doing us all a public service and sharing.
I can build something in maybe 10 minutes that will fingerprint your machine to like 99.99% uniqueness. This solution solves nothing. But now we're just repeating ourselves.
Go take it to the systemd folks yourself and see how they respond.
here’s a fifteen year old stack overflow thread where someone asks where a unique system identifier can be read and someone suggests machine-id.
Lest that be considered old and bad information, I just checked /etc/machine-id on a new install of Debian 13 and the permissions were 444, readable by owner, group and everyone else.
So programs can read machine-id. If programs can read it they can transmit it. I hope someone capable of writing a program that can id my machine doesn’t need a proof of that.
Further, programs reading machine-id don’t necessarily fall into the spyware category by default like you say. There are plenty of perfectly good reasons to request a machine specific identifier.
Getting rid of the literal “papers please!” “Okay officer!” File literally makes investigation more difficult and puts a barrier up to tracking where there was none before. Presenting a unique hashed output based on the systems machine-id prevents a tracking method that is currently as easy as read file -> get identifier.
The fact that other methods of tracking exist doesn’t make preventing this method not worthwhile and you should be ashamed for suggesting that.
Never said things can't read it (in fact, that's very intentional). I even linked you the man page that lays all that out for you. I'm saying your claim that things are transmitting it is baseless. You stated your speculation as fact.
If anything is transmitting this ID it should be considered spyware.
Whatever, I'm just repeating the same thing over and over again as if your reading comprehension will somehow get better.
also there's the TPM chip.
Upvoting both comments for awareness, since Linux is the first of a multi-step process, not a privacy panacea.
But we must be clear that in both theory and practice there’s little comparison between systemd and modern Windows machine-user association.
Someone using Windows regularly has a gaping wound, is actively bleeding out. Switching to Linux is just a tourniquet, but every other treatment is at best no-effect until that tourniquet is applied.
E: transpose
systemd/Windows for clarityAlso as a life long programmer, I have this feeling it is possible to just go in and make some changes so I can have the system just make shit up about the TPM while indeed also doing the equivalent of having system-d decide to respond with random bullshit.
Don't even need to be a programmer, just find a community of them that you trust that distribute their own "fixes".
Definitely not doing that with anything else because its both hidden in compilation and buried like herpes across multiple components. Probably/hopefully not directly related but I really want to know what they changed to break the clipboard service.
And you’d be technically correct, the best kind of correct.
To the inquisitor:
any distro that’s fully OSS can be fully compiled from scratch with any modifications you choose).
Though yes, if you’re still using Windows, the learning curve may look like a wall.
Guessing the X11 [X]Wayland migration KDE Plasma bug report? Should be fixed in 6.5.2.
Adjacent comment. I've found working in a true posix environment is drastically better than the oddities I dealt with Win32. One annoyance is Microsoft has never been able to implement
fork().Though i never messed with x11 as I was never motivated to see what it was like under the figurative hood.
It really is a hell of a lot more sane, instantly missed once you don’t have it. And yeah Fork’s a blessing when used with care lol
Sorry, switched contexts there. Microsoft broke their clipboard service recently which makes me think they added "telemetry" collecting logic somewhere in there.
Oh right, I misread. And yeah not sure (my win32 repro targets have all been locked for a while) but with all the facepalm regressions I’ve read about lately it really could be anything.
From my experience, the number one culprit of legacy code breaking is someone asking if anyone knows how it works. Second most common culprit is someone making a "quick patch" to legacy code.
lol damn, flinched at both even though I was prepared
Yeah, motherboard-level tracking is scary because even the OS won’t be able to detect it. The truly paranoid people (and security researchers) go as far as desoldering chips to ensure nothing phones home.
Where in the source does Firefox expose machine-id to websites?
With a quick grep I'm only seeing it around audio?
If that hacker only knew about tracking by Windows...
I wouldn't call overhauling your entire operating system, including finding alternatives to software you use daily, making sure your hardware is compatible and relearning your entire work method as an "easy trick".
In any other context I'd agree with you, but hacking is the one context where you really do want to do things the hard way. Use ephemeral VMs with passwords only saved in your head, have a dedicated machine for your illegal activities to help isolate your real identity from your hacking.
Honestly even if you're just doing HackTheBox and similar best practice is to spin up a Kali VM and only use that VM for the activity since you're literally connecting to a network with a bunch of hackers, even though what you're doing is entirely above the board
I think you might actually be surprised...