There's a very easy trick to defeat this: use Linux.
If your system uses systemd, it has an etc/machine-id, which is used for a lot of different things. And changing it will break a lot of stuff, probably until you reboot. I guess you could write something to randomly shuffle it every time you reboot? But it is the go-to way for lots of programs (including browsers) to identify themselves. Which means (unless you have done the work to scramble your machine ID) you can be tracked on Linux as well.
The difference is that Linux isn't sending telemetry to some central entity associating that ID to an IP.
Microsoft’s records showed that at that exact same minute, a Windows device carrying GDID g:6755467234350028 had visited the ngrok signup page. Three hours later, the same GDID visited the retailer’s own website, through the same Tzulo proxy address used to set up the ngrok account.
This article is super vague about this as well. How does Microsoft not only have the GDID->IP link, but they have Web history as well? Are they just exposing all this through advertising telemetry?
Fucking gross. And if you know of anything on Linux exposing/transmitting the machine-id, please do let everyone know because nothing should. Anything that does should be considered malware.
It's not just Windows tracking your web browsing history. GPU drivers do it too. Source: https://www.neowin.net/news/intel-windows-driver-to-now-collect-user-telemetry-data-like-website-categories-by-default/
It’s not just Windows tracking your web browsing history. GPU drivers do it too.
..on Windows. if you explicitly install their malware and agree to data sharing.
That's wild. Shit like this makes me distrust proprietary drivers
I distrust proprietary anything at this point
also there's the TPM chip.
Upvoting both comments for awareness, since Linux is the first of a multi-step process, not a privacy panacea.
But we must be clear that in both theory and practice there’s little comparison between systemd and modern Windows machine-user association.
Someone using Windows regularly has a gaping wound, is actively bleeding out. Switching to Linux is just a tourniquet, but every other treatment is at best no-effect until that tourniquet is applied.
E: transpose systemd/Windows for clarity
So they're saying that all these "secret" societies online, like the Peter Thiel psychopathy, are relatively easily identified and rounded up and prosecuted to the fullest extent of the law, and they're just choosing not to do it? I'm shocked.
Why would they catch pedophiles? Their founder is one
I mean Epstein was actively talking about his crimes over plaintext Gmail
What idiot hacker uses Windows?
A genz hacker. In a world where "hacking" is writing prompts and calling IT help desks.
and calling IT help desks.
It always amazes me how much people shit talk social engineering, when it's been a power house for hackers since the beginning.
The human (or I guess AI now) element is always the weakest link
Tbf, some of the best hackers were social engineering their way into the backend just by calling up certain support numbers in the 80s
I refuse to call social engineers hackers, conmen is more fitting.
Hacking is making something work in an unconventional or unexpected way. Social engineers hack people in that way.
Defcon would disagree. I've watched so many presenters talk about all forms of penetration testing, many of which used social engineering and lockpicking as a way to create exploitable vulnerabilities in networks. Whether or not you care to call them hackers... It doesn't really matter, won't stop them from hacking.
The weakest link in cybersecurity are usually the users after all.
Real hackers social-engineered their way into high security systems decades before the first blue haired femboy nerd proudly announced "Btw i am usin Arch!"
Wait, calling IT Help Desks isn’t social engineering now?
It always is. Even if you're actually calling for help, you need to basically trick them into helping you these days.
Gen Z knows how to use Windows?
Sounds like the tagline for a really crap movie. How far we've fallen from two people on one keyboard.
Don't forget breaking out a second keyboard, but both people use one hand on each keyboard instead of one keyboard each!
I can't believe Microslop would do something like this to its loyal customers!
The level of naivete to think it's a good idea using a microsoft account on a microsoft product for your illegal activity is astounding. Especially when you consider the amount of technical knowledge required to do such a thing.
I legitimately cannot make that connection, Microsoft has never been shy about tracking you or their tight relationship with 3 letter agencies. It doesn't take a genius to know they are going to snitch, I figured that was a foregone conclusion.
Kids need to learn about OPSEC.
I was gonna comment something about Linux distro also having a machine ID, but then I remembered that it's not in a big database, and it's so well enforced I routinely have multiple machines with the same ID pop up :D
Linux users will probably tell you their id if you ask them nicely and seem interested in their distro of choice.
I switched to Linux Mint a long ass time ago. Micropenis can go fuck themselves.
My laptop came with Win11, I’ve removed that drive a few months ago and replaced it with Mint.
Does this mean MS has my motherboard, WiFi, other hardware identifiers that would still tie that laptop to their database?
Yup!
Motherboard, CPU, GPU models and serial numbers. Ram size and speed. Those were used during Windows activation as old as windows 95. But likely yes, a full list of every component connected.
Your Android phone collects every WiFi network it has ever seen and sends it to Google, so we should assume Microsoft does the same (Android can locate you without GPS by using your neighbors' WiFi signals as position identifiers, and can triangulate you to a few feet using the relative networks' signal strengths)
GrapheneOS babyyyyy
Cannot wait for the Motorola/GrapheneOS collab phones.
By design.

Cant wait for someone to make or reveal they already have a GDID spoofer and can now make grandma look like the worlds number 1 hacker.
Ctrl-f NSAKEY (sees nothing)
it seems the internet has forgotten the NSAKEY debacle https://en.wikipedia.org/wiki/NSAKEY
It is truly god damn unfortunate that Microsoft has spent decades fostering a level of technical ineptitude among the average person that they cannot even consider getting off their fucking shit ass platform that “just works”. Because that is the real problem. So many people on here will say “just use Linux!” But the vast majority of people cannot fathom where to even start with that and won’t even consider it because Windows “just works” and it has done so for so long that people just can’t be bothered.
Also 10. And 8. Maybe since Vista actually…
It's probably since XP at least. Probably introduced in some form in NT.
He' so stupid for sending ransomware and logging into snapchat/facebook from the same laptop without even using VMs
Technology
This is a most excellent place for technology news and articles.
Our Rules
- Follow the lemmy.world rules.
- Only tech related news or articles.
- Be excellent to each other!
- Mod approved content bots can post up to 10 articles per day.
- Threads asking for personal tech support may be deleted.
- Politics threads may be removed.
- No memes allowed as posts, OK to post as comments.
- Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
- Check for duplicates before posting, duplicates may be removed
- Accounts 7 days and younger will have their posts automatically removed.