896
top 50 comments
sorted by: hot top controversial new old
[-] Diplomjodler3@lemmy.world 174 points 3 weeks ago

There's a very easy trick to defeat this: use Linux.

[-] mic_check_one_two@lemmy.dbzer0.com 18 points 3 weeks ago

If your system uses systemd, it has an etc/machine-id, which is used for a lot of different things. And changing it will break a lot of stuff, probably until you reboot. I guess you could write something to randomly shuffle it every time you reboot? But it is the go-to way for lots of programs (including browsers) to identify themselves. Which means (unless you have done the work to scramble your machine ID) you can be tracked on Linux as well.

[-] treadful@lemmy.zip 56 points 3 weeks ago

The difference is that Linux isn't sending telemetry to some central entity associating that ID to an IP.

Microsoft’s records showed that at that exact same minute, a Windows device carrying GDID g:6755467234350028 had visited the ngrok signup page. Three hours later, the same GDID visited the retailer’s own website, through the same Tzulo proxy address used to set up the ngrok account.

This article is super vague about this as well. How does Microsoft not only have the GDID->IP link, but they have Web history as well? Are they just exposing all this through advertising telemetry?

Fucking gross. And if you know of anything on Linux exposing/transmitting the machine-id, please do let everyone know because nothing should. Anything that does should be considered malware.

[-] hirihit640@sh.itjust.works 20 points 3 weeks ago
[-] treadful@lemmy.zip 31 points 3 weeks ago

It’s not just Windows tracking your web browsing history. GPU drivers do it too.

..on Windows. if you explicitly install their malware and agree to data sharing.

load more comments (1 replies)
[-] inari@piefed.zip 20 points 3 weeks ago

That's wild. Shit like this makes me distrust proprietary drivers

[-] can@sh.itjust.works 21 points 3 weeks ago

I distrust proprietary anything at this point

load more comments (15 replies)
[-] DevDave@piefed.social 20 points 3 weeks ago

also there's the TPM chip.

[-] Septimaeus@infosec.pub 18 points 3 weeks ago* (last edited 3 weeks ago)

Upvoting both comments for awareness, since Linux is the first of a multi-step process, not a privacy panacea.

But we must be clear that in both theory and practice there’s little comparison between systemd and modern Windows machine-user association.

Someone using Windows regularly has a gaping wound, is actively bleeding out. Switching to Linux is just a tourniquet, but every other treatment is at best no-effect until that tourniquet is applied.

E: transpose systemd/Windows for clarity

load more comments (8 replies)
load more comments (1 replies)
load more comments (1 replies)
load more comments (4 replies)
[-] db2@lemmy.world 111 points 3 weeks ago

So they're saying that all these "secret" societies online, like the Peter Thiel psychopathy, are relatively easily identified and rounded up and prosecuted to the fullest extent of the law, and they're just choosing not to do it? I'm shocked.

[-] starman2112@sh.itjust.works 20 points 3 weeks ago

Why would they catch pedophiles? Their founder is one

[-] Trainguyrom@reddthat.com 17 points 3 weeks ago

I mean Epstein was actively talking about his crimes over plaintext Gmail

[-] daggermoon@piefed.world 81 points 3 weeks ago

What idiot hacker uses Windows?

[-] Eximius@lemmy.world 69 points 3 weeks ago

A genz hacker. In a world where "hacking" is writing prompts and calling IT help desks.

[-] Passerby6497@lemmy.world 32 points 3 weeks ago

and calling IT help desks.

It always amazes me how much people shit talk social engineering, when it's been a power house for hackers since the beginning.

The human (or I guess AI now) element is always the weakest link

[-] lordziv@lemmy.nz 23 points 3 weeks ago* (last edited 3 weeks ago)

Tbf, some of the best hackers were social engineering their way into the backend just by calling up certain support numbers in the 80s

[-] skozzii@lemmy.ca 10 points 3 weeks ago

I refuse to call social engineers hackers, conmen is more fitting.

[-] thallamabond@lemmy.world 14 points 3 weeks ago

Hacking is making something work in an unconventional or unexpected way. Social engineers hack people in that way.

[-] Squirrelanna 10 points 3 weeks ago

Defcon would disagree. I've watched so many presenters talk about all forms of penetration testing, many of which used social engineering and lockpicking as a way to create exploitable vulnerabilities in networks. Whether or not you care to call them hackers... It doesn't really matter, won't stop them from hacking.

[-] Cybersteel@lemmy.world 11 points 3 weeks ago

The weakest link in cybersecurity are usually the users after all.

[-] HieroProtagonist@lemmy.ml 7 points 3 weeks ago

Real hackers social-engineered their way into high security systems decades before the first blue haired femboy nerd proudly announced "Btw i am usin Arch!"

load more comments (2 replies)
[-] heartSagan5@lemmy.zip 22 points 3 weeks ago

Wait, calling IT Help Desks isn’t social engineering now?

[-] scutiger@lemmy.world 11 points 3 weeks ago

It always is. Even if you're actually calling for help, you need to basically trick them into helping you these days.

[-] daggermoon@piefed.world 13 points 3 weeks ago

Gen Z knows how to use Windows?

[-] Regrettable_incident@lemmy.world 12 points 3 weeks ago

Sounds like the tagline for a really crap movie. How far we've fallen from two people on one keyboard.

[-] Fetus@lemmy.world 7 points 3 weeks ago

Don't forget breaking out a second keyboard, but both people use one hand on each keyboard instead of one keyboard each!

load more comments (1 replies)
load more comments (1 replies)
[-] someone@lemmy.today 62 points 3 weeks ago

I can't believe Microslop would do something like this to its loyal customers!

[-] the_riviera_kid@lemmy.world 51 points 3 weeks ago* (last edited 3 weeks ago)

The level of naivete to think it's a good idea using a microsoft account on a microsoft product for your illegal activity is astounding. Especially when you consider the amount of technical knowledge required to do such a thing.

I legitimately cannot make that connection, Microsoft has never been shy about tracking you or their tight relationship with 3 letter agencies. It doesn't take a genius to know they are going to snitch, I figured that was a foregone conclusion.

Kids need to learn about OPSEC.

load more comments (5 replies)
[-] cley_faye@lemmy.world 44 points 3 weeks ago

I was gonna comment something about Linux distro also having a machine ID, but then I remembered that it's not in a big database, and it's so well enforced I routinely have multiple machines with the same ID pop up :D

[-] PieMePlenty@lemmy.world 17 points 3 weeks ago

Linux users will probably tell you their id if you ask them nicely and seem interested in their distro of choice.

load more comments (1 replies)
[-] ArmchairAce1944@discuss.online 33 points 3 weeks ago

I switched to Linux Mint a long ass time ago. Micropenis can go fuck themselves.

[-] EpicMuch@sh.itjust.works 28 points 3 weeks ago

My laptop came with Win11, I’ve removed that drive a few months ago and replaced it with Mint.

Does this mean MS has my motherboard, WiFi, other hardware identifiers that would still tie that laptop to their database?

[-] TeddE@lemmy.world 39 points 3 weeks ago

Yup!

Motherboard, CPU, GPU models and serial numbers. Ram size and speed. Those were used during Windows activation as old as windows 95. But likely yes, a full list of every component connected.

Your Android phone collects every WiFi network it has ever seen and sends it to Google, so we should assume Microsoft does the same (Android can locate you without GPS by using your neighbors' WiFi signals as position identifiers, and can triangulate you to a few feet using the relative networks' signal strengths)

[-] Reygle@lemmy.world 13 points 3 weeks ago
[-] TeddE@lemmy.world 14 points 3 weeks ago

Cannot wait for the Motorola/GrapheneOS collab phones.

load more comments (8 replies)
load more comments (14 replies)
load more comments (2 replies)
[-] Hairyfishnuts@feddit.online 22 points 3 weeks ago
[-] JoMiran@lemmy.ml 22 points 3 weeks ago
[-] iterable@sh.itjust.works 13 points 3 weeks ago

Cant wait for someone to make or reveal they already have a GDID spoofer and can now make grandma look like the worlds number 1 hacker.

load more comments (1 replies)
[-] mystik@lemmy.world 12 points 3 weeks ago

Ctrl-f NSAKEY (sees nothing)


it seems the internet has forgotten the NSAKEY debacle https://en.wikipedia.org/wiki/NSAKEY

[-] yucandu@lemmy.world 11 points 3 weeks ago

Identifier. Not tracker. They're not phoning home, thank god.

load more comments (4 replies)
[-] TemplaerDude@sh.itjust.works 11 points 3 weeks ago

It is truly god damn unfortunate that Microsoft has spent decades fostering a level of technical ineptitude among the average person that they cannot even consider getting off their fucking shit ass platform that “just works”. Because that is the real problem. So many people on here will say “just use Linux!” But the vast majority of people cannot fathom where to even start with that and won’t even consider it because Windows “just works” and it has done so for so long that people just can’t be bothered.

load more comments (5 replies)
[-] Arcane2077@sh.itjust.works 9 points 3 weeks ago

Also 10. And 8. Maybe since Vista actually…

[-] frongt@lemmy.zip 8 points 3 weeks ago

It's probably since XP at least. Probably introduced in some form in NT.

load more comments (1 replies)
[-] MehBlah@lemmy.world 9 points 3 weeks ago

Its doesn't have a off switch but you can generate a new one.

load more comments (2 replies)
[-] Semotto@lemmy.world 7 points 3 weeks ago

He' so stupid for sending ransomware and logging into snapchat/facebook from the same laptop without even using VMs

load more comments (1 replies)
load more comments
view more: next ›
this post was submitted on 13 Jul 2026
896 points (100.0% liked)

Technology

86987 readers
2488 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 3 years ago
MODERATORS