A Hacker's Arrest Reveals Microsoft Can Track Users Via a Windows Device ID

https://www.pcmag.com/news/a-hackers-arrest-reveals-microsoft-can-track-users-via-a-windows-device

173 points · 10 comments · view on lemmy.world

10 Comments

Rat_in_a_hat@lemmy.ca · 33 pts · 49d (1 reply)

Poor kid. Seems he was just starting out and didn't get into the weeds of OpSec.

He used a personal laptop with his personal information stored on it tied to an identifier. Not great OpSec. A hardware ID spoofer or a partitioned disk with different OS would've made wonders.

Anonymous_Leaker@lemmy.world · 5 pts · 48d
[ removed ]
unskilled5117@feddit.org · 26 pts · 49d

How does Microsoft know which GDID is accessing which websites?

The document adds that Microsoft records also showed the GDID accessing “multiple sites” from servers at Tzulo, a web hosting provider, to help pull off the hack.

The GDID is one thing, but how is the connection to activities made? Is the GDID sent while making requests to a server (in this case Tzulo), which records it? But then it wouldn’t be microsoft records showing that. But if it isn‘t, how do you know which GDID visits a website? If Microsoft is collecting which website is visited on device and sending it off to their servers then the GDID is the smallest thing to worry about.

Eternal192@anarchist.nexus · 25 pts · 49d

Microslop's Software is spyware? Impossible, they are such a trustworthy company!

ramble81@lemmy.zip · 12 pts · 49d (7 replies)

Maybe I’m missing something here but how is that not a logical conclusion for any service where you have a unique identifier? If it can get your IP it can get a general idea (CGNAT/VPN can screw with it a bit), if it’s allowed network access it can get nearby APs, which are pretty well mapped at this point, and if you allow it GPS, well that’s a no brainer.

ieris19@lemmy.zip · 9 pts · 49d (6 replies)

The whole point of a lot of these unique identifiers is that they’re anonymous so they can legally collect more data on you.

The goal is that you can’t reverse the ID to find the person, because then it ceases to be personally identifiable information.

Anonymous_Leaker@lemmy.world · 7 pts · 48d (5 replies)
[ removed ]
naeap@sopuli.xyz · 4 pts · 48d (4 replies)

...or a Google, Facebook, or... account

But yes

Anonymous_Leaker@lemmy.world · 3 pts · 48d (3 replies)
[ removed ]
naeap@sopuli.xyz · 2 pts · 48d (2 replies)

I was more thinking about 3rd parties using Microsoft, Google, Facebook logins for their shit, so can get tracked even better

But, yes, you're right

Anonymous_Leaker@lemmy.world · 2 pts · 48d (1 reply)
[ removed ]
naeap@sopuli.xyz · 2 pts · 48d

Yeah... I'm currently really shocked and afraid of the ongoing push of chat control on Europe as well
That will be a major impact on privacy and without reason
And they just try again and again - they don't even have a pause, they just start again and hope, that it will go through one time

Not sure how to escape it, and if, you are already labelled a terrorist
Like Spanish police looks if you have a pixel with GrapheneOS, because then they think you're a drug dealer

Or years ago the apartment of a guy in Vienna got raided and all his work IT devices confiscated, just because he ran a remote VPS as Tor exit node

Not sure what we can do

I grew up in the internet and it was a great place.
Now people without any knowledge want to take this all away...

medem@lemmy.wtf · 9 pts · 48d

Kinda his fault for using Window$ tbh

Anonymous_Leaker@lemmy.world · 4 pts · 48d
[ removed ]
musikfreak@friendica.de · 4 pts · 48d

@Moovau That isn't news, they have been able to since the release of Windows 10.