• RainbowBlite ( RainbowBlite@piefed.ca ) 
      link
      fedilink
      English
      arrow-up
      29
      ·
      3 months ago

      The connection is that Windows records everything you do. So the FBI asks for every Windows user who accessed a specific site around a date/time and Microsoft can provide that.

      You accessed a site over VPN? Your ISP has no idea it was you, , and the VPN didn’t keep records, but Windows recorded that and sent it back to the mothership with your unique identifier.

      • Honytawk ( Honytawk@discuss.tchncs.de ) 
        link
        fedilink
        English
        arrow-up
        4
        ·
        3 months ago

        Where did you read that?

        Windows does not record everything you do, and especially does not link everything to an ID. Only the MS authentication and MS store stuff uses this GDID.

        The GDID isn’t even linked to your name if you don’t use a Microsoft Account. The FBI had to jump through hoops to get the information they wanted and only managed to do so after 4 separate instances where they tracked every social media the guy owned and compared it with logins that happened.

        The FBI can use any form of ID to track, and if Linux had a store it could use that ID as well.

        • RainbowBlite ( RainbowBlite@piefed.ca ) 
          link
          fedilink
          English
          arrow-up
          4
          ·
          3 months ago

          From the article:

          Microsoft’s records showed that at that exact same minute, a Windows device carrying GDID g:6755467234350028 had visited the ngrok signup page.

          Seems pretty clear to me. Microsoft tracked acces to an independent sign up page using the GDID.

    • My guess is oauth. He basically used fake Microsoft account to access services during the hack and them used his actual microsoft account to access something else. He used VPN for the hack but he connected from his actual IP to the second service. The only thing linking those was the GID. So they figured out his actual IP address and checked other logins from this IP around the same time and found out his other accounts.

  • RejZoR ( RejZoR@lemmy.ml ) 
    link
    fedilink
    English
    arrow-up
    12
    ·
    3 months ago

    Soooo, what does it stop Google or Meta from using same thing that Windows already offers to track users? Because as we all know, shit like this is NEVER only used by the good guys only.

      • RejZoR ( RejZoR@lemmy.ml ) 
        link
        fedilink
        English
        arrow-up
        2
        ·
        3 months ago

        Not if you’re not using any of their shit and actively blocking their garbage. But if they can just tap into the OS global ID that Microsoft slapped into the OS that’s an issue.

          • RejZoR ( RejZoR@lemmy.ml ) 
            link
            fedilink
            English
            arrow-up
            1
            ·
            3 months ago

            I still use Windows because despite Proton, it’s a hassle to run games on Linux, especially multiplayer ones or use advanced features of Radeon Adrenalin that I just need. As for Microsoft account, fuck that shit.

  • wizardbeard ( wizardbeard@lemmy.dbzer0.com ) 
    link
    fedilink
    English
    arrow-up
    11
    ·
    3 months ago

    So it’s a unique id “stamped” to your Windows install during setup when you sign into a Microsoft account during the OOB setup experience. It gets stored in the machine’s registry, and is used for uniquely identifying your hardware and tying it to a Microsoft account for licensing purposes.

    It does not persist between reinstalls, and it is in a known registry location so therefore viewable and editable now that we know it’s there. We don’t yet know the exact effects of editing it, or how exactly they correlated it in this case with the person’s network activity.


    I expect we’ll have some mitigation plan in the next few months. Obviously starting with the recommendations in the article.

    Completely pulling this from my ass:

    • There should be some ways for researchers to watch what accesses that registry key and when.
    • Hypothetically, one could just randomize their GDID.
      • Could target specific known ones to flood the data collected (everyone uses all zeros)
      • Forge evidence against specific targets (collect the GDID off a target’s machine, then set a VM to that and go nuts)
      • or just randomly generate 1000 then activate Windows on all of them using MASgrave and rotate through them. Would probably need to randomly space out the activations, use generic hardware, and randomly shuffle the ones you used. Would also help to have multiple in use at once generating fake cover data to hide the real stuff in.

    At this point it’s probably easier to just go off grid than to try and make Windows “private”.

  • Aceticon ( Aceticon@lemmy.dbzer0.com ) 
    link
    fedilink
    English
    arrow-up
    10
    ·
    3 months ago

    It makes it easier for Microsoft to know where to push that very special Windows Update that installs whatever the NSA wants installed in the computer of some journalist, foreign politician, syndicalist, high level manager on a foreign company that competes with an American company and other such “extremists”.