Take from the article: do these 20 steps to avoid
My take; use linux.
And don’t look at /etc/machine-id.
What’s it used for?
deleted by creator
The connection is that Windows records everything you do. So the FBI asks for every Windows user who accessed a specific site around a date/time and Microsoft can provide that.
You accessed a site over VPN? Your ISP has no idea it was you, , and the VPN didn’t keep records, but Windows recorded that and sent it back to the mothership with your unique identifier.
Where did you read that?
Windows does not record everything you do, and especially does not link everything to an ID. Only the MS authentication and MS store stuff uses this GDID.
The GDID isn’t even linked to your name if you don’t use a Microsoft Account. The FBI had to jump through hoops to get the information they wanted and only managed to do so after 4 separate instances where they tracked every social media the guy owned and compared it with logins that happened.
The FBI can use any form of ID to track, and if Linux had a store it could use that ID as well.
From the article:
Microsoft’s records showed that at that exact same minute, a Windows device carrying GDID g:6755467234350028 had visited the ngrok signup page.
Seems pretty clear to me. Microsoft tracked acces to an independent sign up page using the GDID.
My guess is oauth. He basically used fake Microsoft account to access services during the hack and them used his actual microsoft account to access something else. He used VPN for the hack but he connected from his actual IP to the second service. The only thing linking those was the GID. So they figured out his actual IP address and checked other logins from this IP around the same time and found out his other accounts.
SOAP in 2026? I need a REST.
I have terrible news for you about most payment processors and banks…
Ok, that’s enough. Bye Windows.
stallmanwasright.jpg
notaboutthekiddiddling.jpg
fairpoint.jpg
Soooo, what does it stop Google or Meta from using same thing that Windows already offers to track users? Because as we all know, shit like this is NEVER only used by the good guys only.
Google has been tracking you for over 15 years, what you mean?
Not if you’re not using any of their shit and actively blocking their garbage. But if they can just tap into the OS global ID that Microsoft slapped into the OS that’s an issue.
My dude, if you are completely de-googled but still running windows (and, even worse, using a microsoft account), that is on you…
I still use Windows because despite Proton, it’s a hassle to run games on Linux, especially multiplayer ones or use advanced features of Radeon Adrenalin that I just need. As for Microsoft account, fuck that shit.
So it’s a unique id “stamped” to your Windows install during setup when you sign into a Microsoft account during the OOB setup experience. It gets stored in the machine’s registry, and is used for uniquely identifying your hardware and tying it to a Microsoft account for licensing purposes.
It does not persist between reinstalls, and it is in a known registry location so therefore viewable and editable now that we know it’s there. We don’t yet know the exact effects of editing it, or how exactly they correlated it in this case with the person’s network activity.
I expect we’ll have some mitigation plan in the next few months. Obviously starting with the recommendations in the article.
Completely pulling this from my ass:
- There should be some ways for researchers to watch what accesses that registry key and when.
- Hypothetically, one could just randomize their GDID.
- Could target specific known ones to flood the data collected (everyone uses all zeros)
- Forge evidence against specific targets (collect the GDID off a target’s machine, then set a VM to that and go nuts)
- or just randomly generate 1000 then activate Windows on all of them using MASgrave and rotate through them. Would probably need to randomly space out the activations, use generic hardware, and randomly shuffle the ones you used. Would also help to have multiple in use at once generating fake cover data to hide the real stuff in.
At this point it’s probably easier to just go off grid than to try and make Windows “private”.
Thats called ProcMon
Microsoft being microsoft. Cancel Bill Gates, Windows is a trojan. Use linux.
It makes it easier for Microsoft to know where to push that very special Windows Update that installs whatever the NSA wants installed in the computer of some journalist, foreign politician, syndicalist, high level manager on a foreign company that competes with an American company and other such “extremists”.
Windows is just bloated mallware.
Well there is a lot of advertising in it, yes, but I wouldn’t fall it a mall
Switch SYSTEM and RESTRICTED permissions on the registry key to DENY. It might stop even RO access to that LID value.




