this post was submitted on 24 Jul 2026
356 points (99.2% liked)
PC Gaming
15108 readers
228 users here now
For PC gaming news and discussion. PCGamingWiki
Rules:
- Be Respectful.
- No Spam or Porn.
- No Advertising.
- No Memes.
- No Tech Support.
- No questions about buying/building computers.
- No game suggestions, friend requests, surveys, or begging.
- No Let's Plays, streams, highlight reels/montages, random videos or shorts.
- No off-topic posts/comments, within reason.
- Use the original source, no clickbait titles, no duplicates. (Submissions should be from the original source if possible, unless from paywalled or non-english sources. If the title is clickbait or lacks context you may lightly edit the title.)
founded 3 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
Yes, it's bad, but worth pointing out, they didn't identify the user directly by somehow extracting GDID from their traffic, they identified them because their GDID happened to be in the same place at the same time at their hacking efforts that became statistically impossible to ignore.
Realistically this kind of tracking could be accomplished with any software with a unique ID that does, say, daily update checks or usage pings. This one is just extra bad because it's ubiquitous (on Windows) and almost impossible to change, so they have a 1-stop-shop for spying.
All tracking is done by amalgamating as many different overlapping signals and indicators together as you can, and then establishing basically a confidence score/threshold.
This one is extra bad because it was never disclosed previously.
Trust = Gone, what else is MSFT hiding?
Which trust?
I think the ngrok tunnel server they setup to exfiltrate data actually sent the GDID to the ngrok servers. This GDID was then linked to non-VPN IP logs by Microsoft.