this post was submitted on 24 Jul 2026
356 points (99.2% liked)

PC Gaming

15108 readers
228 users here now

For PC gaming news and discussion. PCGamingWiki

Rules:

  1. Be Respectful.
  2. No Spam or Porn.
  3. No Advertising.
  4. No Memes.
  5. No Tech Support.
  6. No questions about buying/building computers.
  7. No game suggestions, friend requests, surveys, or begging.
  8. No Let's Plays, streams, highlight reels/montages, random videos or shorts.
  9. No off-topic posts/comments, within reason.
  10. Use the original source, no clickbait titles, no duplicates. (Submissions should be from the original source if possible, unless from paywalled or non-english sources. If the title is clickbait or lacks context you may lightly edit the title.)

founded 3 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] Ludicrous0251@piefed.zip 16 points 3 days ago* (last edited 3 days ago) (2 children)

Your Windows PC Has a Permanent ID That Follows You – Even With a VPN

Yes, it's bad, but worth pointing out, they didn't identify the user directly by somehow extracting GDID from their traffic, they identified them because their GDID happened to be in the same place at the same time at their hacking efforts that became statistically impossible to ignore.

Realistically this kind of tracking could be accomplished with any software with a unique ID that does, say, daily update checks or usage pings. This one is just extra bad because it's ubiquitous (on Windows) and almost impossible to change, so they have a 1-stop-shop for spying.

[–] sp3ctr4l@lemmy.dbzer0.com 13 points 3 days ago* (last edited 3 days ago) (1 children)

All tracking is done by amalgamating as many different overlapping signals and indicators together as you can, and then establishing basically a confidence score/threshold.

This one is extra bad because it was never disclosed previously.

Trust = Gone, what else is MSFT hiding?

[–] Valmond@lemmy.dbzer0.com 3 points 2 days ago
[–] x00z@lemmy.world 3 points 3 days ago

I think the ngrok tunnel server they setup to exfiltrate data actually sent the GDID to the ngrok servers. This GDID was then linked to non-VPN IP logs by Microsoft.