So this kid uses his home computer at his home, and they trace him down with
the IP address, and the IP address also makes a request for Windows Updates.
And that narrows down the Device ID. The device id is now traced to this kid.
That seems more likely, I hope, than Edge/Windows secretly telemetering your GDID and every URL you visit to Redmond. It's a huge privacy hole still, but they can plausibly deny they set out to track you across the web using their OS.> According to Microsoft records, on or about May 12, 2025, at 19:21 UTC—when, according to ngrok records, the ngrok account was created—the device with the GDID accessed, among other ngrok pages, “https://dashboard.ngrok.com/signup,” the ngrok page to set up an ngrok account.
> Microsoft records also indicate: (1) the user of the device assigned the GDID accessed multiple sites from Tzulo servers in May 2025, including the .168 server (the IP address used to create the ngrok account) on May 12, 2025; and (2) the user of the device assigned the GDID, on May 12, 2025 at 22:47 UTC, a little more than three hours after the ngrok account was created, the user visited “[Company F].com” from the .168 proxy server.
Only the first time this happens, before it becomes clear to everyone that such mechanism can be used for tracking. After that... well I have this bridge I've been meaning to sell.
So not only was this “hacker” using Windows and Edge, they singed in to windows with a Microsoft account. And then used that same computer for their social media. Nice.
I'm not a "hacker" by any means, but I would probably use a Qubes based system with a dedicated "hacking" VM, only use anonymous VPNs connected from public WiFi access points (having left my mobile at home) while wearing a fake beard and STILL be paranoid that I somehow somewhere make a mistake.
Serious "hackers" are usually state sponsored now, or members of mature groups.
I saw an article where they analyzed the leaked IP addresses from a breach forum, and some of the top ten were Surfshark and iCloud Private relay.
what's wrong with icloud private relay? It uses a 2-hop architecture so it's probably more private than any single-hop VPN.
Personally I'd say use Qubes because it might be better at preventing you from getting raided in the first place.
Decisions decisions.
So again, the "make an account" is the part you ALWAYS skip. Local accounts or it technically isn't even a PC anymore.
https://www.windowslatest.com/2026/07/10/you-cant-fully-disa...
Note the "or"
I own a Windows 10 machine which has never signed into a Microsoft account. It still has a GDID in the registry.
Hotels last I saw don't collect an obscure gdid...
Did this victim use edge and sync their browser history or something perhaps?
Not to mention that one of the many major UI regressions in Windows is the removal of title bars from application windows, which is fundamental to this "trick." Try opening a PDF in Edge and also in Acrobat. Neither window has a title bar, and they are otherwise almost identical. You have to scrutinize the very few controls around the window to determine which app you're looking at.
Microsoft and its software are trash now.
The import is entirely local, the "sent to Microsoft" bit is if you have Edge sync enabled. This is identical to Chrome importing your Firefox data and then syncing it back to Google. Except the Edge import was, by reports at the time, accidentally auto-enabled. But you'd still have to sign into Edge and enable sync.
>"Massgrave, the group behind Microsoft Activation Scripts, has noted that Windows setup sends hardware info to Microsoft and receives identifiers back that are later used for Store access and licensing. Blocking GDID assignment breaks both activation and UWP apps."
I think probably it sends the gdid back to Microsoft as part of telemetry/updates/MS account periodic re-auth, which lets them know the current IP address, and then once the government has Microsoft's logs and the various target websites' logs, they can correlate based on IP address. I don't think it's actually sending the gdid to the web sites. Maybe.
This serves to further illustrate that nobody should be using Windows for anything that involves the need for privacy. And doubly, triply, and morefold so, nobody should ever sign a Windows machine into a MS account for any reason.
>Send optional diagnostic data to improve Microsoft products [Includes how you use the browser, websites you visit, and enhanced error reporting. Determined by your Windows diagnostic data setting]
>Allow Microsoft to save your browsing activity including history, usage, favourites, web content, and other browsing data to personalise and improve Microsoft Edge and Microsoft services like ads, search, shopping, news, and Copilot [Includes your history, usage, favourites, web content and other browsing data]
Microsoft admits Windows 11 has a GDID tracker with no off switch
https://news.ycombinator.com/item?id=48872561
Full Writeup of the Windows GDID
https://news.ycombinator.com/item?id=48811081
Microsoft Can Track Users via a Windows Device ID
1. If your printer has tracking dots [0] then a printed flyer can be tracked back to your computer, IP, and MS/Apple account.
2. If a device is reported on two computers, MS/Apple know there is some kind of connection between the computers.
[0] https://www.eff.org/pages/list-printers-which-do-or-do-not-d...
LUKS
page 18 answers many of the questions in this thread.
In any case, an executable allowed to run on a host can trivially fingerprint the machine it is running on using a combination of hardware identifiers. Removing or rotating machine-id does not buy you any privacy against a malicious app.
What I find most surprising in this story is how careless these "hackers" were. You would think that people engaged in this type of activities would use throwaway devices running free operating systems and VMs, not personal devices logged into Snapchat and Facebook.
It absolutely can if that's the only identifier an app is looking at.
> You would think that people engaged in this type of activities would use throwaway devices running free operating systems and VMs, not personal devices logged into Snapchat and Facebook.
Well, the smart ones do that, which is why they don't make the news as they don't get caught.
On windows, it does that all by itself, Microsoft tracks you with it. Because windows is the malicious app just like the GP said.