top 50 comments

sorted by: hot top controversial new old
[–] 79 points 2 weeks ago (3 children)

Something this article glosses over is the fact that Microsoft knew all of the web URLs he was visiting. I don't know if that's because he was dumb enough to sign into Edge with his Microsoft account or if they were collecting that a different way, but the GDID wouldn't have been nearly as useful without that info.

  • source
  • hideshow 6 child comments
  • [–] 18 points 2 weeks ago (1 child)

    IDK either. But so much is now like, ppl wanting privacy have to be right every time. The co's wanting our data, only once! A single hidden backdoor siphon to our data and we didn't protect ourself from it. A single telemetry that encodes every URL we visit. A single statistical way to fingerprint us.

    That Sisyphus dude knows our pain.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 15 points 2 weeks ago (1 child)

    Which is why open source is important. Holes can be found and software telemetry can be avoided.

    A lot of the telemetry is sold to people as being in their benefit. Monitor installed software for updates, location data for weather etc.

    If the companies had to document the amount they collected in cash for each user based on ads and send it as a mk though report, it might be eye opening. The source if the cash would also be good. So did companies pay directly or dodgy intermediaries and data brokers.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 7 points 2 weeks ago (1 child)

    I don’t think Microsoft recorded the URLs, just activity from a GDID and IP address at particular timestamps. The authorities would also have subpoenaed records from other accounts they knew were his e.g. Snapchat and Facebook. The GDID was just a way of assigning activity from his device to particular VPN endpoints at particular times. The point of the story is essentially that the GDID allowed them to track his device across multiple IP addresses. But this wouldn’t have been possible without at least some other pieces of the puzzle such as knowing which was his Microsoft account, or Facebook account etc. in the first place.

  • source
  • parent
  • hideshow 1 child comment
  • load more comments (1 reply)
  • [–] 43 points 2 weeks ago (5 children)

    Year of the Linux desktop anyone?

  • source
  • hideshow 7 child comments
  • [–] 4 points 2 weeks ago (4 children)

    Seems like the answer is never. The masses are too addicted to PC games to give it up.

  • source
  • parent
  • hideshow 6 child comments
  • [–] 32 points 2 weeks ago (2 children)

    It's not the PC games keeping people so much. Proton solved a lot of that problem. It's inertia.

    Most people don't care about things. They just don't. Their brains just don't have the juice.

  • source
  • parent
  • hideshow 4 child comments
  • [–] 4 points 2 weeks ago

    I agree. But I think more to the other side of it. I worry that a vast influx, who don't care about privacy and computing freedom, would make for huge market pressure to lock down Linux. Same way we see Windows, IOS, Android locked.

    Game co's, big tech, and others will demand it, if the masses flee to Linux. Today, most Linux users go nah, we want freedom more than your AAA game. If that changes, we could lose the very culture that resists locked down corporate controlled computing.

  • source
  • parent
  • load more comments (2 replies)
  • load more comments (3 replies)
    [–] 26 points 2 weeks ago (2 children)

    Hacker

    Uses windows

    He got what he fucking deserved

  • source
  • hideshow 4 child comments
  • [–] 11 points 2 weeks ago (1 child)

    Okay, buy the thing to take note here is what tech companies can hide.

    You know they're tracking users but there are still things we'll never find out unless they reveal it themselves or are made to reveal in indirectly.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 19 points 2 weeks ago (1 child)
  • [–] [S] 46 points 2 weeks ago (4 children)

    Imagine your computer has a secret ID number that Microsoft gives it when you sign in with your Microsoft account. This number is like a permanent nametag that your computer wears. Even if you use a VPN to hide your location, that nametag stays the same.

    A hacker used a VPN to hide while breaking into a jewelry store's computer system. But Microsoft helped the FBI find him because his computer's secret nametag kept showing up everywhere he went online. They matched that nametag to his social media accounts and other stuff he did, and that's how they caught him. Most people didn't even know this secret nametag existed, and you can't turn it off without breaking your computer.

  • source
  • parent
  • hideshow 8 child comments
  • [–] 27 points 2 weeks ago* (last edited 2 weeks ago) (4 children)

    how dumb can you be to use unhardened windows to hack valuable shit omg.

    even if you didn't know of this system (i didn't) it's well known windows scans for even the color of your underwear.

  • source
  • parent
  • hideshow 7 child comments
  • [–] 5 points 2 weeks ago (4 children)

    the average lemmy user is much more tech literate than an average person

    people really don't know that kind of stuff. to many a computer is a computer, it has internet, and plays games... what's an operating system?

  • source
  • parent
  • hideshow 5 child comments
  • load more comments (3 replies)
  • load more comments (1 reply)
  • [–] 11 points 2 weeks ago (1 child)

    Thanks! He should have used Linux

  • source
  • parent
  • hideshow 2 child comments
  • [–] [S] 6 points 2 weeks ago (3 children)
  • load more comments (2 replies)
  • [–] 19 points 2 weeks ago

    The complaint quotes a Microsoft representative describing the GDID as “a persistent, device-level identifier designed to uniquely identify an installation of a Windows operating system on a device, either a physical device (e.g., a mobile phone or laptop) or virtual machine, across certain Microsoft services and scenarios”

    A Global Device ID (GDID) is a permanent, unique digital fingerprint that Microsoft automatically assigns to your computer when you install Windows or sign into a Microsoft account.

  • source
  • [–] 14 points 2 weeks ago

    Don't forget the unique identifier of Edge and Chrome.

  • source
  • [–] 11 points 2 weeks ago (2 children)
  • load more comments (1 reply)
    [–] 10 points 2 weeks ago* (last edited 2 weeks ago)

    Then there’s activation. Massgrave, the group behind Microsoft Activation Scripts, notes that Windows setup sends hardware info to Microsoft and gets identifiers back, the same tokens later used for Store access and licensing: “It’s impossible to prevent Windows from getting a GDID without breaking activation and UWP app[s].” Anyone who lost a license after swapping a motherboard has already met a smaller version of this.

    I guess this is why people always said it was impossible to remove the watermark that appears when you are not activated, when it was rolled out many years ago.

    Defeating the reasons for activation might've lead the more tech-savvy to figuring out the nature of the identifiers being sent for activation and seeing where else they are sent.

  • source
  • [–] 10 points 2 weeks ago (2 children)

    why would a hacker use windows?

  • source
  • hideshow 2 child comments
  • load more comments (2 replies)
    [–] 8 points 2 weeks ago (3 children)

    Does MS track what you do in Edge and Windows, yes. Does Google track you in Crome and any app of theirs, yes. Does Apple track everything you do on their devices, yes. Does meta, twitter, all social media sites track the fuck out of you, also yes.

  • source
  • hideshow 6 child comments
  • [–] 8 points 2 weeks ago

    the fucked up thing is this GDID thing apparently also show up for VM. So that would mean any VM and even a Quebe?

    Fuck microsoft

  • source
  • [–] 8 points 2 weeks ago* (1 child)

    My company is moving to Windows 11, I had one of my service desk teammates tell me that for an IT support person I'm very critical of change

    Before Windows 11 I was critical of change because every change came with no new training for my team and a giant email to the company explaining very lazily about the changes and with the same text at the end of every email.. "Any problems call the service desk".

    Now we've lost active directory.. Now I'm in a position where an incredibly incompetent IT security have restricted our access to intune and Entra and then the business wants me to still perform my daily duties as normal.

    Upside is that same IT security is getting removed in the next few weeks.

    Probably to be replaced by someone else even worse.

    I just want to learn how to use Entra and Intune.. Everything Microsoft touches turns to shit.

    Active directory just worked.. It was built when people at Microsoft actually knew how the operating system worked.. None of those people are still at Microsoft..

  • source
  • hideshow 2 child comments
  • load more comments
    view more: next ›