Top
Best
New

Posted by rfarley04 4 days ago

GDID Windows – Cut the tracker that follows you even under VPN(korben.info)
75 points | 56 commentspage 2
illithid0 3 hours ago|
If you care about privacy, you simply cannot use Windows. Microsoft has made it clear over the last decade (if not longer) that they have a vested interest in compromising your ability to use software without exploiting and monetizing data about your usage.

Microsoft is a post-privacy corporation. Eventually, we really have to stop acting so shocked about this sort of thing from them.

ck2 3 hours ago||
this is a Windows 11 thing only?

when LTSC exists why are people using W11 ?

gruez 2 hours ago||
It's present on one of my windows 10 LTSC VMs but not the other, so not sure how it got there.
serf 3 hours ago||
windows 11 and LTSC aren't mutually exclusive.
nekusar 2 hours ago||
So, uhh, fuck windows and use Linux if you value your security and privacy?
Razengan 3 hours ago||
wow.. How is this not a bigger deal
SV_BubbleTime 4 hours ago||
Obvious workaround to get off windows and use Linux…

But do any popular linux distributions use an identifier? Ubuntu, Kali, Mint, Arch, etc?

It seems an attractive way for devs to work out telemetry. Awful in reality; but I imagine attractive.

moepstar 4 hours ago|
At least Debian and Ubuntu have /etc/machine-id, presumably easily changed - but it’s there.
NotPractical 4 hours ago|||
I think the difference is that, on Windows, there are background services that constantly ping Microsoft with the device ID. A device ID on its own is not really harmful if it's not exposed to the internet.
Terr_ 3 hours ago||
Right, the danger here isn't stable unique data itself--there's already plenty of that--but the OS "telemetry" which steals [0] it and reports to Big-Brother along with too much other betraying information. Every site you visit, every program you run, the serial numbers of all your hardware, etc. Even if the GDID were totally absent, it would still be a correlate-able privacy nightmare.

Ultimately there's no informed consent here: The average consumer is disbelieving and surprised if you tell them what kinds of stuff Microsoft has/can put into a dossier. Nobody thinks: "Ah, Edge on a fresh Windows install, I'm glad Microsoft knows every site I visit, and can tell I'm a friend with someone because we use the same bluetooth speaker."

[0] It seems wrong to use the verb "leaks" when it's so obviously intentional.

capitainenemo 4 hours ago|||
I mean, there's a ton of unique identifiers on machines already tied to hardware and disks, but that must be a systemd thing since my Devuan machine does not have it.

But given there's no cloud accounts on linux I would imagine it's trivially changed just like a NIC's MAC

Also, seems unlikely it would be used for any single-signon with cloud services.

oasisaimlessly 2 hours ago|||
I'm guessing Devuan still has /var/lib/dbus/machine-id.
capitainenemo 1 hour ago|||
You're right. I have no idea what it's for, but I'm guessing for distinguishing between deployment images. I'm certainly not going to get too concerned about it.

The issue with the microsoft account was not unique IDs - tons of unique things on a machine.... it was a unique thing tied to an account and shipped to remote places.

2b3a51 2 hours ago|||
TIL.

    /var/lib/dbus/machine-id
Exists on Slackware64 15.0 but

    /etc/machine-id
Does not.
NotHereNotThere 3 hours ago|||
There are _some_ cloud accounts for linux such as Ubuntu One, which I would fear could have similar identification capabilities if ever forced by to do so by a 3-letter agency
giantrobot 1 hour ago||
Any sort of online service you're logged into is going to have your IP and account correlated with a timestamp. Dropbox, GDrive, and even your e-mail provider. While a device identifier might be more useful it's not like the lack a device ID will keep you from being tracked.
Xotic007 3 hours ago||
[dead]
pudgywalsh 2 hours ago|
The performative outrage about the GDID is quite comical in the context that everyone continues to be mum about Google Chrome, a browser explicitly designed to hoover up as much data as possible about you, even having been caught doing it in Incognito Mode [1], all while touting "privacy" features; which means no one besides Google is allowed to do it.

[1] https://www.intego.com/mac-security-blog/google-forced-to-de...

brookst 2 hours ago||
Not a fan of whaddaboutism.

It’s much easier to switch browsers than operating systems, especially if you have apps that require windows.

Besides, there is no obligation to be equally outraged about all things.

pudgywalsh 1 hour ago||
Do you have substantive content to contribute to this discussion, or do you plan to continue telling others what commenting styles you are and aren't a fan of? You've done it twice already.
MrNeon 1 hour ago||
What Google was "caught" doing was exactly what it was doing in non-incognito mode already. Anyone expecting the websites you visit to know you're in private mode and to not log data is just lacking basic tech knowledge.

It is silly that Google had to explicitly state that in the disclaimer.