this post was submitted on 11 Jul 2026
440 points (99.3% liked)

Privacy

4891 readers
576 users here now

Icon base by Lorc under CC BY 3.0 with modifications to add a gradient

founded 3 years ago
MODERATORS
all 48 comments
sorted by: hot top controversial new old
[–] Kekzkrieger@feddit.org 100 points 2 weeks ago (1 children)

Take from the article: do these 20 steps to avoid

My take; use linux.

[–] obvs@lemmy.world 81 points 2 weeks ago

This is enough to never use Windows as your primary device.

[–] Tm12@lemmy.ca 30 points 2 weeks ago (2 children)

SOAP in 2026? I need a REST.

[–] _cnt0@sh.itjust.works 6 points 2 weeks ago

Everything after CORBA was a step backwards.

[–] belated_frog_pants@beehaw.org 2 points 2 weeks ago

I have terrible news for you about most payment processors and banks...

[–] artwork@lemmy.world 27 points 2 weeks ago* (last edited 2 weeks ago) (1 children)

When Windows provisions a device against a Microsoft Account, a system service called wlidsvc talks to login.live.com and gets back what Microsoft calls a Device PUID, a Passport Unique ID, inside the server’s SOAP response. Server assigned. Windows never computes it locally from anything on your PC. It receives a string and stores it.

The PUID lands in your own registry hive, in plain text, at HKCU\SOFTWARE\Microsoft\IdentityCRL\ExtendedProperties under a value named LID. From there, the Connected Devices Platform, the same background service (cdp.dll, running as CDPSvc) that powers Phone Link, cloud clipboard, and Nearby Share, reads that PUID and registers it into Microsoft’s Device Directory Service, which is the identity graph behind all of Microsoft’s cross device features. There, the number gets a lowercase g stuck in front and gets written as g:decimal. Delivery Optimization then reports that same value back to Microsoft’s servers as UCDOStatus.GlobalDeviceId every time your PC shares or downloads update data peer to peer.

Source

It likely uses the motherboard's burned-in TPM module API to generate the unique hardware ID on, and associate with the account/license.

It's quite interesting to compare the percent these civilian-scoped features are actually helping and not used for tracking and control of masses, since every accountable fraudster/killer/thief/professional knows about these and could not care less about it.

Yes, it may help for telemetry, and is great to have for an accountable business, which is understandable, but there's a hope these are not used against the civilian, too, respecting the personal lives and the right of human choice out there...

Ave Linux, the transparency, indeed...

The following is a related piece of information, yet I am sorry, but I am not sure about the accountability and accuracy of the paper, since it was written by the sorrowful LLM Claude:
- https://github.com/SmtimesIWndr/gdid-reversal

[–] pulsewidth@lemmy.world 19 points 2 weeks ago (2 children)

When Windows provisions a device against a Microsoft Account, a system service called wlidsvc talks to login.live.com and gets back what Microsoft calls a Device PUID, a Passport Unique ID, inside the server’s SOAP response. Server assigned. Windows never computes it locally from anything on your PC. It receives a string and stores it.

It likely uses the motherboard's burned-in TPM module API to generate the unique hardware ID on, and associate with the account/license.

Bruv... it literally says exactly on the statement you quoted that the ID is generated by Microsoft, and explicitly that its not generated on the device. Why would you then go on to speculate that its generated on device by the TPM...?

AFAIK the TPM doesn't generate anything, its role is for storing cryptographic information - not creating it.

[–] 4am@lemmy.zip 4 points 2 weeks ago

Motherboard TPM sends a cryptographically verifiable serial number ID to Microsoft -> Microsoft generates a Device PUID (this ensures all DPUIDs are in the same format) -> Microsoft send generated DPUID back to the device which is stored within the TPM and is cryptographically verifiable to applications which wish to access and know it, and ensure it is genuine and authentic.

TPMs all have a unique identifier burned into them.

[–] artwork@lemmy.world -2 points 2 weeks ago* (last edited 2 weeks ago)

Please do consider checking out how TPM may be used, and I've provided a reference for more context.

[–] Nukola@feddit.it 24 points 2 weeks ago

Ok, that's enough. Bye Windows.

[–] orlyowl@piefed.ca 21 points 2 weeks ago (1 children)
[–] belated_frog_pants@beehaw.org 9 points 2 weeks ago (1 children)

notaboutthekiddiddling.jpg

[–] orlyowl@piefed.ca 9 points 2 weeks ago

fairpoint.jpg

[–] Aceticon@lemmy.dbzer0.com 18 points 2 weeks ago* (last edited 2 weeks ago)

It makes it easier for Microsoft to know where to push that very special Windows Update that installs whatever the NSA wants installed in the computer of some journalist, foreign politician, syndicalist, high level manager on a foreign company that competes with an American company and other such "extremists".

[–] wizardbeard@lemmy.dbzer0.com 14 points 2 weeks ago (1 children)

So it's a unique id "stamped" to your Windows install during setup when you sign into a Microsoft account during the OOB setup experience. It gets stored in the machine's registry, and is used for uniquely identifying your hardware and tying it to a Microsoft account for licensing purposes.

It does not persist between reinstalls, and it is in a known registry location so therefore viewable and editable now that we know it's there. We don't yet know the exact effects of editing it, or how exactly they correlated it in this case with the person's network activity.


I expect we'll have some mitigation plan in the next few months. Obviously starting with the recommendations in the article.

Completely pulling this from my ass:

  • There should be some ways for researchers to watch what accesses that registry key and when.
  • Hypothetically, one could just randomize their GDID.
    • Could target specific known ones to flood the data collected (everyone uses all zeros)
    • Forge evidence against specific targets (collect the GDID off a target's machine, then set a VM to that and go nuts)
    • or just randomly generate 1000 then activate Windows on all of them using MASgrave and rotate through them. Would probably need to randomly space out the activations, use generic hardware, and randomly shuffle the ones you used. Would also help to have multiple in use at once generating fake cover data to hide the real stuff in.

At this point it's probably easier to just go off grid than to try and make Windows "private".

[–] Pacers31Colts18@piefed.social 7 points 2 weeks ago

Thats called ProcMon

[–] RejZoR@lemmy.ml 13 points 2 weeks ago (2 children)

Soooo, what does it stop Google or Meta from using same thing that Windows already offers to track users? Because as we all know, shit like this is NEVER only used by the good guys only.

[–] krisevol@lemmus.org 3 points 2 weeks ago (1 children)

Google has been tracking you for over 15 years, what you mean?

[–] RejZoR@lemmy.ml 1 points 2 weeks ago (1 children)

Not if you're not using any of their shit and actively blocking their garbage. But if they can just tap into the OS global ID that Microsoft slapped into the OS that's an issue.

[–] Crozekiel@lemmy.zip 1 points 2 weeks ago (1 children)

My dude, if you are completely de-googled but still running windows (and, even worse, using a microsoft account), that is on you...

[–] RejZoR@lemmy.ml 0 points 2 weeks ago

I still use Windows because despite Proton, it's a hassle to run games on Linux, especially multiplayer ones or use advanced features of Radeon Adrenalin that I just need. As for Microsoft account, fuck that shit.

[–] BlackAura@lemmy.world 3 points 2 weeks ago

The device id isn't ever sent to Google or Meta servers. It's created via login data on the windows machine and then sent to Microsoft with other telemetry info to be able to cross reference errors occurring with other telemetry.

At least my old company used to do something similar to track usage of internal tooling (and more importantly to alert us when users were seeing a bunch of unrecognized errors so we could alert and investigate quickly).

That being said why would Google or Meta care about Microsoft's unique identifier? They most definitely have their own they are using to track telemetry data you send them to understand usage patterns and problems.

[–] NateNate60@lemmy.world 12 points 2 weeks ago (2 children)

If you're a hacker and use Windows, you deserve to get caught tbh

[–] wizardbeard@lemmy.dbzer0.com 27 points 2 weeks ago

More so that they used the same Windows machine where they were signed in with their real personal Microsoft account as the machine they used for their illicit actions.

VPN only masks your source IP, not any of the other identifiers, of which we now know a new one.

[–] Aceticon@lemmy.dbzer0.com 8 points 2 weeks ago* (last edited 2 weeks ago)

I'm more worried about other "enemies" of the American Regime, such as journalists, syndicalists, foreign politicians (including in "allied" nations) and even just people who have access to things as simple as internal strategical information in companies that compete with American companies.

I mean, once you have access to it thanks to things like the Cloud Act and the Patriot Act, it's not exactly hard to use internal access to Microsoft and LinkedIn systems to automate mass industrial espionage by linking people to certain positions in companies competing with American companies and specific computers to those people and then push a special Windows Update to track what they're doing and documents that pass through them (though with Windows 11 I bet the eavesdropping part is already done by default on all computers with the data sent to MS).

[–] el3ctron@programming.dev 12 points 2 weeks ago

Microsoft being microsoft. Cancel Bill Gates, Windows is a trojan. Use linux.

[–] 0ndead@infosec.pub 8 points 2 weeks ago

Switch SYSTEM and RESTRICTED permissions on the registry key to DENY. It might stop even RO access to that LID value.

[–] Ceruleum@lemmy.wtf 7 points 2 weeks ago (1 children)

Windows is just bloated mallware.

[–] phoenixz@lemmy.ca 3 points 2 weeks ago (1 children)

Well there is a lot of advertising in it, yes, but I wouldn't fall it a mall

[–] cardfire@sh.itjust.works 1 points 2 weeks ago

Now you mention it, I absolutely would call it a mall.

It exists to vend other services, like their app store, their Xbox online platform, One Drive, Copilot, Office 365....

[–] yestalgia@lemmy.world 6 points 2 weeks ago

What about Windows in a VM?

[–] inclementimmigrant@lemmy.world 4 points 2 weeks ago

Here's how to limit it.

Install Linux.