Full Writeup of the Windows GDID
github.com
github.com
This surveillance is certainly going to expand in scope as age verification comes into widespread usage. Personally I see little legitimate use case for this telemetry. It seems only useful for the purposes of tracking users for law enforcement or targeted advertising purposes.
.. and how do they do that?
While we're on the subject of telemetry, has anyone got a GDPR orientated writeup of what's known?
cat /etc/machine-idI'm familiar with these global IDs because I routinely used the Windows telemetry system as part of my work on the Windows core at Microsoft. We had strong policies on how and when we could access or use data for a single device as identified by global ID.
But ultimately, these policies will have a "government or court order" exception in reality even if not in theory, just like in most other consumer software observability systems. The Windows difference is simply the breadth of data that is intentionally collected by Microsoft or can be identified by any Microsoft-controlled IDs. That difference is huge in potential impact but very small conceptually.
Must a website direct the user to log into their MS account before it is able to get a hold of the user's global ID information?
Isn't every Chrome download unique?
It used to be even though the package contained an Authenticode signature, each installer stub download had a unique hash, because Windows' digital signatures allow a non-executable data area in the trailer which is not computed as part of the signed data.
There is zero technical reason to do this (generating unique binaries) aside from tracking purposes.
then verizon did it for (to?) mobile phones.
I guess these things get normalized, people might say "those jerks" and then put it out of their mind.
The alternative is not running any proprietary tech. This would require people to give up a lot of convenience, build their own tech stack, make tools where none exist, etc. Doable for most on this forum I'd suspect, not really feasible for the population at large so the choice is even worse for them: be spied on, or abstain from using technology all together.
Its a captive audience, and why advocating for privacy is such a difficult, losing battle. People aren't going to stop using Windows because of this, so Microsoft has no incentive to do anything differently. Same goes for Meta, Google, Apple, etc.
Even for myself, I've gotten really lazy over the years and have traded quite a bit of my computing freedoms for the Apple device ecosystem's convenience factors. And that's the trap. When even the people who understand exactly what they're giving up still choose the golden handcuffs, the market has no incentive to change.
As someone pointed out in the X argument comments, this is unconfirmed and most likely NOT how the actual GDID being sent to microsofts servers looks like.
1. The GDID that most closely resembles the one mentioned in the DOJ indictment of Stokes is found inside the registry key Computer\HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\IrisService\IrisActionCreatives, which starts with the "g:" prefix and is explicitly called GLOBALDEVICEID. This keys holds cached json response from microsoft servers and this is clear as night and day what value microsoft servers consider a "GDID"
2. According to the research, a Microsoft account is required. No, it's not necessary. Whether or whether you are not logged into your Microsoft device, GDID is being filled in. Did AI forget to check that?
3. How can author claim this is full writeup of GDID, when you did not verify whether the value your AI found, is the one being sent along with telemetry network requests? Author did not even verify whether he found the right thing
I also verified the value computed as suggested by the repository's creator and it is different from the value discovered inside the Iris registry key that begins with "g:".
Summary: The value author of repo claims is a GDID, is not the same value as saved on microsoft servers.
Some users have been deleting the entire IrisService in the registry, it appears to also be related to the systray icons on the taskbar.
The first link is a couple years old but the second one is from a couple months ago. Apparently triggered now by the latest update kb5094126, so there may be some questionable new changes going on in this particular monkey-business department:
https://gist.github.com/JMMBA/d56923502a74b6b7196dd800fad0a8...
https://thegeekpage.com/taskbar-missing-after-sign-in-6-fixe...
"Fix 3" is the one where the IrisService reg key is nuked.
That's a half truth if I ever saw one. Telemetry also includes the hardware hash (which does use SMBIOS serial number, CPUID, TPM identifiers, etc.) and that one survives OS reinstalls and even hardware swaps. It is the underlying id used for things like Autopilot (the equivalent to Apple's remote MDM lock).
Windows telemetry used to track web activity, link VPN activity to source IP
https://news.ycombinator.com/item?id=48807767
U.S. v. Stokes https://www.justice.gov/usao-ndil/media/1450651/dl
1) Do we think this is actually how the FBI found this kid or is this simply what they're saying in order to keep some other tool hidden?
2) Is there a way to block or manually change the GDID from being revealed. If it's the browser leaking it, do all browsers leak it?