

Join the discussion
Write your take first — we'll ask for email only when you're ready to publish.
- Hacker News
- Stopped using Windows in Windows 7 era, never regretted.by codedokode
- Get-ItemProperty : Cannot find path 'HKCU:\SOFTWAREMicrosoftIdentityCRLExtendedProperties' because it does not exist. At line:1 char:7
I guess I'm good then.
- You're missing all the backslashes, so of course it doesn't exist.by d3Xt3r
- Obvious workaround to get off windows and use Linux…
But do any popular linux distributions use an identifier? Ubuntu, Kali, Mint, Arch, etc?
It seems an attractive way for devs to work out telemetry. Awful in reality; but I imagine attractive.
- At least Debian and Ubuntu have /etc/machine-id, presumably easily changed - but it’s there.by moepstar
- I agree, tracking data via unique identifiers is evil incarnate, unless it's Google or VC-backed adtech doing it, because how else will they make money having architected their entire businesses around it.by pudgywalsh
- Or just use Linux.by Nevin1901
- Exactly , windows should be used for gaming. :Dby subzero06
- That's exactly the advice at the end.by altcognito
- Or don't commit fraud worth millions of dollars using your personal Windows machine.by wnevets
- /etc/machine-id also exists
- Article tells you to paste
> $lid=(Get-ItemProperty 'HKCU:SOFTWAREMicrosoftIdentityCRLExtendedProperties').LID
which obviously does not work because it has all the slashes removed. Article author apparently didn't bother to proofread anything.
- Even if you fix this one, how do you know if you got all of them? How do you know they won't add more another time in some quiet patch?
Just stop already, you are in an abusive relationship. Get out. Remove windows. It's not your friend. It's your computer, you have options.
by imglorp - I cannot believe people tolerate this kind of behavior from such a large company with a huge market.
It does make me wonder if people would react differently if Linux or Apple did the same thing.
by inventor7777 - It's not one homogeneous people reacting to different OSes. It's different people, and they react differently when somebody else's OS does something vs when their OS does something. Windows users don't care or feel locked in because it's the only OS they've known and they depend on it. Linux users expect this type of behavior from Windows, but they can't do more than switching themselves which they already have. Were Linux to do something similar, you remove the offending piece of software.by jolmg
- Better start believing it; Google Chrome has a 71% market share.by pudgywalsh
- I think it's likely that Microsoft is running a process to correlate "new" GDIDs to old ones, ex:
"Oh look, this one has almost all the serial numbers of components and attached-devices as that other one, it's probably the same computer with a fresh install, let's make a note of that..."
by Terr_ - But I've got nothing to hide
- They do not need this, they require you to create a Microsoft account to use your own computer (currently without a phone number, passport and selfie but that will probably change in the future).by codedokode
- Interesting, generally Microsoft bypasses the hosts file name resolution for various MSFT domains. Curious that these were not included (if it works, which I assume the mitigation does).
https://petri.com/windows-10-ignoring-hosts-file-specific-na...
by 0x1d7 - FWIW, YogaDNS stops these bypasses if you tick a settings box ("Block plain DNS over TCP from System Resolver"). Or use similar DNS forcing techniques against port 53.
Windows falls back to the normal resolver in that case.
by Quarrel - Windows 10 LTSC IOT will be the last Windows I ever use.
As I grow older, I simply do not have the patience or the will to do all these workarounds and tweaks to my OS to turn it from a piece of barely-working corporate spyware into something that I can call a productive tool.
It also seems like interacting with the OS is on its way out anyway, as most people essentially interact with computers via the browser (essentially a different sandboxed OS altogether), whether on desktop or mobile device.
by antisthenes - > Microsoft provided the FBI with the history of IP addresses tied to that specific GDID.
This article, and most articles about this, doesn't explain where FBI got that GDID from. Ok, Microsoft has a list of IP addresses that has been used by a computer with a certain GDID, but FBI needs to get the GDID in the first place, and then try to bind that to a person.
I found another article that explains the process a bit better:
> Stokes got caught because he used the same Windows device for everything, and the GDID stitched all of it back together after the fact.
> Scattered Spider members phoned the jewelry retailer’s IT help desk from Google Voice numbers, posed as locked out employees, and talked support staff into resetting three accounts, two with administrator privileges. From there they installed a tunneling tool called ngrok to get past the retailer’s network defenses, moved roughly 77 gigabytes of data to Amazon cloud storage using ngrok [...]
> Investigators later subpoenaed ngrok and found the account used in the attack had been created on May 12, 2025, at 19:21 UTC from a VPN proxy IP address run by Tzulo, a hosting provider. The IP was a dead end. VPN proxies do that. But the GDID is built different.
> Microsoft’s records showed that at that exact same minute, a Windows device carrying GDID g:6755467234350028 had visited the ngrok signup page. Three hours later, the same GDID visited the retailer’s own website, through the same Tzulo proxy address used to set up the ngrok account. It gave the FBI a device, that don’t rotate the way VPN exit nodes do.
https://www.windowslatest.com/2026/07/10/you-cant-fully-disa...
Although this doesn't explain where Microsoft got that traffic data from. How do Microsoft know which sites a computer visit?
by sorenjan - None of this matters really.
This criminal mastermind got caught because he did everything but sign his name to the crimes while holding two pieces of government identification in presence of a notary.
The FBI did the bare minimum in terms of old-fashioned detective work, and correlated evidence from various sources.
The obsession with GDID is a complete nothing-burger and I'm tired of seeing it on the front page every other day.
by pudgywalsh - I'd take all of this with a cup of salt due to law enforcement's use of parallel construction in tech cases.by okasaki
- They claim it was an ngrok account that was used to host an endpoint used in the compromise, tied to a microsoft account / gdid that was passed when ngrok software was downloaded from the "microsoft store".by nickphx
- Thanks, I've added that link to the toptext above.
Edit: actually there have been a few threads about this - the link you mentioned was submitted in the second of these:
Microsoft confirms Windows GDID device identifier that cannot be disabled - https://news.ycombinator.com/item?id=48920338 - July 2026 (60 comments)
Microsoft admits Windows 11 has a GDID tracker with no off switch - https://news.ycombinator.com/item?id=48872561 - July 2026 (15 comments)
Windows GDID Changer - https://news.ycombinator.com/item?id=48818707 - July 2026 (4 comments)
Full Writeup of the Windows GDID - https://news.ycombinator.com/item?id=48811081 - July 2026 (49 comments)
Microsoft GDID telemetry includes full browsing and gaming history - https://news.ycombinator.com/item?id=48787239 - July 2026 (6 comments)
by dang - It's called telemetry. It means Windows sends data back to Microsoft about what you're doing.by inigyou
- They didn’t. They went to ngrok and asked for all the data at the point of signup. They then looked to find the any of that data at the second site. In this case they had two identical data points - the GDID and the IP address.by multjoy
- They make the default web browser on Windows, and that sends your browsing data if you don't disable its telemetry.by crtasm