Join the discussion
Write your take first — we'll ask for email only when you're ready to publish.
- Hacker News
- while it'd be nice for your paranoia to believe this id key is used for surveillance, it's more likely they just use the same type of finger printing that browsers use.
There's zero way to onion.route your internet connection information, unless you plan to go nowhere and do nothing.
Sure, it's worth to highlight privacy-potential-invasions, but the idea that you'll some how escape notice by changing the gdid is short sighted navel gazing.
by cyanydeez - There is literally court documents showing this was used by surveilling in at least one case. How that is paranoiaby dvtkrlbs
- Fun story, when my ex and I split a few years ago, I wiped all connections of my Microsoft account to the machine I built him.
Last week, when I logged into my Microsoft account, I had an extra machine with a funny name. Checking some logs, sure enough that was the hostname he gave that machine. Realized what had happened, refreshed the page, and it was gone.
The URL parameter for these devices in the Microsoft Account page is the GDID. So the Microsoft Account page showed me a GDID of a device I unlinked ~4 years ago. (And I'm slightly obsessive, I check on my Google/Microsoft account every other month.) Gooood job Microsoft.
by nixosbestos - You sure it wasn't one of the other UID numbers that have been in use longer ?by Melatonic
- Sharing in the hope it helps even one person on the fence to convert.
C. 2012 I swore never to use Windows again, and I've managed it! It is possible - macOS is really good (you'll have to unlearn your muscle memory of the Ctrl key) and Linux gaming has come a long way.
If using Windows professionally, consider installing it in a VM on your mac or linux box, then asking your agent to set up scripts that remote to to it (eg. via ssh) and do the required tasks (builds, headless test-runs etc) - remotely.
Offtopic for the GDID thing; but couldn't be more on topic if you think the market shouldn't tolerate GDIDs and such things.
by cadamsdotcom - > you'll have to unlearn your muscle memory of the Ctrl key
There is another option, which is to use Karabiner to revert to PC-like shortcuts. Learning the mac way is probably better if you plan to use mac exclusively, but I was triple-wielding macos+windows+linux for a period and I wanted my muscle memory to work across all of them.
by Retr0id - This is slop (derogatory)
It's missing quite a few things. Not exactly a ringing endorsement for claude
- I’ll bite. What is it missing?by WalterGR
Afaik, this is illegal under GDPR, as an IP has been classified as a personal identifier.> Court reporting in 2026 established that Microsoft held a GDID-to-URL/time/IP association in one investigation.by exceptione- Storing IP address itself is not illegal. The questions are:
1) what is the legal basis for storing it and if that's proper or not (e.g. legitimate interest requires balancing test)
2) if proper GDPR Article 13 notice was given and it covers that processing
3) if all Article 5 principals are being followed in regards to it (e.g. data minimization, retention period etc.)
4) if Microsoft had legal basis to transfer the data to police (they probably did, that's not high bar to clear)
by buzer - FYI this contains major red flags.
Degrading the MS sign in and other features is not sustainable.
If you truly want to get away from GDID and all the other Windows nonsense, start using Linux Mint.
- <Gov AI> this user keeps hitting our instances with no GDID, better look into it.by IronWolve
- Better yet - reply with the same GDID of the machine doing the scanning :-Dby Melatonic
- Windows has a hardcoded list of Microsoft domain names that entirely bypass the hosts file. I see nothing about this, so I would assume there is no countermeasure here. Curiously, this approach appears to have been tested as working anyway.by LoganDark
- Run say a linux firewall vm with PCI nic passthrough and give the host windows machine a virtio-pci/TAP interface as its network access is one countermeasure off the top of my head I can think of.by vetrom
- Is there anyone maintaining a canonical list of such domains and hosts? This would be useful to add as firewall rules on a router upstream of any windows hosts, or to a pihole.by jasonjayr
- Adguard Home running on a Raspberry Pi. Point your router at it for DNS, works like a charm.
Two years now, and it consistently blocks 48% to 54% of all the trash, including _all_ Microsoft domains.
by jerhewet - Wouldn't it make more sense to instead use the same GDID on thousands of hosts?
Or a random GDID on each read?
No GDID sounds like it sticks out a lot more.
by hypfer - Or just have the option of any of these
Same GDID would pollute the data for Microsoft if enough people did it. Which would also incentivise a fix or another way to differentiate.
Random GDID would likely be the most "security through obscurity" approach but still allow tracking per "session" or whatever time period it changed in.
No GDID could stick out more and if enough people did it also incentivise a fix.
Hard to say which is best but I also like another persons suggestion of random GDID assigned at boot. Or maybe no GDID by default with the option to spoof a random GDID manually
by Melatonic - Or recreate it on every boot :)
For example, it you are paranoid about Linux's /var/lib/dbus/machine-id file you can easily use dbus-uuidgen(1) to re-create it on shutdown.
by jmclnx - Trying to make windows work differently than what Microsoft wants is a losing proposition.
It would make more sense just not use windows to begin with.
by happosai - "The mutation path", "the fully lab-validated line. Other accepted builds warn.", "Status can still inspect", "command, verdict, exit code", "device-identity rehydrate sources", "the network gate", "real-shaped PUID"?
WTF.
That was extremely difficult to read. I'm assuming it's LLMese (I've had less trouble with reading the writing of ESL'ers), but one of the strangest dialects of it I've ever seen. It has the flavour of article-spun SEO spam and those shady fake research papers with "tortured phrases". What causes this obfuscated writing style?
by userbinator - Thank you for LLMese, that's gold.by shimman
- Probably every language at once being expressed in the syntax of English.by ptrl600
- It's missing a couple of wrinkles, surfaces, belt-and-suspenders, belt-and-braces, knobs, no-ops, "things that narrate", bookkeeping, stranded sessions, "the gate leads the arrangement", shit-gated, "to be wired after we've dealt with the parked features", "that's not the whole story", "the interface wants classes", slots and "whatever-backed interfaces".
All of this is enhanced claude-era vocabulary minted at the pool-of-efficiency, built as a de-facto evolution of legacy-style language.
Humans and their comment postambles, amirite?
(Here's a literal quote from a claude session: "After the f-war, the evidence itself stops lying."
I don't understand why companies are not focusing more on making these highly intelligent models speak a decent language. Maybe they are, and they're failing. But the last few months have made it pretty difficult to engage with these highly intelligent assistants.)
by jorl17 - Repo "author" here. That's just my custom instructions in the IDE, sometimes they result in hilarious docs, sometimes less so. Using GPT Sol for this project, and Fable for review.by yegor
- "real-shaped PUID" seems like usage of "real-shaped" outside of normal disciplines, but probably accurate enough
- > What causes this obfuscated writing style?
Claude without an editor having worked too long on its own project.
by azalemeth - I like to call this style of writing "advanced technical claudish"by andersa