11
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
this post was submitted on 07 Jul 2026
11 points (100.0% liked)
Technology
95 readers
90 users here now
Blacklisted Sites
List inspired by other community rules.
- Mac Rumors;
- Al Jazeera;
- NBC;
- CNBC;
- Tom’s Hardware;
- ZDNet;
- TechSpot;
- Ars Technica;
- Engadget;
- TechCrunch;
- Gizmodo;
- Futurism;
- PCWorld;
- ComputerWorld;
- Mashable;
- Fortune;
- Hackaday;
- WCCFTECH;
- Neowin;
- Jacobin;
- Yahoo;
- Freethink;
- Big Think;
- Newsweek.
Technology news, blogs and articles.
Forbidden:
- Paywalled content.
- Older than 1 month articles;
- External video links(non native videos);
- Article talking about article, research or news.(Always use original articles).
founded 2 months ago
MODERATORS
Propaganda:
It is Microsoft cloud service telemetry; e.g., Microsoft 365, Outlook, OneDrive, Azure, Xbox, etc.
This is normal: cloud providers monitor abuse, malware uploads, suspicious logins, and compromised accounts.
This is the key line.
Machine IDs here refer to identifiers associated with Microsoft cloud services or malware samples - not a Windows OS‑level “super ID” that tracks all activity. I just wrote recently about Tails OS (Linux) not protecting from these same things! -And it's alleged the most private version of Linux.
Microsoft correlated activity by looking at shared IP addresses -Something any cloud host or server could do. If multiple accounts log in from the same VPN exit node, or the same residential IP, or the same cloud server; they can be linked. It does not imply Microsoft can see through VPN encryption.
The affidavit never states: That Windows sends a universal device ID to Microsoft, that Microsoft can track all web browsing, that Microsoft can deanonymize VPN traffic, or that Microsoft can identify users across unrelated services.
Did you actually read it?
Somehow the FBI got this GDID from ngrok logs made using a VPN, which they then were able to link to their original IPs on Microsoft services.
The question here is how they were able to tie the GDID to a whole bunch of different domain visits. This is not something that is usually sent with web requests, and is not something that a typical web server config would log or be able to correlate.
The most plausible explanation I’ve seen is that some telemetry service checked in over the VPN, allowing Microsoft to log GDID<->IP, and correlate the GDID with other check-ins, from his real IP. If the VPN provider maps one IP per customer/session this would create a quite high confidence link.
Or he did something exceptionally stupid like being signed into a Microsoft account with enabled web history syncing enabled. Which of course would allow them to tie history
Remember, no matter what the commercial VPN companies want you to believe, a VPN only encrypts content between two points and masks your IP. It does very little for privacy on its own as most tracking is done with cookies and other session tokens.