11
submitted 1 week ago by beep@piefed.world to c/tech@piefed.world

You can read about it yourself here on page 12 (or page 8 of affidavit), then page 33 and down (page 29 of affidavit)

First one to notice this: Security researcher, VX-Underground.

top 4 comments
sorted by: hot top new old
[-] madthumbs@lemmy.world 2 points 1 week ago

Propaganda:

It is Microsoft cloud service telemetry; e.g., Microsoft 365, Outlook, OneDrive, Azure, Xbox, etc.

This is normal: cloud providers monitor abuse, malware uploads, suspicious logins, and compromised accounts.

“Cybersecurity researchers at Microsoft… have access to data, such as computer machine IDs, IP addresses, and malware samples associated with sophisticated cybergroups.”

This is the key line.

Machine IDs here refer to identifiers associated with Microsoft cloud services or malware samples - not a Windows OS‑level “super ID” that tracks all activity. I just wrote recently about Tails OS (Linux) not protecting from these same things! -And it's alleged the most private version of Linux.

Microsoft correlated activity by looking at shared IP addresses -Something any cloud host or server could do. If multiple accounts log in from the same VPN exit node, or the same residential IP, or the same cloud server; they can be linked. It does not imply Microsoft can see through VPN encryption.

The affidavit never states: That Windows sends a universal device ID to Microsoft, that Microsoft can track all web browsing, that Microsoft can deanonymize VPN traffic, or that Microsoft can identify users across unrelated services.

[-] x00z@lemmy.world 7 points 1 week ago

Did you actually read it?

Company F server logs show that on or about May 12, 2025, threat actors downloaded, installed, and executed an ngrok agent—the program that creates a secure tunnel—on the Company F server. According to Company F, the ngrok agent had the authentication token17 2x0b1363KPV35LCUuZCkJag0G84_2btDjSM5oY82TQuiLZvaz (the “ngrok authentication token”).

According to Microsoft records, the ngrok account was set up through Global Device Identifier g:6755467234350028 (“the GDID”). According to a Microsoft representative, a Global Device Identifier in the Windows ecosystem is a persistent, device-level identifier designed to uniquely identify an installation of a Windows operating system on a device, either a physical device (e.g., a mobile phone or laptop) or virtual machine, across certain Microsoft services and scenarios. A GDID is a globally unique identifier tied to the installation of Windows on a device. A GDID remains consistent across Windows operating system updates on a device, but a reinstall of Windows, either on the same device or on a different device, will be tied to a new unique GDID.

Somehow the FBI got this GDID from ngrok logs made using a VPN, which they then were able to link to their original IPs on Microsoft services.

[-] SirHaxalot@nord.pub 5 points 1 week ago

The question here is how they were able to tie the GDID to a whole bunch of different domain visits. This is not something that is usually sent with web requests, and is not something that a typical web server config would log or be able to correlate.

The most plausible explanation I’ve seen is that some telemetry service checked in over the VPN, allowing Microsoft to log GDID<->IP, and correlate the GDID with other check-ins, from his real IP. If the VPN provider maps one IP per customer/session this would create a quite high confidence link.

Or he did something exceptionally stupid like being signed into a Microsoft account with enabled web history syncing enabled. Which of course would allow them to tie history

Remember, no matter what the commercial VPN companies want you to believe, a VPN only encrypts content between two points and masks your IP. It does very little for privacy on its own as most tracking is done with cookies and other session tokens.

[-] P00ptart@lemmy.world 1 points 1 week ago

Time to start arresting Microsoft execs.

this post was submitted on 07 Jul 2026
11 points (100.0% liked)

Technology

94 readers
114 users here now

Blacklisted SitesList inspired by other community rules.

  • Mac Rumors;
  • Al Jazeera;
  • NBC;
  • CNBC;
  • Tom’s Hardware;
  • ZDNet;
  • TechSpot;
  • Ars Technica;
  • Engadget;
  • TechCrunch;
  • Gizmodo;
  • Futurism;
  • PCWorld;
  • ComputerWorld;
  • Mashable;
  • Fortune;
  • Hackaday;
  • WCCFTECH;
  • Neowin;
  • Jacobin;
  • Yahoo;
  • Freethink;
  • Big Think;
  • Newsweek.

Technology news, blogs and articles.

Forbidden:

founded 2 months ago
MODERATORS