Microsoft telemetry details in the Scattered Spider complaint

Yes I’ve seen that post linked in the article. But I remember activating my Windows 10 totally offline using the MAS tools. I’ll clean install once again and try it out myself. I could be wrong, but I don’t remeber MAS requiring network connection (other than downloading the tools, which can be prepared offline)

Edit) I haven’t tried it out, but the TSForge option doesn’t seem to require network. HWID activation does. I’ll check out whether I can activate my Windows 10 via TSForge in an air-gapped environment.

I don’t see how offline vs. online activation changes anything. If the machine ever goes online and starts talking to Microsoft, it’ll likely end up with a GDID anyway.

What’s more important is disabling as much telemetry as possible, so there’s as little data as possible associated with that GDID.

1 Like

You’re missing the point. It matters because the activation process per-se can be a part of telemetry. Permanent activation via HWID sends the hardware identifiers to MS servers. Offline activation methods like TSForge prevent this. Disabling GDID and any other telemetry prior to first internet connection is important, as well as offline on-device activation.

The two paragraphs are contradictory. If Windows is used air-gapped, it doesn’t matter whether or not you disable telemetry at all. And GDID itself is a part of Windows’ invasive telemetry, so it’s crucial to turn off GDID along with other options.
There are some scripts on GitHub that automate the process. Example, another example

2 Likes

I don’t understand what you’re trying to achieve. It doesn’t matter how you activate the system, Windows will still send your HWID to check digital license on the servers and restore it. Disabling GDID is practically impossible without breaking the system: disabling DO will break system updates, disabling wlidsvc will break all UWP apps. Even after disabling CDPSvc, Microsoft still has ways to track the user. I did a clean install with all these services disabled, and somehow Microsoft Store still synced my app history, and that’s without even using a Microsoft account.

The only thing that makes sense is either not using Windows at all, or completely blocking all system connections with a firewall when necessary.

1 Like

What Windows edition are you using? The Enterprise LTSC for Windows 10 has significantly less base telemetry compared to the consumer editions.
It does matter how I’m trying to activate. According to MAS, it is possible to activate Windows totally offline. As you said, disabling as much telemetry possible in addition to using firewalls to manually block traffic related to MS servers can drastically improve privacy even in Windows. Don’t use MS store when you can manually install via .exe and verify the checksum. I disabled GDID, and despite using various software including games, I haven’t experienced any issues. Windows updates works fine as well(though I can’t say that Windows updates work with zero telemetry).
Use TSForge for activation, not HWID. I won’t talk about this deeper since it’s related to piracy.

p.s. the wildsvc doesn’t even exist in my windows.

Achieving privacy isn’t all or nothing. You should still strive to enhance yours even it might not be perfect. Simply stating “don’t use windows, switch to linux” isn’t a very constructive argument. It’s essentially the same as “don’t use computers. just use pen and paper”.

This is not a good faith statement. There are plenty of ways to use computers fairly easily and fairly privately that most people would be able to learn.

Most people cannot learn how to do these convoluted steps to use Windows semi-privately. Anyone who knows how to do this stuff probably has enough knowledge that they don’t need to be taking basic privacy advice from strangers on a forum.

We should absolutely be telling people who care about not being tracked by malicious tech companies on a privacy forum not to use Windows.

If you care about privacy and you are not highly tech competent, do not use Windows.

So is true for Windows.

Operating systems are not like ordinary softwares where one can easily replace another. There are basically three major OSes available(Windows, Mac, and Linux distros), and each have their pros and cons. Also, not everyone can migrate to Linux. Not because of their technical incapability or lack of knowledge, but for the sake of work. Many commercial softwares/games run exclusively on Windows, and those who have their entire workflow integrated into it would need excessive effort to change their OS, and even after it doesn’t guarantee it works.

You’re overlooking the fact that not everyone is capable of switching to Linux. The existence of huge amounts of github repos related to Windows hardening and their stars represent this fact. It’s okay to recommend Linux, and it’s also fine to say Windows is awful for privacy. But stating Windows should NOT be used whatsoever isn’t.

4 Likes

This is not true. Basic telemetry is the same, but unlike Home and Pro editions, Enterprise offers the option to reduce it.

I don’t know what kind of privacy you’re planning to improve on Windows, when until recently nobody knew about this GDID until someone got caught with it. Turn off telemetry, good luck, but how much more hidden telemetry like GDID will remain in the system? Nobody knows.

How did you disable GDID? How did you verify that it was disabled? Did you just trust a random script on GitHub? I have all those services disabled, but the system still generated a GDID. So what happened? Nobody knows.

I’ve never seen a decent privacy guide for Windows that’s actively maintained. It’s literally impossible on Windows because full privacy on Windows would break the entire system. The number of stars on GitHub literally means nothing, it doesn’t mean all telemetry will be removed from the system.

though I can’t say that Windows updates work with zero telemetry

You can’t prove anything, yet you’re talking about Windows privacy. Why?

1 Like

Honest question: does Apple have a similar hwid?

I mean, the article unveiling the use of GDID in an investigation by LE shocked the most but it’s not a novelty. Apple had collaborated in the past with authorities for investigations too.

My point is not to defend Microsoft nor Apple, tracking is awful.
It’s about the “obvious solution to switch to Linux” which is sadly impractical in a lot of cases.
The freedom that comes with using Linux is also tied to big downsides that the community here is often too easily willing to dismiss.

Linux for the masses is not a thing unfortunately even if I would love it to succeed.

That said it really sucks today to know that every device we have can be strictly id in a way or another.

1 Like

Not sure if it’s the same thing but I remember from my Hackintosh days that the Mac has a serial number that it needed at least to get iCloud, iMessage etc to work. I.e. it phones home to Apple with it. And in fact if you’re logged into iCloud, their tech support can request to see the screen of your Mac at any time (in theory it always asks first and would only be initiated if you ask for help, in practice if Apple are handed a warrant all bets are off). So the same advice would apply, if targeted law enforcement is a threat, then at minimum don’t log into any of the Apple services. I’d be mildly surprised if it’s not still including the ID in software update checks though.

It didn’t “bypass” VPNs. Telemetry was sent to Microsoft associating visited sites with the GDID. This allowed correlation of browsing activity with and without the VPN, as Microsoft had a record of everything tied to the same GDID. The VPN was still functional, however.

3 Likes
4 Likes

I’m missing something here. How can Microsoft know which website was accessed and precisely when?

Unless the kid used Edge?

It’s also written that GDID is created when a Microsoft Account is created, which can be bypassed:

Now for the version in plain English: Sign into Windows with a Microsoft Account, and a server assigns your installation a permanent ID number. Windows stores it locally, several background services read it, and it gets stamped onto activity your PC reports back to Microsoft.

The GDID is not calculated based on your PC components, such as the motherboard or hard drive, but rather assigned by Microsoft servers. It all starts when we configure Windows with a Microsoft account; at that moment, a system service called wlidsvc communicates with login.live.com to apply for a PUID (a unique Passport ID).

assuming the browser was using the operating systems DNS, and said DNS wasn’t encrypted. Thats likely how.

Who said they know?

No.

After some more reversing of CDP. I provided some misinfo. Using a local account does not prevent a GDID. CDP has an anonymous device path that is taken if no microsoft account.

1 Like

Are there any popular privacy configuration resources similar in spirit to https://privacy.sexy/ (or whatever) that showed intimate knowledge of these identifiers before the recent news story?

https://www.digitaltrends.com/computing/your-windows-pc-has-been-quietly-tracking-you-and-a-hackers-arrest-just-made-it-public/

The identifier, which is automatically assigned to every Windows installation, was enough to link Stokes’ computer to specific websites and third-party services, even though he was running a VPN.

Microsoft records placed the device carrying the GDID on ngrok’s signup page at the exact minute the account was created, and later browsing Company F’s website through the same .168 proxy. From there, the FBI correlated the GDID’s IP history against accounts known to belong to Stokes: Apple, Snapchat, Facebook, and even a Ubisoft/Growtopia game login.

Microsoft’s records showed that at that exact same minute, a Windows device carrying GDID g:6755467234350028 had visited the ngrok signup page. Three hours later, the same GDID visited the retailer’s own website, through the same Tzulo proxy address used to set up the ngrok account. It gave the FBI a device, that don’t rotate the way VPN exit nodes do.

From there the investigation turned into connecting dots. Once agents had a timeline of every IP address that device had used, they cross referenced it against known logins to accounts prosecutors already suspected belonged to Stokes:

  • On June 4, 2024, the GDID’s device used an IP address in Tallinn, Estonia, where Stokes lived. The same IP had logged into his Snapchat account four minutes before that and his Facebook account about 80 minutes after.
  • On November 17 and 18, 2024, the same device showed up on a New York IP address, matched to logins on one of Stokes’ Apple accounts and his Snapchat account. Weeks later, on November 26, the same device visited the website for the Empire Hotel in New York, matching another confirmed Stokes trip. He’d posted a Snapchat photo the day before that investigators matched, down to the carpet and wallpaper, against publicly advertised photos of an Empire Hotel suite.
  • On February 2, 2025, the device appeared on a Thailand based IP, matched again to his Apple and Snapchat logins. Stokes had posted a Snapchat photo captioned “WALDORF ASTORIA BANGKOK” the day before.
  • On January 8, 2025, the same device, now back on an Estonian IP, logged into the mobile game Growtopia. The day before, that same IP address had accessed one of Stokes’ Apple accounts, then a Ubisoft account tied to that Growtopia login two minutes later.

Of course, all these activities doesn’t seem suspicious when taken individually. What made the case is that the same GDID and physical Windows installation, kept showing up at the exact times as accounts investigators already knew were Stokes’, across four countries over roughly eight months.

Something’s still off to me. The hacker wouldn’t have known to use an encrypted DNS?

1 Like

He was probably using Edge. How would encrypted DNS have helped him, even if he had thought of it?

1 Like

This is only possible if he used Edge.

By default in Windows telemetry is set at the Optional diagnostic data level, unless it was disabled during installation or in the settings. With this level of telemetry, Edge collects browsing history.

This type of Optional diagnostic data includes details about web browsing in the Microsoft browsers.
Browser activity, including browsing history and search terms in Microsoft browsers.

As for other options: Bing search engine was installed in the browser, through which the link was sent to the servers, or through SmartScreen.

1 Like