Post #3749601
2026-07-11 20:03 UTC
@earthshine@masto.hackers.town the biggest surprise here is that Microsoft also records _which websites_ are being visited:
> Microsoft’s records showed that at that exact same minute, a Windows device carrying GDID g:6755467234350028 had visited the ngrok signup page. Three hours later, the same GDID visited the retailer’s own website, through the same Tzulo proxy address used to set up the ngrok account.
Replies (2)
-
@CppGuy@infosec.space 2026-07-11 23:16
@rhoot@mastodon.gamedev.place Yes — even, apparently, if you use a VPN. @earthshine@masto.hackers.town
-
@n_dimension@infosec.exchange 2026-07-12 00:24
@rhoot@mastodon.gamedev.place @earthshine@masto.hackers.town The #Microsoft attack is the classic "man in the middle" because they own the endpoint, they can bypass any security measures you may think you have (eg: VPN) At this point in time, you have rocks in your head if you make a choice to use the Windows #surveillance software. #Infosec