Elektrine lite

← Feed

@jenbanim@mastodo.neoliber.al

Post #3822623

2026-07-15 01:13 UTC

#Infosec has anyone pieced together how Microsoft was able to associate this hacker's #GDID with the websites they visited? I've been looking around and all the "explanations" I've found seem like overconfident guesses https://www.ghacks.net/2026/07/12/microsoft-confirms-windows-gdid-device-identifier-that-cannot-be-disabled-documented-in-fbi-case-filing/

Replies (1)

  • @jenbanim@mastodo.neoliber.al I'm speculating a little but this is the chain I imagine: - He used a Microsoft account to log in to Windows (never do that), associating the GDID with his online MS account - That either transfers to Edge directly, or he logged into his MS account on another browser - When he visited the ngrok page, ngrok collaborates with the MS telemetry / advert network, so his browser pings MS with a cookie from his logged-in MS account - The cookie is used to chain to the GDID

    Open ##4442880