[removed]
the gov posted this the 1 of july of this year. "very old"? if you meant the case in general idk, i was aware of this a few hours ago, some post are from april so yeah, maybe its old, but not "very"
you're wrong Ive read the affidavit too, the GDID is what gave his ip address away when used ngrok
Uh. No.
GDID can't give away an IP address.
GDID can't give away an IP address.
if you are on windows, you are in danger. in other news: water is wet, grass is green, and cops are racist.
It is even worse since it seems he used Edge as his browser, the GDID also tracked his web traffic. Having a VPN or Tor connection would not help him since his IP was part of the total telemetry to MS. You can look at all the different settings available and notice: Most of the are enabled by default.
Now, this is not some weapon of MS or some kind of information grab per se but I am sure they are grabbing whatever they think they can get away with.
a512c546
Given this latest piece of news I would suggest... stongly.. to Not Use Windows For Hacking. I mean, come on. You boot up, log into your computer via MS and then bring up your VPN or Tor connection.
But didnt you connect to MS to log into your computer in ther first place?
Before the VPN or Tor connection?
Windows, by design, tracks and logs everything. You would figure with the amount of logging they windows has you would figure that it would be simple to resolve a windows issue, but who hasnt had to spend a few hundred dollars to talk to MS support to mearly be told to Reinstall Windows. This would be after the various, check your cable and reboot the computer.
The various Doc here in tforum in d/OpSec are very good. I understand that actually doing the various things to gain more privacy may not be as convienent as rememberd passwords and auto logins. I get it that it may not be convient to have a separate laptop for your darknet needs. It's easier to use just one computer. Everything you need is there....
and thats the problem. Everything is there.
So, let's all agree that Windows, as far as a useable hacking/darknet operating system, is a no go.
Linux is also having some issue here with age requirement software. In general Linux has pretty much said Fuck You to that, I believe that Ubuntu has some of it already set up via OS updates.
I do not know what, if any, GDID issues there may be concerning using a VM. As I recall, reinstalling the OS gives you some different GDID info, the OS gets the hardware telemetry and sends that to MS, which is then correlated with your old on. In short, it does not seem to matter.
Given Qubes and Whonix et al installed on a Windows host I would suspect that would be safe, as long as you only use the windows machine to run the VMs.
Read the OpSec Docs. Use TailsOS at least.
Now, this is not some weapon of MS or some kind of information grab per se but I am sure they are grabbing whatever they think they can get away with.
a512c546
Given this latest piece of news I would suggest... stongly.. to Not Use Windows For Hacking. I mean, come on. You boot up, log into your computer via MS and then bring up your VPN or Tor connection.
But didnt you connect to MS to log into your computer in ther first place?
Before the VPN or Tor connection?
Windows, by design, tracks and logs everything. You would figure with the amount of logging they windows has you would figure that it would be simple to resolve a windows issue, but who hasnt had to spend a few hundred dollars to talk to MS support to mearly be told to Reinstall Windows. This would be after the various, check your cable and reboot the computer.
The various Doc here in tforum in d/OpSec are very good. I understand that actually doing the various things to gain more privacy may not be as convienent as rememberd passwords and auto logins. I get it that it may not be convient to have a separate laptop for your darknet needs. It's easier to use just one computer. Everything you need is there....
and thats the problem. Everything is there.
So, let's all agree that Windows, as far as a useable hacking/darknet operating system, is a no go.
Linux is also having some issue here with age requirement software. In general Linux has pretty much said Fuck You to that, I believe that Ubuntu has some of it already set up via OS updates.
I do not know what, if any, GDID issues there may be concerning using a VM. As I recall, reinstalling the OS gives you some different GDID info, the OS gets the hardware telemetry and sends that to MS, which is then correlated with your old on. In short, it does not seem to matter.
Given Qubes and Whonix et al installed on a Windows host I would suspect that would be safe, as long as you only use the windows machine to run the VMs.
Read the OpSec Docs. Use TailsOS at least.
STOKES used ngrok tunnels to steal data from Company F, exfiltrating it to his own rented server (.191). He thought he was safe behind VPNs, but he made three critical mistakes:
First, he created the ngrok account from his personal Windows laptop using a VPN. Microsoft logged his GDID, a permanent hardware fingerprint that survives VPNs because it's tied to his physical components, not his network, and his VPN IPs get logged and tied to his GDID thanks to other telemetry events inside Windows. GDID itself is not a log database just an identifier but some Microsoft services running in the background might include tracking.
Second, he used the same VPN exit nodes to both RDP into his criminal server AND check his personal social media. Feds seized the .191 server via warrant, pulled the RDP logs, and saw VPN IPs connecting to it. Those same IPs appeared in Snapchat and Apple records. And also THIS IS IMPORTANT Snapchat is heavily "fedded" and preserves everything. Dude was making posts and having conversations about his entire operation on a platform known for cooperating with law enforcement, likely triggering FBI attention without even realizing it.
Third, a reverse 2703(d) order to Microsoft revealed the residential IPs behind those VPN connections, plus confirmation that the GDID from his laptop created the ngrok account. Microsoft had logs showing that device traveling with him to Tallinn, New York, and Thailand, matching his State Department travel records. You can't argue "someone else was using my VPN" when it's your specific device fingerprint showing up in the logs, moving with you across international borders.
VPNs don't protect you from correlation attacks, and using Snapchat while running a cybercrime operation is like doing deals in front of a police station. When you reuse infrastructure across criminal and personal activity on platforms that actively cooperate with feds, you're basically leaving a trail of breadcrumbs straight to your door. Of course Microsoft played a big role in this, but the mistakes he made were honestly rookie mistakes for a Scattered Spider member, but this group is also full of not so talented teens.
So yes, don't trust Microsoft or any big tech company, not even Apple with their iPhones. I used to love using Windows and I don't think disabling or spoofing this GDID thing makes it safe, it would never be safe, just using a different OS will make a difference.
First, he created the ngrok account from his personal Windows laptop using a VPN. Microsoft logged his GDID, a permanent hardware fingerprint that survives VPNs because it's tied to his physical components, not his network, and his VPN IPs get logged and tied to his GDID thanks to other telemetry events inside Windows. GDID itself is not a log database just an identifier but some Microsoft services running in the background might include tracking.
Second, he used the same VPN exit nodes to both RDP into his criminal server AND check his personal social media. Feds seized the .191 server via warrant, pulled the RDP logs, and saw VPN IPs connecting to it. Those same IPs appeared in Snapchat and Apple records. And also THIS IS IMPORTANT Snapchat is heavily "fedded" and preserves everything. Dude was making posts and having conversations about his entire operation on a platform known for cooperating with law enforcement, likely triggering FBI attention without even realizing it.
Third, a reverse 2703(d) order to Microsoft revealed the residential IPs behind those VPN connections, plus confirmation that the GDID from his laptop created the ngrok account. Microsoft had logs showing that device traveling with him to Tallinn, New York, and Thailand, matching his State Department travel records. You can't argue "someone else was using my VPN" when it's your specific device fingerprint showing up in the logs, moving with you across international borders.
VPNs don't protect you from correlation attacks, and using Snapchat while running a cybercrime operation is like doing deals in front of a police station. When you reuse infrastructure across criminal and personal activity on platforms that actively cooperate with feds, you're basically leaving a trail of breadcrumbs straight to your door. Of course Microsoft played a big role in this, but the mistakes he made were honestly rookie mistakes for a Scattered Spider member, but this group is also full of not so talented teens.
So yes, don't trust Microsoft or any big tech company, not even Apple with their iPhones. I used to love using Windows and I don't think disabling or spoofing this GDID thing makes it safe, it would never be safe, just using a different OS will make a difference.
Your funny i like you
When ware Windows users not in danger?
(3.11 maybe? ;)
(3.11 maybe? ;)
its ok having a vps dmca, a vm windows machine, mullvad multihop+daita, mac changer, O&O shutup?
Members-only continuation
This discussion contains more posts.
Create an account or sign in to continue reading the full conversation. 5 additional posts await inside.