HN user

maxo133

58 karma
Posts1
Comments23
View on HN
GPT-5.6 13 days ago

100% agree with your statement that gemini models have most knowledge in domains. They shine in so many generic topics

A script that requests the generation of a new GDID from Microsoft servers and assigns it to the Windows installation. GDID tracking variable became publicly discussed after it was mentioned in the Peter Stokes indictment

AI-generated "research" once more. How can anyone call it full writeup?

As someone pointed out in the X argument comments, this is unconfirmed and most likely NOT how the actual GDID being sent to microsofts servers looks like.

1. The GDID that most closely resembles the one mentioned in the DOJ indictment of Stokes is found inside the registry key Computer\HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\IrisService\IrisActionCreatives, which starts with the "g:" prefix and is explicitly called GLOBALDEVICEID. This keys holds cached json response from microsoft servers and this is clear as night and day what value microsoft servers consider a "GDID"

2. According to the research, a Microsoft account is required. No, it's not necessary. Whether or whether you are not logged into your Microsoft device, GDID is being filled in. Did AI forget to check that?

3. How can author claim this is full writeup of GDID, when you did not verify whether the value your AI found, is the one being sent along with telemetry network requests? Author did not even verify whether he found the right thing

I also verified the value computed as suggested by the repository's creator and it is different from the value discovered inside the Iris registry key that begins with "g:".

Summary: The value author of repo claims is a GDID, is not the same value as saved on microsoft servers.

I can completely believe this.

I was always convinced that Skype was bought by microsoft so CIA/US intelligence agencies to have listening capabilities.

The first thing Microsoft did after the Skype purchase was making it easier to tap into the calls by removing p2p calling and routing calls using centralized servers.

You are right, but i still have no idea what is the point of this article.

The guy unlocked the bitlocker, then restarted PC just before login screen appeared. He said that's when he had most success. What sense does it make to restart and start looking for key in memory, when bitlocker has been just unlocked.

Too bad the author did not provide hardware specs. Such attack is even harder on DDR4 and DDR5 memory and most publications refer to legacy ram such as DDR3

In my experience I have had the most success restarting the system while Windows is loading but before the login screen has appeared, at least in the case of finding FVEK keys.

So what is this? It was supposed to be memory attack and he's dumping the keys after someone unlocked it and it's booting?

So this is just another theoretical attack where perfect conditions must be met.

This is a good point. It doesn't have to be Mullvad but it's almost guaranteed based on what we've seen in the history (see CIA + swiss crypto company) that some of the major VPN providers are managed by intelligence agencies. Either VPN companies were bought via shell companies after reaching certain market share or they were even developed from the scratch.

So... if they receive valid swiss court order they can be forced to log user passwords on demand and their entire service is then useless? As when you have password you can decrypt entire mailbox content.

They market their service to journalists and activists, which are often targetted by their own governments. Seems that they cannot protect any of them.

How can you advise synology when their system doesn't even have FULL DISK ENCRYPTION? As longas it doesn't have it, i wont be even interested looking at their platform.

Can you imagine it? NAS'es usually are targeted for business users, yet they dont have full disk encryption...

For now i'm using QNAP, in terms of possible features i believe QNAP is little ahead (x86 cpu, virtualization, containers, fde). It has all what synology has + more.

However their platform is badly constructed, most processes are esentially running as root user... You get like firmware update every 2 weeks. It doesn't mean that there are bugs tho. I'm running it for 2 years and never had a problem.