![]()
on July 9, 2026, 11:58 pm
not a hack. a feature
No1
Jul 9
This article is a bit of a technical one, but no less important than any other I’ve posted so far. Maybe even more important as it’s THAT insidious!
Upgrade to paid
First they came for the hacker
And I did not speak out
Because I was not a hacker
Then they came for the journalists
And I did not speak out
Because I was not a journalist
Then they came for the dissidents
And I did not speak out
Because I was not a dissident
Then they came for me
And there was No1 left
To speak out for me
— paraphrased from Niemöller’s poem
His name is Peter Stokes, and for a hacker, he did mostly everything right.
He had his VPN up the whole time. Traffic was tunnelled through ngrok. IP addresses were hopping between Tallinn, New York and Bangkok like a man working three frequent-flyer schemes at once.
Nineteen years old, dual US-Estonian, and allegedly running with Scattered Spider, an extortion crew that’s pulled in over $100 million across a hundred-plus breaches.
Didn’t matter. one. single. bit.
Maybe first a few technical terms out of the way for the people unaware of those:
IP: See this as your home-address, but online. If the gov has your IP, they know who you are (more or less - not going into too much detail here so stop nitpicking - yes yes, talking to my fellow nerds here :wink
.
VPN: this is (mostly) a software solution that encrypts your traffic and shoves it through someone else’s server first, so whoever’s watching sees that server, not you.
ngrok: a legitimate tool developers use to expose a local server to the internet. Also, apparently, popular with people running extortion schemes who need their traffic to look like it’s coming from nowhere in particular. Purely coincidental, I’m sure.
IP hopping: bouncing your connection through different countries so each request looks like it came from a different place.
On May 12 last year, at 19:21 UTC, someone opened ngrok’s signup page and created the account later used to break into a US jeweller for an $8 million ransom.
Microsoft’s own logs, quoted in the federal complaint, show which machine opened that page, down to the minute. NOT the address the VPN was busy disguising. The machine itself.
That’s more or less the whole article.
So you can stop reading now if you want.
The why and how, THAT is what got me all wired up today.
If you’re using a VPN, you’re supposed to be protected as your real IP isn’t known. So the FBI didn’t know it. VPN is still secure. It’s equally useless now this secret is out in the open.
So pray tell… How did they get to this guy’s name?
They called Microsoft.
Windows has something called a GDID - the Global Device Identifier. It comes straight from Microsoft’s telemetry, and if you have Windows 10 or 11, you have been quietly reporting your own details this whole time. No matter where you are, or hop to in this case.
So pray tell… What IS this GDID?
Glad you asked… I would have never told you otherwise /s
A GDID is, without diving into that acronym soup, is something that every Windows installation gets. It’s not a hardware ID, because hardware can change, it’s passed down the first time your computer reports back to Windows (and oh boy, they REALLY like to call back!!).
Each fresh Windows installation gets a new GDID. Which stays with you forever and ever until the end of time (or until you erase that spyware masking as an operating system).
Think about it like a membership card you never asked for and can’t send back.
And no matter what you do, updates, change a harddrive, add more memory, whatever… It sticks. ONLY that clean reinstall will get you a new one. And even then Microsoft’s side of the ledger still keeps the old one, history attached. So if your reinstallation happens to be from the same IP as the old history? It still can get traced back to you.
Now every time you boot into Windows, a background service registers your device into Microsoft’s internal directory. One user’s own support thread has that service shovelling 250 to 300 megabytes home on a single startup.
Per boot. For a name tag. I’m pretty sure it’s more than a name tag which gets sent.
Separately, there is this update-sharing service that reports the exact same number next to your IP and rough location. Another diagnostics pipeline uploads batches on its own schedule. And if your telemetry sits anywhere that is not equal to “turned completely off”, those batches can carry the web addresses of your browser and the URLs your Defender has been checking against Microsoft in real time.
The GDID rides along with every lookup.
Which brings me back to our (unfortunate) hacker… Those background services are almost certainly how “opened ngrok’s signup page” got a timestamp accurate to the minute. They didn’t even had to guess. Windows knew who you were all along.
Nobody asked you to opt in to any of those channels.
There’s not even an off-switch for this, and no, it’s not what the “Diagnostic data” slider controls. That slider is the digital equivalent of asking the universe to pretty please be quiet. The universe remains annoyingly chatty anyway. Much like Windows.
Normally when you install Windows they ask you to register with a Microsoft account, but there is a workaround: a local account.
However, this doesn’t save you either. There’s a fallback baked in that registers the device anyhow. No human interaction necessary.
Now if you’re curious, you can find this via regedit at HKCU\SOFTWARE\Microsoft\IdentityCRL\ExtendedProperties.
That value converts to the exact format that turned up in the indictment.
Good you know that it’s there. But don’t go pasting this anywhere public: that specific number, plus your account, plus a device detail or two, is PRECISELY the combination that gets someone found.
You don’t go posting your ID card either right?
None of this is hidden, exactly. It’s in Microsoft’s own Azure documentation, described in one flat sentence as an identifier “used by Microsoft internally”.
Technically true. Technically a shark is a fish.
Stokes handed over the rest for free. So maybe not the smartest guy in the room, but give him some slack, he’s only 19…
Snapchat photos of cash, watches and a diamond chain spelling “HACK THE PLANET”.
A selfie from an Estonian police station, captioned about how the feds had no idea what they’d just let walk.
He did great with the VPN, and ngrok. But then couldn’t help but post his own location to the internet with a taunt attached.
Once the GDID tied his device to that ngrok account, the rest was bookkeeping: Apple, Facebook, Snapchat, even a Growtopia login, all lining up on the same IPs, cross-checked against his State Department travel records. Tallinn in one window. New York in another. Thailand after that.
The VPN hid where the traffic came from. But it never mattered.
I think it’s good riddance as those people are not innocent. I mean, they drained businesses for millions!
But the tool that caught him doesn’t check anyone’s intentions. It’s always-on on every Windows 10 and 11 machine on the planet.
There’s no published policy on when Microsoft hands that data to a government, no opt-out for anyone who’d rather not be found, and no report telling you how often this already happened quietly, to people who never make the news.
Oh, and before you go rushing off to the nearest Apple Store. Mac ain’t a refuge.
Because GDID was already taken, they called it DSID (Directory Services Identifier). Similarly, it’s a permanent number welded to your Apple ID. And Apple has your full name, phone number, birth date, email address, …
Their analytics send this number to the home turf every tap you make in the App Store or Music, even when told not to send it. “Share Analytics” is basically lipstick on a pig. Doesn’t do jack shit.
If you’re interested: search for Tommy Mysk.
The only place that can help you is Linux. It DOES have an ID too (/etc/machine-id), but the difference is fundamental. That machine ID is generated from a random source during system installation or first boot - on your box, not handed down by a vendor’s server, and no company keeps a copy.
The manual itself says it should be considered “confidential”, and must not be exposed in untrusted environments, in particular on the network.
Don’t like it? rm the file, reboot, and you got a new one.
No OS-level phone-home by default.
Caveat though: the OS isn’t watching in this case, but the apps you install (Chrome, Spotify, a Google login) still phone home on any OS.
Which ties me to my article from yesterday, as this becomes so much more than a self-incriminating teenager. And where things go with the EU, so they go with the US. Just you wait!
Clio the cat, ?July 1997-1 May 2016
Kira the cat, ??2010-3 August 2018
Jasper the Ruffian cat ???-4 November 2021
Georgina the cat ?2006-4 December 2025
Toni the cat ?2005-25 March 2026![]()
Responses