This is a systemd identifier, not strictly speaking a "Linux" identifier.
In any case, an executable allowed to run on a host can trivially fingerprint the machine it is running on using a combination of hardware identifiers. Removing or rotating machine-id does not buy you any privacy against a malicious app.
What I find most surprising in this story is how careless these "hackers" were. You would think that people engaged in this type of activities would use throwaway devices running free operating systems and VMs, not personal devices logged into Snapchat and Facebook.
> Removing or rotating machine-id does not buy you any privacy against a malicious app.
It absolutely can if that's the only identifier an app is looking at.
> You would think that people engaged in this type of activities would use throwaway devices running free operating systems and VMs, not personal devices logged into Snapchat and Facebook.
Well, the smart ones do that, which is why they don't make the news as they don't get caught.
sounds like you can rotate it, but it doesn't really matter because the registration/rotation process sends a bunch of static information to microsoft, which means they can re-correlate the the old id back to the new id.