|
|
|
|
|
by NotPractical
7 days ago
|
|
> Microsoft has a list of IP addresses that has been used by a computer with a certain GDID, but FBI needs to get the GDID in the first place What they did was the opposite: ask Microsoft for GDIDs used by attacker-associated IPs within several 24-hour time periods during which attack-related activity took place. Windows pings Microsoft regularly with the GDID, establishing links between your GDID and any IP addresses you use. The IP logs from Microsoft and the VPS provider showed at least 10 instances where a single VPN IP accessed the attacker's VPS and also pinged Microsoft with at least one GDID within a 24-hour period. They found a constant GDID that all instances shared. This seems to have been the most damning GDID-related evidence in the DOJ complaint [1] and yet it wasn't mentioned in the article you linked (or any other articles about this I've seen pop up on HN). It includes the diagram from the complaint (page 18) that outlines this, but devoid of context. The ngrok stuff that the article focuses on was just the cherry on top and was discussed later in the complaint. What also becomes clear when you read the complaint is that the GDID was just one piece of the puzzle and that they had plenty of other evidence. Attacker-associated IPs were used to access the suspect's Apple, Snapchat, and Facebook accounts, at least one of which was his actual residential IP, not a VPN IP. Once they had revealed the identity of the person who owned these accounts, they were able to all-but-confirm that this was in fact the attacker. What remains unclear even after reading the complaint is how they were so sure that the GDID they obtained visited specific websites, but honestly, at that point, they were already drowning in evidence, so I don't know if it matters that much. It could be as simple as "he was signed into Edge with his Microsoft account and had sync enabled". [1] https://www.justice.gov/usao-ndil/media/1450651/dl?inline |
|
* Microsoft collects timestamped GDID - IP address combinations at some interval.
* Other Service (eg your website) collects timestamped IP address data.
Combine the above and you can tell which GDID visited the service without the service knowing anything about GDID.
Eg
At 9:47:00 Microsoft gets a ping from a computer at IP address "123" with a GDID of "abc".
At 9:48:07 mywebsite.com is visited by IP address "123".
You combine both sets of data and you can be reasonably sure that GDID "abc" visited mywebsite.com at 9:48:07.