this post was submitted on 13 Jul 2026
910 points (99.0% liked)

Technology

86580 readers
3237 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 3 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[โ€“] Honytawk@discuss.tchncs.de 2 points 1 week ago (1 children)

If you use your Microsoft account to login, they have to be able to identify you somehow when you try to authenticate. It is basic usage. Not Telemetry. That is what caught him.

[โ€“] Windex007@lemmy.world 1 points 1 week ago

This is where I'm really fuzzy on the mechanics.

Any authentication is to establish an identity. At what point does that involve getting a unique id associated with an OS installation instance?

My original question is how the hardware id and ngrok get associated at all.

So, after getting frustrated and just going to sign up for an account myself, it looks like ngrok has options to sign is as a Google account, or sign in as a github account.

I'm guessing they picked github, and that's why Microsoft had any visibility at all on the fact that they accessed a site that isn't owned by Microsoft.

It still doesn't answer the question of how the browser knows this id which is set at the os level. It still begs the question of what github authentication looks like differently between operating systems. Obviously a osx or Linux machine wouldn't have that id at all. Is it part of the initial authentication request? Is there some kind of challenge and response?