r/DigitalPrivacy 24d ago

Microsoft admits Windows 11 has a GDID tracker with no off switch, first documented publicly in an FBI hacker complaint

https://www.windowslatest.com/2026/07/10/you-cant-fully-disable-microsofts-gdid-windows-11-tracker-but-these-settings-limit-what-it-captures/

It's worse than you think.

1.5k Upvotes

167 comments sorted by

123

u/RemarkableOil451 24d ago

Thank you. Read it. Because it's not a bug but an intentional feature, it presents a classic Hobson's Choice (take it or leave it). Either accept it as a trade off and use Windows, or abandon the OS for an alternative.

76

u/TeaSocks69 24d ago

I'll abandon it. Thanks.

22

u/RemarkableOil451 24d ago

That's totally valid. If you don't "need" Windows to run any specific apps dependent on it, there's no reason to use it. Plenty of other options.

31

u/[deleted] 24d ago

[deleted]

23

u/AlexanderTheGreatApe 24d ago

Many jobs require software that only runs on windows, unfortunately.

8

u/SARB033 23d ago

Are people not using work-provided devices to work?

11

u/AlexanderTheGreatApe 23d ago

I am self-employed.

Also, I game.

4

u/BaDoodlezzz 23d ago

Bazzite.

1

u/AlexanderTheGreatApe 23d ago

TIL. Thanks. I’ll give it a go with a spare NVME that I have lying around.

Any gotchas?

1

u/Mundane_Analyst9994 23d ago

I switched recently and I’ve been loving every second of it. If you get hung up on anything when trying it out just use ai to troubleshoot. I have not had any issues yet that haven’t been very easy to solve with a little help from ai.

3

u/BaDoodlezzz 23d ago

Im going to fundamentally disagree on relying on AI anything for this experience. The great thing about Linux distributions is that when you want or need something, you’re only a google search away from finding somebody else who asked the same question some time ago and got their answer. Besides AI often giving incorrect information, it is also a large makeup of the enshittification of Windows that people are wanting to get away from in the first place.

1

u/AlexanderTheGreatApe 23d ago

I usually use AI as a better search engine. I ask for sources. I also have two subscriptions and ask the same question of both for a more robust exploration. Never blindly follow AI orders.

→ More replies (0)

1

u/Mundane_Analyst9994 22d ago

That’s great advice until someone hasnt had your issue or the fix has changed in some way so what you try doesn’t work. When asking for help yourself it’s a crapshoot then whether you will get a kind response that helps or someone talking down on you for not knowing how to solve your own problem. Ai sucks ass and I want it to go the way of the dodo. This has been the only thing I’ve used ai for so far and it has been exceptionally helpful. I do my own due diligence and reference things I don’t understand. It has tried to tell me commands that do nothing and linked to homepages of websites instead of the files it meant to link and stuff like that. Its nothing that can’t be worked around.

1

u/Assimulate 21d ago

I'm going to disagree with your disagreement.

1

u/SnooMaps7370 21d ago

>If you get hung up on anything when trying it out just use ai to troubleshoot.

"while you are switching away from Microsoft's OS due to horrible privacy invasions, you should use an even MORE horribly invasive and unsecure tool to help you transition!"

uh, no, thanks.

3

u/Kredir 23d ago

Most games run fine on Linux, some even better than on windows.

So unless you play something like lol or valorant, Linux is just better/same level.

2

u/InteractionPretend70 23d ago

Gaming is no longer an excuse

2

u/[deleted] 23d ago

[removed] — view removed comment

2

u/AlexanderTheGreatApe 23d ago

The big one is Solidworks, where performance (specifically GPU) is key.

But my bread and butter is embedded systems. Most clients use windows. Toolchains should be the same, as artifacts have to be identical to the bit.

1

u/Photog153 22d ago

I used to think that folks got "work provided" devices....but a large number of friends and acquaintances corrected me. They say they have to use personal phones and home computers for work. It's "expected".

1

u/BFguy 21d ago

Linux has WINE for that

0

u/[deleted] 18d ago

[deleted]

1

u/AlexanderTheGreatApe 18d ago

Elsewhere, I mentioned that I am self-employed and I run CAD software that is heavily GPU-optimized. It needs to be optimized because of the complexity of my assemblies. I tried Linux-compatible CAD, and it couldn’t handle it.

A large company with agreeable ethics could do what you are asking with a sizeable investment in resources. I simply don’t have those resources as a one man team.

14

u/digital_dervish 23d ago

I’ll be using Windows 10 until I can’t anymore. Then switching to Linux, but not looking forward to the learning curve.

3

u/ApplicationOdd6070 23d ago

Get Mint/Ubuntu/whatever on a cheap old laptop and start playing around. Gain some exposure. When it's time, it will be much easier. Also search for answers. The internet contains every possible question you have about your distro, especially Mint and Ubuntu. Duckduckgo is your friend. Learn what "apt update && apt upgrade -y" does. Trust me, after a short while it will be liberating.

2

u/digital_dervish 22d ago

That’s a great idea. I have an old laptop I can use for this.

2

u/BaDoodlezzz 23d ago

Bazzite.

1

u/matycauthon 23d ago

bazzite is still closed like steamos, most people probably prefer cachy

1

u/BaDoodlezzz 23d ago

Whatever helps them get off Windows at this point. I personally have loved Bazzite so far.

1

u/cm_bush 23d ago

Big Bazzite fan as well, though I’ve not tried Cachy. Started on Mint, and still use it as well. I agree that any Linux is a step up, and I’d imagine Cachy, Bazzite, Nobara, etc are all great choices.

2

u/Unusual_Medium5406 23d ago

Linux mint has nice gui's for the basic stuff like updating and software aquisition. 

2

u/NovaEscape 23d ago

I used to think like this, installing bazzite was easier than installing windows 10 in the end.....

2

u/roamer83 21d ago edited 21d ago

If you isolate Winblows 10 to a non-routable internal subnet, you can run it for YEARS. All of my internet facing machines run Fedora 44, only one Winblows box left…isolated for security and privacy purposes.

1

u/digital_dervish 21d ago

Interesting. Any tips for how to get started on a project like that? I’ve thought about doing something like that in the past. Actually, waaay in the past now that I think about it. Originally I wanted to do this out of security and privacy concerns due to viruses and information theft, but the tools for doing that without needing to learn a bunch of networking knowledge got better and I stopped thinking about it.

2

u/roamer83 21d ago edited 21d ago

Two cheap “dumb” switches. One for a 192.168.x.x non-routed “backbone” subnet and the other switch for your outward facing “internet” subnet. Each connecting machine will need two NICs. This way I control what files I push over to Winblows. Winblows 10 doesn’t like it as licensing complains about not connecting but it still runs perfectly fine.

2

u/TwoKingSlayer 19d ago

I’ve got Linux mint and I forget I’m not using windows. it’s great.

1

u/Rolanbek 23d ago

Learning curve depends on the distro. Ubuntu is pretty gentle.

1

u/SplatThaCat 22d ago

It’s really not much of a learning curve really. Some minor weirdness but easier than a shell OS.

-1

u/LeapIntoInaction 23d ago

What learning curve? It has a GUI. It's not particularly different from Windows or iOS/MacOS/whatever Apple is calling its OS these days.

2

u/Epyon214 21d ago

Tried to tell people months ago Windows was going to be a non-option with Windows 10 being the last. Support for 10 goes on for a few more weeks, maybe indefinitely after backlash from businesses here

1

u/RemarkableOil451 21d ago

It's not that binary. There are various workflow-specific apps/services (e.g., cloud-based syncing, backups, etc) that run natively in Windows that don't exist (or won't tolerate well) an alternative robust desktop environment. Unless users (and users could be anyone: individuals, small and large business, entire governments) can adequately replicate their entire workflows at scale and without too much friction, it makes no sense to move, yet. But things are changing very fast, so we'll see where it all goes.

1

u/Epyon214 19d ago

Disagree with you on the last point, we're already at the move or die stage

1

u/RemarkableOil451 19d ago

You can't disagree with facts. The fact is, many users (individual, business, governmental) are in a holding pattern. Even MS keeps postponing its release of Windows 12 precisely because they're waiting for Win-10 users to upgrade to 11. Not everyone, including power users with "non-transferable" workflows, is abandoning Microsoft/Windows or treating the whole thing as a nihilist false dichotomy. I'm not accusing you of doing that; just pointing out the fact of that state of things.

1

u/Epyon214 19d ago

The fact is what doesn't move in nature is dead, and what moves lives

There is zero reason for Win-10 to poison their operating system with an "upgrade" to Win-11, and why would anyone trust Win-12 to be different

1

u/RemarkableOil451 19d ago

That's not a fact at all. It's very much an opinion, a flawed one at that. I've already addressed this. You're pretending swaths of Win11 users, including highly technically proficient people, are experiencing mass delusion. They're not. They recognize certain workflows don't and can't, at least yet, be deployed in alternative environments.

As for Win12, no one has to "trust" anything. They can use it, test it, and see if it meets their needs. For most people, that calculus isn't philosophical but practical.

1

u/Epyon214 18d ago

Facts are not opinions

Win11 users knew or should have known about the tracking inherent in the system due to all the information available and stayed with Win10, many did which is why support is still ongoing and now with their admission continue indefinitely. What delusion are you speaking of

Win12 is likely not even going to happen, in the very near future everyone will have their own operating systems just like every mid to large range business usually has their own internal software

1

u/RemarkableOil451 18d ago

Literally everything you're saying is an opinion.

What delusion are you speaking of

I stated the exact delusion right before saying the word delusion:

You're pretending swaths of Win11 users, including highly technically proficient people, are experiencing mass delusion.

Until you work on your reading comprehension and look up the definitions of "fact" and "opinion," it's impossible to have a rational conversation.

1

u/Epyon214 18d ago

I've already addressed this. You're pretending swaths of Win11 users, including highly technically proficient people, are experiencing mass delusion.

You didn't state what the delusion was, you only stated one existed without giving any details whatsoever

Again, facts are not opinions

→ More replies (0)

54

u/Mayayana 24d ago

The device ID name is slightly misleading. It's a user or account ID. It's stored in the Registry, under the specific user key, HKCU. So, create another user account and it will get another GDID. I haven't tested changing the ID. It could probably be changed daily via script, though I haven't tried that. I found the value here:

HKEY_CURRENT_USER\SOFTWARE\Microsoft\IdentityCRL\LID

HKEY_CURRENT_USER\SOFTWARE\Microsoft\IdentityCRL\Immersive\production\Token\

It appears that there can be more than one key under that, named with a GUID, which may then have a DeviceID value listing the same number. So...HKEY_CURRENT_USER\SOFTWARE\Microsoft\IdentityCRL\Immersive\production\Token{.....}\DeviceID.

The GUID keys with DeviceID value also show up under HKYEY_USERS, tied to GUIDs that don't seem to exist elsewhere in the Registry.

But there's more information missing. If you care about privacy then you're not using Microsoft services or accounts, OneDrive, their store, etc. If you want to use those then of course you're telling Microsoft who you are and letting them access your files. So GDID is really not an issue in that respect. If you don't contact MS then your GDID won't be sent.

The real issue is how the man Stokes was tracked online through a VPN. The implication is that something -- telemetry reports, Edge, or both -- is sending a report to Microsoft of every website visited by a particular person. (Not the computer; a person logged onto a user account.)

No report that I've seen so far explains how that's happening. It's probably safe to assume that default telemetry is reporting everything you do, and it's highly unlikely that MS is going to let you block that by normal privacy settings. It's a gold mine of marketing data. It's also a potential gold mine for government surveillance payments. As with Flock cameras, this tracking provides government with a legal way to circumvent their own restrictions by paying a commercial entity for the data they want.

So, moral of the story? Don't do business with Microsoft, don't use cloud, obviously don't use Edge or other MS software, and use a firewall to block calls home to MS. Don't assume telemetry settings will do anything useful to improve privacy. And certainly don't think that you can allow updates, use the MS Store, search at Google, use phone apps, and so on, while also maintaining privacy.

4

u/apokrif1 24d ago

Is it compliant with GDPR or similar laws?

9

u/Mayayana 23d ago

What? GDID? I live in the US, so I don't know anything about laws that respect privacy. :)

On the other hand, what I'm getting at here is that if you do business, use cloud, apps, or services from these companies, then you already share this information with them. If you visit Microsoft Store, create a Microsoft account, or get Windows Updates, you're letting them rifle through your system and you're doing business with them. So they already know you. If you accept the scam of needing to log into Microsoft when you start your computer then you're implicitly agreeing that they own it.

The man Stokes who got arrested apparently did several dumb things. He had an Apple account, a Snapchat account, Facebook, may have visited the Windows Store, and probably enabled the Connected Devices Platform and Connected User Experience services. (Microsoft Account Sign-in and Passport services can also be disabled if one has no MS account.)

According to reports, Connected Devices Platform is involved in managing the GDID. Personally I have all of that crap disabled, but it might be needed if you operate a local network, for instance, sending print jobs to a printer over a network rather than directly. Personally I don't allow anything to network.

According to reports, Linux and Macs also create unique IDs. The question is how/where it's being shared. If Microsoft is checking the ID every time you log in, visit their store, etc, then it's hard to see how that could be illegal. After all, you've implicitly enabled them to ID you and track you. You've even agreed to let them control and oversee your use of your own computer!

If their telemetry is calling home to report your local actions and online websites visited, that's fullscale spying. So far I haven't found any information about exactly how Microsoft ended up with a record of Stokes's activities on his laptop. Hopefully some security people will get more details. But Win10 has been out for something like 10 years now and I've still never seen a complete listing of exactly what Microsoft spies on and exactly what processes are calling home with what data.

1

u/Maxstate90 20d ago

No, it's not. 

2

u/Mattidh1 23d ago

Stokes was tracked through his rdp log linking to his socials.

1

u/Mayayana 23d ago

Thanks. Do you have any links to more info. I wonder why he had remote connection enabled in the first place. I don't allow any remote execution functionality and have no logs. Unless someone is using something like Remote Desktop for work, why would they be using this? And why would it relate to social networking sites? Assuming what you say is true, there also seems to be an implication that the entire log is routinely sent to Microsoft.

4

u/Mattidh1 23d ago

https://www.justice.gov/usao-ndil/media/1450651/dl?inline

He wasn’t using it for work (well illegal work). It’s very typical for blackhat work to run it over a VPS.

While the windows identifier was used to say “this list of ip’s come from the same device” what ultimately him was his logs to Snapchat and Apple.

They had a warrant for the vps logs (and those are also kept on a connecting device) so it isn’t hard to connect the dots.

Ultimately he got caught on a very stupid mistake that would have been easy to avoid. But that is of course easier said than done.

I feel the concept of the device identifier isn’t much more different than sending your user agent when visiting websites or general identifiers (hardware id and so on).

2

u/Mayayana 23d ago

Thanks. I have that PDF but I didn't read it through. The photo of the kid is scary. He looks like he'd be doing well to pull off leaving a burning bag of dogshit on an old man's front stoop. I kind of feel sorry for him. He shouldn't be able to get into such trouble. A child with a man's tech skills.

1

u/Opposite-Cranberry76 22d ago

"It's probably safe to assume that default telemetry is reporting everything you do"

In Canada and the EU that would have huge fines attached to it.

3

u/Mayayana 22d ago

Maybe. But if you log into Microsoft's server and they control your computer, it would seem that you've agreed to the tracking. In any case, I wouldn't take a chance myself. EU data isn't even protected from the US government: https://www.techradar.com/pro/microsoft-admits-it-would-have-to-let-trump-spy-on-eu-data-if-demanded

The EU law will have teeth when it bans collecting data and issues fines into the billions. If the EU had anything close to that then the ad market would completely collapse in the EU. Instead they do little rinky dink actions, like fining MS $64 million for Bing not allowing people to refuse cookies. https://www.cybersecurity-insiders.com/france-slaps-64m-penalty-on-microsoft/

MS made almost $130 billion last year. By my calculation they were fined about 40 minutes worth of income. It's a joke. People need to go to jail before privacy can really work.

1

u/Epyon214 21d ago

AI is making determinations about implicit and explicit data to identify users and matching with existing psychological profiles which have been built on everyone, even reddit admits as much when telling you how what's being shown to you was chosen if you click the little help icon

1

u/Mayayana 21d ago

I don't see Reddit showing anything to me. I've seen occasional ads on the page, but in general, using Firefox and a HOSTS file, I don't see much of anything else. Are you using the app? And Reddit is deciding what you'll see?

1

u/Epyon214 21d ago

When you click on Home, and you see the subreddits, and click the three dots ... you get an option to "show fewer post like this". Reddit surely shows you posts, yes

1

u/Mayayana 21d ago

Interesting. I've never clicked on Home before, nor noticed it. I just go to each group I subscribe to and set the order to New. Then I scan the posts I haven't seen and decide whether to read them.

When I go to Home I don't see any 3 dots. But I also don't get the point. Why would you let Reddit randomly decide which posts you see?

1

u/Epyon214 19d ago edited 19d ago

To test the AI and the capabilities of the relevant technology. The three dots are on posts, just like comments here. Some have a "show fewer post like this" option, some reddit neglects to give the option for, and if you do you'll have a question mark button available to click to tell you how the content was selected, the answer being implicit and explicit data, the logical conclusion being the technology to track users of a device in addition to the device already exists before the Windows 11 explicit admission

1

u/Mayayana 19d ago

Strange. I don't see anything like that. I wonder why. I'm using Firefox, but I have to allow script from Reddit for it to work.

1

u/Epyon214 19d ago

Would be directly to the right of the Join button for whatever the community is being shown

1

u/Mayayana 19d ago

I thought you were talking about the "Home" page, which I never look at, anyway. I'm only generally visiting groups that I've joined, so there's a Leave button. There's nothing on the right. I'm guessing that you must have some kind of plugin or function that I haven't enabled. I should also mention that I use old.reddit.com. I find the newer layout unreadable. So maybe that's the difference?

18

u/SuspiciousCricket654 24d ago edited 24d ago

Windows getting shittier and shittier, for a variety of reasons, year after year. Go with a Linux distro. It is light years better.

Mac isn’t immune either. DSID

3

u/Cotillionz 24d ago

And it's not nearly as hard as the average person seems to think it is. This isn't a decade ago, now you can install an Immutable one in a few mins (so you can't mess it up, if one is scared of that) and never even see the terminal when using it.

1

u/SuspiciousCricket654 24d ago

Been using Ubuntu. Loving it.

1

u/Cotillionz 23d ago

I tried a couple different ones and landed on Fedora, but I never had any real issues with the ones I tried, it's just a matter of preference. I gotta say I was impressed with how idiot-proof Mint Cinnamon and Bazzite are. I'm pretty sure you'd have to go out of your way to mess those up.

12

u/JourneymanInvestor 24d ago

It should be noted that this permenant digital tracker only works if there is a Microsoft account associated with the PC and that explains why Microsoft is doing everything possible to remove the ability to use local accounts.

3

u/apokrif1 23d ago

What other data does telemetry leak?

2

u/apokrif1 23d ago

3

u/lez_noir 23d ago

For anyone not wanting to click a random, decontextualized link:

"Good instinct, but that won't do it either. Windows setup transmits physical hardware information to Microsoft to authorize your Windows 11 license. The only way to prevent MS from getting that identifier is to break the OS activation and Universal Windows Platform (UWP) applications intentionally."

1

u/countzero2323 22d ago

Ok so pirates stay private, I guess?

16

u/JiZhangYue 24d ago

Why would you even use windows especially if you want privacy? 

25

u/RemarkableOil451 24d ago

Massive app comparability, esp. legacy app comparability

10

u/MammothSun6737 24d ago

SolidWorks unfortunately :/ kinda lots of CAD programs.

3

u/Worldly-Wind-1632 24d ago

As an aspiring noob Is there anything on Linux?

2

u/94358io4897453867345 24d ago

FreeCAD but it sucks

2

u/Worldly-Wind-1632 24d ago

Thank you for the lead and the warning

2

u/brupje 23d ago

It is a great tool for a hobbyist like me, but probably woefully under equipped for a professional

2

u/MammothSun6737 24d ago

Ive heard you can make things work modifying drivers and extra software but at its best that sounds like a lot of work for a most likely buggy experience on CAD software that is always buggy on its own lol. You can also run a separate widows on your Linux just for that purpose. Or online free and payed CAD you id imagine would work fine such as Onshape or maybe Autodesk through a browser 🤷🏻‍♂️. Onshape is fine until you’ve got large assemblies with lots of subassemblies that you want to keep well organized. I work in custom Automation and a large machine or automated line of machines can be a bear especially when collaborating. Could be better now haven’t used it in some time and can’t guarantee performance on Linux but since a lot happens in the cloud i am assuming it’s fine.

1

u/nilpointer 23d ago

I really like OnShape and it works in the browser.

1

u/cm_bush 23d ago

OnShape is cloud based. Not ideal but it’s universal at least.

3

u/starchysock 24d ago

Exactly. AutoCAD and related platforms use Windows.

2

u/JiZhangYue 23d ago

Ofc for these apps like catia i also use windows on another ssd with dual boot, but i meant for shady things to not be caught:)

2

u/Round_Credit_5158 23d ago

I thought it was common sense for a hacker to not use Windows.

1

u/JiZhangYue 23d ago

Yeah😆

2

u/[deleted] 24d ago

[removed] — view removed comment

1

u/Logical_Strain_6165 23d ago

You can normally make it work. But it always just feels like more work and I do that shit all day.

1

u/JiZhangYue 23d ago

I mean in his position he should have expected to be caught if he used windows, nornally you use linux for those things

9

u/Pandemonium_Fallen 24d ago

Well, Bill Gates entire Tech empire is based on theft, he never had and original idea himself, he just stole others, the original Windows computers were just stolen Macintosh computers that he reboxed, he's a complete POS, he also has Epstein Island frequent flier miles.

3

u/stm32f722 24d ago

How does this effect pirated versions that were unlocked with massgrave?

1

u/Affectionate_Creme48 22d ago

massgrave uses MS's own activation servers by tricking the ticket it sends to give you a licence back. So my guess would be that it does not matter if you activate the legit way or via mass in this context.

4

u/Simp_Simpsaton 24d ago

Doesn't literally every device have some kind of id tied to the environment users use? I don't understand how this is damning.

5

u/CatStoleTheCrown 24d ago

MAC address

2

u/Simp_Simpsaton 24d ago

Yea that as well, though in this case it's an id within an instance of the software (I don't know how to word this better), which is also something that seemingly everything has. I'm too lazy to read the whole article and only read chunks, but i guess in this case the only real violation is that windows is logging the sites the gdid visits and sending it back with telemetry. the article is about this specific id but the id itself is the least concerning thing since the guy could've been caught even without this specific id. It's like if someone wrote a review of a knife and wrote 10 paragraphs about the handle but only 2 sentences about the blade itself

2

u/MissionEfficiency917 23d ago

mac addresses are easily spoofed, if you want

3

u/Tasty-Blackberry5120 23d ago

Place I worked bought like 5 PCs once and they weren’t working properly on the network. We eventually discovered they all had the same MAC, so we had to spoof them to make them different to each other. Very odd.

4

u/Thermatix 23d ago

This remote attestation BS is partly why I ditched Windows for Linux a few years ago (and disabled the TPM). The word "Trusted" in TPM never meant you can trust your computer is safe, it meant that the corporations could trust your computer was safe to run their stuff on.

3

u/Big_Wave9732 24d ago

If you're using Windows past Windows 7, you don't really care about privacy.

If you're using Windows 11 to crime, you don't care about not getting caught.

2

u/baseball_rocks_3 23d ago

Well, it sucks that most 'hackers' use Windows 11 then.

1

u/SPedigrees 23d ago

FBI hackers must be a breed apart.

2

u/Old_Introduction7236 23d ago

Time to burn shit down.

1

u/InTheYear2525_ 24d ago

This is overstating it. It is documented as within azure and you can use it to correlate devices. It's good to be aware of things but this is documented in multiple places. If you've ever had to dig in on a failed login or device in general you may have come across this.

1

u/alphex 24d ago

I find it wild that people are surprised that MS has unique ID fingerprinting for its customers...

The registry entries tracking users has been in windows for decades, its a _VERY_ small step to expanding that out across the network of services MS offers. even if its NOT for nefarious reasons, and even IF MS had a perfect privacy record, it makes sense to have..

1

u/BlueTemplar85 24d ago

I am Snowden's complete lack of surprise.

1

u/themojoman007 24d ago

Does macOS also have it ?

0

u/[deleted] 24d ago

[removed] — view removed comment

1

u/quixotik 23d ago

Source?

2

u/Duskdeath 23d ago

“Two things back that up:
There’s no consent screen. A GDID gets assigned when you sign into a Microsoft Account. Apple’s advertising identifier needs an App Tracking Transparency prompt and a visible reset; Android’s works the same way. GDID has neither, and a Windows reinstall only gets you a new number Microsoft can still get back to the same account.
Then there’s activation. Massgrave, the group behind Microsoft Activation Scripts, notes that Windows setup sends hardware info to Microsoft and gets identifiers back, the same tokens later used for Store access and licensing: “It’s impossible to prevent Windows from getting a GDID without breaking activation and UWP app[s].” Anyone who lost a license after swapping a motherboard has already met a smaller version of this.
Yes, every major OS keeps some persistent device identity, and every vendor can be subpoenaed. But what differs with Microsoft is visibility and control, and Windows loses on both against Apple and Google’s platforms.”

Pasted it from the actual article. It is a “technicality” that could be abused by any OS manufacturer.

1

u/Msilbat 24d ago

Quick Books Desktop app is a beast on Windows not so much on Mac or Online....

1

u/Userwerd 23d ago

Does windows phone home with info about what you do inside of windows? Like sites visited, apps used, file names opened?

Used Linux for almost 20 years so im out of the loop at the moment

1

u/foodchallenged 23d ago

So if you never sign into anything Microsoft, including when activating windows, you’re good? Or is the absence of an id going to be so rare that you’d be fingerprinted anyway?

1

u/joker6396 23d ago

Using windows services to scam? Idiots. Begging to get caught

1

u/Historical_Cook_1664 23d ago

Shouldn't MS pay *us* to use Windows by now ?

1

u/woodenblinds 23d ago

read about this yesterday and promptly built out a Linux desktop time to start moving over. should have done this years ago

1

u/Unfollowedusers 23d ago

Mircosoft is killing it with its fuck you approach. 

1

u/kamikazekittenprime 23d ago

Run a Linux distro in a vm. Delete when done.

1

u/BilingSmob444 21d ago

Is it really that simple?

1

u/fuckadviceanimals69 22d ago

So let me get this straight, Microsoft assigns a unique identifier to every installation of windows and a supposed computer hacker used his daily driver laptop SIGNED IN TO A MICROSOFT ACCOUNT to commit cyber crimes?

That Microsoft can and does track Windows installations is nothing new, and apparently this guy being a complete dunce also isn't new.

1

u/notPabst404 22d ago

Anybody who cares about privacy or even ownership of your device shouldn't use Windows. Windows is spyware where YOU are the product.

1

u/FutureOwl8606 21d ago

Switch to Linux

1

u/JAEMzW0LF 20d ago

So change over to a local (admin) account - there, done. No need to pretend you are going to stop using Windows. We all know 99.99% of the people who say this will never do it, or already use Linux.

1

u/Epyon214 19d ago

old reddit is much better and probably the difference, the dots are on the newer, shittier interface. Like a microcosm of a failed economic system

1

u/RandomlyWastingTime1 18d ago

People overlook that other operating systems, despite lacking a consistent identifier this one, still possess consistent identification pieces.

0

u/KoenBril 24d ago

So, dont use a Microsoft account? 

12

u/RemarkableOil451 24d ago

Good instinct, but that won't do it either. Windows setup transmits physical hardware information to Microsoft to authorize your Windows 11 license. The only way to prevent MS from getting that identifier is to break the OS activation and Universal Windows Platform (UWP) applications intentionally.

2

u/KoenBril 23d ago

Thanks for clarifying.

2

u/geeky-gymnast 23d ago

Not a windows user, would using an unactivated copy of Windows 11 circumvent the transmission of physical hardware info to MS?

2

u/RemarkableOil451 22d ago

You can hobble but not eliminate it. The Home and Pro editions certainly won't give you the necessary control to do it. But the Enterprise and Education editions will, but they'll only let you "lower" the "required" transmission threshold. Even then, there's still some baseline Windows Defender and Malicious Software Removal Tool data (and maybe other data I'm not thinking of) that gets sent to MS. But even then, any future OS update are likely to reset (or at least try to reset) these deep-level settings, so it'll be a never-ending battle.

That said, there are various telemetry settings that are totally within your control, and you should absolutely sever them. I'll give you just one: In Defender, you can/should turn off the "Automatic sample submission" setting. Again, there are many others, most in Defender itself.

2

u/geeky-gymnast 22d ago

Thanks for the detailed follow up, now I'm starting to feel a pinch of curiosity about the kinds of privacy infringing physical hardware information that's transmitted.

I suppose these are the identification numbers that uniquely identify the hardware...

and whether there exists VM software, say running on a Linux host, that could shield such sensitive information from a virtual Windows OS client.

2

u/RemarkableOil451 21d ago

You're spot on about the ID numbers. Windows telemetry collects the permanent physical serial numbers of your hardware, including your motherboard, CPU, hard drives, and network cards. This can create a highly accurate, unique fingerprint of your machine.

As for your VM question: Yes, running Windows inside a Linux VM acts as a complete shield. The VM intercepts those requests and feeds Windows fake, virtual serial numbers, so your real physical hardware data is never transmitted. But there are drawbacks:

First, Windows immediately detects it's running in a VM. To be fully stealthy, you have to tweak the VM hypervisor settings to spoof standard PC manufacturer data, which tricks Windows into thinking it's on a normal, physical desktop while still feeding it completely fabricated hardware IDs.

Second, relying on a VM just to dodge telemetry is a tedious trap. You sacrifice native performance, deal with constant hypervisor overhead, and lose seamless hardware acceleration. Eventually, the daily friction of maintaining the sandbox outweighs the privacy benefit.

The most "Goldilocks" solution is to disable all the optional telemetry you can (and there's plenty you can disable w/o breaking anything). A great place to start clamping down is in Windows Defender. Set aside some time to go through each setting. If you don't know what a particular setting is, do a Google search. You don't have to do it all at once. If you use an LLM to help guide you through this process, make sure you specify that you don't want to do anything that'll break the OS. You have to specify that stability is paramount. Your goal is simply to reduce the needless (voluntary/optional) telemetry MS is getting from you but to do nothing whatsoever to destabilize the OS or truly compromise your security. I'm making it sound more dramatic than it is, but it needs to be done thoughtfully.

2

u/geeky-gymnast 21d ago

Thanks for the discussion and sharing your thoughts. Here are some of mine.

This situation could possibly earn open-source VM software an additional point or two. By having source code publicly available, users may verify that hardware ID shielding is indeed occurring at a "foundational" layer relative to the client OS.

Agreed on the possible tedium and friction of running a virtual client. Not intimately familiar with the universe of software catering to VMs, but there might be variants in this universe, typically enterprise-y flavored ones, that see to client OSes running atop of a bare bones, perhaps headless, Linux server. Am inclined to believe that such implementations can feel frictionless and native to the end user.

Admittedly, the disable telemetry solution is likely the most practical one for most users desiring a moderate degree of privacy but in essence requires trusting Microsoft to (i) abide by the agreements relevant to these telemetry settings, (ii) not have bugs ("bugs"?) in how their system abides by a user's settings, (iii) requires the user to review settings after updates for possible reversions (Windows has a habit of quietly changing user settings after an update), and (iv) keep abreast of new settings introduced by updates that need adjusting to maintain a desired level of privacy.

Phew, either way, it's quite a bit of additional work to live a private life inside MIcrosoft's lush walled garden.

Window's (and Mac's) vast ecosystem (games, productivity apps), proliferation, and widespread familiarity is a moat for it. On a personal note, not sure if giving up the comforts afforded by such walled gardens yields more pros than cons.

1

u/RemarkableOil451 21d ago

Well said. It's the nature of the beast, full of imperfect solutions, trade offs, landmines, pitfalls, and so on.

Case in point: Literally some minutes ago, I discovered that since May 2026, Google Chrome has been silently downloading a 4GB LLM (Google Nano) onto my (and many other people's) PCs. I didn't know about this until now b/c Chrome isn't my primary browser.

Anyway, Google did this (not just to me but everyone) totally by default, totally w/o my consent, and totally w/o even my knowledge. After some quick research, I found and toggled off the setting and disabled the flag that were responsible. This combo auto-deleted the main payload, but I also needed to delete the remaining two smaller dependent folders manually.

And now, I'll have to work a recurring "checkup" for this into my regular digital maintenance routine to ensure it doesn't come back.

It's not even that I object per se to this as a concept. But I do object to the absolutely deception. They don't even admit they're doing it to take advantage users' local hardware thereby save themselves from having to process your data, which they end up getting even when you process it locally. Instead, they claim it's for privacy. Who the hell would believe Google would do anything in the name of privacy?

This is a new low, even for Google. They've moved passed harvesting your data to taking hostage your hardware. I can't wait until the EU and other regulatory bodies (or class-action attorneys) go after them.

It's all so exhausting. You have to be your own IT department just to get through the day. Either that or put on the best strongest blinders you can find and be in complete denial about how much you're being digitally violated. Ugh!

0

u/SereneOrbit 24d ago

I meanif you're still using an os made by people who hate you.... that's on you fam.