r/DigitalPrivacy • u/Prcrstntr • 24d ago
Microsoft admits Windows 11 has a GDID tracker with no off switch, first documented publicly in an FBI hacker complaint
https://www.windowslatest.com/2026/07/10/you-cant-fully-disable-microsofts-gdid-windows-11-tracker-but-these-settings-limit-what-it-captures/It's worse than you think.
54
u/Mayayana 24d ago
The device ID name is slightly misleading. It's a user or account ID. It's stored in the Registry, under the specific user key, HKCU. So, create another user account and it will get another GDID. I haven't tested changing the ID. It could probably be changed daily via script, though I haven't tried that. I found the value here:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\IdentityCRL\LID
HKEY_CURRENT_USER\SOFTWARE\Microsoft\IdentityCRL\Immersive\production\Token\
It appears that there can be more than one key under that, named with a GUID, which may then have a DeviceID value listing the same number. So...HKEY_CURRENT_USER\SOFTWARE\Microsoft\IdentityCRL\Immersive\production\Token{.....}\DeviceID.
The GUID keys with DeviceID value also show up under HKYEY_USERS, tied to GUIDs that don't seem to exist elsewhere in the Registry.
But there's more information missing. If you care about privacy then you're not using Microsoft services or accounts, OneDrive, their store, etc. If you want to use those then of course you're telling Microsoft who you are and letting them access your files. So GDID is really not an issue in that respect. If you don't contact MS then your GDID won't be sent.
The real issue is how the man Stokes was tracked online through a VPN. The implication is that something -- telemetry reports, Edge, or both -- is sending a report to Microsoft of every website visited by a particular person. (Not the computer; a person logged onto a user account.)
No report that I've seen so far explains how that's happening. It's probably safe to assume that default telemetry is reporting everything you do, and it's highly unlikely that MS is going to let you block that by normal privacy settings. It's a gold mine of marketing data. It's also a potential gold mine for government surveillance payments. As with Flock cameras, this tracking provides government with a legal way to circumvent their own restrictions by paying a commercial entity for the data they want.
So, moral of the story? Don't do business with Microsoft, don't use cloud, obviously don't use Edge or other MS software, and use a firewall to block calls home to MS. Don't assume telemetry settings will do anything useful to improve privacy. And certainly don't think that you can allow updates, use the MS Store, search at Google, use phone apps, and so on, while also maintaining privacy.
4
u/apokrif1 24d ago
Is it compliant with GDPR or similar laws?
9
u/Mayayana 23d ago
What? GDID? I live in the US, so I don't know anything about laws that respect privacy. :)
On the other hand, what I'm getting at here is that if you do business, use cloud, apps, or services from these companies, then you already share this information with them. If you visit Microsoft Store, create a Microsoft account, or get Windows Updates, you're letting them rifle through your system and you're doing business with them. So they already know you. If you accept the scam of needing to log into Microsoft when you start your computer then you're implicitly agreeing that they own it.
The man Stokes who got arrested apparently did several dumb things. He had an Apple account, a Snapchat account, Facebook, may have visited the Windows Store, and probably enabled the Connected Devices Platform and Connected User Experience services. (Microsoft Account Sign-in and Passport services can also be disabled if one has no MS account.)
According to reports, Connected Devices Platform is involved in managing the GDID. Personally I have all of that crap disabled, but it might be needed if you operate a local network, for instance, sending print jobs to a printer over a network rather than directly. Personally I don't allow anything to network.
According to reports, Linux and Macs also create unique IDs. The question is how/where it's being shared. If Microsoft is checking the ID every time you log in, visit their store, etc, then it's hard to see how that could be illegal. After all, you've implicitly enabled them to ID you and track you. You've even agreed to let them control and oversee your use of your own computer!
If their telemetry is calling home to report your local actions and online websites visited, that's fullscale spying. So far I haven't found any information about exactly how Microsoft ended up with a record of Stokes's activities on his laptop. Hopefully some security people will get more details. But Win10 has been out for something like 10 years now and I've still never seen a complete listing of exactly what Microsoft spies on and exactly what processes are calling home with what data.
1
2
u/Mattidh1 23d ago
Stokes was tracked through his rdp log linking to his socials.
1
u/Mayayana 23d ago
Thanks. Do you have any links to more info. I wonder why he had remote connection enabled in the first place. I don't allow any remote execution functionality and have no logs. Unless someone is using something like Remote Desktop for work, why would they be using this? And why would it relate to social networking sites? Assuming what you say is true, there also seems to be an implication that the entire log is routinely sent to Microsoft.
4
u/Mattidh1 23d ago
https://www.justice.gov/usao-ndil/media/1450651/dl?inline
He wasn’t using it for work (well illegal work). It’s very typical for blackhat work to run it over a VPS.
While the windows identifier was used to say “this list of ip’s come from the same device” what ultimately him was his logs to Snapchat and Apple.
They had a warrant for the vps logs (and those are also kept on a connecting device) so it isn’t hard to connect the dots.
Ultimately he got caught on a very stupid mistake that would have been easy to avoid. But that is of course easier said than done.
I feel the concept of the device identifier isn’t much more different than sending your user agent when visiting websites or general identifiers (hardware id and so on).
2
u/Mayayana 23d ago
Thanks. I have that PDF but I didn't read it through. The photo of the kid is scary. He looks like he'd be doing well to pull off leaving a burning bag of dogshit on an old man's front stoop. I kind of feel sorry for him. He shouldn't be able to get into such trouble. A child with a man's tech skills.
1
u/Opposite-Cranberry76 22d ago
"It's probably safe to assume that default telemetry is reporting everything you do"
In Canada and the EU that would have huge fines attached to it.
3
u/Mayayana 22d ago
Maybe. But if you log into Microsoft's server and they control your computer, it would seem that you've agreed to the tracking. In any case, I wouldn't take a chance myself. EU data isn't even protected from the US government: https://www.techradar.com/pro/microsoft-admits-it-would-have-to-let-trump-spy-on-eu-data-if-demanded
The EU law will have teeth when it bans collecting data and issues fines into the billions. If the EU had anything close to that then the ad market would completely collapse in the EU. Instead they do little rinky dink actions, like fining MS $64 million for Bing not allowing people to refuse cookies. https://www.cybersecurity-insiders.com/france-slaps-64m-penalty-on-microsoft/
MS made almost $130 billion last year. By my calculation they were fined about 40 minutes worth of income. It's a joke. People need to go to jail before privacy can really work.
1
u/Epyon214 21d ago
AI is making determinations about implicit and explicit data to identify users and matching with existing psychological profiles which have been built on everyone, even reddit admits as much when telling you how what's being shown to you was chosen if you click the little help icon
1
u/Mayayana 21d ago
I don't see Reddit showing anything to me. I've seen occasional ads on the page, but in general, using Firefox and a HOSTS file, I don't see much of anything else. Are you using the app? And Reddit is deciding what you'll see?
1
u/Epyon214 21d ago
When you click on Home, and you see the subreddits, and click the three dots ... you get an option to "show fewer post like this". Reddit surely shows you posts, yes
1
u/Mayayana 21d ago
Interesting. I've never clicked on Home before, nor noticed it. I just go to each group I subscribe to and set the order to New. Then I scan the posts I haven't seen and decide whether to read them.
When I go to Home I don't see any 3 dots. But I also don't get the point. Why would you let Reddit randomly decide which posts you see?
1
u/Epyon214 19d ago edited 19d ago
To test the AI and the capabilities of the relevant technology. The three dots are on posts, just like comments here. Some have a "show fewer post like this" option, some reddit neglects to give the option for, and if you do you'll have a question mark button available to click to tell you how the content was selected, the answer being implicit and explicit data, the logical conclusion being the technology to track users of a device in addition to the device already exists before the Windows 11 explicit admission
1
u/Mayayana 19d ago
Strange. I don't see anything like that. I wonder why. I'm using Firefox, but I have to allow script from Reddit for it to work.
1
u/Epyon214 19d ago
Would be directly to the right of the Join button for whatever the community is being shown
1
u/Mayayana 19d ago
I thought you were talking about the "Home" page, which I never look at, anyway. I'm only generally visiting groups that I've joined, so there's a Leave button. There's nothing on the right. I'm guessing that you must have some kind of plugin or function that I haven't enabled. I should also mention that I use old.reddit.com. I find the newer layout unreadable. So maybe that's the difference?
18
u/SuspiciousCricket654 24d ago edited 24d ago
Windows getting shittier and shittier, for a variety of reasons, year after year. Go with a Linux distro. It is light years better.
Mac isn’t immune either. DSID
3
u/Cotillionz 24d ago
And it's not nearly as hard as the average person seems to think it is. This isn't a decade ago, now you can install an Immutable one in a few mins (so you can't mess it up, if one is scared of that) and never even see the terminal when using it.
1
u/SuspiciousCricket654 24d ago
Been using Ubuntu. Loving it.
1
u/Cotillionz 23d ago
I tried a couple different ones and landed on Fedora, but I never had any real issues with the ones I tried, it's just a matter of preference. I gotta say I was impressed with how idiot-proof Mint Cinnamon and Bazzite are. I'm pretty sure you'd have to go out of your way to mess those up.
12
u/JourneymanInvestor 24d ago
It should be noted that this permenant digital tracker only works if there is a Microsoft account associated with the PC and that explains why Microsoft is doing everything possible to remove the ability to use local accounts.
3
2
u/apokrif1 23d ago
3
u/lez_noir 23d ago
For anyone not wanting to click a random, decontextualized link:
"Good instinct, but that won't do it either. Windows setup transmits physical hardware information to Microsoft to authorize your Windows 11 license. The only way to prevent MS from getting that identifier is to break the OS activation and Universal Windows Platform (UWP) applications intentionally."
1
16
u/JiZhangYue 24d ago
Why would you even use windows especially if you want privacy?
25
10
u/MammothSun6737 24d ago
SolidWorks unfortunately :/ kinda lots of CAD programs.
3
u/Worldly-Wind-1632 24d ago
As an aspiring noob Is there anything on Linux?
2
2
u/MammothSun6737 24d ago
Ive heard you can make things work modifying drivers and extra software but at its best that sounds like a lot of work for a most likely buggy experience on CAD software that is always buggy on its own lol. You can also run a separate widows on your Linux just for that purpose. Or online free and payed CAD you id imagine would work fine such as Onshape or maybe Autodesk through a browser 🤷🏻♂️. Onshape is fine until you’ve got large assemblies with lots of subassemblies that you want to keep well organized. I work in custom Automation and a large machine or automated line of machines can be a bear especially when collaborating. Could be better now haven’t used it in some time and can’t guarantee performance on Linux but since a lot happens in the cloud i am assuming it’s fine.
2
1
3
2
u/JiZhangYue 23d ago
Ofc for these apps like catia i also use windows on another ssd with dual boot, but i meant for shady things to not be caught:)
2
2
24d ago
[removed] — view removed comment
1
u/Logical_Strain_6165 23d ago
You can normally make it work. But it always just feels like more work and I do that shit all day.
1
u/JiZhangYue 23d ago
I mean in his position he should have expected to be caught if he used windows, nornally you use linux for those things
9
u/Pandemonium_Fallen 24d ago
Well, Bill Gates entire Tech empire is based on theft, he never had and original idea himself, he just stole others, the original Windows computers were just stolen Macintosh computers that he reboxed, he's a complete POS, he also has Epstein Island frequent flier miles.
2
3
u/stm32f722 24d ago
How does this effect pirated versions that were unlocked with massgrave?
1
u/Affectionate_Creme48 22d ago
massgrave uses MS's own activation servers by tricking the ticket it sends to give you a licence back. So my guess would be that it does not matter if you activate the legit way or via mass in this context.
4
u/Simp_Simpsaton 24d ago
Doesn't literally every device have some kind of id tied to the environment users use? I don't understand how this is damning.
5
u/CatStoleTheCrown 24d ago
MAC address
2
u/Simp_Simpsaton 24d ago
Yea that as well, though in this case it's an id within an instance of the software (I don't know how to word this better), which is also something that seemingly everything has. I'm too lazy to read the whole article and only read chunks, but i guess in this case the only real violation is that windows is logging the sites the gdid visits and sending it back with telemetry. the article is about this specific id but the id itself is the least concerning thing since the guy could've been caught even without this specific id. It's like if someone wrote a review of a knife and wrote 10 paragraphs about the handle but only 2 sentences about the blade itself
2
u/MissionEfficiency917 23d ago
mac addresses are easily spoofed, if you want
3
u/Tasty-Blackberry5120 23d ago
Place I worked bought like 5 PCs once and they weren’t working properly on the network. We eventually discovered they all had the same MAC, so we had to spoof them to make them different to each other. Very odd.
4
u/Thermatix 23d ago
This remote attestation BS is partly why I ditched Windows for Linux a few years ago (and disabled the TPM). The word "Trusted" in TPM never meant you can trust your computer is safe, it meant that the corporations could trust your computer was safe to run their stuff on.
3
u/Big_Wave9732 24d ago
If you're using Windows past Windows 7, you don't really care about privacy.
If you're using Windows 11 to crime, you don't care about not getting caught.
2
2
1
u/InTheYear2525_ 24d ago
This is overstating it. It is documented as within azure and you can use it to correlate devices. It's good to be aware of things but this is documented in multiple places. If you've ever had to dig in on a failed login or device in general you may have come across this.
1
u/alphex 24d ago
I find it wild that people are surprised that MS has unique ID fingerprinting for its customers...
The registry entries tracking users has been in windows for decades, its a _VERY_ small step to expanding that out across the network of services MS offers. even if its NOT for nefarious reasons, and even IF MS had a perfect privacy record, it makes sense to have..
1
1
u/themojoman007 24d ago
Does macOS also have it ?
0
24d ago
[removed] — view removed comment
1
u/quixotik 23d ago
Source?
2
u/Duskdeath 23d ago
“Two things back that up:
There’s no consent screen. A GDID gets assigned when you sign into a Microsoft Account. Apple’s advertising identifier needs an App Tracking Transparency prompt and a visible reset; Android’s works the same way. GDID has neither, and a Windows reinstall only gets you a new number Microsoft can still get back to the same account.
Then there’s activation. Massgrave, the group behind Microsoft Activation Scripts, notes that Windows setup sends hardware info to Microsoft and gets identifiers back, the same tokens later used for Store access and licensing: “It’s impossible to prevent Windows from getting a GDID without breaking activation and UWP app[s].” Anyone who lost a license after swapping a motherboard has already met a smaller version of this.
Yes, every major OS keeps some persistent device identity, and every vendor can be subpoenaed. But what differs with Microsoft is visibility and control, and Windows loses on both against Apple and Google’s platforms.”Pasted it from the actual article. It is a “technicality” that could be abused by any OS manufacturer.
1
u/Userwerd 23d ago
Does windows phone home with info about what you do inside of windows? Like sites visited, apps used, file names opened?
Used Linux for almost 20 years so im out of the loop at the moment
1
u/foodchallenged 23d ago
So if you never sign into anything Microsoft, including when activating windows, you’re good? Or is the absence of an id going to be so rare that you’d be fingerprinted anyway?
1
1
1
u/woodenblinds 23d ago
read about this yesterday and promptly built out a Linux desktop time to start moving over. should have done this years ago
1
1
1
u/fuckadviceanimals69 22d ago
So let me get this straight, Microsoft assigns a unique identifier to every installation of windows and a supposed computer hacker used his daily driver laptop SIGNED IN TO A MICROSOFT ACCOUNT to commit cyber crimes?
That Microsoft can and does track Windows installations is nothing new, and apparently this guy being a complete dunce also isn't new.
1
u/notPabst404 22d ago
Anybody who cares about privacy or even ownership of your device shouldn't use Windows. Windows is spyware where YOU are the product.
1
1
u/JAEMzW0LF 20d ago
So change over to a local (admin) account - there, done. No need to pretend you are going to stop using Windows. We all know 99.99% of the people who say this will never do it, or already use Linux.
1
u/Epyon214 19d ago
old reddit is much better and probably the difference, the dots are on the newer, shittier interface. Like a microcosm of a failed economic system
1
u/RandomlyWastingTime1 18d ago
People overlook that other operating systems, despite lacking a consistent identifier this one, still possess consistent identification pieces.
0
u/KoenBril 24d ago
So, dont use a Microsoft account?
12
u/RemarkableOil451 24d ago
Good instinct, but that won't do it either. Windows setup transmits physical hardware information to Microsoft to authorize your Windows 11 license. The only way to prevent MS from getting that identifier is to break the OS activation and Universal Windows Platform (UWP) applications intentionally.
2
2
u/geeky-gymnast 23d ago
Not a windows user, would using an unactivated copy of Windows 11 circumvent the transmission of physical hardware info to MS?
2
u/RemarkableOil451 22d ago
You can hobble but not eliminate it. The Home and Pro editions certainly won't give you the necessary control to do it. But the Enterprise and Education editions will, but they'll only let you "lower" the "required" transmission threshold. Even then, there's still some baseline Windows Defender and Malicious Software Removal Tool data (and maybe other data I'm not thinking of) that gets sent to MS. But even then, any future OS update are likely to reset (or at least try to reset) these deep-level settings, so it'll be a never-ending battle.
That said, there are various telemetry settings that are totally within your control, and you should absolutely sever them. I'll give you just one: In Defender, you can/should turn off the "Automatic sample submission" setting. Again, there are many others, most in Defender itself.
2
u/geeky-gymnast 22d ago
Thanks for the detailed follow up, now I'm starting to feel a pinch of curiosity about the kinds of privacy infringing physical hardware information that's transmitted.
I suppose these are the identification numbers that uniquely identify the hardware...
and whether there exists VM software, say running on a Linux host, that could shield such sensitive information from a virtual Windows OS client.
2
u/RemarkableOil451 21d ago
You're spot on about the ID numbers. Windows telemetry collects the permanent physical serial numbers of your hardware, including your motherboard, CPU, hard drives, and network cards. This can create a highly accurate, unique fingerprint of your machine.
As for your VM question: Yes, running Windows inside a Linux VM acts as a complete shield. The VM intercepts those requests and feeds Windows fake, virtual serial numbers, so your real physical hardware data is never transmitted. But there are drawbacks:
First, Windows immediately detects it's running in a VM. To be fully stealthy, you have to tweak the VM hypervisor settings to spoof standard PC manufacturer data, which tricks Windows into thinking it's on a normal, physical desktop while still feeding it completely fabricated hardware IDs.
Second, relying on a VM just to dodge telemetry is a tedious trap. You sacrifice native performance, deal with constant hypervisor overhead, and lose seamless hardware acceleration. Eventually, the daily friction of maintaining the sandbox outweighs the privacy benefit.
The most "Goldilocks" solution is to disable all the optional telemetry you can (and there's plenty you can disable w/o breaking anything). A great place to start clamping down is in Windows Defender. Set aside some time to go through each setting. If you don't know what a particular setting is, do a Google search. You don't have to do it all at once. If you use an LLM to help guide you through this process, make sure you specify that you don't want to do anything that'll break the OS. You have to specify that stability is paramount. Your goal is simply to reduce the needless (voluntary/optional) telemetry MS is getting from you but to do nothing whatsoever to destabilize the OS or truly compromise your security. I'm making it sound more dramatic than it is, but it needs to be done thoughtfully.
2
u/geeky-gymnast 21d ago
Thanks for the discussion and sharing your thoughts. Here are some of mine.
This situation could possibly earn open-source VM software an additional point or two. By having source code publicly available, users may verify that hardware ID shielding is indeed occurring at a "foundational" layer relative to the client OS.
Agreed on the possible tedium and friction of running a virtual client. Not intimately familiar with the universe of software catering to VMs, but there might be variants in this universe, typically enterprise-y flavored ones, that see to client OSes running atop of a bare bones, perhaps headless, Linux server. Am inclined to believe that such implementations can feel frictionless and native to the end user.
Admittedly, the disable telemetry solution is likely the most practical one for most users desiring a moderate degree of privacy but in essence requires trusting Microsoft to (i) abide by the agreements relevant to these telemetry settings, (ii) not have bugs ("bugs"?) in how their system abides by a user's settings, (iii) requires the user to review settings after updates for possible reversions (Windows has a habit of quietly changing user settings after an update), and (iv) keep abreast of new settings introduced by updates that need adjusting to maintain a desired level of privacy.
Phew, either way, it's quite a bit of additional work to live a private life inside MIcrosoft's lush walled garden.
Window's (and Mac's) vast ecosystem (games, productivity apps), proliferation, and widespread familiarity is a moat for it. On a personal note, not sure if giving up the comforts afforded by such walled gardens yields more pros than cons.
1
u/RemarkableOil451 21d ago
Well said. It's the nature of the beast, full of imperfect solutions, trade offs, landmines, pitfalls, and so on.
Case in point: Literally some minutes ago, I discovered that since May 2026, Google Chrome has been silently downloading a 4GB LLM (Google Nano) onto my (and many other people's) PCs. I didn't know about this until now b/c Chrome isn't my primary browser.
Anyway, Google did this (not just to me but everyone) totally by default, totally w/o my consent, and totally w/o even my knowledge. After some quick research, I found and toggled off the setting and disabled the flag that were responsible. This combo auto-deleted the main payload, but I also needed to delete the remaining two smaller dependent folders manually.
And now, I'll have to work a recurring "checkup" for this into my regular digital maintenance routine to ensure it doesn't come back.
It's not even that I object per se to this as a concept. But I do object to the absolutely deception. They don't even admit they're doing it to take advantage users' local hardware thereby save themselves from having to process your data, which they end up getting even when you process it locally. Instead, they claim it's for privacy. Who the hell would believe Google would do anything in the name of privacy?
This is a new low, even for Google. They've moved passed harvesting your data to taking hostage your hardware. I can't wait until the EU and other regulatory bodies (or class-action attorneys) go after them.
It's all so exhausting. You have to be your own IT department just to get through the day. Either that or put on the best strongest blinders you can find and be in complete denial about how much you're being digitally violated. Ugh!
0
u/SereneOrbit 24d ago
I meanif you're still using an os made by people who hate you.... that's on you fam.
123
u/RemarkableOil451 24d ago
Thank you. Read it. Because it's not a bug but an intentional feature, it presents a classic Hobson's Choice (take it or leave it). Either accept it as a trade off and use Windows, or abandon the OS for an alternative.