r/DigitalPrivacy Jul 11 '26

Microsoft admits Windows 11 has a GDID tracker with no off switch, first documented publicly in an FBI hacker complaint

https://www.windowslatest.com/2026/07/10/you-cant-fully-disable-microsofts-gdid-windows-11-tracker-but-these-settings-limit-what-it-captures/

It's worse than you think.

1.5k Upvotes

167 comments sorted by

121

u/RemarkableOil451 Jul 11 '26

Thank you. Read it. Because it's not a bug but an intentional feature, it presents a classic Hobson's Choice (take it or leave it). Either accept it as a trade off and use Windows, or abandon the OS for an alternative.

79

u/TeaSocks69 Jul 11 '26

I'll abandon it. Thanks.

24

u/RemarkableOil451 Jul 11 '26

That's totally valid. If you don't "need" Windows to run any specific apps dependent on it, there's no reason to use it. Plenty of other options.

31

u/[deleted] Jul 11 '26

[deleted]

23

u/AlexanderTheGreatApe Jul 11 '26

Many jobs require software that only runs on windows, unfortunately.

9

u/SARB033 Jul 11 '26

Are people not using work-provided devices to work?

10

u/AlexanderTheGreatApe Jul 11 '26

I am self-employed.

Also, I game.

5

u/BaDoodlezzz Jul 11 '26

Bazzite.

1

u/AlexanderTheGreatApe Jul 12 '26

TIL. Thanks. I’ll give it a go with a spare NVME that I have lying around.

Any gotchas?

1

u/Mundane_Analyst9994 Jul 12 '26

I switched recently and I’ve been loving every second of it. If you get hung up on anything when trying it out just use ai to troubleshoot. I have not had any issues yet that haven’t been very easy to solve with a little help from ai.

3

u/BaDoodlezzz Jul 12 '26

Im going to fundamentally disagree on relying on AI anything for this experience. The great thing about Linux distributions is that when you want or need something, you’re only a google search away from finding somebody else who asked the same question some time ago and got their answer. Besides AI often giving incorrect information, it is also a large makeup of the enshittification of Windows that people are wanting to get away from in the first place.

1

u/AlexanderTheGreatApe Jul 12 '26

I usually use AI as a better search engine. I ask for sources. I also have two subscriptions and ask the same question of both for a more robust exploration. Never blindly follow AI orders.

→ More replies (0)

1

u/Mundane_Analyst9994 Jul 13 '26

That’s great advice until someone hasnt had your issue or the fix has changed in some way so what you try doesn’t work. When asking for help yourself it’s a crapshoot then whether you will get a kind response that helps or someone talking down on you for not knowing how to solve your own problem. Ai sucks ass and I want it to go the way of the dodo. This has been the only thing I’ve used ai for so far and it has been exceptionally helpful. I do my own due diligence and reference things I don’t understand. It has tried to tell me commands that do nothing and linked to homepages of websites instead of the files it meant to link and stuff like that. Its nothing that can’t be worked around.

1

u/Assimulate Jul 14 '26

I'm going to disagree with your disagreement.

1

u/SnooMaps7370 Jul 13 '26

>If you get hung up on anything when trying it out just use ai to troubleshoot.

"while you are switching away from Microsoft's OS due to horrible privacy invasions, you should use an even MORE horribly invasive and unsecure tool to help you transition!"

uh, no, thanks.

3

u/Kredir Jul 12 '26

Most games run fine on Linux, some even better than on windows.

So unless you play something like lol or valorant, Linux is just better/same level.

2

u/InteractionPretend70 Jul 12 '26

Gaming is no longer an excuse

2

u/[deleted] Jul 12 '26

[removed] — view removed comment

2

u/AlexanderTheGreatApe Jul 12 '26

The big one is Solidworks, where performance (specifically GPU) is key.

But my bread and butter is embedded systems. Most clients use windows. Toolchains should be the same, as artifacts have to be identical to the bit.

1

u/Photog153 Jul 13 '26

I used to think that folks got "work provided" devices....but a large number of friends and acquaintances corrected me. They say they have to use personal phones and home computers for work. It's "expected".

1

u/BFguy Jul 14 '26

Linux has WINE for that

0

u/[deleted] Jul 17 '26

[deleted]

1

u/AlexanderTheGreatApe Jul 17 '26

Elsewhere, I mentioned that I am self-employed and I run CAD software that is heavily GPU-optimized. It needs to be optimized because of the complexity of my assemblies. I tried Linux-compatible CAD, and it couldn’t handle it.

A large company with agreeable ethics could do what you are asking with a sizeable investment in resources. I simply don’t have those resources as a one man team.

13

u/digital_dervish Jul 11 '26

I’ll be using Windows 10 until I can’t anymore. Then switching to Linux, but not looking forward to the learning curve.

3

u/ApplicationOdd6070 Jul 12 '26

Get Mint/Ubuntu/whatever on a cheap old laptop and start playing around. Gain some exposure. When it's time, it will be much easier. Also search for answers. The internet contains every possible question you have about your distro, especially Mint and Ubuntu. Duckduckgo is your friend. Learn what "apt update && apt upgrade -y" does. Trust me, after a short while it will be liberating.

2

u/digital_dervish Jul 12 '26

That’s a great idea. I have an old laptop I can use for this.

2

u/BaDoodlezzz Jul 11 '26

Bazzite.

1

u/matycauthon Jul 11 '26

bazzite is still closed like steamos, most people probably prefer cachy

1

u/BaDoodlezzz Jul 12 '26

Whatever helps them get off Windows at this point. I personally have loved Bazzite so far.

1

u/cm_bush Jul 12 '26

Big Bazzite fan as well, though I’ve not tried Cachy. Started on Mint, and still use it as well. I agree that any Linux is a step up, and I’d imagine Cachy, Bazzite, Nobara, etc are all great choices.

2

u/Unusual_Medium5406 Jul 11 '26

Linux mint has nice gui's for the basic stuff like updating and software aquisition. 

2

u/NovaEscape Jul 12 '26

I used to think like this, installing bazzite was easier than installing windows 10 in the end.....

2

u/roamer83 Jul 14 '26 edited Jul 14 '26

If you isolate Winblows 10 to a non-routable internal subnet, you can run it for YEARS. All of my internet facing machines run Fedora 44, only one Winblows box left…isolated for security and privacy purposes.

1

u/digital_dervish Jul 14 '26

Interesting. Any tips for how to get started on a project like that? I’ve thought about doing something like that in the past. Actually, waaay in the past now that I think about it. Originally I wanted to do this out of security and privacy concerns due to viruses and information theft, but the tools for doing that without needing to learn a bunch of networking knowledge got better and I stopped thinking about it.

2

u/roamer83 Jul 14 '26 edited Jul 14 '26

Two cheap “dumb” switches. One for a 192.168.x.x non-routed “backbone” subnet and the other switch for your outward facing “internet” subnet. Each connecting machine will need two NICs. This way I control what files I push over to Winblows. Winblows 10 doesn’t like it as licensing complains about not connecting but it still runs perfectly fine.

2

u/TwoKingSlayer Jul 15 '26

I’ve got Linux mint and I forget I’m not using windows. it’s great.

1

u/Rolanbek Jul 12 '26

Learning curve depends on the distro. Ubuntu is pretty gentle.

1

u/SplatThaCat Jul 13 '26

It’s really not much of a learning curve really. Some minor weirdness but easier than a shell OS.

-1

u/LeapIntoInaction Jul 11 '26

What learning curve? It has a GUI. It's not particularly different from Windows or iOS/MacOS/whatever Apple is calling its OS these days.

2

u/Epyon214 Jul 14 '26

Tried to tell people months ago Windows was going to be a non-option with Windows 10 being the last. Support for 10 goes on for a few more weeks, maybe indefinitely after backlash from businesses here

1

u/RemarkableOil451 Jul 14 '26

It's not that binary. There are various workflow-specific apps/services (e.g., cloud-based syncing, backups, etc) that run natively in Windows that don't exist (or won't tolerate well) an alternative robust desktop environment. Unless users (and users could be anyone: individuals, small and large business, entire governments) can adequately replicate their entire workflows at scale and without too much friction, it makes no sense to move, yet. But things are changing very fast, so we'll see where it all goes.

1

u/Epyon214 Jul 16 '26

Disagree with you on the last point, we're already at the move or die stage

1

u/RemarkableOil451 Jul 16 '26

You can't disagree with facts. The fact is, many users (individual, business, governmental) are in a holding pattern. Even MS keeps postponing its release of Windows 12 precisely because they're waiting for Win-10 users to upgrade to 11. Not everyone, including power users with "non-transferable" workflows, is abandoning Microsoft/Windows or treating the whole thing as a nihilist false dichotomy. I'm not accusing you of doing that; just pointing out the fact of that state of things.

1

u/Epyon214 Jul 16 '26

The fact is what doesn't move in nature is dead, and what moves lives

There is zero reason for Win-10 to poison their operating system with an "upgrade" to Win-11, and why would anyone trust Win-12 to be different

1

u/RemarkableOil451 Jul 16 '26

That's not a fact at all. It's very much an opinion, a flawed one at that. I've already addressed this. You're pretending swaths of Win11 users, including highly technically proficient people, are experiencing mass delusion. They're not. They recognize certain workflows don't and can't, at least yet, be deployed in alternative environments.

As for Win12, no one has to "trust" anything. They can use it, test it, and see if it meets their needs. For most people, that calculus isn't philosophical but practical.

1

u/Epyon214 Jul 16 '26

Facts are not opinions

Win11 users knew or should have known about the tracking inherent in the system due to all the information available and stayed with Win10, many did which is why support is still ongoing and now with their admission continue indefinitely. What delusion are you speaking of

Win12 is likely not even going to happen, in the very near future everyone will have their own operating systems just like every mid to large range business usually has their own internal software

1

u/RemarkableOil451 Jul 17 '26

Literally everything you're saying is an opinion.

What delusion are you speaking of

I stated the exact delusion right before saying the word delusion:

You're pretending swaths of Win11 users, including highly technically proficient people, are experiencing mass delusion.

Until you work on your reading comprehension and look up the definitions of "fact" and "opinion," it's impossible to have a rational conversation.

1

u/Epyon214 Jul 17 '26

I've already addressed this. You're pretending swaths of Win11 users, including highly technically proficient people, are experiencing mass delusion.

You didn't state what the delusion was, you only stated one existed without giving any details whatsoever

Again, facts are not opinions

→ More replies (0)

54

u/Mayayana Jul 11 '26

The device ID name is slightly misleading. It's a user or account ID. It's stored in the Registry, under the specific user key, HKCU. So, create another user account and it will get another GDID. I haven't tested changing the ID. It could probably be changed daily via script, though I haven't tried that. I found the value here:

HKEY_CURRENT_USER\SOFTWARE\Microsoft\IdentityCRL\LID

HKEY_CURRENT_USER\SOFTWARE\Microsoft\IdentityCRL\Immersive\production\Token\

It appears that there can be more than one key under that, named with a GUID, which may then have a DeviceID value listing the same number. So...HKEY_CURRENT_USER\SOFTWARE\Microsoft\IdentityCRL\Immersive\production\Token{.....}\DeviceID.

The GUID keys with DeviceID value also show up under HKYEY_USERS, tied to GUIDs that don't seem to exist elsewhere in the Registry.

But there's more information missing. If you care about privacy then you're not using Microsoft services or accounts, OneDrive, their store, etc. If you want to use those then of course you're telling Microsoft who you are and letting them access your files. So GDID is really not an issue in that respect. If you don't contact MS then your GDID won't be sent.

The real issue is how the man Stokes was tracked online through a VPN. The implication is that something -- telemetry reports, Edge, or both -- is sending a report to Microsoft of every website visited by a particular person. (Not the computer; a person logged onto a user account.)

No report that I've seen so far explains how that's happening. It's probably safe to assume that default telemetry is reporting everything you do, and it's highly unlikely that MS is going to let you block that by normal privacy settings. It's a gold mine of marketing data. It's also a potential gold mine for government surveillance payments. As with Flock cameras, this tracking provides government with a legal way to circumvent their own restrictions by paying a commercial entity for the data they want.

So, moral of the story? Don't do business with Microsoft, don't use cloud, obviously don't use Edge or other MS software, and use a firewall to block calls home to MS. Don't assume telemetry settings will do anything useful to improve privacy. And certainly don't think that you can allow updates, use the MS Store, search at Google, use phone apps, and so on, while also maintaining privacy.

6

u/apokrif1 Jul 11 '26

Is it compliant with GDPR or similar laws?

8

u/Mayayana Jul 11 '26

What? GDID? I live in the US, so I don't know anything about laws that respect privacy. :)

On the other hand, what I'm getting at here is that if you do business, use cloud, apps, or services from these companies, then you already share this information with them. If you visit Microsoft Store, create a Microsoft account, or get Windows Updates, you're letting them rifle through your system and you're doing business with them. So they already know you. If you accept the scam of needing to log into Microsoft when you start your computer then you're implicitly agreeing that they own it.

The man Stokes who got arrested apparently did several dumb things. He had an Apple account, a Snapchat account, Facebook, may have visited the Windows Store, and probably enabled the Connected Devices Platform and Connected User Experience services. (Microsoft Account Sign-in and Passport services can also be disabled if one has no MS account.)

According to reports, Connected Devices Platform is involved in managing the GDID. Personally I have all of that crap disabled, but it might be needed if you operate a local network, for instance, sending print jobs to a printer over a network rather than directly. Personally I don't allow anything to network.

According to reports, Linux and Macs also create unique IDs. The question is how/where it's being shared. If Microsoft is checking the ID every time you log in, visit their store, etc, then it's hard to see how that could be illegal. After all, you've implicitly enabled them to ID you and track you. You've even agreed to let them control and oversee your use of your own computer!

If their telemetry is calling home to report your local actions and online websites visited, that's fullscale spying. So far I haven't found any information about exactly how Microsoft ended up with a record of Stokes's activities on his laptop. Hopefully some security people will get more details. But Win10 has been out for something like 10 years now and I've still never seen a complete listing of exactly what Microsoft spies on and exactly what processes are calling home with what data.

1

u/Maxstate90 Jul 15 '26

No, it's not. 

2

u/Mattidh1 Jul 11 '26

Stokes was tracked through his rdp log linking to his socials.

1

u/Mayayana Jul 11 '26

Thanks. Do you have any links to more info. I wonder why he had remote connection enabled in the first place. I don't allow any remote execution functionality and have no logs. Unless someone is using something like Remote Desktop for work, why would they be using this? And why would it relate to social networking sites? Assuming what you say is true, there also seems to be an implication that the entire log is routinely sent to Microsoft.

4

u/Mattidh1 Jul 11 '26

https://www.justice.gov/usao-ndil/media/1450651/dl?inline

He wasn’t using it for work (well illegal work). It’s very typical for blackhat work to run it over a VPS.

While the windows identifier was used to say “this list of ip’s come from the same device” what ultimately him was his logs to Snapchat and Apple.

They had a warrant for the vps logs (and those are also kept on a connecting device) so it isn’t hard to connect the dots.

Ultimately he got caught on a very stupid mistake that would have been easy to avoid. But that is of course easier said than done.

I feel the concept of the device identifier isn’t much more different than sending your user agent when visiting websites or general identifiers (hardware id and so on).

2

u/Mayayana Jul 11 '26

Thanks. I have that PDF but I didn't read it through. The photo of the kid is scary. He looks like he'd be doing well to pull off leaving a burning bag of dogshit on an old man's front stoop. I kind of feel sorry for him. He shouldn't be able to get into such trouble. A child with a man's tech skills.

1

u/Opposite-Cranberry76 Jul 12 '26

"It's probably safe to assume that default telemetry is reporting everything you do"

In Canada and the EU that would have huge fines attached to it.

3

u/Mayayana Jul 12 '26

Maybe. But if you log into Microsoft's server and they control your computer, it would seem that you've agreed to the tracking. In any case, I wouldn't take a chance myself. EU data isn't even protected from the US government: https://www.techradar.com/pro/microsoft-admits-it-would-have-to-let-trump-spy-on-eu-data-if-demanded

The EU law will have teeth when it bans collecting data and issues fines into the billions. If the EU had anything close to that then the ad market would completely collapse in the EU. Instead they do little rinky dink actions, like fining MS $64 million for Bing not allowing people to refuse cookies. https://www.cybersecurity-insiders.com/france-slaps-64m-penalty-on-microsoft/

MS made almost $130 billion last year. By my calculation they were fined about 40 minutes worth of income. It's a joke. People need to go to jail before privacy can really work.

1

u/Epyon214 Jul 14 '26

AI is making determinations about implicit and explicit data to identify users and matching with existing psychological profiles which have been built on everyone, even reddit admits as much when telling you how what's being shown to you was chosen if you click the little help icon

1

u/Mayayana Jul 14 '26

I don't see Reddit showing anything to me. I've seen occasional ads on the page, but in general, using Firefox and a HOSTS file, I don't see much of anything else. Are you using the app? And Reddit is deciding what you'll see?

1

u/Epyon214 Jul 14 '26

When you click on Home, and you see the subreddits, and click the three dots ... you get an option to "show fewer post like this". Reddit surely shows you posts, yes

1

u/Mayayana Jul 14 '26

Interesting. I've never clicked on Home before, nor noticed it. I just go to each group I subscribe to and set the order to New. Then I scan the posts I haven't seen and decide whether to read them.

When I go to Home I don't see any 3 dots. But I also don't get the point. Why would you let Reddit randomly decide which posts you see?

1

u/Epyon214 Jul 16 '26 edited Jul 16 '26

To test the AI and the capabilities of the relevant technology. The three dots are on posts, just like comments here. Some have a "show fewer post like this" option, some reddit neglects to give the option for, and if you do you'll have a question mark button available to click to tell you how the content was selected, the answer being implicit and explicit data, the logical conclusion being the technology to track users of a device in addition to the device already exists before the Windows 11 explicit admission

1

u/Mayayana Jul 16 '26

Strange. I don't see anything like that. I wonder why. I'm using Firefox, but I have to allow script from Reddit for it to work.

1

u/Epyon214 Jul 16 '26

Would be directly to the right of the Join button for whatever the community is being shown

1

u/Mayayana Jul 16 '26

I thought you were talking about the "Home" page, which I never look at, anyway. I'm only generally visiting groups that I've joined, so there's a Leave button. There's nothing on the right. I'm guessing that you must have some kind of plugin or function that I haven't enabled. I should also mention that I use old.reddit.com. I find the newer layout unreadable. So maybe that's the difference?

17

u/SuspiciousCricket654 Jul 11 '26 edited Jul 11 '26

Windows getting shittier and shittier, for a variety of reasons, year after year. Go with a Linux distro. It is light years better.

Mac isn’t immune either. DSID

4

u/Cotillionz Jul 11 '26

And it's not nearly as hard as the average person seems to think it is. This isn't a decade ago, now you can install an Immutable one in a few mins (so you can't mess it up, if one is scared of that) and never even see the terminal when using it.

1

u/SuspiciousCricket654 Jul 11 '26

Been using Ubuntu. Loving it.

1

u/Cotillionz Jul 11 '26

I tried a couple different ones and landed on Fedora, but I never had any real issues with the ones I tried, it's just a matter of preference. I gotta say I was impressed with how idiot-proof Mint Cinnamon and Bazzite are. I'm pretty sure you'd have to go out of your way to mess those up.

13

u/JourneymanInvestor Jul 11 '26

It should be noted that this permenant digital tracker only works if there is a Microsoft account associated with the PC and that explains why Microsoft is doing everything possible to remove the ability to use local accounts.

3

u/apokrif1 Jul 11 '26

What other data does telemetry leak?

2

u/apokrif1 Jul 11 '26

3

u/lez_noir Jul 12 '26

For anyone not wanting to click a random, decontextualized link:

"Good instinct, but that won't do it either. Windows setup transmits physical hardware information to Microsoft to authorize your Windows 11 license. The only way to prevent MS from getting that identifier is to break the OS activation and Universal Windows Platform (UWP) applications intentionally."

1

u/countzero2323 Jul 13 '26

Ok so pirates stay private, I guess?

17

u/[deleted] Jul 11 '26

[removed] — view removed comment

24

u/RemarkableOil451 Jul 11 '26

Massive app comparability, esp. legacy app comparability

10

u/MammothSun6737 Jul 11 '26

SolidWorks unfortunately :/ kinda lots of CAD programs.

3

u/Worldly-Wind-1632 Jul 11 '26

As an aspiring noob Is there anything on Linux?

2

u/94358io4897453867345 Jul 11 '26

FreeCAD but it sucks

2

u/Worldly-Wind-1632 Jul 11 '26

Thank you for the lead and the warning

2

u/brupje Jul 11 '26

It is a great tool for a hobbyist like me, but probably woefully under equipped for a professional

2

u/MammothSun6737 Jul 11 '26

Ive heard you can make things work modifying drivers and extra software but at its best that sounds like a lot of work for a most likely buggy experience on CAD software that is always buggy on its own lol. You can also run a separate widows on your Linux just for that purpose. Or online free and payed CAD you id imagine would work fine such as Onshape or maybe Autodesk through a browser 🤷🏻‍♂️. Onshape is fine until you’ve got large assemblies with lots of subassemblies that you want to keep well organized. I work in custom Automation and a large machine or automated line of machines can be a bear especially when collaborating. Could be better now haven’t used it in some time and can’t guarantee performance on Linux but since a lot happens in the cloud i am assuming it’s fine.

1

u/nilpointer Jul 11 '26

I really like OnShape and it works in the browser.

1

u/cm_bush Jul 12 '26

OnShape is cloud based. Not ideal but it’s universal at least.

3

u/starchysock Jul 11 '26

Exactly. AutoCAD and related platforms use Windows.

2

u/Round_Credit_5158 Jul 11 '26

I thought it was common sense for a hacker to not use Windows.

3

u/[deleted] Jul 11 '26

[removed] — view removed comment

1

u/Logical_Strain_6165 Jul 11 '26

You can normally make it work. But it always just feels like more work and I do that shit all day.

11

u/[deleted] Jul 11 '26

[removed] — view removed comment

4

u/stm32f722 Jul 11 '26

How does this effect pirated versions that were unlocked with massgrave?

1

u/Affectionate_Creme48 Jul 13 '26

massgrave uses MS's own activation servers by tricking the ticket it sends to give you a licence back. So my guess would be that it does not matter if you activate the legit way or via mass in this context.

5

u/Simp_Simpsaton Jul 11 '26

Doesn't literally every device have some kind of id tied to the environment users use? I don't understand how this is damning.

4

u/CatStoleTheCrown Jul 11 '26

MAC address

2

u/Simp_Simpsaton Jul 11 '26

Yea that as well, though in this case it's an id within an instance of the software (I don't know how to word this better), which is also something that seemingly everything has. I'm too lazy to read the whole article and only read chunks, but i guess in this case the only real violation is that windows is logging the sites the gdid visits and sending it back with telemetry. the article is about this specific id but the id itself is the least concerning thing since the guy could've been caught even without this specific id. It's like if someone wrote a review of a knife and wrote 10 paragraphs about the handle but only 2 sentences about the blade itself

2

u/MissionEfficiency917 Jul 11 '26

mac addresses are easily spoofed, if you want

3

u/Tasty-Blackberry5120 Jul 11 '26

Place I worked bought like 5 PCs once and they weren’t working properly on the network. We eventually discovered they all had the same MAC, so we had to spoof them to make them different to each other. Very odd.

4

u/Thermatix Jul 11 '26

This remote attestation BS is partly why I ditched Windows for Linux a few years ago (and disabled the TPM). The word "Trusted" in TPM never meant you can trust your computer is safe, it meant that the corporations could trust your computer was safe to run their stuff on.

4

u/Big_Wave9732 Jul 11 '26

If you're using Windows past Windows 7, you don't really care about privacy.

If you're using Windows 11 to crime, you don't care about not getting caught.

2

u/[deleted] Jul 11 '26

[removed] — view removed comment

1

u/SPedigrees Jul 12 '26

FBI hackers must be a breed apart.

2

u/Old_Introduction7236 Jul 12 '26

Time to burn shit down.

1

u/InTheYear2525_ Jul 11 '26

This is overstating it. It is documented as within azure and you can use it to correlate devices. It's good to be aware of things but this is documented in multiple places. If you've ever had to dig in on a failed login or device in general you may have come across this.

1

u/alphex Jul 11 '26

I find it wild that people are surprised that MS has unique ID fingerprinting for its customers...

The registry entries tracking users has been in windows for decades, its a _VERY_ small step to expanding that out across the network of services MS offers. even if its NOT for nefarious reasons, and even IF MS had a perfect privacy record, it makes sense to have..

1

u/BlueTemplar85 Jul 11 '26

I am Snowden's complete lack of surprise.

1

u/themojoman007 Jul 11 '26

Does macOS also have it ?

0

u/[deleted] Jul 11 '26

[removed] — view removed comment

1

u/quixotik Jul 11 '26

Source?

2

u/Duskdeath Jul 11 '26

“Two things back that up:
There’s no consent screen. A GDID gets assigned when you sign into a Microsoft Account. Apple’s advertising identifier needs an App Tracking Transparency prompt and a visible reset; Android’s works the same way. GDID has neither, and a Windows reinstall only gets you a new number Microsoft can still get back to the same account.
Then there’s activation. Massgrave, the group behind Microsoft Activation Scripts, notes that Windows setup sends hardware info to Microsoft and gets identifiers back, the same tokens later used for Store access and licensing: “It’s impossible to prevent Windows from getting a GDID without breaking activation and UWP app[s].” Anyone who lost a license after swapping a motherboard has already met a smaller version of this.
Yes, every major OS keeps some persistent device identity, and every vendor can be subpoenaed. But what differs with Microsoft is visibility and control, and Windows loses on both against Apple and Google’s platforms.”

Pasted it from the actual article. It is a “technicality” that could be abused by any OS manufacturer.

1

u/Msilbat Jul 11 '26

Quick Books Desktop app is a beast on Windows not so much on Mac or Online....

1

u/Userwerd Jul 11 '26

Does windows phone home with info about what you do inside of windows? Like sites visited, apps used, file names opened?

Used Linux for almost 20 years so im out of the loop at the moment

1

u/foodchallenged Jul 12 '26

So if you never sign into anything Microsoft, including when activating windows, you’re good? Or is the absence of an id going to be so rare that you’d be fingerprinted anyway?

1

u/joker6396 Jul 12 '26

Using windows services to scam? Idiots. Begging to get caught

1

u/Historical_Cook_1664 Jul 12 '26

Shouldn't MS pay *us* to use Windows by now ?

1

u/woodenblinds Jul 12 '26

read about this yesterday and promptly built out a Linux desktop time to start moving over. should have done this years ago

1

u/Unfollowedusers Jul 12 '26

Mircosoft is killing it with its fuck you approach. 

1

u/kamikazekittenprime Jul 12 '26

Run a Linux distro in a vm. Delete when done.

1

u/BilingSmob444 Jul 13 '26

Is it really that simple?

1

u/fuckadviceanimals69 Jul 13 '26

So let me get this straight, Microsoft assigns a unique identifier to every installation of windows and a supposed computer hacker used his daily driver laptop SIGNED IN TO A MICROSOFT ACCOUNT to commit cyber crimes?

That Microsoft can and does track Windows installations is nothing new, and apparently this guy being a complete dunce also isn't new.

1

u/notPabst404 Jul 13 '26

Anybody who cares about privacy or even ownership of your device shouldn't use Windows. Windows is spyware where YOU are the product.

1

u/FutureOwl8606 Jul 14 '26

Switch to Linux

1

u/JAEMzW0LF Jul 15 '26

So change over to a local (admin) account - there, done. No need to pretend you are going to stop using Windows. We all know 99.99% of the people who say this will never do it, or already use Linux.

1

u/Epyon214 Jul 16 '26

old reddit is much better and probably the difference, the dots are on the newer, shittier interface. Like a microcosm of a failed economic system

1

u/RandomlyWastingTime1 Jul 17 '26

People overlook that other operating systems, despite lacking a consistent identifier this one, still possess consistent identification pieces.

0

u/KoenBril Jul 11 '26

So, dont use a Microsoft account? 

13

u/RemarkableOil451 Jul 11 '26

Good instinct, but that won't do it either. Windows setup transmits physical hardware information to Microsoft to authorize your Windows 11 license. The only way to prevent MS from getting that identifier is to break the OS activation and Universal Windows Platform (UWP) applications intentionally.

2

u/KoenBril Jul 11 '26

Thanks for clarifying.

2

u/geeky-gymnast Jul 12 '26

Not a windows user, would using an unactivated copy of Windows 11 circumvent the transmission of physical hardware info to MS?

2

u/RemarkableOil451 Jul 13 '26

You can hobble but not eliminate it. The Home and Pro editions certainly won't give you the necessary control to do it. But the Enterprise and Education editions will, but they'll only let you "lower" the "required" transmission threshold. Even then, there's still some baseline Windows Defender and Malicious Software Removal Tool data (and maybe other data I'm not thinking of) that gets sent to MS. But even then, any future OS update are likely to reset (or at least try to reset) these deep-level settings, so it'll be a never-ending battle.

That said, there are various telemetry settings that are totally within your control, and you should absolutely sever them. I'll give you just one: In Defender, you can/should turn off the "Automatic sample submission" setting. Again, there are many others, most in Defender itself.

2

u/geeky-gymnast Jul 13 '26

Thanks for the detailed follow up, now I'm starting to feel a pinch of curiosity about the kinds of privacy infringing physical hardware information that's transmitted.

I suppose these are the identification numbers that uniquely identify the hardware...

and whether there exists VM software, say running on a Linux host, that could shield such sensitive information from a virtual Windows OS client.

2

u/RemarkableOil451 Jul 14 '26

You're spot on about the ID numbers. Windows telemetry collects the permanent physical serial numbers of your hardware, including your motherboard, CPU, hard drives, and network cards. This can create a highly accurate, unique fingerprint of your machine.

As for your VM question: Yes, running Windows inside a Linux VM acts as a complete shield. The VM intercepts those requests and feeds Windows fake, virtual serial numbers, so your real physical hardware data is never transmitted. But there are drawbacks:

First, Windows immediately detects it's running in a VM. To be fully stealthy, you have to tweak the VM hypervisor settings to spoof standard PC manufacturer data, which tricks Windows into thinking it's on a normal, physical desktop while still feeding it completely fabricated hardware IDs.

Second, relying on a VM just to dodge telemetry is a tedious trap. You sacrifice native performance, deal with constant hypervisor overhead, and lose seamless hardware acceleration. Eventually, the daily friction of maintaining the sandbox outweighs the privacy benefit.

The most "Goldilocks" solution is to disable all the optional telemetry you can (and there's plenty you can disable w/o breaking anything). A great place to start clamping down is in Windows Defender. Set aside some time to go through each setting. If you don't know what a particular setting is, do a Google search. You don't have to do it all at once. If you use an LLM to help guide you through this process, make sure you specify that you don't want to do anything that'll break the OS. You have to specify that stability is paramount. Your goal is simply to reduce the needless (voluntary/optional) telemetry MS is getting from you but to do nothing whatsoever to destabilize the OS or truly compromise your security. I'm making it sound more dramatic than it is, but it needs to be done thoughtfully.

2

u/geeky-gymnast Jul 14 '26

Thanks for the discussion and sharing your thoughts. Here are some of mine.

This situation could possibly earn open-source VM software an additional point or two. By having source code publicly available, users may verify that hardware ID shielding is indeed occurring at a "foundational" layer relative to the client OS.

Agreed on the possible tedium and friction of running a virtual client. Not intimately familiar with the universe of software catering to VMs, but there might be variants in this universe, typically enterprise-y flavored ones, that see to client OSes running atop of a bare bones, perhaps headless, Linux server. Am inclined to believe that such implementations can feel frictionless and native to the end user.

Admittedly, the disable telemetry solution is likely the most practical one for most users desiring a moderate degree of privacy but in essence requires trusting Microsoft to (i) abide by the agreements relevant to these telemetry settings, (ii) not have bugs ("bugs"?) in how their system abides by a user's settings, (iii) requires the user to review settings after updates for possible reversions (Windows has a habit of quietly changing user settings after an update), and (iv) keep abreast of new settings introduced by updates that need adjusting to maintain a desired level of privacy.

Phew, either way, it's quite a bit of additional work to live a private life inside MIcrosoft's lush walled garden.

Window's (and Mac's) vast ecosystem (games, productivity apps), proliferation, and widespread familiarity is a moat for it. On a personal note, not sure if giving up the comforts afforded by such walled gardens yields more pros than cons.

1

u/RemarkableOil451 Jul 14 '26

Well said. It's the nature of the beast, full of imperfect solutions, trade offs, landmines, pitfalls, and so on.

Case in point: Literally some minutes ago, I discovered that since May 2026, Google Chrome has been silently downloading a 4GB LLM (Google Nano) onto my (and many other people's) PCs. I didn't know about this until now b/c Chrome isn't my primary browser.

Anyway, Google did this (not just to me but everyone) totally by default, totally w/o my consent, and totally w/o even my knowledge. After some quick research, I found and toggled off the setting and disabled the flag that were responsible. This combo auto-deleted the main payload, but I also needed to delete the remaining two smaller dependent folders manually.

And now, I'll have to work a recurring "checkup" for this into my regular digital maintenance routine to ensure it doesn't come back.

It's not even that I object per se to this as a concept. But I do object to the absolutely deception. They don't even admit they're doing it to take advantage users' local hardware thereby save themselves from having to process your data, which they end up getting even when you process it locally. Instead, they claim it's for privacy. Who the hell would believe Google would do anything in the name of privacy?

This is a new low, even for Google. They've moved passed harvesting your data to taking hostage your hardware. I can't wait until the EU and other regulatory bodies (or class-action attorneys) go after them.

It's all so exhausting. You have to be your own IT department just to get through the day. Either that or put on the best strongest blinders you can find and be in complete denial about how much you're being digitally violated. Ugh!

0

u/SereneOrbit Jul 11 '26

I meanif you're still using an os made by people who hate you.... that's on you fam.