Microsoft has confirmed that every Windows PC carries a Global Device ID (GDID) that remains persistent and cannot be removed by the user. This tracking capability allows the company to monitor user activity across different networks, including VPNs and proxy servers, and even when users travel between countries. The revelation matters because it establishes a permanent digital fingerprint for every Windows installation, fundamentally changing how user identity is managed on the platform. Users should be aware that their device identity is now locked to their Microsoft account or initial setup, regardless of local system changes.

Persistent identifier allows Microsoft to track activity across networks
The GDID is assigned during the initial Windows setup or when a user signs in to a Microsoft account. Once created, this identifier is stored in the Windows registry on the local machine and on Microsoft's servers. The system applies this tracking mechanism to both Windows 10 and Windows 11 installations that connect to Microsoft services. The identifier remains in place even after major system updates, ensuring continuity of the tracking record over time.
Technical details indicate that the GDID is an unremovable identifier embedded within the operating system's core configuration. Microsoft retains server-side records of this ID, linking it to the specific device and user account. The company uses this data to track activity across various network environments, including instances where users attempt to mask their location with VPNs or proxies. This cross-network tracking capability extends to scenarios where users move between different countries, maintaining a continuous log of device activity.
The practical implications of this tracking system are illustrated by recent law enforcement actions involving Microsoft's cooperation. Finnish police and US prosecutors used GDID data to identify and arrest cybercriminal Peter Stokes. This case demonstrates how the persistent identifier can be leveraged by authorities to trace illegal activities back to specific hardware. The confirmation of these capabilities highlights the extent of Microsoft's ability to maintain long-term device association.
Source: TweakTown




Discussion
0 comments