So Apparently Windows Has Been Watching You This Whole Time (A Rant)

A look at Microsoft's Global Device Identifier (GDID), permanent machine tracking, law enforcement disclosures, and why the local account bypass keeps disappearing.

7 min read

Note: A detailed technical follow-up with corrections and registry mechanics has been published — read GDID Explained: Windows’ Hidden Device Identity.

ok so by now people have probably seen something about this GDID thing, the Scattered Spider guy who got caught partly because of it. i wanted to actually sit and figure out what the number even is because the headlines mostly skip the mechanics and just go straight to “scary.”

GDID stands for Global Device Identifier. it’s Microsoft’s thing. permanent id number, assigned the moment you set up windows. not your account, not your email. the machine gets a number and it just kind of… stays. follows the install around. only way it changes is a full wipe.

you probably already know the shape of the case, Peter Stokes, 19, tied to Scattered Spider, arrested in Finland, extradited to Chicago earlier this year. what i didn’t realize until i actually dug in was how specific it got. one device id, g:6755467234350028, tracked across VPNs and proxies and four different countries for something like eight months. he was being somewhat careful the whole time and it didn’t matter. that’s the part that actually gets me. it’s less that he was careless and more that the leak was never in his hands to begin with. you can’t vpn around your own operating system.

and most people had no idea this thing existed. it’s not in the privacy settings menu, there’s no toggle for it. before this case the only public reference was apparently a line buried in some Azure Monitor doc that literally nobody but sysadmins reads. real “we told you” energy from a company that’s never once been accused of over-communicating.

what windows actually collects

two tiers. Required and Optional. worth separating these because people mash them together a lot.

Required is baseline stuff, device config, whether things are crashing, patch status. Microsoft’s line is the os needs this to run safely at all and honestly, fine, i mostly buy that one.

Optional is where it gets murkier. this tier covers what sites you’re visiting, general usage, and — this one surprised me — it can grab a chunk of your device’s memory during a crash. so mid-typing something, pc dies, there’s a chance fragments of that get swept up too. not the whole file. still not nothing though.

here’s the thing that actually annoyed me most reading through this. saying no to Optional doesn’t get you out of being identified. Required data still gets tied to a unique id on their end regardless. so the “opt out” isn’t really an opt out of the tracking part, it’s an opt out of the deeper data layer sitting on top of it. and they don’t even pull Optional evenly, they sample it, some percentage of machines get pinged for certain data types and others just don’t. there’s a tool, Diagnostic Data Viewer, if you want to check which bucket your pc landed in.

ai, the newer wrinkle

you’ve probably seen the Recall backlash already. screenshots your whole screen periodically so you can search your own activity later. what’s less talked about is how much Microsoft walked that back through 2026. supposedly runs fully on-device now on newer hardware, encrypted, gated behind Windows Hello, not shipped to the cloud, not used for training. that’s the official version at least.

there was also reporting earlier this year that Microsoft was internally rethinking the whole ai push, after people got sick of constant copilot popups in office and after the simple checkbox to just turn it off quietly disappeared. pulling the off switch is usually not the move if you actually want people trusting a feature. by build 2026 the messaging shifted again, local agents, “zero trust for personal data,” a dashboard for controlling what each agent can see. and the copilot+ pc branding they were pushing so hard barely showed up at that keynote. reads like a quiet step back.

microsoft doesn’t really need copilot to collect data on you though. the pipeline’s already there, been there since 2015. ai is sitting on top of it. so blaming “the ai” specifically kind of misses where the actual plumbing is.

the local account thing

you’ve probably noticed windows setup pushing a microsoft account harder than it used to. the bypass commands got disabled in newer builds. official framing is reliability, making sure setup completes properly.

i don’t think that’s the whole story though. more accounts, more people locked into onedrive, more people on copilot, harder to leave once everything’s tangled up in it. no single piece of that is evil by itself. funny that the company built on “a computer on every desk” now acts personally offended you’d want to own the desk part without renting the computer part back monthly.

he also kind of did this to himself

not letting stokes off the hook here. the gdid alone wasn’t the whole story. he reportedly used ngrok in the same browser session he was logged into his own facebook and snapchat. that part’s not a microsoft problem, that’s a him problem. investigators also connected him to a hotel stay partly through photos he’d posted of the room. himself. the telemetry mattered but honestly the human error probably mattered just as much, and that tends to get left out of the scarier version of the headline.

ok here’s what i actually think

most coverage of this lands on “well it caught a criminal, but also privacy matters” and calls it a day. i don’t think that’s a real conclusion, i think it’s a way of avoiding one.

microsoft built the identifier. microsoft decided what counts as required versus optional. microsoft decided there’s no consumer-facing off switch on home or pro. and then, when it’s useful, microsoft hands the output of all that to law enforcement and calls it lawful cooperation. every single decision in that chain was made by one side. the user doesn’t get a vote at any point, they get the disclosure after the fact, in a court filing instead of a settings menu, months or years later.

“but it caught a criminal” gets used to end this conversation a lot and i think that’s a little cheap honestly. a lot of surveillance catches criminals eventually, that was never really in dispute. the actual question is whether you knew what was being collected and whether you had a real choice about it. and for a regular person on a home license the answer’s just no. catching one guy allegedly running an eight million dollar extortion attempt doesn’t really tell you anything about whether this is a fair setup for the other billion plus people running windows who never asked to be a data source in the first place. those get treated like the same argument a lot and they’re not.

so i’m not going to land on both sides have a point. a company that ships a permanent id with no visible toggle, then makes local accounts quietly harder to set up around the same time, then leans further into ai features that all want more context on you — that company’s optimizing for something, and it’s not really user choice. probably not malicious in any cartoonish sense. more likely just what happens when incentives point one direction for ten straight years and nobody with any leverage pushes back. still. not malicious and actually fine aren’t the same thing.

this is probably the real reason some people end up drifting toward linux over stuff like this, not some grand statement about surveillance, just, on linux you generally get to decide what leaves the machine. on windows microsoft decides what counts as necessary and you find out later. feels like the “this is your machine” era of the company quietly ended around when gates stopped being the public face of it and started doing malaria interviews instead. nobody with real skin in windows staying user-friendly has really been in that seat since.