ON
← Back to feed
Windows: Global Device ID leads to identification with legal effect
Germany🏛️ PoliticsCenteryesterday

Windows: Global Device ID leads to identification with legal effect

Microsoft uses a Global Device ID (GDID) in Windows, which uniquely identifies installations and persists through restarts and updates. This identifier cannot be removed and is used for telemetry purposes, sending data to Microsoft servers regardless of whether the system is set up with a Microsoft account or local user. Recently, the GDID was used in a legal case to identify a suspect linked to the 'Scattered Spider' cybergroup, despite the individual using a VPN. The indictment explains that Microsoft cybersecurity researchers identified the suspect based on the GDID, along with other data such as IP addresses and malware samples. Microsoft acknowledges that the GDID allows unique identification of Windows installations across physical or virtual devices but notes that it is regenerated during reinstallation.

Microsoft's use of a Global Device ID (GDID) within its Windows operating system has led to its legal recognition as a means of uniquely identifying devices, according to recent court documents. The GDID, which persists through restarts and updates, was instrumental in identifying a suspect allegedly linked to the cybercriminal group Scattered Spider, despite the individual using a virtual private network (VPN) to mask their identity. The GDID is part of Windows' telemetry system and is transmitted to Microsoft’s servers regardless of whether the user signs in with a Microsoft account or a local account. It functions as a persistent identifier that allows for unique identification of a Windows installation on a device, whether physical or virtual, through specific Microsoft services and scenarios. This feature enables Microsoft to track installations over time, even after hardware changes or system reinstalls. The GDID is stored as a string in references related to Azure cloud systems. While it is not easily accessible to users, it is used internally by Microsoft for tracking purposes. A GitHub user named “SmtimesIWndr” compiled information showing that the GDID is sent alongside other data such as computer hardware IDs, IP addresses, and malware samples. These data points help cybersecurity researchers identify patterns and link activities to specific devices. In a recent case, prosecutors cited the GDID as evidence against an alleged member of the Scattered Spider group. Despite the suspect using a VPN, the GDID allowed authorities to trace the device back to the individual. According to court filings, the GDID is described as a persistent identifier that ensures a unique identification of a Windows installation across different environments. This capability is particularly useful in forensic investigations and digital forensics. Microsoft acknowledges that the GDID is regenerated during a new installation, making it difficult to permanently remove. Users who wish to avoid the GDID can opt for alternative methods, such as setting up new virtual machines regularly, which generate fresh identifiers. However, this approach requires technical expertise and may not be suitable for all users. For those seeking greater privacy, switching to alternative operating systems like Linux could offer more control over device identification mechanisms. Other major tech companies, including Apple and Google, have implemented similar tracking features in their operating systems. As such, the use of persistent identifiers is becoming increasingly common in modern computing environments. While these features enhance security and investigative capabilities, they also raise concerns about user privacy and data collection practices. The legal recognition of the GDID underscores the growing role of technology in law enforcement and cybersecurity efforts.

How each side covered it

The same event, grouped by the political lean of the outlets covering it.

How each side covered it

Support independent, bias-aware news and unlock the social pulse, community voting, and your personalized For You feed.

Become a Supporter

Covered around the world

The same event as reported in other countries.

Covered around the world

Support independent, bias-aware news and unlock the social pulse, community voting, and your personalized For You feed.

Become a Supporter

Claims check

Key factual claims, and how many sources assert vs dispute each.

Claims check

Support independent, bias-aware news and unlock the social pulse, community voting, and your personalized For You feed.

Become a Supporter

Go to the primary sources (3)

The official sources this coverage is built on. Read them directly to bypass framing.

1 reports

heise online logoheise onlineIndependentCenterFactual 65Objective 60yesterday
Windows: Global Device ID leads to identification with legal effect

Microsoft uses a Global Device ID (GDID) in Windows, which uniquely identifies installations and persists through restarts and updates. This identifier cannot be removed and is used for telemetry purposes, sending data to Microsoft servers regardless of whether the system is set up with a Microsoft account or local user. Recently, the GDID was used in a legal case to identify a suspect linked to the 'Scattered Spider' cybergroup, despite the individual using a VPN. The indictment explains that Microsoft cybersecurity researchers identified the suspect based on the GDID, along with other data such as IP addresses and malware samples. Microsoft acknowledges that the GDID allows unique identification of Windows installations across physical or virtual devices but notes that it is regenerated during reinstallation.

Bias read (Center): The article presents factual information about Microsoft's technology and its use in a legal case without overtly favoring any side. It includes technical details, references to Microsoft documentation, and court documents, providing balanced context without apparent ideological framing.

Why factuality (65): The article discusses the Global Device ID (GDID) in Windows and its legal implications, referencing Microsoft's internal use of the ID in Azure Cloud systems. It mentions a case where a suspect was identified via GDID despite using a VPN. However, the primary source document does not mention legal

Why objectivity (60): The tone leans towards reporting on controversy around GDID, suggesting it 'sorgt nach wie vor für Aufregung' and implies that the legal use of GDID is surprising. While not overtly biased, the framing suggests some level of public concern, which could be seen as slightly subjective.

Keep the news honest.

ObjectiveNews is reader-funded and ad-free — we show you the bias instead of hiding it. Support independent journalism for €5/month.

Become a Supporter

Related stories