Microsoft uses a Global Device ID (GDID) in Windows, which uniquely identifies installations and persists through restarts and updates. This identifier cannot be removed and is used for telemetry purposes, sending data to Microsoft servers regardless of whether the system is set up with a Microsoft account or local user. Recently, the GDID was used in a legal case to identify a suspect linked to the 'Scattered Spider' cybergroup, despite the individual using a VPN. The indictment explains that Microsoft cybersecurity researchers identified the suspect based on the GDID, along with other data such as IP addresses and malware samples. Microsoft acknowledges that the GDID allows unique identification of Windows installations across physical or virtual devices but notes that it is regenerated during reinstallation.
Bias read (Center): The article presents factual information about Microsoft's technology and its use in a legal case without overtly favoring any side. It includes technical details, references to Microsoft documentation, and court documents, providing balanced context without apparent ideological framing.
Why factuality (65): The article discusses the Global Device ID (GDID) in Windows and its legal implications, referencing Microsoft's internal use of the ID in Azure Cloud systems. It mentions a case where a suspect was identified via GDID despite using a VPN. However, the primary source document does not mention legal
Why objectivity (60): The tone leans towards reporting on controversy around GDID, suggesting it 'sorgt nach wie vor für Aufregung' and implies that the legal use of GDID is surprising. While not overtly biased, the framing suggests some level of public concern, which could be seen as slightly subjective.




