GDID Windows: Cut the Tracker That Follows You Even Under VPN

GDID Windows – Cut the tracker that follows you even under VPN

GDID Windows: Cut the Tracker That Follows You Even Under VPN

I discovered that Windows carries a persistent GDID identifier tied to your Microsoft account, which tracks you even when using a VPN. Deleting registry keys or disabling telemetry fails because the ID is stored on Microsoft's servers and re-downloads automatically. I developed scripts to block the specific services and endpoints that report this data, offering a practical way to limit tracking without losing account access, though true anonymity requires moving away from Windows entirely.

The only truly solid option for sensitive activity is more drastic: don't do that activity on Windows.
  1. sorenjan

    > Microsoft provided the FBI with the history of IP addresses tied to that specific GDID.

    This article, and most articles about this, doesn't explain where FBI got that GDID from. Ok, Microsoft has a list of IP addresses that has been used by a computer with a certain GDID, but FBI needs to get the GDID in the first place, and then try to bind that to a person.

    I found another article that explains the process a bit better:

    > Stokes got caught because he used the same Windows device for everything, and the GDID stitched all of it back together after the fact.

    > Scattered Spider members phoned the jewelry retailer’s IT help desk from Google Voice numbers, posed as locked out employees, and talked support staff into resetting three accounts, two with administrator privileges. From there they installed a tunneling tool called ngrok to get past the retailer’s network defenses, moved roughly 77 gigabytes of data to Amazon cloud storage using ngrok [...]

    > Investigators later subpoenaed ngrok and found the account used in the attack had been created on May 12, 2025, at 19:21 UTC from a VPN proxy IP address run by Tzulo, a hosting provider. The IP was a dead end. VPN proxies do that. But the GDID is built different.

    > Microsoft’s records showed that at that exact same minute, a Windows device carrying GDID g:6755467234350028 had visited the ngrok signup page. Three hours later, the same GDID visited the retailer’s own website, through the same Tzulo proxy address used to set up the […]

  2. inventor7777

    I cannot believe people tolerate this kind of behavior from such a large company with a huge market.

    It does make me wonder if people would react differently if Linux or Apple did the same thing.

  3. 0x1d7

    Interesting, generally Microsoft bypasses the hosts file name resolution for various MSFT domains. Curious that these were not included (if it works, which I assume the mitigation does).

    https://petri.com/windows-10-ignoring-hosts-file-specific-na...

  4. Terr_

    I think it's likely that Microsoft is running a process to correlate "new" GDIDs to old ones, ex:

    "Oh look, this one has almost all the serial numbers of components and attached-devices as that other one, it's probably the same computer with a fresh install, let's make a note of that..."

  5. pudgywalsh

    I agree, tracking data via unique identifiers is evil incarnate, unless it's Google or VC-backed adtech doing it, because how else will they make money having architected their entire businesses around it.

More from this day

2026-07-25