Yahoo
Skip to main content
Advertisement
Advertisement
Advertisement
Advertisement

VPN Provider Fights Microsoft's Hidden Windows Device Tracking

Microsoft logo
Microsoft logo - Photo by Samuel Boivin/NurPhoto via Getty Images

A hacker's arrest exposed a little-known way Microsoft can track users on a Windows PC , but VPN provider Windscribe says it developed a process to shut it down.

Windscribe says its experimental computer script can remove the Global Device ID (GDID) from a Windows PC. That identifier was used by the FBI to identify 19-year-old Peter Stokes, an alleged member of the hacking group Scattered Spider . Agents uncovered that an IP address associated with his hacks was linked to Stokes's Windows PC through the 16-digit GDID.

A GDID on a Windows 11 PC.

The unsealed criminal complaint also revealed that Microsoft can associate a GDID with third-party services, including the time a Windows PC accesses them. The news sparked concerns that it could be abused for surveillance, with no way for a Windows user to opt out or easily stop the tracking. The complaint against Stokes notes that "A GDID remains consistent across Windows operating system updates on a device"; only a Windows OS reinstall creates a new GDID.

Advertisement
Advertisement

On Monday, Windscribe tweeted , "Windows is spying on you. By design...VPNs don't help. Local accounts don't fix it. So we built deGDID."

The deGDID project is designed to prevent Windows from using any GDID functionality on the system. "Our research suggests the server-issued ID is minted through Windows identity and account-registration flows, with hardware signals involved in the request. Hardware alone does not determine it, though," Windscribe wrote in a blog post .

Still, it's unclear exactly how GDID works, including why and when it can tie itself to third-party services on a PC. A Microsoft document lists the "GlobalDeviceId" as an "identifier used by Microsoft internally." Windscribe's own blog post cautions: "To be clear, we are not claiming GDID is sent to every website you visit. The public case does not identify the exact Windows component or event that produced the logs. The careful claim is narrower: GDID can exist on your machine, Microsoft can associate it with activity, and local privacy advice often ignores it."

During the research, Windscribe found that its test computer, a Windows virtual machine , would still create a GDID even if it was just a local user account. After manually deleting the GDID from the Windows registry, it reappeared after a reboot, indicating that the OS can rebuild the identifier from other sources. 

Running deGDID via PowerShell on an old Windows 11 PC.

In response, the deGDID project attempts to remove the identifier by deleting the 16-digit number from known locations on the PC and blocking paths that the OS uses to retrieve a replacement GDID. There's a downside, though; that path blocking can shut down account sign-ins for Microsoft services, including device sync, passkeys, and Windows Hello.

Advertisement
Advertisement

"Unfortunately, this can break some Microsoft services, but OS functionality remains intact," the company added.

We tried deGDID on a Windows 11 laptop by downloading the computer script from the GitHub  page  and running it via Windows PowerShell with admin privileges. The project seemed to remove the GDID identifier after we tried pulling it up using known methods . But we could no longer log in to certain Microsoft services, including Xbox, Outlook, and the Microsoft Store, because our PC detected that it had lost internet access, likely due to new firewall rules. Our internet connection for browsing or using Steam remained intact. 

Our Windows 11 PC couldn't sign in to Microsoft services after we ran deGDID.

The project is so experimental that Windscribe says, "Running it can break Microsoft account features. Use it at your own risk, on systems you're authorized to modify. Neither Windscribe nor [CEO] Yegor Sak is liable for any damage or loss that results."

Windscribe also can't guarantee it'll shut down every instance of the GDID system. The other issue is that it does nothing to erase records that Microsoft already has on your PC.

Advertisement
Advertisement

As a result, it's not really worth the hassle. An ideal solution would be for Microsoft to explain GDID's functionality and create a way for users to opt out of the potential tracking. But so far, the company hasn't commented on the identifier. The GDID is likely used for many legitimate purposes, such as "updates, fraud prevention, licensing, sync, account security, abuse response, and diagnostics," as Windscribe notes. But how it ended up in an FBI investigation into a hacker is a mystery.

In the meantime, Windscribe tweeted: "If you don't like Windows tracking and don't want to fiddle around with such tools, Linux is that way."

PCMag and Yahoo may earn commission from links in this article.

Check out Yahoo's latest VPN advice, based on hands-on testing.

Advertisement
Advertisement

Best VPNs in 2026 | The best VPNs for streaming in 2026 | The fastest VPNs in 2026 | Best VPN for Mac in 2026 | Most secure VPN in 2026 | 8 ways to make your VPN run faster | Does using a VPN impact internet speeds? | Are VPNs really safe? | See Yahoo Tech's full VPN coverage

Advertisement
Advertisement
Mobilize your Website
View Site in Mobile | Classic
Share by: