Microsoft has been approcribing Windows computers with a hidden identifier that lasted after system updates and allowed you to distinguish one installation from another. The existence of the Global Device Identifier, or GDID, became widely known only after U.S. prosecutors uncovered the details of the investigation against an alleged member of the hacker group Scattered Spider.
The investigation claims that a permanent identifier helped the FBI to track the suspect through changing VPN servers, proxies and connections from different countries. IP addresses have changed regularly, but Windows continued to transfer the same GDID to Microsoft services. Such a digital footprint allowed to link disparate sessions with a specific installation of the operating system.
GDID is created when you set up Windows with Microsoft account. Several system services request an identifier from the company's servers, register a computer in the device directory and then use the resulting value when working with updates, app store and other services.
The identifier is stored in the Windows registry at HKCU\SOFTWARE\Microsoft\IdentityCL\ExtendedProperties. The value begins with the lowercase letter g, after which a long number follows. An ordinary user will not see GDID in the system settings and will not be notified when creating an identifier.
Microsoft previously mentioned GDID in Azure Monitor documentation, but limited to the wording “an identifier that Microsoft uses for internal purposes.” A more detailed description appeared in the materials of the criminal case. A company spokesperson called the GDID a permanent device-level identifier that allows you to recognize a specific Windows installation in individual Microsoft services and scripts.
According to prosecutors, the FBI used GDID in the investigation of Peter Stokes, who is considered a member of Scattered Spider. Investigators observed its supposed activity for about eight months and compared technical data with accounts in social networks, gaming services and ecosystems of large technology companies.
In the case file there is a specific identifier. The investigation recorded it on the Ngrok registration page around the moment when the user created an account associated with the attack through the VPN proxy Tzulo. Three hours later, the same GDID appeared when visiting the website of the company that became the target of the attackers, and the connection again passed through the same proxy.
The FBI compared the identifier with the IP addresses associated with Stokes’ accounts in Snapchat, Facebook*, Apple and Ubisoft. Connections were recorded in Estonia, the United States, Thailand and other countries. Photos from the public Snapchat profile, according to the investigation, coincided with hotel reservations, travel routes and places where a computer with the same GDID appeared.
The investigation showed the weak point of the usual model of anonymity through a change of IP address. A VPN hides the source address of the user from the visited site, but does not necessarily interfere with the operating system to share official data with the developer. If Windows continues to tell Microsoft a regular identifier, new VPN servers don’t break the connection between individual sessions.
After a clean reinstallation of Windows, the system creates a new GDID. Completely break the previous connection may not work. Login to the same Microsoft account, the restoration of OneDrive and activation data allow the company to compare the new installation with the previous history of the device.
Researchers are concerned not only about the technical ability to track, but also the lack of understandable settings. Windows does not show a separate consent window, does not explain the purpose of GDID and does not offer a button to reset the identifier. Apple and Google allow users to manage advertising identifiers, while the Microsoft mechanism works lately and is associated with system functions.
According to experts, the blocking of services involved in the creation and transmission of GDID can disrupt the activation of Windows and the operation of Microsoft Store applications. Therefore, it is impossible to disable the identifier with a conventional switch without consequences. Microsoft also did not report plans to add separate settings or detailed documentation for users.
You can reduce the volume of connected telemetry through the “Privacy and Security” section in Windows settings. The system allows you to disable optional diagnostic data, personalized advertising, tracking application launch, action history and cloud search. A local account also reduces the number of connections to Microsoft services, although new versions of Windows 11 are increasingly requiring authorization during installation.
It will not be possible to completely hide from identification only with the help of a commercial VPN. The operating system, browser, applications and cloud accounts leave their own features that can be compared with each other. The case of Scattered Spider has become a rare public example of how much Microsoft is able to learn in detail the separate installation of Windows and transmit related information to law enforcement on a legal request.
Microsoft has not yet revealed what versions of Windows GDID works on, which services receive an identifier and how long the company stores the history of appeals. The most detailed public description of the mechanism is still not contained in the user documentation, but in a federal complaint against the alleged hacker.
The investigation claims that a permanent identifier helped the FBI to track the suspect through changing VPN servers, proxies and connections from different countries. IP addresses have changed regularly, but Windows continued to transfer the same GDID to Microsoft services. Such a digital footprint allowed to link disparate sessions with a specific installation of the operating system.
GDID is created when you set up Windows with Microsoft account. Several system services request an identifier from the company's servers, register a computer in the device directory and then use the resulting value when working with updates, app store and other services.
The identifier is stored in the Windows registry at HKCU\SOFTWARE\Microsoft\IdentityCL\ExtendedProperties. The value begins with the lowercase letter g, after which a long number follows. An ordinary user will not see GDID in the system settings and will not be notified when creating an identifier.
Microsoft previously mentioned GDID in Azure Monitor documentation, but limited to the wording “an identifier that Microsoft uses for internal purposes.” A more detailed description appeared in the materials of the criminal case. A company spokesperson called the GDID a permanent device-level identifier that allows you to recognize a specific Windows installation in individual Microsoft services and scripts.
According to prosecutors, the FBI used GDID in the investigation of Peter Stokes, who is considered a member of Scattered Spider. Investigators observed its supposed activity for about eight months and compared technical data with accounts in social networks, gaming services and ecosystems of large technology companies.
In the case file there is a specific identifier. The investigation recorded it on the Ngrok registration page around the moment when the user created an account associated with the attack through the VPN proxy Tzulo. Three hours later, the same GDID appeared when visiting the website of the company that became the target of the attackers, and the connection again passed through the same proxy.
The FBI compared the identifier with the IP addresses associated with Stokes’ accounts in Snapchat, Facebook*, Apple and Ubisoft. Connections were recorded in Estonia, the United States, Thailand and other countries. Photos from the public Snapchat profile, according to the investigation, coincided with hotel reservations, travel routes and places where a computer with the same GDID appeared.
The investigation showed the weak point of the usual model of anonymity through a change of IP address. A VPN hides the source address of the user from the visited site, but does not necessarily interfere with the operating system to share official data with the developer. If Windows continues to tell Microsoft a regular identifier, new VPN servers don’t break the connection between individual sessions.
After a clean reinstallation of Windows, the system creates a new GDID. Completely break the previous connection may not work. Login to the same Microsoft account, the restoration of OneDrive and activation data allow the company to compare the new installation with the previous history of the device.
Researchers are concerned not only about the technical ability to track, but also the lack of understandable settings. Windows does not show a separate consent window, does not explain the purpose of GDID and does not offer a button to reset the identifier. Apple and Google allow users to manage advertising identifiers, while the Microsoft mechanism works lately and is associated with system functions.
According to experts, the blocking of services involved in the creation and transmission of GDID can disrupt the activation of Windows and the operation of Microsoft Store applications. Therefore, it is impossible to disable the identifier with a conventional switch without consequences. Microsoft also did not report plans to add separate settings or detailed documentation for users.
You can reduce the volume of connected telemetry through the “Privacy and Security” section in Windows settings. The system allows you to disable optional diagnostic data, personalized advertising, tracking application launch, action history and cloud search. A local account also reduces the number of connections to Microsoft services, although new versions of Windows 11 are increasingly requiring authorization during installation.
It will not be possible to completely hide from identification only with the help of a commercial VPN. The operating system, browser, applications and cloud accounts leave their own features that can be compared with each other. The case of Scattered Spider has become a rare public example of how much Microsoft is able to learn in detail the separate installation of Windows and transmit related information to law enforcement on a legal request.
Microsoft has not yet revealed what versions of Windows GDID works on, which services receive an identifier and how long the company stores the history of appeals. The most detailed public description of the mechanism is still not contained in the user documentation, but in a federal complaint against the alleged hacker.