The Arrest That Exposed Windows' Hidden Tracking Mechanism
A 19-year-old alleged hacker boarded a flight in Helsinki this April carrying two two-terabyte hard drives, believing his VPN and multiple aliases had kept him anonymous. He was wrong. What tripped him up wasn't a slip in operational security—it was a permanent, server-generated identifier embedded in his Windows installation that he couldn't see, couldn't disable, and likely didn't know existed.
![]() |
| Credit: Google |
g: followed by a long decimal string, is assigned to every Windows installation—whether on a physical PC, laptop, or virtual machine—and it stays with that installation for life.What makes this different from the device identifiers we've all become accustomed to? Unlike cookies that can be cleared, advertising IDs that can be reset, or IP addresses that change with every network switch, the GDID persists through Windows updates, survives VPN connections, and provides Microsoft—and potentially law enforcement—with a permanent thread connecting your device to everything you do online.
What the GDID Actually Is—And Isn't
Microsoft's own description, buried in a federal criminal complaint, defines the GDID as "a persistent, device-level identifier designed to uniquely identify an installation of a Windows operating system on a device, either a physical device (e.g., a mobile phone or laptop) or virtual machine, across certain Microsoft services and scenarios".
But that clinical definition obscures what the GDID really is: a Microsoft Account Device PUID (Passport Unique ID), generated on Microsoft's servers, not derived from your hardware. Independent researchers who reverse-engineered the mechanism found that when you connect Windows to a Microsoft account, the Passport identity service contacts Microsoft's servers, which return this identifier. Windows then stores it locally in the registry at HKCU\SOFTWARE\Microsoft\IdentityCRL\ExtendedProperties.
The persistence claim is critical here. Reinstall Windows and you get a new GDID, but Microsoft retains the old one along with all the historical data tied to it. Your hardware may be identical, but the identifier changes because it's tied to the installation instance, not the machine itself. This means Microsoft's servers maintain an accumulating archive of every device identity you've ever used, linked together through your Microsoft account.
How the GDID Tracks Across Services—Even With a VPN
The Stokes case demonstrates the GDID's reach with unsettling clarity. According to the unsealed criminal complaint, Stokes used a VPN while hacking a luxury jewelry retailer in May 2025, stealing at least 77GB of data and demanding roughly $8 million in cryptocurrency ransom. The VPN should have obscured his real IP address.
But Microsoft's records showed that Stokes' GDID—the unique identifier g:6755467234350028—accessed the signup page for ngrok, a developer tunneling tool, at a specific timestamp. Hours later, the same GDID accessed the victim's site through the same VPN proxy. Over months, that same GDID appeared in IP address records from Tallinn, New York, and Thailand—locations that matched Stokes' travel history and even his social media posts.
The GDID effectively became a permanent anchor that no VPN could sever. While IP addresses changed and identities shifted, the device identifier stayed constant, allowing investigators to reconstruct a coherent timeline of activity across multiple services and jurisdictions.
Why This Matters Beyond Law Enforcement
For the average Windows user, the GDID raises uncomfortable questions that go far beyond criminal investigations. Here's the reality: Microsoft can associate your device's activity with your identity through a permanent identifier you cannot disable. There is no setting in Windows privacy controls to turn it off.
The identifier is embedded into a startling range of Windows services. Windows activation ties to it. Microsoft Store purchases and license verification carry it. Diagnostic data includes it. If you enable Edge's enhanced diagnostics, your browsing history gets attached to it. Cross-device features like Phone Link and cloud clipboard sync rely on it. Even Delivery Optimization—the system that distributes Windows updates—reports it through diagnostic data.
This means Microsoft potentially has a record of your device's activity across third-party services, not just Microsoft ones. The company may be able to track which websites your Windows PC visited independent of your browser history and cookie settings. Privacy researchers have described the GDID as behaving "more like a covert tracking beacon than a typical advertising ID".
The Regulatory Blind Spot
Here's where the story gets legally interesting—and troubling. Under GDPR and similar privacy frameworks, unique device identifiers that can be linked to an individual are generally considered personal data. Yet Microsoft has never provided users with meaningful transparency about the GDID's existence, let alone an opt-out mechanism.
The company's public documentation on the GDID has been minimal. Until the Stokes case forced its hand, Microsoft had acknowledged the identifier in exactly one sentence of its Azure Monitor reference documentation, describing it as something used "internally by Microsoft". No consumer-facing privacy notice explains what the GDID is, how it's used, or who it might be shared with.
This lack of transparency matters because the GDID isn't just a technical curiosity—it's a surveillance capability baked into the world's most popular operating system, affecting roughly 1.6 billion PCs globally. Users cannot meaningfully consent to something they don't know exists.
What You Can—and Can't—Do
The honest answer to "how do I disable the GDID?" is: you can't. The identifier is generated server-side when Windows communicates with Microsoft's account infrastructure. Disabling it would require breaking the underlying Microsoft Account sign-in service, which would also break Store access, cloud sync, and activation.
However, you can reduce the amount of data attached to it. Using a local Windows account instead of a Microsoft account limits how easily Microsoft can tie the GDID to your personal identity. Turning off optional diagnostic data through Settings > Privacy & security > Diagnostics & Feedback reduces telemetry transmission. Disabling activity history—though this affects convenience features like Phone Link—can further limit data collection.
These measures are mitigations, not solutions. They reduce what Microsoft collects but don't eliminate the underlying identifier. The only way to truly escape the GDID's tracking is to stop using Windows entirely—a step few users are willing or able to take.
The Broader Implication: When Convenience Becomes Surveillance
The GDID story reveals something fundamental about the trade-offs embedded in modern computing. Device identifiers are genuinely useful—they enable seamless sign-in, license verification, and cross-device experiences. But when those identifiers become permanent, inescapable, and opaque to the user, they cross a line from utility to surveillance.
Microsoft's defense will likely be that the GDID serves legitimate purposes: fighting cybercrime, preventing fraud, and managing licenses. Those aren't invalid arguments. The Stokes case actually demonstrates the public safety value of such tracking—a prolific hacker was caught because his Windows device couldn't hide.
But the absence of transparency and choice is the problem. Users should have the right to know what identifiers their devices carry, how those identifiers are used, and whether they can opt out. Microsoft's silence on the GDID until a criminal complaint forced disclosure suggests the company understood this would be an uncomfortable conversation.
What Happens Next
The GDID is unlikely to disappear. Microsoft needs device identifiers for its ecosystem to function, and the company has shown no inclination to remove or provide opt-outs for this one. But the public revelation may accelerate regulatory scrutiny. Privacy advocates are already asking whether the GDID complies with GDPR's requirements for transparency and consent. European regulators may demand answers Microsoft has so far avoided providing.
For Windows users, the practical takeaway is sobering: your operating system contains a permanent tracking mechanism you cannot disable, and Microsoft has been less than forthcoming about it. The Stokes case didn't create the GDID—it just exposed it. Now that the exposure has happened, the question is whether Microsoft will respond with genuine transparency or continue treating user privacy as an inconvenient afterthought.
.webp)