In what should be a surprise to absolutely nobody, Microsoft assigns a persistent identifier to every Windows installation, tying it to its user, and the company has no issues handing it over to law enforcement. Abhijith M B at windows Latest dove into the details, and it’s just as bad as you would expect.
Am I glad Stokes got caught? Yes, without hesitation. Thirty-five pages of a teenager bragging about diamond chains spelling out “HACK THE PLANET” while extorting a jewelry store don’t leave much room for sympathy, whatever role Microsoft’s telemetry played in building the case.
But that doesn’t make the GDID okay. Every company selling you software has some version of this, and a persistent device identity is a reasonable thing to build into activation and fraud systems. What gets me is that most people had never come across the term GDID before a federal court filing such as this. Microsoft wrote one sentence about it in an Azure Monitor reference table meant for enterprise IT admins pulling update reports, not for the 1.6 billion or so regular people whose PCs are generating this data.
You might be tech savvy enough to turn off Activity History, pick a local account, and strip out every scrap of optional telemetry, but none of it changes the fact that the identifier exists, and that it answers to your Microsoft Account instead of you. Microsoft only told the public about it once a court forced the issue.
↫ Abhijith M B at windows Latest
The thing is, even without this GDID, I can’t imagine Microsoft would have much trouble tying a Windows installation to a specific user. Consequently, I’m afraid the following is going to happen: this story gains even more traction, Microsoft removes the GDID, and everyone thinks the problem is resolved. Of course, in reality, any one of the hundreds of other metrics and data Microsoft collects can and will still be used in the exact same way as this GDID thing in this case.
If my experiences with Windows 11 weren’t clear enough – don’t use Windows. Just don’t.

Well it’s something i’ve said for years… Proper hackers don’t use windows except for throwaway testing instances in virtual machines and targets they’re breaking in to. Day to day activity happens on Linux or BSD, important data is stored on Linux or BSD. If you’re stupid enough to use windows for illegal activity then you’re clearly not very good at it and are going to get caught.
Even fans of microsoft are souring to microsoft’s agenda. Still, many people won’t boycott it; the reality is many consumers only know windows. Heck even linux users like me are still dependent on jobs that sometimes require windows. It’s incredible to me that customer happiness is so irrelevant to modern microsoft. They have no remorse going against their own customers. Coercively forcing anti-features is the official game plan.
A forced microsoft windows update just destroyed hours of work for me today. It was a long running process that must not be interrupted and yet the assholes at microsoft decided it would be hilarious to terminate it mid-run. There was an “update” alert and I selected “not now”, but I walked away from the desk for less than 10 minutes and when I returned microsoft killed my processes and started the update without permission. Owners don’t control their own machines.
The OS has become unfit for purpose for serious work,
To top it off, I use Firefox almost exclusively and microsoft once again replaced it with MS Edge. This has happened before, no surprise there, but I noticed something even more F’ed up this time: my firefox session (searches and web pages that were open in firefox tabs) got scraped from firefox and moved into MS edge without even asking. Anyone else notice this? Holly hell microsoft are going to sneaky lengths to steal market share from firefox.
This is getting ever more off topic, but in more bad news for firefox a few days ago I noticed that I was being blocked on every website “protected by cloudflare”. Apparently they botched a release and even though the FF browser passed all the checks. cloudflare was denying to it. It wasn’t just me, cloudflare outage reports were up on on downdetector. This lasted several hours. I took a screenshot:
https://i.postimg.cc/jjH5Yr3R/cloudflare-service-failure.png
Mistakes like this can and do happen, but I find the threat of denial of service becoming increasingly problematic as the web becomes more centralized around a few major providers. Even though it was an accident, cloudflare caused millions of websites to become inaccessible to me on firefox. Mainstream websites were effectively offline, blocked by cloudflare. Cloudflare are supposed to be the “good guys” but IMHO it is dangerous that the web is evolving around centralized gate keeping. Not that I have any choice in the matter.
I’m not feeling very optimistic about tech right now.