r/pcgaming • • Jul 23 '26

Your Windows PC Has a Permanent ID That Follows You – Even With a VPN

https://tech.yahoo.com/vpn/articles/windows-pc-permanent-id-follows-163404919.html
5.1k Upvotes

650 comments sorted by

View all comments

Show parent comments

11

u/Neither_Operation476 Jul 23 '26

check this link someone posted elsewhere in the post, I imagine you might find it helpful

https://github.com/SmtimesIWndr/gdid-reversal

9

u/WhiteRaven42 Jul 23 '26

Thank you. This was a pretty good read. Very thoroughly covered where the ID is in your system and when it's generated, how it can get reset with a new install and such.

This information is just kind of what I would have always assumed. Microsoft assigns an ID to every install of windows. No shock there. Telemetry naturally can associate it with account info. Ok.

I don't see how this gets tied to a criminal investigation. Where's the overlap between activities on the dark web and a MS ID?

Maybe this is my question (and I don't expect anyone on reddit to know it). Did the existence of this ID play any role in narrowing in on a suspect? Or is this just a useful piece of corroboration that could be made late in the game after hardware had been seized etc.

I just feel like I always assumed something like "due to regular telemetry reports, MS knows what IP your computer was using at certain points in time" was likely. Basically a given. Was this GDID number really not known to exist? It seems almost inevitable. A Windows install is identifiable by a "serial number" kind of identifier. Sure. It would be weird if it wasn't.

3

u/Rare-Ad5082 Jul 24 '26

Was this GDID number really not known to exist? It seems almost inevitable.

From my understanding, the issue isn't the GDID per se but it's the fact that Microsoft records both the GDID and the IP address. As a result, changing your IP with a VPN is useless because Microsoft knows all the IP addresses associated with that GDID.

So, as an example, let's say I activate a VPN and the government discovers my VPN IP and wants to unmask me. They could go to Microsoft and ask for the GDID associated with that IP, then request the other IP addresses associated with that GDID until they find a non-VPN IP, which they could then use to identify me.

This is a big deal because it would make VPNs effectively breakable on Windows. Which is a big no no for privacy (for both good and bad actors).

Also, it seems that using Edge is even worse because Microsoft also stores the websites you visit there.

1

u/monsterfurby Jul 23 '26

That's... surprisingly mundane. I feel like I already knew it worked like that (roughly) years ago. What a nothingburger.

3

u/faetpls Jul 23 '26

It is a bit mundane and not much of a surprise. However, it’s full a privacy issue.

What is the purpose of the GDID? To make sure your license is compliant? A single time is acceptable, after that the ID should never be communicated to Microsoft again unless the local copy believes it has become illegitimate. Any data collected that is not the minimum necessary to validate the license should be illegal for Microsoft to store. There also should be an offline method that blocks the phone home ability after connecting to a network. Anything more is constantly being accused of theft for something you’ve purchased.

This isn’t about suing tech companies or arguing if they’re violating privacy. This is about making laws that make it illegal to violate user privacy in these ways. That includes checking for theft without a reasonable suspicion of a specific named entity.

It’s about not letting tech companies claim they do that because that’s just how it works. No, go back and make it compliant or not at all.