Microsoft uses a Global Device ID (GDID) in Windows. This makes Windows installations uniquely identifiable, survives reboots and Windows updates, and cannot be removed. This continues to cause a stir – but it shouldn't really surprise anyone. What's actually surprising is that the GDID has now held up in court and led to the identification of a suspected perpetrator.
Fundamentally, such mechanisms are already known in Windows operating systems. For example, tinkerers notice this when they replace an SSD or a motherboard. Windows then asks for a new activation – the system's machine IDs no longer match. However, the GDID goes a step further. Microsoft also documents it, albeit somewhat hidden in references for Azure cloud systems. There, the “GlobalDeviceID” appears as a string. The description explains that it is Microsoft's Global Device Identifier, which Microsoft uses internally.
On GitHub, a user with the handle “SmtimesIWndr” has taken the trouble to gather information about the Windows GDID. It is said to be a component of Windows telemetry that is sent to Microsoft's servers along with other information. This happens regardless of whether Windows was set up with a Microsoft account or a local account.
GDID can be used for user identification
About three weeks ago, it became known that a suspected member of the cyber gang “Scattered Spider” was indicted. The criminal complaint states that the defendant was identified by the Windows GDID despite using VPN services. The documents explain, for example, that Microsoft's cybersecurity researchers have access to data such as computer machine IDs, IP addresses, and malware samples. Accomplices of the criminals can therefore be identified by the use of the same IP address that the original perpetrator used.
On page 30, the prosecutors explain that the defendant could be identified by a specific Global Device Identifier. According to Microsoft, it is a persistent device-level identifier that allows for the unique identification of an installation of the Windows operating system on a device – whether physical or virtual machine – through certain, not further specified Microsoft services and scenarios. While the GDID survives updates and reboots, it is regenerated upon reinstallation, Microsoft admits there.
The Global Device Identifier cannot simply be gotten rid of. In general, Windows' need to communicate can be somewhat curbed with a few simple steps. Those who want more privacy without a unique GDID can, for example, always set up new VMs and work with them, which then always provides a new GDID. However, those who don't want this have to switch to other operating systems. The probability that operating systems from other major corporations like Android, ChromeOS, or macOS contain similar mechanisms is high, however. The most obvious solution is therefore to switch, for example, to Linux.
(dmk)
Don't miss any news – follow us on Facebook, LinkedIn or Mastodon.
This article was originally published in German. It was translated with technical assistance and editorially reviewed before publication.