Computing Microsoft's Global Device Identifier Revealed as Tracking Tool in Cybercrime Case
Article Content
- •Microsoft's GDID tracks user behavior across all Windows installations since Vista.
- •The GDID played a crucial role in identifying a cybercriminal linked to a major data breach.
- •Concerns have been raised about the transparency and privacy implications of the GDID.
A US court filing has disclosed that Microsoft's Global Device Identifier (GDID) tracks user behavior across Windows installations. This persistent key, tied to every Windows OS since Vista, is generated on Microsoft's servers and stored locally, enabling tracking of various services like Edge and the Microsoft Store. The GDID was instrumental in tracing a cybercriminal, Peter Stokes, who was arrested for a major data breach involving a jewelry retailer. Stokes used the GDID while accessing the victim's site through a VPN, leading to his identification by the FBI. While Microsoft claims the GDID is for internal use, its lack of transparency raises concerns among users and security experts. The incident highlights the potential misuse of such tracking mechanisms in cybercrime.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both…