AntiMalwareJuly 10, 2026🇷🇺Translated from Russian

Windows Tracks Users Through Persistent GDID Identifier: How to Minimize Your Digital Footprint

The case of a 19-year-old hacker who was tracked down using his Windows GDID identifier has once again demonstrated that Microsoft maintains a persistent device fingerprint that is difficult to erase. Even when users rely on VPNs or frequently change IP addresses, the underlying Windows installation remains recognizable to Microsoft services through this unique identifier.

What is GDID and Why It Matters

GDID is a permanent device identifier used across Microsoft’s ecosystem, including licensing verification, the Microsoft Store, telemetry collection, and various cloud services. Because it is tied directly to the Windows installation, it survives network changes and creates a stable link between a user’s device and their activity history.

Practical Steps to Reduce Tracking

Although Microsoft does not provide a single switch to disable GDID entirely, users can take several concrete measures to limit data exposure:

  • Use a local account instead of a Microsoft Account. Signing in with a Microsoft Account strengthens the connection between the device, OneDrive, the Store, and activity history. A local profile remains significantly more private.
  • Disable activity history. Navigate to Settings → Privacy & security → Activity history and turn off the option to store activity history. This may affect features such as cross-device synchronization and the cloud clipboard, but it reduces the data sent to Microsoft.
  • Limit diagnostic and feedback data. In Settings → Privacy & security → Diagnostics & feedback, disable the sending of optional diagnostic data. While basic telemetry cannot be fully removed, this step prevents the transmission of non-essential information.
  • Disable unused background services. Turn off Phone Link, Nearby Share, cloud synchronization, unnecessary AI features, and any startup programs that connect to Microsoft servers. The fewer connections to the Microsoft ecosystem, the smaller the digital footprint.

It is important to note that reinstalling Windows does not automatically solve the problem. While a fresh installation generates a new GDID, signing back into the same Microsoft Account allows Microsoft to link the new installation with previous ones through account activity, license activation, and service history.

Related articles

HabrPrivacy & Surveillance

Gesture Dynamics CAPTCHA Emerges as Privacy-Focused Drop-in Alternative to reCAPTCHA

A new open-source CAPTCHA system called Aptogon replaces traditional image-based challenges with analysis of hand gesture dynamics to verify human users. Instead of clicking on traffic lights or buses, visitors draw a free-form gesture for about ten seconds while the system measures velocity variance, pause entropy, rhythm irregularity, and micro-corrections that distinguish human motor patterns from bots. The solution addresses recent reCAPTCHA restrictions, including Google's reduction of free monthly verifications from one million to ten thousand and tightened GDPR data responsibility rules starting in April 2026. An iframe architecture loaded from the vendor origin eliminates cross-origin issues and CORS blocks while supporting public and secret key pairs for domain validation. Machine learning relies on a local gradient boosting model for confident decisions and an LLM only for borderline cases, with fail-closed behavior returning 503 errors when the classifier is unavailable. Coordinates never leave the browser; only derived statistics are sent, satisfying GDPR requirements without cookie banners or biometric templates. The project is released under AGPL-3.0 with a free tier of one thousand checks per month and integration examples for HTML, React, Node, Python, and PHP.

HabrPrivacy & Surveillance

Cat Tunnels Service Deploys Kotator-Rotator to Counter Mass Blocking of Relay Nodes in Russia

The operators of the decentralized Cat Tunnels service faced a sudden wave of blocks that disabled all several dozen of their tracker nodes inside Russia. Without these anchor relays, new user connections slowed dramatically and existing sessions degraded. The team responded by building Kotator-Rotator, an automated system that continuously evaluates node reachability from the client side and replaces failing relays with fresh instances. The decision engine relies on Grohotator, an aggregated availability metric derived from client technical logs that also triggers an audible alarm when thresholds are crossed. Analysis of the logs revealed that blocking activity follows a clear weekday pattern, pausing on Friday evenings and resuming Monday mornings. The experience demonstrated that server-side health checks alone are insufficient when censors interfere with paths between clients and relays.

AntiMalwarePrivacy & Surveillance

Google Chrome Tests Visible Global Privacy Control Toggle in Canary

Google is testing a new visible toggle for Global Privacy Control in Chrome Canary that lets users send a standardized request asking websites not to sell or share their personal data and not to use it for targeted advertising. When enabled, the browser adds the Sec-GPC: 1 header to web requests and exposes the setting via navigator.globalPrivacyControl. In regions with supporting laws such as California's CCPA, the signal can serve as a formal opt-out from data sales. The feature currently appears primarily on Android, with experimental flags available on Windows, macOS, Linux, and ChromeOS, though the desktop interface remains incomplete. Two separate flags are required—one to show the toggle and another to actually transmit the signal—because enabling only the UI does not send Sec-GPC: 1. The mechanism is not a guaranteed enforcement tool; websites decide how to respond, and effectiveness depends on legal frameworks and site compliance. The feature is absent from the stable Chrome release and may still change before wider rollout.

AntiMalwarePrivacy & Surveillance

OpenAI ChatGPT Computer History Feature on macOS Could Expose Detailed User Activity Logs to Infostealers

OpenAI has introduced the Computer History feature in its macOS ChatGPT app, which records application switches, clicks, keystrokes, and accessibility context to generate AI summaries and memories. The feature is disabled by default and requires explicit activation of Memories, with availability limited to Pro, Business, and Enterprise users outside the EEA, Switzerland, and the UK. While raw event files are deleted after 48 hours and not used for model training, the resulting Markdown memory files remain unencrypted on the local Mac. These files can be read by any process running under the same user account, creating a ready-made activity log for infostealers and other malware. OpenAI also warns about prompt injection risks where hidden instructions from websites or apps could influence ChatGPT or Codex behavior. Users retain controls to select participating apps, pause collection, or delete history, but the lack of encryption on stored memories raises significant privacy concerns.