A privacy story about Windows has been making the rounds this month, and the scary version, "Microsoft is secretly tracking you and there's no way to stop it," is a good deal more alarming than the reality. But the real version still carries a lesson worth knowing, especially if anyone at your business assumes a VPN makes them anonymous.
What actually happened
Researchers and journalists documented a persistent identifier that Windows assigns to a device, sometimes called the Global Device Identifier, or GDID. It is tied to your device and your Microsoft account, there is no consumer opt-out, and removing it breaks Windows activation. It came to public attention through a U.S. federal court filing: investigators used a device's identifier to help link an alleged member of the Scattered Spider hacking group to activity that had been routed through VPNs and proxy servers. Microsoft had documented the identifier only briefly, in a technical reference aimed at enterprise administrators, not in anything an ordinary user would ever see.
What it is, and what it is not
It is worth being precise, because the headlines are not:
- What it is: a stable, device-level identifier that can, with legal process such as a warrant, help tie online activity back to a specific machine, even when a VPN is hiding the network address.
- What it is not, on the evidence so far: it is not Microsoft broadcasting your browsing history to advertisers, and it is not mass surveillance of the public. The case that exposed it was law enforcement, using legal process, to de-anonymize a specific criminal suspect. That is a very different thing from being spied on and sold.
So this is not a five-alarm fire, and you do not need to abandon Windows. What it is, is a useful and slightly uncomfortable reminder about how privacy on modern devices actually works.
The real lesson: a VPN is not anonymity
If there is one thing for a small business to take from this, it is this. A VPN encrypts your traffic and hides your address from the websites you visit, which is genuinely useful. It does not make you anonymous. It does nothing about device-level identifiers, the accounts you sign into, or the fingerprint your browser leaves. Anyone on your team who believes "we run a VPN, so we're private" is working from the wrong mental model, and that mistaken confidence is more dangerous than the identifier itself.
The broader point is that modern operating systems and apps collect identifiers and telemetry as a matter of course. Some of it you can reduce; some of it, like this identifier, you cannot fully remove. Privacy is not one magic switch. It is understanding what your tools actually collect and setting realistic expectations around it.