Microsoft Brings “Age Verification” System To Windows

Just in time for the global digital ID agenda playing out, Microsoft has published instructions for developers on how to use an API that is not yet active.

The API, or programming interface, is designed to let apps on the Windows 11 operating system find out a user’s age bracket, and whether that age has been verified by an “identity provider.”

The age bracket is very broad: under 10, 10-12, 13-15, 16-17, and 18 and over. The verification status, on the other hand, can be one of five options: Verified, Unverified, OptedOut, TemporarilyUnavailable, or NotApplicable.

Microsoft does not go into what these identity providers will be, or what evidence they will use to verify a person’s age. The company only says that the second value returned by the API will show “whether the user’s age has been independently verified by the identity provider.”

Microsoft frames this as a way to improve privacy, by giving app developers a way to determine a user’s age without actually knowing their date of birth, or any other personally identifiable information. According to Microsoft, this is a “privacy-preserving mechanism” that will allow apps to comply with regulations concerning child safety. But, as we’ve seen from bills that call for this type of technology to be installed in operating system, this is all about normalizing age checks (and therefore ID checks) at all stages of digital life.

In this case, an age signal does not directly expose the user’s age or date of birth. Instead, it provides a way to adapt content, features, or access controls in an app based on the user’s age range and age verification status. For example, an app can use the age signal for user-generated content, social or communication tools, in-app purchases, virtual currencies, or maturity-rated media.

Microsoft goes into some detail about how developers can use the API, but notes that it is not yet available and will not return any useful data until it is turned on later in the year. For now, the company is providing the documentation ahead of the release to give developers a head start.

In January 2024, Microsoft was more cautious about the possibility of creating a system to determine a user’s age online. At the time, the company said it was exploring various methods and seeking expert input, but was not sure that the technical solution was there yet.

“There is currently no clear technical solution to age assurance that achieves the accuracy needed to effectively identify or verify a user’s age without risking trade-offs such as potential security, privacy, and human rights risks,” a Microsoft blog post said at the time.

California has since created its own framework for age verification.

Keep reading

Microsoft knows your entire browser history — and it can send it to the FBI

Virtual Private Networks are meant to shield your browsing history from all manner of prying eyes, including your internet service provider, your workplace or school, and even potential hackers. If you use a VPN with your Windows PC, though, I have some bad news: Microsoft has a full record of your browsing habits, and it can even report your activity to the FBI.

According to court documents released on July 1, a 19-year-old young man working with the cyber criminal group known as Scattered Spider was caught hacking into a computer system belonging to a luxury jewelry store. While inside, the hacker stole company data and demanded $8 million in cryptocurrency for ransom. Ultimately, the jewelry store kicked the hacker out of its system without paying the ransom, and the perpetrator was later arrested and charged.

It’s a simple case of conspiracy, digital intrusion, and fraud … but there’s a catch.

The hacker’s identity should have been hidden from the feds.

Keep reading

Microsoft Word’s Woke New Feature Will Help You Always Be Inclusive Of ‘Every Gender’

Microsoft Word introduced a new “inclusiveness” feature to look for supposed bias in documents — including language it deems not representative of “all genders.”

Clarity, formality, conciseness and now inclusiveness are all categories of “refinements” Microsoft offers under the editing tool on Word. The woke tool suggests changes to make word choice “inclusive of all genders,” like changing “chairman” to “chairperson” and “mankind” to “humankind” or “humanity,” among many others, as a Consumers’ Research video shows. 

Microsoft did not immediately respond to the Daily Caller News Foundation’s request for comment.

“It’s hardly surprising that Microsoft has an ‘inclusiveness editor’ for Word documents so that users are forced to comply with woke madness. Suggesting users change common words like ‘mankind’ and ‘firemen’ to be more gender-neutral is not a true grammatical error; it is a targeted ideological tactic to remove the very notion of gender from society,” Will Hild, executive director of Consumers’ Research said in a statement to the DCNF.

This adds to Microsoft’ efforts to support woke ideology, which include donating money to “groups promoting gender ideology on kids” and offering a library of videos to train people on being inclusive, according to Consumers’ Research.

The company’s innovation has come from its “commitment to [d]iversity and [i]nclusion,” Lindsay-Rae McIntyre, Microsoft’s Chief Diversity Officer and Corporate Vice President of Talent and Learning, said in Microsoft’s 2024 Global Diversity and Inclusion Report.

Keep reading

Microsoft Confirms Windows GDID Device Identifier That Cannot Be Disabled, Documented in FBI Case Filing

Microsoft has publicly acknowledged the existence of the Global Device Identifier (GDID), a device-specific ID assigned to Windows installations, in a federal complaint filed by US prosecutors against an alleged member of the Scattered Spider hacking group.

The ID is generated when Windows is set up with a Microsoft Account, persists through Windows updates, and cannot be disabled without affecting Windows activation and Microsoft Store apps.

Microsoft briefly mentioned GDID in the Azure Monitor documentation, describing it only as “an identifier used by Microsoft internally.” The complaint cites a Microsoft representative describing GDID as “a persistent, device-level identifier designed to uniquely identify an installation of a Windows operating system on a device, either a physical device such as a mobile phone or laptop or a virtual machine, across certain Microsoft services and scenarios.”

What the Windows Global Device Identifier Is and How the FBI Used It

The Global Device Identifier (GDID) is a permanent ID assigned when Windows provisions against a Microsoft Account. It is generated by a chain of Windows services.

The wlidsvc service requests a Device PUID from login.live.com, which is then registered into Microsoft’s Device Directory Service by the Connected Devices Platform.

Delivery Optimization reports the GDID back to Microsoft when the PC shares or downloads updates. This identifier is stored in the Windows registry under HKCU\SOFTWARE\Microsoft\IdentityCRL\ExtendedProperties and formatted with a lowercase “g” prefix followed by a decimal number.

It is reported to Microsoft servers and remains persistent across Windows updates, but it is not retained after a clean reinstall. Microsoft has acknowledged that one user can have multiple GDIDs linked through their account, OneDrive, and activation history.

The FBI used the GDID to track Peter Stokes, alleged member of Scattered Spider, across VPN connections, proxy servers, and through four countries over roughly eight months.

According to the complaint, the GDID g:6755467234350028 was recorded visiting the ngrok signup page at the same time an account used in the attack was created via a Tzulo VPN proxy. Three hours later, the same GDID accessed a victim retailer’s website through the same proxy.

The device was cross-referenced with IP addresses linked to Stokes’s accounts on Snapchat, Facebook, Apple, and Ubisoft across Estonia, New York, Thailand, and other locations. Stokes’s public Snapchat photos matched hotel bookings, locations, and travel timelines associated with the GDID.

The persistent nature of the GDID across VPN sessions proved a key investigative asset. While VPN IP addresses change frequently, the underlying Windows installation continued reporting the same identifier, aiding investigators in their tracking efforts.

Keep reading

CISA: Windows BlueHammer flaw now exploited by ransomware gangs

CISA confirmed on Monday that ransomware gangs have begun exploiting a high-severity Microsoft Defender privilege escalation vulnerability that has previously been abused in zero-day attacks.

Dubbed BlueHammer, the security flaw (CVE-2026-33825) was leaked by a security researcher known as “Nightmare Eclipse” in early April, together with proof-of-concept exploit code, in protest at how the Microsoft Security Response Center (MSRC) handles the disclosure process.

“Insufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges locally,” Microsoft explains in a security advisory.

Will Dormann, principal vulnerability analyst at Tharros, told BleepingComputer in April that while the issue is not easy to exploit, it gives local attackers access to the Security Account Manager (SAM) database, which contains password hashes for local accounts.

With this access, they can escalate to SYSTEM privileges and potentially take complete control of the targeted system.

“At that point, [the attackers] basically own the system, and can do things like spawn a SYSTEM-privileged shell,” Dormann said.

Keep reading

Nadella’s Hedge: Microsoft Wants To Make AI Models Cheap – Then Own The Rails They Run On

The entire AI capital cycle – roughly $700 billion in hyperscaler capex this year, an estimated $2 trillion-plus through 2028 – is collateralized by one belief: that intelligence is scarce, and therefore priceable. That belief is already under strain. Per-token inference prices have fallen on the order of 200× in a year, and the only thing holding revenue up is volume; the cost of intelligence is dropping even as the cost of deploying it climbs. Hyperscaler free cash flow is rolling over. The Fed has named AI capital spending a systemic risk. 

And after falling behind in the race to build the best AI, Microsoft is setting up for a massive hedge. The company is on track to spend north of $120 billion this fiscal year – most of it on GPUs and the data centers that house them, $37.5 billion in a single quarter alone, pushing free cash flow negative for the first time in a generation. That is a company betting intelligence is scarce. Yet to the Wall Street Journal last week, Nadella argued the opposite is coming – that intelligence is about to get cheap. The tell isn’t a contradiction. It’s a hedge: if you can’t win the race to build the best model, you make the model worthless and own the road it runs on.

Microsoft is already executing on the hedge. In the weeks surrounding the interview, the company rolled out a new wave of lower-cost models and made Copilot Cowork generally available worldwide – an autonomous agent designed for long-running tasks that lets users (or the system) dynamically route work across multiple models, explicitly including cheaper options. Axios reported that Microsoft is also actively weighing whether to host a version of DeepSeek, the ultralow-cost Chinese model, directly inside Azure for Copilot customers. The model would be optional for users, fully hosted on Microsoft’s infrastructure, and wrapped in the company’s enterprise security, compliance, and data-residency controls.

These aren’t side-quests, they are the product-level proof of the thesis: make intelligence abundant and interchangeable while keeping the customer, the data, and the workflow inside Microsoft’s perimeter.

Nadella believes intelligence is about to become abundant, interchangeable, and cheap, as a wave of agents routes work to the lowest bidder. And as the cost per unit of intelligence plummets, he wants Microsoft to own the rails it runs on.

Keep reading

Wife of Ex-Microsoft CEO Steve Ballmer Bails Out NPR With $80 Million Donation After Trump Cut Federal Funding

National Public Radio (NPR) has secured $113 million in donations as it continues to grapple with the fallout from major federal funding cuts under the Trump administration.

The largest donation, $80 million, came from philanthropist Connie Ballmer, the wife of former Microsoft CEO Steve Ballmer.

NPR said it is the biggest donation from a living donor in the network’s history.

The company said in a statement:

These gifts will be used to expand audience connection, accelerate digital transformation, and increase the sustainability of the national NPR Network. These gifts are extraordinary and unprecedented commitments that will help secure NPR’s future as America’s premier public service journalism network.

Philanthropist Connie Ballmer has given $80 million to support the digital innovation that is essential to meeting the needs and serving the interests of public media audiences wherever they are and whenever they seek information.

Further gifts from an anonymous donor totaling $33 million will go towards strengthening and increasing the sustainability of the NPR Network, enabling NPR to build and acquire tools and services that will be shared with public media organizations serving communities across the nation.

I support NPR because an informed public is the bedrock of our society, and democracy requires strong, independent journalism,” said Ballmer. “My hope is that this commitment provides the stability and the spark NPR needs to innovate boldly and strengthen its national network.

Despite being a public broadcasting organization, NPR is notorious for its aggressive left-wing bias and support for the Democratic Party.

The funding boost comes after Congress slashed roughly $1.1 billion from public broadcasting last year, putting over 200 NPR stations and hundreds of PBS outlets at risk.

NPR CEO Katherine Maher said the donations would help secure the network’s long-term financial footing.

Keep reading

Xbox Now Wants Your Face to Let You Play Games You Already Own in Singapore

Singapore gamers who bought and downloaded Xbox titles years ago are now being told they need to prove they’re adults before they can keep playing them.

Microsoft has started rolling out identity verification requirements across its Xbox and Microsoft Store platforms in Singapore, demanding face scans, government ID uploads, or authentication through the country’s national digital identity system, Singpass.

The price of accessing games you already own is now a biometric selfie or a copy of your passport.

The trigger is Singapore’s Online Safety Code of Practice for App Distribution Services, a regulation from the Infocomm Media Development Authority (IMDA) that took effect on April 1, 2026.

The rule requires app stores to prevent anyone estimated to be under 18 from downloading apps rated for adults, including dating services and content with sexual material. Five storefronts are covered: Apple’s App Store, Google Play, Samsung Galaxy Store, Huawei AppGallery, and Microsoft Store (which includes Xbox).

Each company has chosen its own methods for compliance. The methods vary, but they all share one thing in common: they collect sensitive personal data that didn’t exist in the platform’s records before this regulation.

Microsoft announced its approach on March 17, 2026, framing the verification as optional, while making it mandatory for anyone who wants full access.

“Microsoft users in Singapore will have multiple options to complete age assurance for our stores, giving people flexibility while prioritising privacy,” the company wrote, listing those options as Singpass verification, “secure facial age estimation using a selfie,” or uploading “an official government ID such as a national ID, driver’s license, passport, or residence permit.”

The company describes this as a one-time process. What it doesn’t describe is who processes the data, how long it exists in transit, or what happens if the system holding it gets breached.

Discord learned this lesson last year when its own partner leaked user data. The company that promises to delete your face scan still has to receive it first.

Singapore residents have started receiving emails from Xbox notifying them about the verification requirement, prompting confusion and concern.

Keep reading

Microsoft says Copilot is for entertainment purposes only, not serious use — firm pushing AI hard to consumers and businesses tells users not to rely on it for important advice

Microsoft used to push its AI services towards its user base, especially with the launch of the Copilot+ PC, but it seems that even the company itself does not trust its creation. According to the Microsoft Copilot Terms of Use, which was updated in October last year, the AI large language model (LLM) is designed for entertainment use only, and users should not use it for important advice. While this may be a boilerplate disclaimer, it’s quite ironic given how hard the company wants people to use Copilot for business uses and has integrated it into Windows 11.

“Copilot is for entertainment purposes only. It can make mistakes, and it may not work as intended,” the document said. “Don’t rely on Copilot for important advice. Use Copilot at your own risk.” This isn’t limited to Copilot, too. Other AI LLMs have similar disclaimers. For example, xAI says “Artificial intelligence is rapidly evolving and is probabilistic in nature; therefore, it may sometimes: a) result in Output that contains “hallucinations,” b) be offensive, c) not accurately reflect real people, places or facts, or d) be objectionable, inappropriate, or otherwise not suitable for your intended purpose.”

These may sound common sense for people familiar with how LLMs work, but, unfortunately, some people treat AI output as gospel, even those who are supposed to know better. We’ve seen this with Amazon’s services, after some AWS outages were reportedly caused by an AI coding bot after engineers let it solve an issue without oversight. The Amazon website itself has also been hit with a few “high blast radius” incidents that were linked to “Gen-AI assisted changes,” resulting in senior engineers being called up in a meeting to resolve the matter.

Keep reading

Energy bills set to spike for Washington state residents — while Microsoft gets rate cut: report

Electric bills are set to jump more than 16% for 1.25 million Washington state residents — even as Microsoft gets a rate cut under a special deal, according to a report.

Puget Sound Energy, a utility company that is owned by a consortium of Canadian and Dutch pension funds, is seeking state government approval for rate hikes of 16.75% next year, 3.76% in 2028, and 8.81% in 2029.

The request, which is subject to approval by Washington’s state regulators at Utilities and Transportation Commission, also includes a proposed rate cut for Microsoft, according to the local news site Zoned Out PNW.

If PSE gets its way, the Redmond, Wash.-based software giant, which as of Wednesday boasted a market capitalization of $2.76 trillion, will see its rates slashed by 12.49% next year; 2.04% in 2028; and 3.06% in 2029.

The UTC board is chaired by Brian Rybarik, who held various roles at Microsoft before he was appointed to his current position by Gov. Bob Ferguson, a Dem.

Microsoft reportedly qualifies for the rate cuts because the tech giant falls under the category of a “special contracts” customer.

Keep reading