Microsoft Confirms Windows GDID Device Identifier That Cannot Be Disabled, Documented in FBI Case Filing

Microsoft has publicly acknowledged the existence of the Global Device Identifier (GDID), a device-specific ID assigned to Windows installations, in a federal complaint filed by US prosecutors against an alleged member of the Scattered Spider hacking group.

The ID is generated when Windows is set up with a Microsoft Account, persists through Windows updates, and cannot be disabled without affecting Windows activation and Microsoft Store apps.

Microsoft briefly mentioned GDID in the Azure Monitor documentation, describing it only as “an identifier used by Microsoft internally.” The complaint cites a Microsoft representative describing GDID as “a persistent, device-level identifier designed to uniquely identify an installation of a Windows operating system on a device, either a physical device such as a mobile phone or laptop or a virtual machine, across certain Microsoft services and scenarios.”

What the Windows Global Device Identifier Is and How the FBI Used It

The Global Device Identifier (GDID) is a permanent ID assigned when Windows provisions against a Microsoft Account. It is generated by a chain of Windows services.

The wlidsvc service requests a Device PUID from login.live.com, which is then registered into Microsoft’s Device Directory Service by the Connected Devices Platform.

Delivery Optimization reports the GDID back to Microsoft when the PC shares or downloads updates. This identifier is stored in the Windows registry under HKCU\SOFTWARE\Microsoft\IdentityCRL\ExtendedProperties and formatted with a lowercase “g” prefix followed by a decimal number.

It is reported to Microsoft servers and remains persistent across Windows updates, but it is not retained after a clean reinstall. Microsoft has acknowledged that one user can have multiple GDIDs linked through their account, OneDrive, and activation history.

The FBI used the GDID to track Peter Stokes, alleged member of Scattered Spider, across VPN connections, proxy servers, and through four countries over roughly eight months.

According to the complaint, the GDID g:6755467234350028 was recorded visiting the ngrok signup page at the same time an account used in the attack was created via a Tzulo VPN proxy. Three hours later, the same GDID accessed a victim retailer’s website through the same proxy.

The device was cross-referenced with IP addresses linked to Stokes’s accounts on Snapchat, Facebook, Apple, and Ubisoft across Estonia, New York, Thailand, and other locations. Stokes’s public Snapchat photos matched hotel bookings, locations, and travel timelines associated with the GDID.

The persistent nature of the GDID across VPN sessions proved a key investigative asset. While VPN IP addresses change frequently, the underlying Windows installation continued reporting the same identifier, aiding investigators in their tracking efforts.

Keep reading

Chip Roy Unveils Bill Requiring Hospitals Participating in Federal Healthcare Programs to Report Immigration Status Data

Rep. Chip Roy (R-TX) is introducing legislation that would require hospitals participating in federal health care programs to ask patients to indicate their immigration status.

The hospitals would have to report aggregate totals, including the number of patients who say they are not lawfully present in the United States. 

Roy’s “Illegal Alien Patient Reporting Act” would amend Title XI of the Social Security Act and exclude hospitals from participation in federal healthcare programs if they fail to comply with the legislation’s reporting requirements.

“For years, Americans have watched overcrowded emergency rooms, rising healthcare costs, and strained hospital resources while being kept in the dark about the potential billions of taxpayer dollars spent on healthcare for those who are in the country illegally,” Roy told Breitbart News.

“That lack of accountability is unacceptable and absurd,” the Texas Republican continued. “The Illegal Alien Patient Reporting Act delivers the transparency and accountability Americans deserve by ensuring hospitals report the extent to which illegal aliens are adding to the fiscal burden of our healthcare system.”

Under the bill, hospital admission, registration, and other intake forms would be required to ask patients or their authorized representatives to indicate the patient’s immigration status.

Keep reading

Quote of the day by Sun Microsystems CEO Scott McNealy: ‘You have zero privacy anyway. Get over it’ — an early declaration foreshadowing the modern era

Sun Microsystems was a huge force in the technology landscape, with its co-founder and CEO Scott McNealy an outspoken and brash maverick in the early Silicon Valley ecosystem. The company had just launched a new system, and McNealy was quick to push back on any critique centering around the implications for user data.

During an informal Q&A session with reporters, McNealy slapped down concerns that the newly launched Jini platform could pose a risk to user privacy.

The system, as it was engineered, was a revelation – but ultimately failed to catch on due to some pretty significant hardware hurdles. Designed to allow devices to communicate with and share resources, the Jini network architecture allowed unadulterated communication without configuration, driver installations, or human intervention.

It was an early and ambitious effort to establish a vision for smart homes and offices. The trouble was that it required devices to continuously upload data and lease space on networks, with the system creating a massive digital footprint.

Erosion of privacy

McNealy’s comments, unsurprisingly, drew immediate and sharp criticism from privacy advocates and campaigners. Lori Fena, then chairman of the board of the Electronic Frontier Foundation, said the comments were “completely irresponsible”, for example.

Keep reading

Prince Harry Loses Years-Long Privacy Lawsuit Against Daily Mail Publisher, as Controversial UK Trip Is Off to a Bad Start

A victory for free press, or a whitewashing?

We have been reporting here on how Prince Harry’s UK trip ended up mired in controversy and logistical chaos.

He was just told by Buckingham Palace that he would not be able to stay there anymore for confirming his presence too late.

And in his first public engagement, Harry was dealt a big setback, as the Duke of Sussex lost his years-long, £50 million privacy lawsuit against Associated Newspapers Limited, the publisher of the Daily Mail and the Mail on Sunday.

Fox News reported:

“Harry and six other claimants, including Elton John and Elizabeth Hurley, lost their privacy case against the publisher. The U.K.’s High Court dismissed their claims after finding the claimants had failed to prove their allegations of unlawful information gathering.”

Keep reading

Mexican Government Delays Biometric Registration Deadline After Massive Public Resistance

Mexico’s President Claudia Sheinbaum has announced an extension to a controversial deadline that required Mexican citizens and foreign residents to register their phone lines with their identification. The move comes after less than half of the country signed up to register their phone lines.

On Thursday morning, Mexico’s Telecommunications Regulatory Commission (CRT) announced a staggered extension for citizens to register their mobile phone lines with their identification. This controversial requirement has received pushback and resistance from the Mexican population, many of whom question how their data will be stored and used.

According to the announcement, prepaid phone lines that have not yet been linked to an identity will now have until between August and December to complete the process, with the deadline based on the last digit of the phone number. The new policy states that after the deadline expires, telephone companies will suspend service to non-compliant lines within 72 hours.

“For the safety of all, every telephone number must be registered in the name of one person, in order to eliminate the anonymity that has allowed crime such as fraud or extortion,” the press release reads. “With this measure, Mexico will cease to be one of the few countries that allowed the acquisition of a SIM card without identification, and will join the international practice currently in place in 166 countries.”

Calls for a deadline extension have increased in recent weeks, as many critics believe the government did not adequately prepare the public for the change. In late May, Mexican billionaire Carlos Slim called for an extension because the process was “very complicated” and progressing slowly.

With the extension of the deadline, the Mexican government and telecom companies are hoping extra time is all that will be necessary to convince more than 50 million people to comply with the mandate. This may prove more challenging than they anticipated in a country well known for mistrust of official institutions.

The requirement to link a person’s ID with their phone line is a fairly new development in Mexico—one of the few places in the world where individuals could still purchase and use SIM cards in cellphones without registering a name or showing some form of identification. All of that changed in July 2025 when several new laws took effect that compel the population to register for a biometric program required to access many services, including phone and internet access. Phone users were originally instructed to register their phone line with their telecommunications provider before June 30, 2026, or face interruption of service. This would force businesses selling these services to check a customer’s CURP before purchase.

Keep reading

New EU proposal aims to stop drivers from speeding using satellites

According to the proposal, every new car would be equipped with a device that can limit the engine’s power for drivers who are speeding. This would be done remotely, based on their speed and location.

The system would use a combination of GPS technology, satellite data, and cameras to identify speed limits and monitor vehicle speed.

How would this work? First, satellites pinpoint the car’s location and determine its speed. Next, the car’s onboard cameras spot traffic signs that indicate the maximum speed. If a driver is speeding, the car’s built-in computer forces it to slow down to the maximum speed limit.

Safety campaigners believe the technology will significantly reduce casualties by 20%.

If approved, the system could be mandatory for all new vehicles in the EU by 2030.

The United Kingdom would be exempted because of Brexit. However, experts expect that car manufacturers will introduce the proposed technology in the UK as well, as it would be too expensive to build cars just for the UK market.

Shadow Transport Secretary Richard Holden has raised concerns about the technology’s reliability, fears of hacking, and doubts about drivers’ privacy.

Keep reading

The House Just Voted for KOSA, a Privacy and Free Speech Disaster

The House voted Monday night to build the machinery of online identity checks into federal law, packaging the mandate inside a bundle of kids online safety bills that cleared the chamber 267-117, with 47 members not voting.

It marks the first time any version of the Kids Online Safety Act, known as KOSA, has escaped the lower chamber, and the version that survived carries a structure that pushes platforms to figure out who you are before you can use them.

The legislation, called the Kids Internet and Digital Safety Act, or KIDS Act (H.R. 7757), stitches together more than a dozen separate bills, including KOSA, the SCREEN Act, the SAFE BOTs Act, COPPA 2.0, and the SPY Kids Act, plus data broker rules and research initiatives.

House leaders rushed it to the floor under suspension of the rules, a fast-track path requiring a two-thirds majority. Committee Chairman Brett Guthrie and ranking Democrat Frank Pallone, who announced their agreement a week earlier, said the bill would “hold Big Tech accountable” and described months of cross-aisle work toward what Guthrie called a “workable compromise.”

If you’ve been following our updates, you’ll know the accountability positioning hides the actual design. The bill defines “know” or “knows” to mean “to know or should have known,” and that phrase runs through sections covering platforms, AI chatbots, and gaming services.

A company that fails to spot a minor faces legal exposure, which gives every platform a reason to gather more information about everyone who shows up. The text tries to defuse this, stating that nothing in it may be construed “to require the provider of a covered platform to implement an age gating or age verification functionality on the covered platform.”

The reassurance collapses on contact. A platform forbidden from ignoring a user’s age, yet liable the moment it “should have known” someone was a minor, has one move left. It starts checking ages, deploying age-estimation tools, demanding ID, or watching behavior closely enough to guess. The law does not order surveillance outright, it engineers the incentive and lets companies build the rest.

That is the First Amendment problem dressed as a child-safety provision. Verifying age means verifying identity, and identity checks sit between a person and ordinary protected activity, whether that is reading, watching, posting, or speaking. Adult websites would face explicit age-verification requirements under the package, which functionally means every visitor proves who they are before viewing lawful content. Anonymous and pseudonymous speech, the kind the Supreme Court has shielded for decades, gets harder to find the more platforms lean on identity to limit their liability.

The bill tightens how data brokers handle children’s information and updates the Children’s Online Privacy Protection Act to widen its reach.

But, to do that, it would require platforms that know a user is a minor to offer controls that limit communications, restrict geolocation sharing, cut compulsive-use features, and let users opt out of personalized recommendation systems, with default settings for minors set to what the bill calls “the most protective level of control with respect to privacy and safety.”

These are strong protections on paper and would be good if they applied evenly to all users, but they all depend on the platform identifying minors first, which loops straight back to the same question of how much data gets pulled from users, adult or not, to sort out who the children are.

The encryption language carries the same gap. The bill says platform requirements may not override encrypted communications and that companies must comply in ways that “do not compromise the integrity of strong encryption.” That could read as a shield until you notice that regulatory pressure to monitor behavior or flag certain users can hollow out encryption without ever formally banning it. Compliance routes around the protection the text claims to offer.

Getting the package across the floor cost the duty of care provision, the piece many child-safety groups and KOSA’s Senate authors consider the heart of the bill. The text now states that nothing in it may be construed to “impose a duty of care on a provider of a covered platform.”

Sen. Richard Blumenthal (D-Conn.), a KOSA co-author, wrote that “KOSA without a duty of care isn’t KOSA,” and said last week that the House version is “dead in the Senate.” Sen. Marsha Blackburn (R-Tenn.), the other co-author, agrees the provision was central. Sen. Ted Cruz (R-Texas), who chairs the Senate Commerce Committee, told reporters he stays open to negotiating with the House.

That stalemate is the most encouraging thing about this whole fight.

The Senate’s standalone KOSA (S.1748) keeps the duty of care, which would legally require platforms to “exercise reasonable care” to prevent broad categories of harm to minors. On the free speech axis, that is the more dangerous of the two bills, not the safer one. A duty of care over vaguely defined harms compels companies to police or re-engineer recommendation algorithms for lawful, constitutionally protected content, under threat of liability so open-ended that the rational corporate response is to over-remove anything that might draw a lawsuit.

So neither chamber holds the civil-liberties high ground. The Senate bill compels platforms to suppress protected speech, while the House bill conscripts them into identity verification, and a conference committee tasked with reconciling the two could just as easily graft the worst of each onto a single law as split the difference.

The good news for anyone who values either anonymity or free expression is that the two chambers, each representing a different type of civil liberties disaster, do not appear close to agreement.

Keep reading

UNPRECEDENTED: EU Parliament President Roberta Metsola Pushing Controversial Scanning of Online Content, Ignoring That EMPs Have Already Rejected the Idea Multiple Times

Another EU tyrant on the move.

Leave it to the EU to have a dizzying number of ‘chiefs’, signaling a bloated bureaucracy that has become more of a problem than a solution for the issues that European nations face.

Fasten up for the list: the European Commissioner (currently Ursula von der Leyen/VDL): a ‘member of the European Commission’s College responsible for overseeing one specific policy area (portfolio), such as trade, climate, or digital affairs.’

The President of the European Council (currently Antonio Costa): ‘Chairs summits of EU heads of state and government, drives consensus on the EU’s overall political direction and priorities, and ensures the EU’s external representation at that level’.

High Representative of the European Union for Foreign Affairs and Security Policy (currently Kaja Kallas): ‘Leads and coordinates the EU’s Common Foreign and Security Policy (CFSP), chairs the Foreign Affairs Council, represents the EU on the world stage as its chief diplomat, and serves as a Vice-President of the European Commission’.

Hold on, that’s not all. President of the European Parliament (currently Roberta Metsola): ‘Chairs plenary sessions and key internal bodies, oversees the Parliament’s work and rules, signs adopted legislation, and represents the Parliament to other EU institutions and externally’.

Keep reading

AMD silently removes memory encryption from consumer Ryzen CPUs

According to a report by Ars Technica, AMD has quietly stripped a critical security feature from its lower-end CPUs, leaving unaware users potentially vulnerable to physical attacks. Following a months-long investigation tracked on GitHub, Ben Kilpatrick confirmed that the Transparent Secure Memory Encryption (TSME) feature — which protects CPUs against physical exploits that siphon data from connected memory chips — was suddenly no longer available on AMD CPUs outside the company’s Pro lineup.

As the exhaustive inquiry, which involved conversations with AMD engineers, board vendors, and other CPU users, was coming to a head, an AMD engineer abruptly cut discussions short, stating, “My apologies, but I don’t have any more information to share on this topic.” As of this report, AMD has neither officially acknowledged nor explained the disappearance of the security feature.

TSME is a protection feature that encrypts the data stored in memory, making it unusable to physical attackers. AMD initially added this feature to its high-end CPUs, then later extended it to lower-end CPUs. Eventually, the feature became a given, leaving lower-end chip users assured in its availability as part of the chip package. However, without prior notice, AMD appears to have scrapped the security feature in these processors.

According to the Ars report, the company’s only official reaction to the matter — not counting the GitHub discussions — is an email response stating that TSME “is a security feature only applied to PRO CPUs as part of AMD PRO Technologies,” notably the first time the company has publicly stated such a restriction, despite the feature having worked on consumer chips for years. However, it remains unclear whether the disappearance is an intentional policy decision by AMD to reserve TSME for Pro chips or an unintentional regression that was introduced in AGESA 1.2.7.0, a newer firmware release.

Another concerning aspect of the removal is that the feature’s disappearance is completely undetectable on Windows machines and requires significant technical work to identify on Linux. That means the security feature was removed, leaving users unaware that anything had changed.

Kilpatrick, a self-described “privacy-conscious Linux hobbyist” who first reported the change, was installing a new operating system on his machine running a Ryzen 7 9700X from the Zen 5 architecture. To confirm that all his security protections were enabled, he ran Host Security ID (HSI), an auditing feature that evaluates a system’s firmware and hardware security configurations. To his surprise, HSI reported that TSME was no longer supported — even though he had enabled it in his BIOS settings all along. The contradiction sent him searching for answers.

Keep reading

The KIDS Act: A Bipartisan Mass Surveillance Megabill

Just weeks after Americans criticized the United Kingdom for imposing intrusive and heavy-handed social media rules, Congress is now advancing legislation that raises strikingly similar concerns about government overreach, privacy erosion, and the expansion of online surveillance.

A bipartisan agreement on children’s online safety legislation unveiled by House Energy and Commerce Committee leaders would impose new obligations on social media platforms, while creating powerful incentives for companies to end online anonymity.

The proposal is part of the Kids Internet and Digital Safety Act (KIDS Act), an omnibus package that bundles together multiple bills, including the Kids Online Safety Act (KOSA), the SCREEN Act, the SAFE BOTs Act, COPPA 2.0, the SPY Kids Act, and more, as well as data broker provisions and research and education initiatives.

We obtained a copy of the bill for you here.

Committee Chairman Brett Guthrie and ranking Democrat Frank Pallone announced Monday that they had reached agreement on the legislation, which would require social media companies to provide additional safeguards and parental tools for minors. The lawmakers said it would “hold Big Tech accountable.”

“We worked across the aisle for many months and have now found common ground on policies to significantly improve the digital environment for kids,” Guthrie and Pallone said in a joint statement.

As always, under that framing lies a familiar and deeply controversial approach: imposing broad obligations on platforms that hinge on whether companies know a user is a minor, without clearly defining how that knowledge is supposed to be obtained.

Congress has tried for years to set national rules for social media and youth safety. Those efforts have repeatedly stalled, in part because of unresolved tensions between child protection goals and fundamental privacy rights. In the absence of federal action, states have moved ahead with their own laws, often pushing even more aggressive requirements.

One of the main disputes appears to have been resolved in favor of House Republicans. According to a committee spokesperson, the agreement does not include a “duty of care” provision, a requirement backed by many child-safety advocates and several Senate lawmakers.

The bill text states that nothing in it may be construed to “impose a duty of care on a provider of a covered platform.”

Keep reading