Jul 18, 2026 · 4 hr 19 min · 19 segments
Don't let the weather change the plan. Stormburst is built for unpredictable days, wet trails, and whatever the forecast throws your way.—grab 15% off here: https://vessi.com/wanshow • Free shipping •…
Luke LafreniereHostLet's jump right into our headline topic, which is, of course, Microsoft admitting to the existence of a secret global device identifier, or GDID, that was revealed after US prosecutors unsealed a federal complaint regarding alleged hacker Peter Stokes, who was wanted in connection with the 2025 breach of a US luxury jewelry retailer.
I'm not being all like, like, uh, conspiracy theory, "Where's my tinfoil hat? Keep the radio waves out of my brain." This is a serious problem.
A Microsoft representative explained GDID in the complaint as, this is a quote, "a persistent device-level identifier that is designed to uniquely identify an installation of Windows operating system on a device, either a physical device, e.g., mobile phone or laptop, or virtual machine across certain Microsoft services and scenarios." End of quote.
According to the story posted by Windows Latest, Microsoft uses it to manage software licensing and Windows Store apps, but because it links all your online activities on that computer back to one single identity, law enforcement can use it to track a device's true owner across the internet.
Now, reinstalling Windows does generate a new global device identifier, so it doesn't stay with you forever.
But because all of this is being fed back to Microsoft, the second that you sign in to another account that you were signed into on the old machine, [snaps finger] it's linked, and they would be able to resolve both of those GDIDs to one individual person.
The Windows Latest story has some suggestions on how you might maintain your privacy, and there's a full reverse engineering analysis from GitHub user sometimes-wonder if you really wanna get into the weeds.
So Dan, if you could throw that link into the chat for all the wonderful folks who are watching today.
In general, I have taken a pretty loose approach to the trackability of my devices.
This is different because it was not disclosed at any time, and there was no implicit tracking Like, in the modern age, if I sign into a web service y- using a credit card or using an email that I, that I use across various services, there- there's, at, uh, at least as a technical user, there's some level of understanding that the, there's some tracking here.
Let's jump right into our headline topic, which is, of course, Microsoft admitting to the existence of a secret global device identifier, or GDID, that was revealed after US prosecutors unsealed a federal complaint regarding alleged hacker Peter Stokes, who was wanted in connection with the 2025 breach of a US luxury jewelry retailer.
I'm not being all like, like, uh, conspiracy theory, "Where's my tinfoil hat? Keep the radio waves out of my brain." This is a serious problem.
A Microsoft representative explained GDID in the complaint as, this is a quote, "a persistent device-level identifier that is designed to uniquely identify an installation of Windows operating system on a device, either a physical device, e.g., mobile phone or laptop, or virtual machine across certain Microsoft services and scenarios." End of quote.
According to the story posted by Windows Latest, Microsoft uses it to manage software licensing and Windows Store apps, but because it links all your online activities on that computer back to one single identity, law enforcement can use it to track a device's true owner across the internet.
Now, reinstalling Windows does generate a new global device identifier, so it doesn't stay with you forever.
But because all of this is being fed back to Microsoft, the second that you sign in to another account that you were signed into on the old machine, [snaps finger] it's linked, and they would be able to resolve both of those GDIDs to one individual person.
The Windows Latest story has some suggestions on how you might maintain your privacy, and there's a full reverse engineering analysis from GitHub user sometimes-wonder if you really wanna get into the weeds.
So Dan, if you could throw that link into the chat for all the wonderful folks who are watching today.
In general, I have taken a pretty loose approach to the trackability of my devices.
This is different because it was not disclosed at any time, and there was no implicit tracking Like, in the modern age, if I sign into a web service y- using a credit card or using an email that I, that I use across various services, there- there's, at, uh, at least as a technical user, there's some level of understanding that the, there's some tracking here.
The rest of this transcript — segmented and speaker-labeled, so you land on the exact moment something was said
Search every transcript — by keyword, by phrase, or by meaning, across every show Radar indexes
Trends — what is surging across podcasts, measured against its own baseline
Alerts — when a name you follow appears in a newly indexed episode
No account is needed to search Radar.