Neither Tor nor VPN could save him: what GDID is in Windows and why it is dangerous for each of us

A while ago, the story of 19-year-old hacker Peter Stokes from the Scattered Spider group went viral. The guy breached a jewelry store network and demanded $8 million for non-disclosure of data. He wasn’t an idiot: he used a VPN, operated via RDP, and covered his tracks. But the FBI knocked on his door anyway. Do you know what tripped him up? It wasn’t an IP leak or snitching on accomplices. It was his own computer via GDID technology.
 
GDID (Global Device Identifier) is a unique identifier that Microsoft binds inextricably to every Windows installation. It is not tied to hardware or an account, but is a digital passport of your system. And this system maniacally collects telemetry: which programs you open, which websites you visit, and when you turn off your computer.
 
How does the VPN trap work? Many people think they become anonymous after turning it on. Metaphorically, a VPN is like fake mustaches and dark sunglasses. You put them on (change your IP), enter Telegram or Tor to read opposition channels, and go about your business. Windows records: “User with GDID №12345 opened Tor.exe at 14:00.” Then you take off your “fake mustaches” (turn off the VPN) to log into your banking app and place an order on Ozon using your real home IP (as you probably already know, it is impossible to access many Russian services with a VPN turned on). Shortly after, Windows makes another entry: “User with GDID №12345 logged in to play Dota from an IP address in the city of Syzran.” Then, all of this is sent in a neat little package to the servers of the “Corporation of Good” in Redmond.
 
But I’m in Russia, Microsoft has left, the FBI won’t reach us?! Yes, a Major cannot simply send a fax to Bill Gates requesting the logs of an opposition figure. But:
 
1) Broker data and telemetry leak regularly. Intelligence services are perfectly capable of buying the necessary databases from providers and corporations on the black market.
2) State trojans and spyware (which can reach you disguised as anything) can read your GDID locally. From there, it’s just a matter of technique—matching it with provider logs, which, under the “Yarovaya Law,” already record all your traffic.
3) If they want to get to you, they can fabricate a “cyber fraud” case and send a request through Interpol. Corporations often satisfy such requests without unnecessary questions.
 
How, then, can you protect yourself?
 
The radical solution is switching to Linux. If you engage in opposition activities, admin channels, or work with sensitive information—delete Windows. Stop voluntarily letting a corporate overseer into your home. In 2026, Linux is not just a black screen for geeks. Something like Linux Mint or Ubuntu can be installed in a couple of clicks and looks more intuitive than Windows. An open-source system doesn’t snitch out of the box.
 
The compromise solution is to gag Windows. Because sometimes you can’t do without Windows: specific work requirements, corporate software, favorite games. And if you are forced to live in the same room as a snitch, you should at least tape his mouth shut. To this end, enthusiasts have created excellent free utilities: wpd.app (Windows Privacy Dashboard) and O&O ShutUp10++.
 
Download them, run them, and in a couple of clicks, cut out all telemetry. They disable data collection, block report transmissions to Microsoft, shut down Cortana, and prevent applications from reading your location. But there is an important nuance: Windows is a stubborn creation. After every major update, the system will try to secretly reset your settings and start spying again. So, check these utilities after updates.
 
And remember the main rule of digital hygiene: separate your identities! The device you use to write posts about freedom should not know your name, where you live, or what your favorite type of coffee is when ordering delivery.

Voluntarist, Bitarch

How the state helps hackers steal our data

Some might think that security regulation is a necessary pursuit for society. However, in reality, because of the actions of regulators, the exact opposite happens—endless security checks and reports, which are supposed to protect us, actually do the reverse. Companies spend insane amounts of money and a ton of time just to appear secure in the eyes of officials. Consequently, there is neither the energy, the nerves, nor the budget left for actual data protection. The result? Another hack, another leak.

For example, take 23andMe. These cool guys do DNA tests so you can find out that you are 3% Mongol, 5% Swedish, and 92% an ordinary person who simply has nothing to do on a Friday night. You would think they would guard the data like Fort Knox. Yet, the year before last, hackers pulled nearly half of all user data, and now millions of genetic profiles are floating around the internet.

Think this is an exception? No, it’s more of a rule. Take our Sber. You’d expect a major bank, with stricter laws and constant reporting requirements, to be secure. And then—bam—a data leak of 52 million customers. And that’s just from the “Spasibo” loyalty program. Apparently, the customers said “thank you” to the bank, but someone decided that “you’re welcome” meant letting their data scatter across the darknet.

But that’s not all. Remember Yandex.Eda? There was a downright anecdotal case there: they delivered a pizza to someone in the secret apartment of an FSB officer. A data leak from the service revealed the addresses of famous people and security force employees. Thus, the state accidentally stepped on its own tail. It was almost funny, but not for those whose addresses became public.

Why does this happen? Because regulators love checking boxes. They adore paperwork and reports. A hypothetical Vasya from the security department spends 70% of his time on reporting and only 30% on fighting real threats. Then hackers break the defense that no one had time to strengthen while Vasya was trying to figure out how to fill out another form for Roskomnadzor. It becomes a vicious cycle: hacked → fine → even more reports → hacked again.

And the state only adds fuel to the fire. Remember the “Yarovaya Law”? Telecom companies are forced to store giant volumes of data, spending billions of rubles. Now guess who is salivating while looking at these massive data arrays? Exactly—hackers. Because gathering all of this in one place is like putting a huge safe in the middle of the city and hanging a note: “Dear thieves, there are valuables here; we aren’t guarding them because the money went toward buying the safe.”

Of course, the picture is roughly the same in the USA. Medical data leaks there have already become a national sport. So many records were leaked last year that you could give several to every American. The hack of Equifax, the credit history giant, is a “genre classic.” 147 million records fell into the hands of criminals, and the company received a $700 million fine. Imagine how much security could have been improved if that money had been put to work in advance, rather than into paperwork and fines? The moral here is simple: the more a stationary bandit forcibly “protects” our data, the more often that data is lost.

So, what should be done? Probably force companies less to spend their energy on pointless paperwork. Instead of hundreds of mandatory checks, let there be one clear standard: “Protect the data or pay—but not with reports, with money.” And the companies will find the best way themselves. Otherwise, it’s like the joke about the elephant in a china shop: the state stomps around, the dishes break, and the elephant is, of course, to blame. Therefore, it is necessary to stick to simple and clear rules. Regulators come and go anyway, but for some reason, our data remains wandering the network forever!

Voluntarist, Bitarch