The latest Microsoft privacy controversy begins with what initially looks like a success story for modern digital policing. American authorities were pursuing an alleged member of the notorious Scattered Spider cybercrime group, and the suspect appears to have taken the sort of precautions that people are routinely told will conceal their identity online. He allegedly used a VPN, separating his apparent internet address from his real one. Yet investigators were still able to connect important pieces of his activity together. The reason has exposed a largely invisible layer of Windows telemetry and raised a much larger question: when we buy a computer, just how much information is the operating system itself capable of reporting about us?

The Blaze has presented the story under the alarming headline, "Microsoft knows your entire browser history — and it can send it to the FBI." The underlying story is real, but that headline goes further than the evidence presently warrants. There is no demonstration that Microsoft secretly maintains a permanent, comprehensive database containing every website visited by every Windows user. What has been demonstrated is nevertheless sufficiently disturbing without exaggeration. Windows employs persistent device identifiers; Microsoft receives substantial diagnostic, account and network telemetry from Windows and Edge; Microsoft acknowledges that optional diagnostic information can include websites and URLs; and information associated with Microsoft's systems can be supplied to law enforcement when Microsoft receives legally valid demands. The interesting question is therefore not whether Microsoft has installed some mythical FBI button inside every PC. It is how much information an operating system vendor can accumulate simply through the normal operation of the modern connected computer.

The case that brought the issue into public view concerns Peter Stokes, a 19-year-old dual US-Estonian citizen whom American prosecutors allege was associated with Scattered Spider, also known as Octo Tempest, UNC3944 and 0ktapus. The US Department of Justice says the group has been involved in more than 100 network intrusions and more than $100 million in ransom payments. Stokes is accused of participating in a May 2025 intrusion into a luxury jewellery retailer, during which data were allegedly stolen and an approximately $8 million cryptocurrency ransom was demanded. The company managed to eject the intruders without paying, although prosecutors say the incident still caused at least $2 million in losses. These remain allegations and Stokes is entitled to the presumption of innocence.

What makes the case important for everyone else is the appearance in the investigative record of Microsoft's Global Device Identifier, or GDID. This is essentially a persistent identifier associated with a Windows installation. Technical researchers examining the system have since argued that some of the more dramatic claims circulating about GDID are inaccurate. It does not appear to be an immortal hardware fingerprint derived permanently from the serial numbers of the physical components, and reinstalling Windows can result in a different identifier. But none of this makes the underlying capability trivial. A sufficiently persistent identifier allows activities that appear disconnected at the network level to be recognised as originating from the same Windows environment.

That matters enormously when a VPN is involved. People sometimes misunderstand what a VPN actually does. A VPN creates an encrypted connection between the user's device and the VPN provider and substitutes the VPN server's public internet address for the user's ordinary public address when traffic emerges onto the wider internet. This can prevent an internet provider or destination website from seeing some information that would otherwise be visible to it. But a VPN cannot make the computer itself ignorant of what the computer is doing. If Windows or an application running on Windows independently communicates telemetry to Microsoft, the fact that the browser's outward-facing internet traffic passes through a VPN does not magically erase information available at the operating-system or application level.

This is the conceptual breakthrough produced by the GDID affair. The traditional privacy model imagines surveillance occurring somewhere along the communications pipe. The internet provider can watch one section of the pipe, the VPN another, the website another, and intelligence agencies may attempt to intercept communications somewhere along the route. Encryption and VPNs are consequently designed largely around protecting the pipe. But what happens if the observation occurs at one of the endpoints? Protecting the transmission channel does not protect information voluntarily or automatically generated by the operating system itself.

Microsoft's own documentation makes clear that Windows and Edge can transmit remarkably detailed information. Microsoft says optional Edge diagnostic data can include websites visited, URLs, page titles, how a page was accessed, information about page content and other information concerning navigation. Its Windows documentation similarly describes a "Browsing History" diagnostic-data category and says that URLs may include search terms. Microsoft says these data are pseudonymised and used for such purposes as diagnostics, security and product improvement, and users have controls over optional diagnostic collection. Those qualifications are important, but so is the underlying fact: the technological capacity to transmit highly revealing browsing telemetry is not speculation advanced by Microsoft critics. Microsoft documents it itself.

Edge adds another layer. Microsoft states that browsing history is ordinarily stored on the device, while depending upon the user's settings it can also be sent to Microsoft. Microsoft's current privacy statement says browsing activity can include browsing history, favourites, usage information and web content, and explains that users can stop sharing Edge browsing activity through Edge settings. This is a long way from proving that Microsoft secretly possesses every person's complete browsing history regardless of configuration. But it equally disposes of the comforting assumption that browsing history necessarily remains inside the browser on one's own computer.

We should therefore distinguish three things that are too easily collapsed into one. There is ordinary local browser history stored on the computer. There is diagnostic and service telemetry transmitted to Microsoft. And there are persistent identifiers capable of allowing events generated at different times or by different services to be correlated with the same installation, device environment or account ecosystem. It is the combination rather than any single component that creates the privacy problem.

This also helps clarify the much abused word "backdoor." There is presently no public evidence that Windows contains a secret FBI backdoor through which American agents can remotely open any Windows computer and browse its contents at will. Microsoft explicitly denies providing governments with direct or unfettered access to customer data and explicitly says that it does not build backdoors into its products. Under Microsoft's stated policy, law enforcement must use legal process: the company says it requires a subpoena or equivalent process for non-content information and a warrant or equivalent for customer content. Microsoft also says its compliance teams review requests and reject demands that are legally defective.

There is no reason to call that claim false without evidence. But there is a semantic danger here. A company can truthfully say, "There is no government backdoor," while simultaneously possessing an immense quantity of information that government agencies can obtain through the front door of lawful process. Those are different privacy problems. A literal backdoor allows covert or privileged access to a system. Centralised telemetry produces stored information that can subsequently be subpoenaed, warranted or otherwise lawfully demanded. For the individual whose activities are reconstructed afterwards, the distinction matters legally and technically but may feel considerably less impressive in practical terms.

Microsoft's transparency figures demonstrate that this is not hypothetical. In the second half of 2025 alone Microsoft reports receiving 27,412 law-enforcement requests for consumer data worldwide. About 61 per cent resulted in disclosure of non-content information and just over 5 per cent in disclosure of content, while other requests were rejected or produced no responsive data. In the United States during the same six months Microsoft says it received 5,587 legal demands concerning consumer data. Microsoft deserves some credit for publishing these figures, but the numbers illustrate the scale on which technology companies have become intermediaries between citizens and governments.

This is one of the great transformations of privacy in the twenty-first century. Historically, police wanting to know what somebody had been reading might have needed to search his house, examine his papers or question a bookseller or librarian. Each investigative step involved another physical obstacle and frequently another legal threshold. Digital life has progressively concentrated those scattered fragments of information into databases. Search engines know searches, telecommunications companies know connections, cloud providers know stored files, social-media companies know social networks, and operating-system vendors potentially know an extraordinary amount about how their software and associated services are being used.

The result is surveillance by accumulation. No sinister conspiracy is required. Each individual piece of telemetry can have a perfectly reasonable explanation. Device identifiers help services recognise computers. Diagnostic information helps engineers identify crashes. Browsing telemetry can identify malicious websites. Cloud accounts allow settings to synchronise across devices. Security services protect users from malware. Update systems need to know which machines have received patches. Advertising systems want to avoid showing irrelevant advertisements. Every individual data stream therefore arrives carrying an apparently sensible justification.

Put the streams together, however, and something qualitatively different emerges. An identifier connects one event to another. An account connects the identifier to a person. An IP address supplies a location or network. Browser telemetry reveals interests and destinations. Cloud services contain documents and communications. Security logs provide timestamps. The surveillance system does not necessarily need to have been designed as a surveillance system. It can emerge from the integration of systems designed for identification, convenience, diagnostics, security and commercial personalisation.

That is why the controversy over GDID is more important than the prosecution that revealed it. Few people will have much sympathy for ransomware gangs, and law enforcement plainly has a legitimate interest in identifying people who break into corporate networks and demand millions of dollars. If Microsoft's telemetry helped investigators identify a genuine cybercriminal, most people will regard that particular result as desirable.

But constitutional and privacy protections are not designed around the proposition that information will only ever be used against people whom we already know to be guilty. Infrastructure built to identify ransomware suspects does not possess a moral sensor that prevents its use in other investigations. Once a capability exists, the relevant questions become who can use it, under what legal authority, for what offences, subject to what oversight and for how long the underlying information remains available.

The distinction between capability and present intention is crucial. Microsoft may have no desire whatsoever to create a mass-surveillance architecture. The FBI may employ this sort of information overwhelmingly against serious criminals. Neither proposition settles the civil-liberties issue. Institutions change, laws change and governments change. Data accumulated for benign purposes today can become useful for purposes never contemplated when it was collected.

There is also the question of function creep. A device identifier created for account management, updates, diagnostics or service continuity can acquire investigative significance because it does its job extremely well: it distinguishes one computer environment from another. Data do not retain the moral purpose for which they were originally gathered. Once retained, they can answer questions that their designers never originally intended anybody to ask.

The development is particularly important because ordinary users have been encouraged to think about privacy mainly in terms of cookies, browser history and IP addresses. Delete the history, reject the cookies, use private-browsing mode and turn on a VPN, and one feels relatively invisible. Yet the modern computer exists inside a much larger ecosystem of operating-system telemetry, cloud authentication, synchronisation, security services, device identifiers and application-level reporting. Incognito mode was never designed to make a person invisible to the operating system, employer, network administrator, service provider or government. Nor was a VPN.

The GDID case is therefore best understood not as proof that VPNs are fraudulent but as proof of their limits. A VPN can conceal one category of identifying information while another category identifies the machine. A person wearing a mask remains identifiable if he simultaneously carries a radio transmitter broadcasting a persistent serial number. The mask has not failed; it was simply solving a different problem.

Some privacy researchers have already responded technologically. VPN provider Windscribe developed a tool called "deGDID" intended to remove existing GDID information from a Windows machine and interfere with recreation of the identifier. But even this is not a magic answer. Reporting on the project notes that interfering with the underlying Windows identity infrastructure can break Microsoft services, including account authentication, and previously accumulated server-side information obviously cannot be pulled back merely by changing the local computer. The episode illustrates the deeper problem: privacy-conscious users may find themselves fighting mechanisms deeply integrated into an operating system whose normal functionality increasingly assumes communication with cloud infrastructure.

There is consequently a legitimate policy question about whether "optional" is enough. Ordinary computer users cannot reasonably be expected to understand dozens of telemetry categories, registry identifiers, cloud authentication systems and privacy toggles. Consent becomes questionable when meaningful understanding would require expertise in operating-system architecture. Clicking "accept," or failing to locate a buried switch, is a very thin basis upon which to construct the proposition that a person knowingly agreed to extensive collection of his digital behaviour.

Nor should the issue be reduced to Microsoft alone. Apple, Google, Meta and countless application developers operate their own forms of telemetry, identification and cloud integration. Microsoft is important because Windows remains one of the world's dominant desktop operating systems and because the GDID episode gives us an unusually clear glimpse of what device-level information can contribute to an investigation. Turning Microsoft into a uniquely villainous corporation would miss the structural problem.

The structural problem is that computing has changed from owning a machine to inhabiting an ecosystem. The personal computer once largely executed programs locally. Increasingly it authenticates itself to remote servers, synchronises information, downloads configurations, submits diagnostic information, checks reputation databases, updates automatically and integrates with cloud accounts. Every connection may be defensible in isolation. Collectively they mean that the supposedly "personal" computer is engaged in a continuing conversation with corporations beyond the owner's desk.

This is where talk of "backdoors" can actually distract us. We should certainly oppose secret government access mechanisms, deliberately weakened encryption and undisclosed privileged entry into devices. But the more subtle danger may require no backdoor at all. If commercially useful operating systems routinely generate enough telemetry to reconstruct significant aspects of users' activities, governments need only obtain the records through whatever lawful powers the political system gives them.

That leads to the genuinely difficult question. How much information should exist in the first place? The traditional privacy debate concentrates heavily upon access: police should need a warrant, corporations should have security controls, employees should be prevented from browsing databases casually, and governments should not receive unfettered access. All are necessary safeguards. But access controls do not solve the prior problem of accumulation. Information that was never collected cannot be leaked, stolen, sold, subpoenaed or repurposed by a future government.

Data minimisation is therefore ultimately more important than promises of benevolent stewardship. The safest database is often the database that does not exist. Persistent identifiers should have clearly defined purposes and reasonable lifetimes. Diagnostic information should be genuinely necessary rather than merely useful. Browsing information should remain local wherever remote collection is unnecessary. Optional telemetry should be genuinely off unless deliberately activated, rather than depending upon users navigating complicated privacy menus.

The Stokes prosecution does not prove that Microsoft secretly records everything every Windows user does. Claims that GDID itself maintains an indestructible record of every website ever visited appear to outrun the presently available evidence, and presenting the story that way gives Microsoft an easy rebuttal.

The demonstrated reality is more interesting and, in some respects, more important. Microsoft openly acknowledges that Windows and Edge can collect browsing and diagnostic information containing URLs and related information. Windows employs persistent identifiers capable of helping correlate activity. Microsoft's online ecosystem generates account, device and network records. And Microsoft, like other major technology companies, can be legally compelled to provide information in its possession to government investigators. None of that requires an FBI backdoor.

That is precisely the point. The architecture of modern computing may increasingly make the old-fashioned backdoor unnecessary. When operating systems, browsers, cloud services, accounts and persistent identifiers continuously generate interconnected records, the surveillance potential is created before the police ever arrive. Law enforcement merely asks for information that the commercial technological ecosystem has already found reasons to collect.

Catching ransomware criminals is easy to applaud. Building a digital society in which every ordinary citizen leaves behind an increasingly reconstructable trail is much harder to justify. The civil-liberties question raised by Microsoft's GDID is therefore not whether Peter Stokes deserved privacy while allegedly participating in an $8 million extortion attempt. It is whether hundreds of millions of innocent Windows users should inhabit the same technical architecture merely because, on occasion, that architecture makes catching a criminal easier. The old privacy question was whether somebody was watching you. The new one is more unsettling: whether your computer has been quietly taking notes.