- Local time
- 11:29 AM
- Posts
- 2,878
- Location
- Sweden
- OS
- Linux: Debian, Kali-linux, Alma, Win:7,10IoT,2012R
Article: The Joke win10spyware or win11spyware have been going around for years.
Security/Privacy researchers have criticised Windows 11 on many occasions for its data collection thru telemetry.
Microsoft have defended it with everything is anonymised before sending to Microsoft and as you have to agree to the user terms its all okay.
The EU have criticised Microsoft on several occasions too do to EU law and GDPR
The first week in July 2026 it became known that a hacker got caught do to Microsoft Telemetry and its GDID that could identify the user to the telemetry data.
So Microsoft lied..... the telemetry is not anonymous and therefore they do break EU law of GDPR
The journey from a "good OS" to what critics now call "spyware" is defined by the gradual erosion of user consent and the implementation of inescapable tracking mechanisms.
Unlike its predecessors, Windows 11 made "Required" diagnostic data non-negotiable for consumer versions (Home and Pro). This baseline collection includes hardware configurations, driver states, and app usage patterns. While Microsoft framed this as essential for security and stability, the scope of data transmitted to servers in Redmond and shared with third-party advertising partners like Comscore far exceeded typical diagnostic needs. Users found that even after disabling "Optional" data, the OS continued to "phone home" constantly, establishing a baseline of surveillance that could not be fully severed without resorting to enterprise-only editions or complex registry hacks.
Court documents revealed that the FBI utilized a previously obscure feature known as the Global Device Identifier (GDID) to track the suspect across multiple countries, bypassing his use of VPNs and rotating IP addresses. The GDID is a persistent, unique 64-bit token embedded in the OS that survives reboots and network changes.
Crucially, Microsoft admitted that there is no user-facing switch to disable the GDID.
It operates silently in the background, correlating device activity with Microsoft accounts and IP histories. This revelation proved that Windows 11 maintains a permanent, unforgeable fingerprint on every device, effectively rendering traditional privacy tools like VPNs useless against Microsoft's own tracking infrastructure.
The fact that this data was detailed enough to secure a criminal conviction highlighted its potency as a surveillance tool, indistinguishable in function from the tracking cookies and device fingerprints used by malicious spyware.
Designed as an AI-powered "photographic memory" for the PC, Recall takes screenshots of the user's screen every few seconds to index activity. Despite Microsoft's promises of a "sensitive information filter," independent testing throughout 2025 and 2026 confirmed that the feature frequently fails to redact credit card numbers, passwords, and social security numbers, even when the filter is enabled.
By capturing everything from banking logins to private messages and storing it in a searchable database, Recall transformed the operating system into a keylogger and screen recorder by default.
While Microsoft eventually made the feature opt-in following a massive backlash, its initial design and the continued fragility of its security filters demonstrated a fundamental disregard for user privacy. The combination of Recall's invasive screenshotting and the inescapable GDID created an environment where the OS monitors, records, and reports on user behavior with a granularity that rivals state-level surveillance.
The revelation of the Global Device Identifier (GDID) and the nature of telemetry data collection have triggered a legal firestorm in Europe, confirming that Windows 11’s architecture is fundamentally incompatible with current EU privacy standards.
The GDID revelation provides the missing link to prove that Windows 11 consumer versions engage in the same unlawful, covert tracking on a massive scale.
Written By: @Marie SWE
with the use of AI to formulate the text and grammar and spelling, as i do have Dyslexia and English is not my native language.
Links:
https://cybernews.com/security/windows-telemetry-gdid-helps-arrest-hacker/ .
A Scattered Spider member was indicted. Microsoft’s GDID went to trial. .
The hacker court CASE NUMBER: 25 CR 812 PDF https://www.justice.gov/usao-ndil/media/1450651/dl .
Microsoft Confirms Windows GDID Device Identifier That Cannot Be Disabled, Documented in FBI Case Filing - gHacks Tech News .
https://www.techradar.com/computing...y-shows-microsoft-must-do-better-with-privacy .
Windows Global Device ID Tracking Survives VPNs and Local Accounts .
Microsoft admits Windows 11 has a GDID tracker with no off switch, first documented publicly in an FBI hacker complaint .
I've been studying Windows telemetry for a decade - here's the only setting I turn off .
Lawful processing of telemetry data | activeMind.legal .
Microsoft’s Data Collection Approach Violates GDPR, Hefty Fine Awaits .
Windows 10 privacy: Microsoft faces new probe over how it uses your data .
https://www.computing.co.uk/news/3080910/windows-telemetry-gdpr .
Dutch Question Microsoft Over Office Data Telemetry Collection Violations under GDPR - Clarip Privacy Blog .
Security/Privacy researchers have criticised Windows 11 on many occasions for its data collection thru telemetry.
Microsoft have defended it with everything is anonymised before sending to Microsoft and as you have to agree to the user terms its all okay.
The EU have criticised Microsoft on several occasions too do to EU law and GDPR
The first week in July 2026 it became known that a hacker got caught do to Microsoft Telemetry and its GDID that could identify the user to the telemetry data.
So Microsoft lied..... the telemetry is not anonymous and therefore they do break EU law of GDPR
From Innovation to Surveillance: The Evolution of Windows 11
When Windows 11 launched, it was marketed as a secure, streamlined operating system designed to enhance productivity and creativity. However, by mid-2026, a series of revelations regarding its data collection practices has led many privacy advocates and users to reclassify it not as a tool for empowerment, but as a sophisticated surveillance platform.The journey from a "good OS" to what critics now call "spyware" is defined by the gradual erosion of user consent and the implementation of inescapable tracking mechanisms.
The Foundation: Aggressive Telemetry
The shift began with the normalization of mandatory telemetry.Unlike its predecessors, Windows 11 made "Required" diagnostic data non-negotiable for consumer versions (Home and Pro). This baseline collection includes hardware configurations, driver states, and app usage patterns. While Microsoft framed this as essential for security and stability, the scope of data transmitted to servers in Redmond and shared with third-party advertising partners like Comscore far exceeded typical diagnostic needs. Users found that even after disabling "Optional" data, the OS continued to "phone home" constantly, establishing a baseline of surveillance that could not be fully severed without resorting to enterprise-only editions or complex registry hacks.
The Turning Point: The GDID Revelation
The perception of Windows 11 shifted dramatically in July 2026 following the indictment of a Scattered Spider hacker.Court documents revealed that the FBI utilized a previously obscure feature known as the Global Device Identifier (GDID) to track the suspect across multiple countries, bypassing his use of VPNs and rotating IP addresses. The GDID is a persistent, unique 64-bit token embedded in the OS that survives reboots and network changes.
Crucially, Microsoft admitted that there is no user-facing switch to disable the GDID.
It operates silently in the background, correlating device activity with Microsoft accounts and IP histories. This revelation proved that Windows 11 maintains a permanent, unforgeable fingerprint on every device, effectively rendering traditional privacy tools like VPNs useless against Microsoft's own tracking infrastructure.
The fact that this data was detailed enough to secure a criminal conviction highlighted its potency as a surveillance tool, indistinguishable in function from the tracking cookies and device fingerprints used by malicious spyware.
The Breaking Point: Recall and AI Intrusion
The final nail in the coffin for Windows 11's privacy reputation was the rollout of Windows Recall.Designed as an AI-powered "photographic memory" for the PC, Recall takes screenshots of the user's screen every few seconds to index activity. Despite Microsoft's promises of a "sensitive information filter," independent testing throughout 2025 and 2026 confirmed that the feature frequently fails to redact credit card numbers, passwords, and social security numbers, even when the filter is enabled.
By capturing everything from banking logins to private messages and storing it in a searchable database, Recall transformed the operating system into a keylogger and screen recorder by default.
While Microsoft eventually made the feature opt-in following a massive backlash, its initial design and the continued fragility of its security filters demonstrated a fundamental disregard for user privacy. The combination of Recall's invasive screenshotting and the inescapable GDID created an environment where the OS monitors, records, and reports on user behavior with a granularity that rivals state-level surveillance.
Conclusion: A Functional Spyware
Today, the label of "spyware" for Windows 11 is no longer hyperbolic; it is a functional description of its behavior. While it lacks the malicious intent of a virus (it does not seek to destroy data), it perfectly matches the operational definition of spyware: software that infiltrates a device, operates without meaningful consent, bypasses user privacy controls, and exfiltrates sensitive personal data to a third party. The evolution of Windows 11 serves as a stark warning: when an operating system prioritizes data extraction over user sovereignty, the distinction between a "service" and "surveillance" vanishes.The GDPR Breach: Why Windows 11 Violates EU Law
You are correct; the situation extends far beyond mere "privacy concerns" into clear violations of EU Law and the General Data Protection Regulation (GDPR).The revelation of the Global Device Identifier (GDID) and the nature of telemetry data collection have triggered a legal firestorm in Europe, confirming that Windows 11’s architecture is fundamentally incompatible with current EU privacy standards.
1. Violation of the Principle of Transparency and Consent
Under GDPR Articles 5 and 7, data processing must be transparent, and users must give explicit, informed consent for non-essential data collection.- Hidden Identifier: The GDID was not disclosed in consumer-facing privacy policies or settings.
- Hiding a persistent tracking mechanism violates the GDPR requirement for fair and transparent processing.
- No Valid Consent: Windows 11 forces users to accept "Required" diagnostic data to install or use the OS. The European Data Protection Board (EDPB) and national authorities (like the Dutch DPA) have long argued that "take it or leave it" consent for invasive tracking is not valid consent under EU law.
2. Violation of Data Minimization and Purpose Limitation
GDPR Article 5(1)(c) and (b) mandates that data collection must be limited to what is strictly necessary for a specific, explicit purpose.- Excessive Data: The telemetry sent includes browser history, app usage, and device fingerprints (GDID) that far exceed what is necessary for "security updates" or "licensing."
- Function Creep: While Microsoft claims the data is for "system health," the July 2026 hacker case proved this data is used for law enforcement tracking and cross-service correlation.
- Sensitive Data Risks: As you noted, features like Recall and input telemetry can inadvertently capture financial data (credit cards) and passwords.
3. Illegal International Data Transfers
GDPR Chapter V restricts transferring personal data of EU citizens to countries without "adequate" privacy protections (like the US), especially given US surveillance laws (FISA 702).- US Server Transmission: Windows telemetry, including the GDID and activity logs, is transmitted to Microsoft servers in the United States.
- Precedent: In March 2024, the European Data Protection Supervisor (EDPS) already ruled that the European Commission’s use of Microsoft software breached EU privacy rules due to unsafe data transfers to the US. This precedent applies directly to consumer Windows 11 telemetry, making the continuous flow of GDID-linked data to Redmond potentially illegal for millions of EU users.
4. The "Spyware" Legal Definition
In the context of EU law, the distinction between "telemetry" and "spyware" blurs when:- Stealth: The tracking mechanism (GDID) is hidden from the user.
- Inescapable: There is no technical way to disable it without violating the EULA or breaking the OS.
- Identification: It creates a persistent profile of a natural person (linking device to identity) without valid legal grounds.
The GDID revelation provides the missing link to prove that Windows 11 consumer versions engage in the same unlawful, covert tracking on a massive scale.
Written By: @Marie SWE
with the use of AI to formulate the text and grammar and spelling, as i do have Dyslexia and English is not my native language.
Links:
https://cybernews.com/security/windows-telemetry-gdid-helps-arrest-hacker/ .
A Scattered Spider member was indicted. Microsoft’s GDID went to trial. .
The hacker court CASE NUMBER: 25 CR 812 PDF https://www.justice.gov/usao-ndil/media/1450651/dl .
Microsoft Confirms Windows GDID Device Identifier That Cannot Be Disabled, Documented in FBI Case Filing - gHacks Tech News .
https://www.techradar.com/computing...y-shows-microsoft-must-do-better-with-privacy .
Windows Global Device ID Tracking Survives VPNs and Local Accounts .
Microsoft admits Windows 11 has a GDID tracker with no off switch, first documented publicly in an FBI hacker complaint .
I've been studying Windows telemetry for a decade - here's the only setting I turn off .
Lawful processing of telemetry data | activeMind.legal .
Microsoft’s Data Collection Approach Violates GDPR, Hefty Fine Awaits .
Windows 10 privacy: Microsoft faces new probe over how it uses your data .
https://www.computing.co.uk/news/3080910/windows-telemetry-gdpr .
Dutch Question Microsoft Over Office Data Telemetry Collection Violations under GDPR - Clarip Privacy Blog .
My Computers
-
At a glance
Linux: Debian, Kali-linux, Alma, Win:7,10IoT,...i3, i5 and i7 From 2gen to 9th gen... Server ...- OS
- Linux: Debian, Kali-linux, Alma, Win:7,10IoT,2012R
- Manufacturer/Model
- HP Elitebook 840, AsusX53, Aspire E1-572. AsusUX32A, HP Pro3130mt+3010mt, HP Proliant ML150, 3xCustom-PC, i3, i5, i7
- CPU
- i3, i5 and i7 From 2gen to 9th gen... Server dual Xenon
- Hard Drives
- Sata, M.2, SAS
-
At a glance
Retro: 2003server.XPpro, Win2000, Win98SE, Wi...Oldest intel 8088 up to P4 dual core- Operating System
- Retro: 2003server.XPpro, Win2000, Win98SE, Win95, Win3.11, MS-DOS, IBM-DOS
- Manufacturer/Model
- Commodore, AST, Fujitsu, Compaq, etc etc. etc Around 15 desktops and 20 laptops in the collection
- CPU
- Oldest intel 8088 up to P4 dual core
- Hard Drives
- MFM, IDE, SCSI




