Why a VPN Alone Cannot Guarantee Privacy: The Growing Role of Persistent Device Identifiers
CybersecurityVirtual private networks have become the default privacy tool for millions of internet users. They encrypt traffic, conceal a user’s public IP address, and make it more difficult for websites, internet providers, and network operators to monitor online activity. For many people, a VPN has become almost synonymous with anonymity.
In reality, however, a VPN protects only one layer of the digital identity stack. Modern operating systems, cloud platforms, and online services increasingly rely on persistent device identifiers that remain constant regardless of network location. These identifiers can allow a device to be recognized even as its IP address changes repeatedly.
Recent reports surrounding a criminal investigation involving an alleged member of the cybercrime group Scattered Spider have reignited discussions about how operating system telemetry can assist law enforcement. According to publicly available court documents cited by several technology news outlets, investigators were reportedly able to associate network activity with a persistent Windows device identifier that remained consistent across multiple internet connections, including VPN sessions.

Although many technical details remain undisclosed, the case highlights an important reality: changing your IP address does not necessarily change your digital identity.
Device Identity Has Become Part of Modern Operating Systems
For decades, network identity was closely tied to an IP address. Today, cloud-connected operating systems maintain additional identifiers that help authenticate devices, synchronize services, improve security, and manage software licenses.
Microsoft Windows, like many modern operating systems, generates unique identifiers during installation. These identifiers support a variety of legitimate functions, including:
- Device registration
- Security verification
- Software licensing
- Enterprise management
- Telemetry and diagnostics
- Synchronization with Microsoft cloud services
Unlike an IP address, which may change every time a device connects to a different network, these identifiers are designed to remain stable throughout the life of an operating system installation.
This persistence provides operational benefits for both users and administrators, but it also means that network anonymity and device anonymity are not necessarily the same thing.
Understanding Persistent Device Identifiers
A persistent device identifier functions much like a serial number. It is intended to uniquely distinguish one installation of an operating system from another.
Unlike cookies stored inside a web browser, these identifiers operate at the operating system level and may be associated with hardware components, firmware, or trusted security modules.
Modern operating systems commonly maintain several categories of identifiers, including:
- Installation identifiers
- Hardware-derived identifiers
- TPM-related security identifiers
- Licensing identifiers
- Cloud device registration identifiers
Some of these values exist only on the local machine, while others may also be stored by cloud services when a user signs into an online account.
Because they serve security and management purposes, these identifiers are generally designed to survive routine operating system updates, software upgrades, and account changes.
The Reported Role of Windows GDID
According to reports discussing the investigation, one identifier that attracted attention was Microsoft’s Global Device Identifier, commonly abbreviated as GDID.
Public reporting suggests that this identifier is associated with a Windows installation and can remain linked to a device across multiple network sessions. Investigators reportedly obtained historical records that associated numerous IP addresses with the same device identifier, allowing them to reconstruct the movement of the system across different networks and geographic regions.
Microsoft has not published extensive technical documentation describing every aspect of GDID, and many implementation details remain proprietary. As a result, outside researchers have only a partial understanding of exactly how the identifier is generated, stored, and managed.
What appears clear is that persistent identifiers represent another source of information beyond conventional network logs.
Why Changing IP Addresses Is No Longer Enough
A VPN changes the visible source IP address of internet traffic by routing communications through encrypted tunnels.
This remains extremely valuable because it prevents:
- Internet service providers from seeing the final destination of encrypted traffic
- Websites from directly identifying the user’s residential IP address
- Local network operators from monitoring browsing destinations
However, a VPN does not modify information generated by the operating system itself.
If an operating system communicates with its own cloud infrastructure using persistent device identifiers, changing the external IP address does not necessarily prevent the service provider from recognizing the device.
An analogy helps illustrate the distinction.
Imagine a vehicle traveling with different license plates every day. To observers on the road, the car appears different. But the manufacturer still recognizes it by its factory-assigned vehicle identification number (VIN). The visible identifier changes, while the permanent identity remains the same.
A VPN primarily changes the “license plate.” Device identifiers may function more like the VIN.
Telemetry Plays an Important Role
Modern operating systems collect varying levels of diagnostic information to improve reliability, detect compatibility problems, and strengthen security.
Microsoft categorizes diagnostic data into several levels depending on operating system version and administrative settings.
Telemetry can include information such as:
- Device configuration
- Hardware characteristics
- Driver versions
- System crashes
- Application compatibility
- Performance metrics
Enterprise administrators often rely on this information to manage thousands of computers efficiently.
Privacy advocates, however, have long argued that persistent telemetry creates additional opportunities for long-term device tracking, especially when combined with cloud-based services.
The precise relationship between diagnostic data and persistent identifiers depends on operating system version, configuration, and user settings.
Cloud Services Strengthen Device Associations
The connection between a device and its online identity becomes stronger whenever users authenticate with cloud platforms.
Services such as:
- Microsoft 365
- OneDrive
- Outlook
- Microsoft Edge synchronization
- Microsoft Store
- Xbox services
may associate a device with a user account for legitimate authentication, licensing, synchronization, and security purposes.
From a usability perspective, this creates a seamless experience. Files synchronize automatically, passwords appear across devices, and settings follow the user.
From a privacy perspective, however, cloud integration naturally increases the amount of information that can be associated with a particular device over time.
What a VPN Still Protects
Discussions about persistent identifiers should not be interpreted as evidence that VPNs have become obsolete.
They remain one of the most effective tools for protecting communications against many common forms of monitoring.
A VPN still provides significant benefits by:
- Encrypting traffic over untrusted networks
- Hiding public IP addresses from most websites
- Preventing local network surveillance
- Reducing ISP visibility into browsing activity
- Helping bypass geographic restrictions in many situations
- Protecting users on public Wi-Fi networks
For the overwhelming majority of users, these protections remain valuable.
The key point is that a VPN addresses network privacy rather than complete device anonymity.
Improving Privacy Beyond a VPN
Users seeking stronger privacy typically combine multiple protective measures instead of relying on a single technology.
Possible approaches include:
- Reviewing operating system privacy settings
- Limiting optional diagnostic data where possible
- Disabling unnecessary telemetry services in enterprise or advanced configurations
- Using separate user accounts for different activities
- Reducing dependence on cloud synchronization services
- Employing privacy-focused browsers and search engines
- Keeping software updated to reduce security risks
- Considering open-source operating systems when appropriate
Linux distributions, for example, generally provide greater transparency because their source code is publicly available and telemetry is typically much more limited or entirely optional. That said, privacy ultimately depends on the complete software ecosystem, not merely the operating system itself.
Privacy Is Becoming a Multi-Layer Problem
The internet no longer identifies users solely by IP addresses. Operating systems, browsers, mobile devices, cloud accounts, hardware security modules, and online services all contribute pieces of information that can be combined to establish a persistent digital identity.
As a result, privacy has become a layered challenge rather than a single technical problem.
A VPN continues to play an important role by protecting network communications, but it should not be viewed as a universal anonymity solution. Persistent operating system identifiers, cloud-based authentication, browser fingerprinting, and telemetry all operate independently of IP address masking.
Understanding these different layers allows individuals and organizations to make more informed decisions about their security architecture, privacy expectations, and the technologies they choose to trust.