# Microsoft telemetry details in the Scattered Spider complaint

**URL:** https://discuss.privacyguides.net/t/microsoft-telemetry-details-in-the-scattered-spider-complaint/39017
**Category:** General
**Created:** 2026-07-06T17:04:02Z
**Posts:** 41

## Post 1 by @Sabife — 2026-07-06T17:04:02Z

The Scattered Spider complaint includes some pretty striking details about Microsoft telemetry.

The DOJ affidavit describes a GDID (Global Device Identifier) tied to a specific Windows installation, acting as a persistent identifier unless the OS is fully wiped. Microsoft telemetry linked to this GDID reportedly included visited websites, changing IP addresses over time, and other internet activity signals collected in the background.

According to the filing, Microsoft was able to correlate this data across sessions, effectively tying together browsing activity and network connections even when IP addresses were changing through VPN use. In practice, the VPN didn’t really break the chain of correlation once everything was tied back to the same device identifier and telemetry stream.

[https://www.justice.gov/usao-ndil/media/1450651/dl?inline](https://www.justice.gov/usao-ndil/media/1450651/dl?inline)

---

## Post 2 by @GolCor — 2026-07-06T17:45:54Z

Goodness gracious. Sometimes you just have to take a minute to sigh and shake your head.

It’s not that anything here should be surprising. But it sure can be frustrating.

---

## Post 3 by @Link — 2026-07-06T19:11:43Z

This is crazy!!! (assuming this tweet isn’t lying)

 ![image](https://forum-uploads.privacyguidesusercontent.com/original/3X/e/8/e8ee5ac248da6374359fa9b9b9754f593bd06ffc.jpeg)

When they say “web activity” I wonder if that means he was using Edge? Or perhaps the start menu search wasn’t turned off? (games played is likely game bar telemetry?)

It is insane to me that a hacker is using Windows with stock settings because I assume this much information isn’t transmitted with even slight amount of configuration lol, guess criminals usually aren’t very smart but wow

---

## Post 4 by @Quantum — 2026-07-06T21:30:40Z

The suspect is 19 years old and literally took pictures of his crimes and posted them to Snapchat. So OPSEC was not strong.

With that said, the Windows telemetry which Microsoft was able to provide to the FBI is _extensive_ and defeats all normal attempts at anonymity. I do not know if this is able to be turned off at the user level or blocked at the network level.

In anycase, make this example 3,568 of why Windows is trash.

---

## Post 5 by @Dwayne — 2026-07-06T23:00:06Z

So basically, they first tied **one of IP addresses** to his activity, then asked Microsoft which **Windows Global Device Identifier** was associated with that IP. **Microsoft identified the GDID** and then provided logs showing that the same **GDID** had visited **ngrok** (including the **signup page** ), **used Tzulo VPN/proxy servers** (including the **same exit IP used to create the ngrok account** ), visited **Company F’s website** , **Growtopia/Ubisoft login pages** , and that the same **GDID was consistently associated with the IPs** used to access his **Apple, Facebook, and Snapchat accounts** across multiple countries ( **Estonia, New York, and Thailand** ).

If all of this is accurate, it’s honestly pretty shocking how much information Microsoft collects.

---

## Post 6 by @CookieCrumbler — 2026-07-06T23:32:44Z

This case really drives home how weak Windows privacy is, since a single device ID can bypass a VPN and expose your entire activity history. I’m all for fighting for strong privacy rights and security for everyone, but that shouldn’t mean using these tools to break the law or hide criminal acts. We need better protections for regular users without inadvertently aiding malicious actors.

---

## Post 7 by @Quantum — 2026-07-07T00:27:11Z

Privacy tools are morally neutral. There is no way, on a technical level, to block malicious actors but not legitimate ones. This is something many governments continually fail to understand (looking at you UK). The proper place for investment of government energy is in helping to secure critical digital infrastructure instead of hoarding zero-days for their own surveillance purposes.

---

## Post 8 by @eteszi — 2026-07-07T01:03:28Z

> [@Link](#):
>
> It is insane to me that a hacker is using Windows with stock settings because I assume this much information isn’t transmitted with even slight amount of configuration lol, guess criminals usually aren’t very smart but wow

It doesn’t matter whether it’s default settings or not. There’s no way to disable this. In any case, the system collects and sends HWID/GDID to servers during updates, license checks, activation, etc.

He could use split tunneling to proxy only the necessary applications, bypassing system services, or simply use a VPN extension in the browser. Use a firewall to block unnecessary connections. Or just switch to Linux.

But, as I can see, he even had a Microsoft account, the VPN IP addresses weren’t changed, and they were used for everything, which led to a bunch of IP leaks.

---

## Post 9 by @JohnDose — 2026-07-07T01:16:20Z

Is that GDID thing sent to MS servers only when the user signs in to his/her microsoft account? Or is it force sent regardless of whether the Windows installation is tied to an account?

---

## Post 10 by @Quantum — 2026-07-07T02:15:34Z

It is established with the install of the OS, no account needed. PCmag has a good article on it.

> **[A Hacker's Arrest Reveals Microsoft Can Track Users Via a Windows Device ID](https://www.pcmag.com/news/a-hackers-arrest-reveals-microsoft-can-track-users-via-a-windows-device)**
>
> The FBI used a Microsoft device identifier, dubbed GDID, to link a teenager to a hack attributed to Scattered Spider, raising privacy red flags about Windows' surveillance capabilities.

---

## Post 11 by @JohnDose — 2026-07-07T02:23:42Z

Thanks. I also foudn this [GitHub - SmtimesIWndr/gdid-reversal · GitHub](https://github.com/SmtimesIWndr/gdid-reversal)

github post about gdid.

---

## Post 12 by @Tux — 2026-07-07T04:54:56Z

It is really surprising though, and do you honestly believe Apple is any better?

The only solution against this kind of abuse is hardware and software under the control of the user.

---

## Post 13 by @Pedja — 2026-07-07T23:53:33Z

He probably left telemetry enabled, and I believe he was using Edge with SmartScreen. But the fact that Microsoft tracks IPs and links them to unique IDs is concerning by itself.

---

## Post 14 by @DanielM — 2026-07-08T09:30:12Z

A while back when I used their “Edge” browser, I analyzed the network traffic and it was sending a lot of requests to their own servers.

Here are some typical blocked domains (some might be “legitimate”):

- [substrate.office.com](http://substrate.office.com)
- [c.s-microsoft.com](http://c.s-microsoft.com)
- [exo.nel.measure.office.net](http://exo.nel.measure.office.net)
- [events.data.microsoft.com](http://events.data.microsoft.com)
- appcenter.ms

You have to block the subdomains too.  
If someone is willing to use the Edge browser or Windows, for example, and wants greater privacy, block all IPs and domains belonging to the Microsoft corporation and its “affiliates, partners, etc.”.

In such cases, to install updates manually (security patches, system updates, etc.) without relying on Windows Update as if you were offline, you can install them manually yourself. It may or may not require external tools. It will take a bit more time and the willingness to do it.

---

## Post 15 by @PurpleDime — 2026-07-08T09:33:23Z

**TL:DR:**

> _ **A teenager allegedly used a VPN to cover his tracks while hacking a US jewelry retailer, but Microsoft knew anyway.** _
> 
> _ **Court documents unsealed in the US case against Peter Stokes, a 19-year-old dual US-Estonian citizen accused of being a member of the notorious Scattered Spider hacking group, reveal that Microsoft provided the FBI with records tied to a tracking mechanism called the Global Device Identifier, or GDID.** _
> 
> **- DIGITAL TRENDS**

> **[A hacker’s arrest just revealed how Microsoft can track your Windows device](https://www.digitaltrends.com/computing/your-windows-pc-has-been-quietly-tracking-you-and-a-hackers-arrest-just-made-it-public/)**
>
> A hacker used a VPN to stay anonymous. Microsoft's Windows Global Device Identifier logged his activity anyway and handed it to the FBI.

> The identifier, which is automatically assigned to every Windows installation, was enough to link Stokes’ computer to specific websites and third-party services, even though he was running a VPN.

[https://cybernews.com/security/windows-telemetry-gdid-helps-arrest-hacker/](https://cybernews.com/security/windows-telemetry-gdid-helps-arrest-hacker/)

> **[Windows Device Identifier Feature Leads to Arrest of Scattered Spider Hacking...](https://cybersecuritynews.com/windows-device-identifier-tracking/)**
>
> A 19-year-old dual U.S.-Estonian citizen used VPNs, tunneling tools, and rotated IPs across multiple countries to hide his tracks. The FBI still caught him, and the key evidence came from a little-known Windows telemetry feature buried in every...

---

## Post 16 by @7379bronze — 2026-07-08T13:26:36Z

Is there a current solution available? I’m aware of [GitHub - undergroundwires/privacy.sexy: Open-source tool to enforce privacy & security best-practices on Windows, macOS and Linux, because privacy is sexy · GitHub](https://github.com/undergroundwires/privacy.sexy), but it hasn’t been updated in quite some time.

---

## Post 17 by @user1 — 2026-07-08T13:53:52Z

> **[GitHub - SmtimesIWndr/gdid-reversal](https://github.com/SmtimesIWndr/gdid-reversal#8-reducing-the-exposure)**
>
> Contribute to SmtimesIWndr/gdid-reversal development by creating an account on GitHub.

There is also a script from the same dev, it should be vetted first though.

---

## Post 18 by @bogo — 2026-07-09T01:43:01Z

I feel like there isn’t enough attention pointed to the fact that, in the report, point 26, Microsoft records had a log of the exact URL he was on when creating the account? It is a https website, but they specifically knew that he was on ngrok dot com / signup, not just ngrok dot com. This could be explained pretty easily by “He was using Edge browser and had all the telemetry settings on which sent all the URLs he visited to microsoft defender which in turn logged every single site he was accessing with a timestamp” rather than “Windows is indefensibly spying on every single URL you visit no matter what measures you take”. I know that the court document isn’t a technical report by any means but there’s probably a reason they were very vague with the details but went out of their way to bring up some OS ID that no one has ever heard of.

“eteszi”'s claim of “There’s no way to disable this.” also seems a bit far fetched to me considering this could very well be a setting you can disable in the windows settings GUI, a setting that O&O10 would block with the default “yes” settings, or something you could easily evade by having something akin to simplewall set to block by default and interactively allowing applications to use the internet.

---

## Post 19 by @jerm — 2026-07-13T09:21:01Z

> **[Microsoft admits Windows 11 has a GDID tracker with no off switch, first...](https://www.windowslatest.com/2026/07/10/you-cant-fully-disable-microsofts-gdid-windows-11-tracker-but-these-settings-limit-what-it-captures/)**
>
> GDID is the persistent Windows ID that helped FBI trace a Scattered Spider hacker despite VPNs. Here's how it works and how to limit it.

---

## Post 20 by @JohnDose — 2026-07-13T12:07:48Z

Great article.

The GDID also gets generated and sent to MS servers even when you never sign in to a MS account. I use Windows 10 Enterprise LTSC 2021, setup totally offline, and only connect to internet for windos update and activation(via Massgrave script). Yet, I have confirmed several times that all the services related to GDID was active and has been sending telemetry.

Since then, I included disabling the GDID into my Windows initialization process. AFAIK activating Windows totally offline is also possible (at least for win 10). I might have to check if GDID still gets sent despite these hardenings.

---

## Post 21 by @JohnDose — 2026-07-13T12:15:03Z

Yes I’ve seen that post linked in the article. But I remember activating my Windows 10 totally offline using the MAS tools. I’ll clean install once again and try it out myself. I could be wrong, but I don’t remeber MAS requiring network connection (other than downloading the tools, which can be prepared offline)

Edit) I haven’t tried it out, but the TSForge option doesn’t seem to require network. HWID activation does. I’ll check out whether I can activate my Windows 10 via TSForge in an air-gapped environment.

---

## Post 22 by @Pedja — 2026-07-14T00:02:06Z

I don’t see how offline vs. online activation changes anything. If the machine ever goes online and starts talking to Microsoft, it’ll likely end up with a GDID anyway.

What’s more important is disabling as much telemetry as possible, so there’s as little data as possible associated with that GDID.

---

## Post 23 by @JohnDose — 2026-07-14T03:11:39Z

You’re missing the point. It matters because the activation process per-se can be a part of telemetry. Permanent activation via HWID sends the hardware identifiers to MS servers. Offline activation methods like TSForge prevent this. Disabling GDID and any other telemetry prior to first internet connection is important, as well as offline on-device activation.

> [@Pedja](#):
>
> If the machine ever goes online and starts talking to Microsoft, it’ll likely end up with a GDID anyway.
> 
> What’s more important is disabling as much telemetry as possible, so there’s as little data as possible associated with that GDID.

The two paragraphs are contradictory. If Windows is used air-gapped, it doesn’t matter whether or not you disable telemetry at all. And GDID itself is a part of Windows’ invasive telemetry, so it’s crucial to turn off GDID along with other options.  
There are some scripts on GitHub that automate the process. [Example](https://github.com/Korben00/no-gdid), [another example](https://github.com/SmtimesIWndr/GDID-Disabler)

---

## Post 24 by @eteszi — 2026-07-14T19:09:21Z

I don’t understand what you’re trying to achieve. It doesn’t matter how you activate the system, Windows will still send your HWID to check digital license on the servers and restore it. Disabling GDID is practically impossible without breaking the system: disabling DO will break system updates, disabling wlidsvc will break all UWP apps. Even after disabling CDPSvc, Microsoft still has ways to track the user. I did a clean install with all these services disabled, and somehow Microsoft Store still synced my app history, and that’s without even using a Microsoft account.

The only thing that makes sense is either not using Windows at all, or completely blocking all system connections with a firewall when necessary.

---

## Post 25 by @JohnDose — 2026-07-15T03:29:06Z

What Windows edition are you using? The Enterprise LTSC for Windows 10 has significantly less base telemetry compared to the consumer editions.  
It does matter how I’m trying to activate. According to MAS, it is possible to activate Windows totally offline. As you said, disabling as much telemetry possible in addition to using firewalls to manually block traffic related to MS servers can drastically improve privacy even in Windows. Don’t use MS store when you can manually install via .exe and verify the checksum. I disabled GDID, and despite using various software including games, I haven’t experienced any issues. Windows updates works fine as well(though I can’t say that Windows updates work with zero telemetry).  
Use TSForge for activation, not HWID. I won’t talk about this deeper since it’s related to piracy.

p.s. the wildsvc doesn’t even exist in my windows.

Achieving privacy isn’t all or nothing. You should still strive to enhance yours even it might not be perfect. Simply stating “don’t use windows, switch to linux” isn’t a very constructive argument. It’s essentially the same as “don’t use computers. just use pen and paper”.

---

## Post 26 by @dadnerd — 2026-07-15T05:14:17Z

> [@JohnDose](#):
>
> Simply stating “don’t use windows, switch to linux” isn’t a very constructive argument. It’s essentially the same as “don’t use computers. just use pen and paper”.

This is not a good faith statement. There are plenty of ways to use computers fairly easily and fairly privately that most people would be able to learn.

Most people cannot learn how to do these convoluted steps to use Windows semi-privately. Anyone who knows how to do this stuff probably has enough knowledge that they don’t need to be taking basic privacy advice from strangers on a forum.

We should absolutely be telling people who care about not being tracked by malicious tech companies on a privacy forum not to use Windows.

If you care about privacy and you are not highly tech competent, do not use Windows.

---

## Post 27 by @JohnDose — 2026-07-15T06:00:47Z

> [@dadnerd](#):
>
> There are plenty of ways to use computers fairly easily and fairly privately that most people would be able to learn.

So is true for Windows.

> [@dadnerd](#):
>
> If you care about privacy and you are not highly tech competent, do not use Windows.

Operating systems are not like ordinary softwares where one can easily replace another. There are basically three major OSes available(Windows, Mac, and Linux distros), and each have their pros and cons. Also, not everyone can migrate to Linux. Not because of their technical incapability or lack of knowledge, but for the sake of work. Many commercial softwares/games run exclusively on Windows, and those who have their entire workflow integrated into it would need excessive effort to change their OS, and even after it doesn’t guarantee it works.

You’re overlooking the fact that not everyone is capable of switching to Linux. The existence of huge amounts of github repos related to Windows hardening and their stars represent this fact. It’s okay to recommend Linux, and it’s also fine to say Windows is awful for privacy. But stating Windows should NOT be used whatsoever isn’t.

---

## Post 28 by @eteszi — 2026-07-15T06:17:32Z

This is not true. Basic telemetry is the same, but unlike Home and Pro editions, Enterprise offers the option to reduce it.

I don’t know what kind of privacy you’re planning to improve on Windows, when until recently nobody knew about this GDID until someone got caught with it. Turn off telemetry, good luck, but how much more hidden telemetry like GDID will remain in the system? Nobody knows.

How did you disable GDID? How did you verify that it was disabled? Did you just trust a random script on GitHub? I have all those services disabled, but the system still generated a GDID. So what happened? Nobody knows.

I’ve never seen a decent privacy guide for Windows that’s actively maintained. It’s literally impossible on Windows because full privacy on Windows would break the entire system. The number of stars on GitHub literally means nothing, it doesn’t mean all telemetry will be removed from the system.

> though I can’t say that Windows updates work with zero telemetry

You can’t prove anything, yet you’re talking about Windows privacy. Why?

---

## Post 29 by @user1 — 2026-07-15T06:54:52Z

Honest question: does Apple have a similar hwid?

I mean, the article unveiling the use of GDID in an investigation by LE shocked the most but it’s not a novelty. Apple had collaborated in the past with authorities for investigations too.

My point is not to defend Microsoft nor Apple, tracking is awful.  
It’s about the “obvious solution to switch to Linux” which is sadly impractical in a lot of cases.  
The freedom that comes with using Linux is also tied to big downsides that the community here is often too easily willing to dismiss.

Linux for the masses is not a thing unfortunately even if I would love it to succeed.

That said it really sucks today to know that every device we have can be strictly id in a way or another.

---

## Post 30 by @Bluetacked — 2026-07-15T11:08:44Z

Not sure if it’s the same thing but I remember from my Hackintosh days that the Mac has a serial number that it needed at least to get iCloud, iMessage etc to work. I.e. it phones home to Apple with it. And in fact if you’re logged into iCloud, their tech support can request to see the screen of your Mac at any time (in theory it always asks first and would only be initiated if you ask for help, in practice if Apple are handed a warrant all bets are off). So the same advice would apply, if targeted law enforcement is a threat, then at minimum don’t log into any of the Apple services. I’d be mildly surprised if it’s not still including the ID in software update checks though.

---

## Post 32 by @lyricism — 2026-07-16T13:52:47Z

It didn’t “bypass” VPNs. Telemetry was sent to Microsoft associating visited sites with the GDID. This allowed correlation of browsing activity with and without the VPN, as Microsoft had a record of everything tied to the same GDID. The VPN was still functional, however.

---

## Post 33 by @user1 — 2026-07-29T06:13:18Z

> **[Windows Tracks You With a Hidden ID. So We Built deGDID to Block It.](https://windscribe.com/blog/windows-tracks-you-with-a-hidden-id-so-we-built-degdid-to-block-it/)**
>
> Windows has obvious identifiers, like your computer name, and less obvious ones buried in Microsoft's identity systems. One of the more interesting ones is the Global Device Identifier, or GDID: a Microsoft-issued identifier tied to a Windows...

---

## Post 34 by @win11.shading291 — 2026-08-01T01:15:39Z

I’m missing something here. How can Microsoft know which website was accessed and precisely when?

Unless the kid used Edge?

It’s also written that GDID is created when a Microsoft Account is created, which can be bypassed:

> **Now for the version in plain English:** Sign into Windows with a Microsoft Account, and a server assigns your installation a permanent ID number. Windows stores it locally, several background services read it, and it gets stamped onto activity your PC reports back to Microsoft.

> The GDID is not calculated based on your PC components, such as the motherboard or hard drive, but rather **assigned by Microsoft servers**. It all starts when we configure Windows with a Microsoft account; at that moment, a system service called **wlidsvc communicates with [login.live.com](http://login.live.com)** to apply for a PUID (a unique Passport ID).

---

## Post 35 by @kabob3801 — 2026-08-01T03:19:30Z

assuming the browser was using the operating systems DNS, and said DNS wasn’t encrypted. Thats likely how.

---

## Post 36 by @eteszi — 2026-08-01T03:24:09Z

> [@win11.shading291](#):
>
> How can Microsoft know which website was accessed and precisely when?

Who said they know?

> [@win11.shading291](#):
>
> It’s also written that GDID is created when a Microsoft Account is created, which can be bypassed

[No.](https://github.com/SmtimesIWndr/gdid-reversal)

> **After some more reversing of CDP. I provided some misinfo. Using a local account does not prevent a GDID. CDP has an anonymous device path that is taken if no microsoft account.**

---

## Post 37 by @privacyisconsent — 2026-08-01T11:43:21Z

Are there any popular privacy configuration resources similar in spirit to [https://privacy.sexy/](https://privacy.sexy/) (or whatever) that showed intimate knowledge of these identifiers before the recent news story?

---

## Post 38 by @7379bronze — 2026-08-02T13:59:14Z

> <https://github.com/undergroundwires/privacy.sexy/issues/624>
>
> This project hasn't been updated in near a year now, what alternatives are there…?
> Preferably open source.

---

## Post 39 by @win11.shading291 — 2026-08-09T23:27:05Z

> [@eteszi](#):
>
> Who said they know?

[https://www.digitaltrends.com/computing/your-windows-pc-has-been-quietly-tracking-you-and-a-hackers-arrest-just-made-it-public/](https://www.digitaltrends.com/computing/your-windows-pc-has-been-quietly-tracking-you-and-a-hackers-arrest-just-made-it-public/)

> The identifier, which is automatically assigned to every [Windows installation](https://www.digitaltrends.com/computing/how-to-install-windows-11/), was enough to link Stokes’ computer to specific websites and third-party services, even though he was running a VPN.

> **[Windows Device Identifier Feature Leads to Arrest of Scattered Spider Hacking...](https://cybersecuritynews.com/windows-device-identifier-tracking/)**
>
> A 19-year-old dual U.S.-Estonian citizen used VPNs, tunneling tools, and rotated IPs across multiple countries to hide his tracks. The FBI still caught him, and the key evidence came from a little-known Windows telemetry feature buried in every...

> Microsoft records placed the device carrying the GDID on ngrok’s signup page at the exact minute the account was created, and later browsing Company F’s website through the same `.168` proxy. From there, the FBI correlated the GDID’s IP history against accounts known to belong to Stokes: Apple, Snapchat, Facebook, and even a Ubisoft/Growtopia game login.

> **[Microsoft admits Windows 11 has a GDID tracker with no off switch, first...](https://www.windowslatest.com/2026/07/10/you-cant-fully-disable-microsofts-gdid-windows-11-tracker-but-these-settings-limit-what-it-captures/)**
>
> GDID is the persistent Windows ID that helped FBI trace a Scattered Spider hacker despite VPNs. Here's how it works and how to limit it.

> Microsoft’s records showed that at that exact same minute, a Windows device carrying GDID g:6755467234350028 had visited the ngrok signup page. Three hours later, the same GDID visited the retailer’s own website, through the same Tzulo proxy address used to set up the ngrok account. It gave the FBI a device, that don’t rotate the way VPN exit nodes do.
> 
> From there the investigation turned into connecting dots. Once agents had a timeline of every IP address that device had used, they cross referenced it against known logins to accounts prosecutors already suspected belonged to Stokes:
> 
> - **On June 4, 2024,** the GDID’s device used an IP address in Tallinn, Estonia, where Stokes lived. The same IP had logged into his Snapchat account four minutes before that and his Facebook account about 80 minutes after.
> - **On November 17 and 18, 2024** , the same device showed up on a New York IP address, matched to logins on one of Stokes’ Apple accounts and his Snapchat account. Weeks later, on **November 26** , the same device visited the website for the Empire Hotel in New York, matching another confirmed Stokes trip. He’d posted a Snapchat photo the day before that investigators matched, down to the carpet and wallpaper, against publicly advertised photos of an Empire Hotel suite.
> - **On February 2, 2025** , the device appeared on a Thailand based IP, matched again to his Apple and Snapchat logins. Stokes had posted a Snapchat photo captioned “WALDORF ASTORIA BANGKOK” the day before.
> - **On January 8, 2025** , the same device, now back on an Estonian IP, logged into the mobile game Growtopia. The day before, that same IP address had accessed one of Stokes’ Apple accounts, then a Ubisoft account tied to that Growtopia login two minutes later.
> 
> Of course, all these activities doesn’t seem suspicious when taken individually. What made the case is that the same GDID and physical Windows installation, kept showing up at the exact times as accounts investigators already knew were Stokes’, across four countries over roughly eight months.

> [@kabob3801](#):
>
> assuming the browser was using the operating systems DNS, and said DNS wasn’t encrypted. Thats likely how.

Something’s still off to me. The hacker wouldn’t have known to use an encrypted DNS?

---

## Post 40 by @Pedja — 2026-08-10T00:31:50Z

He was probably using Edge. How would encrypted DNS have helped him, even if he had thought of it?

---

## Post 41 by @eteszi — 2026-08-10T06:16:14Z

This is only possible if he used Edge.

By default in Windows telemetry is set at the Optional diagnostic data level, unless it was disabled during installation or in the settings. With this level of telemetry, [Edge collects browsing history](https://www.microsoft.com/en-us/privacy/data-collection-windows).

> This type of **Optional diagnostic data** includes details about web browsing in the Microsoft browsers.  
> Browser activity, including browsing history and search terms in Microsoft browsers.

As for other options: Bing search engine was installed in the browser, through which the link was sent to the servers, or through SmartScreen.
