
IPVanish has introduced a remote browser isolation feature designed to prevent Windows telemetry from directly correlating browsing activity with Microsoft's persistent Global Device Identifier (GDID).
The company announced IPVanish Secure Browser, citing the recently disclosed use of Windows telemetry in a US cybercrime investigation, in which Microsoft records helped identify an alleged hacker despite the use of VPN infrastructure.
According to an unsealed federal criminal complaint, Microsoft associated activity with a persistent GDID tied to a Windows installation and correlated that identifier with IP address changes, including VPN endpoints and residential, hotel, and mobile connections allegedly used by Scattered Spider member Peter Stokes.
IPVanish is a commercial VPN and privacy service operated by Ziff Davis. Its new Secure Browser uses Remote Browser Isolation (RBI), which moves web browsing away from the user's physical computer and into temporary cloud-hosted Linux containers.
A traditional VPN encrypts traffic between a user's device and the VPN server, hiding the user's real IP address from websites and local network observers. However, it does not prevent Windows itself from generating telemetry or associating network activity with identifiers tied to the operating system.
In the Stokes case, prosecutors said Microsoft records linked the same Windows GDID to activity occurring across multiple IP addresses. That telemetry was only one part of a broader body of evidence that also included provider records, social media accounts, seized infrastructure, and travel information.
Browsing moved off the local PC
IPVanish says its Secure Browser reduces this exposure by running websites, scripts, DNS lookups, cookies, and other browser processes inside a remote container rather than directly on the Windows system.
The local computer maintains an encrypted connection to the remote browsing service, while destination websites are contacted from the cloud environment. When the session ends, IPVanish says the temporary container and its associated browsing data are deleted.
This means Windows can still see that the computer is connected to the Secure Browser service, but it should not directly observe individual websites, destination IP addresses, or DNS requests generated within the remote session.
Importantly, the feature does not disable or remove Microsoft's GDID. The identifier remains present on the Windows installation, and Microsoft can continue to receive any telemetry the operating system is configured to send. Instead, the isolation layer is intended to keep specific browsing activity outside the local operating system's direct view.
Remote browser isolation can also limit exposure to malicious websites because web code executes in the cloud rather than on the endpoint. It may also reduce local browser artifacts such as cookies, cache files, and browsing history.
However, RBI does not make users anonymous. Signing into personal accounts or providing identifying information can still link remote sessions to an individual, while the remote browsing provider itself becomes part of the trust model.
Users seeking stronger privacy should treat VPNs as a single layer and consider compartmentalized or isolated browsing for activities where reducing local telemetry exposure is important.







Leave a Reply