Q: If a Chinese company had done this, it could have become a major issue in the US.
A:
Yes, you're right — it almost certainly would have become a major national security and policy issue in the US.
Why the Double Standard Exists
- Geopolitical context: Microsoft is a US company subject to US laws (e.g., warrants, CLOUD Act). US authorities can compel data with legal process. A Chinese company is subject to China's National Intelligence Law, which requires cooperation with state intelligence efforts. This creates a fundamental trust gap in the eyes of US policymakers.
- Precedents with Chinese tech:
- TikTok/ByteDance: Faced intense scrutiny, attempted bans, forced sale attempts, and national security reviews precisely over data collection, potential access by the Chinese government, and telemetry/behavioral tracking.
- Huawei/ZTE: Effectively banned from critical US infrastructure over concerns that their equipment could enable surveillance or backdoors.
- Other Chinese apps/OS: Similar restrictions or warnings (e.g., WeChat, certain drones, Kaspersky — though the latter is Russian).
If a Chinese firm had a persistent device identifier like GDID, built-in telemetry that survives VPNs, and cooperated with law enforcement (or intelligence) in the same way, it would likely trigger:
- Congressional hearings.
- CFIUS reviews or outright bans.
- Executive orders.
- Public campaigns labeling it a "spyware" threat.
The Microsoft Case Reality
The GDID/telemetry story has generated privacy discussions and some media coverage, but
no comparable outrage or calls for bans. Reasons include:
- Microsoft is a domestic champion and complies with US legal requests.
- The capabilities are framed as "diagnostics" and law enforcement tools rather than foreign espionage risks.
- Similar (or stronger) telemetry exists across Big Tech (Apple, Google, etc.), so there's normalization.
Critics (including privacy advocates) argue this highlights
selective enforcement: US companies get the benefit of the doubt on surveillance capabilities that would be treated as existential threats if foreign.
Broader Truth
All major platforms (US, Chinese, European) collect significant device and behavioral data. The real differentiator in US policy is often
national allegiance and legal jurisdiction, not the raw technical capability. This is why "trusted" vs. "untrusted" vendors is a recurring theme in supply chain security.
The Stokes case is a reminder that modern operating systems are inherently telemetry platforms. Whether that's acceptable depends on who controls the company and which government can access the data.
If you'd like examples of similar capabilities in other ecosystems (Android, iOS, etc.) or deeper dives into the policy angles, just say the word.
------
Post added on Jul 11, 2026 at 8:06 AM