3 ms·
I too believe that for most people Windows 10 out-of-the-box is more secure than most Linux distros. Sure you can lock-down an Arch build but it's difficult (ev
by sumtotal 7y ago
I too believe that for most people Windows 10 out-of-the-box is more secure than most Linux distros. Sure you can lock-down an Arch build but it's difficult (even for the technically inclined), time-consuming and needs constant monitoring and sometimes manual updating/reconfiguration.
For Windows I do all of the things shared below (plus a few other tweaks) which are good enough a medium security risk level. The combination of all of them represent a significant barrier to non-state actors;
-Upgrade to Windows Pro
-Change computer name to something nondescript
-Use a local login account (no email address)
-Create a separate Admin and Standard account
-Install favourite Anti-Virus and Firewall
-Enable Exploit Protection (CFG, DEP, Mandatory ASLR, Bottom-up ASLR, High-entropy ASLR, SEHOP and Heap Integrity)
-Enable Windows Defender Application Guard and Core isolation memory integrity
-Install preferred VPN
-Install trusted password manager
-Crank UAC to the highest setting
-Use an encrypted Virtual Drive for files
-Disable AutoPlay for all devices
-Activate all privacy toggles in Windows Settings
-Reduce telemetry to the minimum allowed
-Ensure cloud clipboard is disabled (!)
-Defer feature updates but allow quality (security) updates
-Receive updates directly from Microsoft and not third-parties
-Run PowerShell script to remove any pre-installed, non-Microsoft, junkware
-Enable BitLocker with triple factor authentication (TPM + Enhanced PIN + USB)
-Activate BitLocker 256-bit encryption in XTS-AES mode
-Disable BitLocker recovery key
-Require Secure Boot and Additional Authentication at -Startup
-Enable device lockout after X number of invalid login attempts
-Disable NTLM and SMB
-Disable debugging logs
-Disable Sleep Mode
-Disable Hide extensions for known file types
-Enable Show hidden files, folders and drives
-Harden web browser by disabling all unnecessary features
-Install content blockers into web browser
- lcall 7y ago> I too believe that for most people Windows 10 out-of-the-box is more secure than most Linux distros. At the risk of being off-topic: Even if that were true (which I doubt but it has been better-debated elsewhere) ... 1) that list would be much-changing over time, and 2) it seems like Debian (or Devuan) stays on top of things reasonably well, especially if you add a firewall (I've liked the "arno-iptables-firewall" one though it doesn't seem to auto-start any more except on Devuan). Also, the length and changeability of that list illustrate why I use OpenBSD: it is more secure by default (as a key goal), and then when you make changes to the default config you can consider the security implications of each change. They put a lot of attention into auditing and making good design choices. Having said all that, many people simply won't like the feel of bsd or linux, and prefer a more commercial experience (for lack of a better term). (Edit: more of my thoughts on that, hopefully lightweight and skimmable, at http://lukecall.net/e-9223372036854587380.html http://lukecall.net/e-9223372036854587380.html ) But thanks for posting that list, as it could help someone. Edit: I also posted here some things I do on any system, for safer browsing: https://yro.slashdot.org/comments.pl?sid=13803908&cid=58464622 https://yro.slashdot.org/comments.pl?sid=13803908&cid=584646... (part of: https://yro.slashdot.org/story/19/04/19/2345227/incognito-mode-isnt-really-private-try-browser-compartmentalization https://yro.slashdot.org/story/19/04/19/2345227/incognito-mo... ).