3 ms·
Install free Comodo Internet Security. Disable DNS cache service so that all your apps resolve DNS themselves (can only be done via the registry, change the se
by walkingby111723 4y ago
Install free Comodo Internet Security.
Disable DNS cache service so that all your apps resolve DNS themselves (can only be done via the registry, change the service's startup type from 2 (auto) to 4 (disabled)).
In CIS, create a new group for all files under c:/windows.
Create a rule denying all in/out requests to that group.
Create a rule allowing only DHCP and NTP requests (255.255.255.255:67 and <whatever-timeserver-you-trust>:123) for svchost.exe (place that rule above the one for c:/windows to ensure precedence).
Use third-party utilities instead of the likes of ping.exe, e.g. hrping.
Refer to CIS documentation in case of any troubles.
Enjoy your privacy-hardened windows.
- walkingby111723 4y ago
- walkingby111723 4y ago
- Jon_Lowtek 4y agotake it with two tablespoons of salt if someone who avoids the onboard ping tool claims there are no ill effect of blocking all network connections of OS components except DHCP and NTP. This recommendation will cripple windows features and your enjoyment may vary. (breaking updates, breaking crls, breaking active directory integration, breaking office integration, breaking push notifications, breaking companion app integration, ... and so on)
- ccbccccbbcccbb 4y ago[dead]
- Jon_Lowtek 4y agoyou misunderstood the reference: "this" was meant to mean the recommendation in the parent post. I edited my post to be clearer. concerning the intentional breaking of the windows updater and then using a third party update tool: such workarounds don't make the recommendation less bad. The question is: why break the onboard updater in the first place? And all those other features? Sure you have an alternative to office365 and to onedrive and live without the companion app is possible and happy, and maybe you even have a third party crl updater as well and a workaround for the side effects of blocking oscp. But honestly if you want to replace everything because microsoft is bad and can't be trusted, then start by replacing the kernel.
- ccbccccbbcccbb 4y ago> The question is: why break the onboard updater in the first place? And all those other features? Because none of those features are irreplaceable and/or crucial to run a perfectly fine workstation. > if you want to replace everything because microsoft is bad and can't be trusted, then start by replacing the kernel. Unless Windows kernel phones home over some covert physical channel which is undetectable by tools like Wireshark running on a separate gateway (and secretly supported by all routers in existence), there's absolutely zero need to replace the kernel when all said phoning home can be stopped with a properly configured firewall.