12 ms·
Windows 11 x64 security hardening guide
- cowtools 4y ago
- pid-1 4y agoIn a business environmeny many of those configs can be automated either using GPOs or Intune/ MDM.
- politelemon 4y agoInteresting list. Any idea of the 'why' behind this? > No "Tuning" tools (not even stuff like Ccleaner!) Also what is a better alternative to 7zip > avoid insecure software like 7-Zip (which e.g. lacks Anti-Exploit and MOTW support)
- oriettaxx 4y ago> Any idea of the 'why' behind this? I'm pretty curious, too > Also what is a better alternative to 7zip is 7zip necessary nowadays? can the built in zip/unzip feature be enough?
- Bluecobra 4y agoThe built in one only supports .zip format AFAIK. 7zip supports basically everything you will come across including .rar and .gz. Also it’s nice to have the Explorer shortcuts (right click, unzip here).
- cshokie 4y agoWindows has a version of tar included nowadays which helps with some of the non-zip formats (although only from the command line).
- unionpivo 4y agoDoesn't work on all zip files I receive. Doesn't support the bz2 and other that are quite frequent in my environment. I haven't tested it, but my perception is that it's slower when there are a lot of small files.
- scrlk 4y ago> avoid insecure software like 7-Zip (which e.g. lacks Anti-Exploit and MOTW support) MOTW support has been introduced in v22.00 [1]: >- New option "Propagate Zone.Id stream" in Tools/Options/7-Zip menu. [1] https://www.7-zip.org/history.txt https://www.7-zip.org/history.txt
- deleted 4y ago[deleted]
- deleted 4y ago[deleted]
- fzfaa 4y agoI didn't know anybody saw MOTW as a positive. I hate it and I don't see what problem it solves.
- judge2020 4y agoReally? When it’s not you but a tech illiterate computer ‘newbie’, you don’t see any benefit to a popup warning them that “programs downloaded from the internet could be dangerous”?
- josefx 4y agoDidn't we go through this with Vista? The average tech illiterate user only ends up trained to ignore and continue. You might as well drop a few hundred knives labeled "warning sharp" in the middle of a playground.
- josephcsible 4y agoIt's reasonable to have guessed that there'd be a benefit before it was implemented, but now that we actually have such a popup, it's clear that there's not, because the newbies all ignore its warning and run the malware anyway.
- AshamedCaptain 4y agoThe entire list can be summarized into "Just use the latest versions of Microsoft everything, and uninstall all 3rd party software" (how convenient, I bet they also recommend using OneDrive). They even explicitly recommend against any 3rd party security software. Yet however 7-zip gets the boot because it apparently is not compatible with a 3rd party "Anti-Exploit" software (Malwarebytes) ?
- invokestatic 4y agoIt’s actually not bad advice, and it feels crazy to say this considering the security of Windows was atrocious 15 years ago. At least the bundled zip extractor receives auto-updates via Windows Update. If a zero day RCE drops in 7-zip, how many users will actually be patched 6 months later? 1 year later? I would imagine it would still be a viable exploit because not many people keep their third party software up to date. Edge really does have security and isolation features that far exceed any other browser (WDAG), Windows Defender is surprisingly adequate and third-party AV software expose a substantial attack surface.
- kevingadd 4y ago7-zip is infamous at this point for having security holes, and iirc it still is compiled without things like control flow integrity or stack checks. It at least has ASLR now. For zips the windows built in support might be adequate, but I've yet to find a safe 7z unarchiver :(
- cbsks 4y agoI haven’t use it, but this fork of 7zip claims to have added some security features including Control Flow Guard and Control-flow Enforcement Technology (CET) Shadow Stack: https://github.com/M2Team/NanaZip https://github.com/M2Team/NanaZip
- Rafert 4y agoWas curious about 7-zip too, TIL about "origin laundering": https://textslashplain.com/2016/04/04/downloads-and-the-mark-of-the-web/ https://textslashplain.com/2016/04/04/downloads-and-the-mark...
- pid-1 4y ago> create another Admin account and transform your current one to limited/ restricted/ standard user account to reduce the attack surface enormously. Don't use Admin account for your tasks! It's crazy how Windows doesn't have a sane way for users to became administrators temporarily. LAPS is a weird hack and Azure PIM doesn't work for local admin.
- kevingadd 4y agoThere's a 'run as' mechanism built in and accessible via GUI inside of Task Manager (File -> Run New Task) and the command prompt ('runas'). You can also open an Administrator Command Prompt.
- glowingly 4y agoAt work, we have an applied policy that shows an elevated prompt for most things that need admin permissions. It's apparently one of those hidden UAC settings that either needs GPO or regedit to enable. So it's there, just not really exposed to end users.
- oritsnile 4y agoIt's crazy, if you don't separate your admin account, the UAC prompt can be bypassed due to the default settings.
- BrandoElFollito 4y ago> enormously [citation needed] https://xkcd.com/1200/ https://xkcd.com/1200/ What is the valuable thing for an attacker? User data, credentials? Available as a user Computer capacities for mining? Available as a user Installing persistence? Available as a user Installing remote management? Available as a user
- rubenbe 4y agoAs a long time Linux user, I recently got confronted with the Windows group policy editor. You can use it to disable (blacklist) all the Windows crapware (xbox, etc). Or in the extreme case, whitelist only specific files. I still prefer a text config file over the GUI, but this thing is insanely powerful.
- delta_p_delta_x 4y agoAlmost all office IT departments use `gpedit.msc` to provision and disable features for employee devices. `gpedit.msc`, `regedit.msc`, PowerShell, and Active Directory are pretty much the standard toolset for any Windows sysadmin.
- josephcsible 4y agoKeep in mind that it's restricted to Pro and up. Are you a home user who wants to disable all the crapware and telemetry Microsoft infected your machine with? You've got to pay Microsoft more money to be allowed to do that!
- encryptluks2 4y agoA quick Google search will show how easy it is to enable the Local Group Policy Editor on Windows Home.
- TingPing 4y agoSure it's easy to crack windows too. They still put too much behind Pro like disk encryption, something that should be default.
- encryptluks2 4y agoI don't argue with that... I think it should be default, but I am hopeful that people will still try it out. The steps to install Group Policy in Windows Home are pretty straightforward and similar to adding other Windows features.
- 4y ago
- josephcsible 4y ago> avoid insecure software like 7-Zip (which e.g. lacks Anti-Exploit and MOTW support), Open/ LibreOffice, Firefox, True/Veracrypt, ... This is such bad advice that I can't take the rest of this guide seriously. Edit: The rest is even worse than I was expecting. E.g.: > execute/ open new files with one-day-delay because after one day, the malware is not 0-day anymore > use the only browser on Windows that natively supports hardware isolation: Edge
- scrlk 4y agoThe whole thing gives off a smell of cargo cult security. E.g. "7-Zip doesn't have anti exploit support". Dug in to the source for that claim - it's a forum post of someone running Windows XP in 2020 (!) with an ancient version of Malwarebytes.
- dwattttt 4y agoIt's still true today; the current version of 7zip doesn't support Control Flow Guard (validated on Win11), and there's lots of security features that come _after_ supporting that.
- scrlk 4y agoI'm not a Windows developer, so this might be a stupid question: is simply a case of just building 7-Zip from source and enabling the Control Flow Guard flag in Visual Studio, or does it require more work?
- Bolkan 4y agoHow much of this applies to win10?
- claudiojulio 4y agoThe best and simplest way to keep Windows 11 safe is to burn the disk it is installed on with gasoline; buying another and installing a Linux distribution such as Debian, OpenSuse and Fedora.
- 0x_rs 4y agoI don't like this guide at all. Some of its points are questionable, but the thing is, it doesn't know what it wants to be and aimed at whom. Starting from the most obvious red flag, falling for the baseless boycotting of 7zip like some equally questionable sites and threads have been pushing (and their motives, such as sourceforge bad, all Russian developers bad and the proposed alternatives.. let's not get started). [0] [1] This suggests not to use privacy tools (most of which are FOSS and perfectly safe with proper usage), and to rely on official documentation only. I suppose there's some trouble in people for example disabling (extremely invasive) updates and forgetting about it, the average Joe that is. Some others are a compromise on privacy, I'd never accept cloud-based protection. Veracrypt is perfectly safe software, unlike the claims in this page that goes on to just mention how it breaks the boot trust chain, furthermore I'd trust it more than anything BitLocker does unless it's strictly a pre-boot authentication password with no TPM. Windows cannot be made perfectly safe, accept and move on, this self-flagellation seeking the most hardened possible setup with things such as avoiding Firefox is a waste of time. Microsoft itself distributes what some may define malware, autorunning at startup forever on with a rundll process with Windows Update (see: logitech download assistant if you plug in one of their mice). 0. https://news.ycombinator.com/item?id=31876896 https://news.ycombinator.com/item?id=31876896 1. https://www.theregister.com/2022/06/27/7zip_compression_tool/ https://www.theregister.com/2022/06/27/7zip_compression_tool...
- nick9847 4y agoTalk about unnecessary complication. This is extreme paranoia in this day and age.