How make the Windows more security for free beyond installing another O.S.?Even by apply the concept defense in depth, the Windows looks pretty hard to keep well defense.


You can't. But if you really want to, disconnect from the net.

Alright, if you really really have to, then your best bet may be to separate it into it's own protected network segment. I imagine putting it into it's own VLAN might be a good idea.
Use your own DIY router.
Also and most importantly put that PC behind a DIY hardware firewall. It must be a HARDWARE firewall. And it should be one using either BSD or Linux.


But IMO, and no flame intended, securing WIndows 'properly' is a pipe dream.


disable powershell
disable macros in word
use auto updates
uninstall java / flash /silverlight
run in usermode rather than admin

windows 10 is very secure, it's just not private.


Also, like on any other platform, install and use NoScript.
That'll already do quite a lot.


Is there anything similar to Tiny7 for Windows 10 ? I just got the latest iso by generation from trackers and god damn it has a lot of bullsoykaf bloat.


I just want to improve the security. I don't silly dream in making the same a fortress, just a barricade.

Like the open-wrt?

I agree with the list case but, why disable the PowerShell?

Isn't better use umatrix block everything in global and allow case by case?


open-wrt yes. bbbbbbbbbbbbbbbbbbbbbbbbbbbbbb


Thats what I do,

I believe in noise, we need a minimum amount of noise to stay under the radar IMO. So I use windows 10 for gaming. Because of SteamVR etc.

Use Spybot Anti-beacon, it will block a lot of crap, use FOSS as much as you can, browse site like this with TOR.

You wont be a fortress, bout you will be noisy enough to be ignored while doing your thing.

Make sure you stay up to day, dont run odd programs, keep it behind NAT at all times!


Also work on securing your god damn phone most of all.

Your desktop is nothing to the, compared to your phone.

If on android get rid of google apps, that soykaf is a cancer, install MicroG if you need to compatibility layer, run AFWall to block out all non FOSS apps until you need them. Use FOSS apps as much as you can.

Keep location and the radios off if you are not using them.

Use a completely FOSS ROM too, MicroG works best with them, encrypt it and thats that.

For internet at work I use a wifi repeater at my window. no cell data during the day.


There have been / are many many vulns / viruses that leverage powershell.


win 10 decided to reinstall flash for me after i removed it


you see, phones are broken by design, and your (backdoored) sim/firmware blobs are always there, turning on those features at will


They are, and they should not be trusted, but we need to be realistic.

If you are at the point where you have a state player involved you should have already burnt your phone, or ensure its powered off.

They are broken by design, but we should be pragmatic and plan ahead encase the soykaf does hit the fan.


Same here. I just use Windows for 4 things: Learn how make the windows security, old games, use a normal e-mail.

Thanks for the tip.

Also, I trying use MBSA and EMET.


Please, could move the thread to >>>/sec/?


Not particularly spoopy when you agreed to them doing that in the EULA. Just a symptom of non-free software.


