privacyguides.org icon indicating copy to clipboard operation
privacyguides.org copied to clipboard

Re-write of Windows Page

Open dngray opened this issue 2 years ago • 42 comments

Description

https://privacyguides.org/operating-systems/#win10

This page does need to be re-written. It is quite a bit out of date. I think we could benefit from bringing https://github.com/privacytools/privacytools.io/issues/926 forward into this PR.

Additionally regarding removal of Cortana, (something that wasn't possible when that page was written), we should provide instruction https://github.com/privacytools/privacytools.io/issues/926#issuecomment-707844416.

It's worth noting O&O ShutUp10, already supports Windows 11.

Closes: https://github.com/privacyguides/privacyguides.org/issues/172#issuecomment-942002749

dngray avatar Oct 05 '21 09:10 dngray

I would recommend adding a guide to disable telemetry as indicated here: https://github.com/privacyguides/privacyguides.org/discussions/169#discussioncomment-1474036

  1. The first step is to activate Windows, it can be followed the official way or the "unofficial one" (parenthesis points refer to the "unofficial", be aware that depending on the place you live this operation may be not completely legal and that the following activation procedure is made for Windows 10 but with the right changes can be easily adapted to Windows 11): (2.) Go to Settings ------> Update & security ------> Activation --------> Change product key (3.) Enter the following generic product key and click Next. Follow the prompts all the way through. (4.) XGVPP-NMH47-7TTHJ-W3FW7-8HV2C [source] (5.) Now reboot the computer (6.) Use massgravel's HWID activation method: https://github.com/massgravel/Microsoft-Activation-Scripts§
  2. (7.) Follow the official guidelines to deactivate telemetry: https://docs.microsoft.com/en-us/windows/privacy/configure-windows-diagnostic-data-in-your-organization

It would also be a good idea for those who want more security (and also performance) at the expense of some functionality (in particular, it will only be possible to install apps from Microsoft Store*) to switch to Windows S mode. At the moment Windows 11 in S mode is available only for the Home edition, while Windows 10 in S mode is available for all its editions: Home, Enterprise, Education and Pro.

*Note: If you switch out of S mode, you can install 32-bit (x86) Windows apps that aren’t available in the Microsoft Store in Windows. If you make this switch, it's permanent, and 64-bit (x64) apps still won't run.

JnTon avatar Oct 15 '21 00:10 JnTon

The S mode has a lot of things to be noted btw :

  • you can only install apps from microsoft store

  • you can't change your default browser ( edge will always stay as the default ) . You can however install other web browsers

  • also you cannot change the search engine of microsoft edge to anything other than bing . It forces people to use bing .

  • you can't use powershell ,cmd etc

  • you don't have access to windows registry through registry editor either ...

Overall I don't think it's a good thing unless it's been set up in a school or something

ghost avatar Nov 14 '21 12:11 ghost

I would recommend ThisIsWindows11 It's an open source software and is visually appealing and user friendly to use

ghost avatar Nov 15 '21 08:11 ghost

Regarding shutup10, we might want to see if the same thing is possible with the https://docs.microsoft.com/en-us/windows/privacy/windows-10-and-privacy-compliance

dngray avatar Dec 19 '21 03:12 dngray

Another thing regarding this we should mention uninstalling Cortana, which was made possible as of May 2020 (build 2004). It's possible via PowerShell:

Get-appxpackage -allusers *Microsoft.549981C3F5F10* | Remove-AppxPackage

Or if you have Winget:

winget uninstall cortana

dngray avatar Dec 19 '21 03:12 dngray

I really think you guys should look into Windows Enterprise and level 0 telemetry (they renamed to diagnostic data something in W11). As far as I know, most (if not all) of the privacy changes can be made via group policy or the settings so there's really no need for 3rd party tools.

ghost avatar Dec 20 '21 03:12 ghost

Windows Enterprise and level 0 telemetry (they renamed to diagnostic data something in W11

Pretty sure that is the Windows Restricted Traffic Limited Functionality Baseline.

dngray avatar Dec 20 '21 06:12 dngray

Another thing we have to look into is recommending that if people eill be using Windows, is that they shoild try and choose computers which support the neccesary features for hardware based security. Things like intel vt-d for iommu and uefi/tpm for secureboot.

The best is that peoppe choose devuces which are certified by the windows secure core program.

blacklight447 avatar Jan 01 '22 17:01 blacklight447

Windows Enterprise and level 0 telemetry (they renamed to diagnostic data something in W11

Pretty sure that is the Windows Restricted Traffic Limited Functionality Baseline.

Not exactly. I got to play around and level 0 telemetry is only a part of the group policies that the restricted functionality baseline deploys (https://docs.microsoft.com/en-us/windows/privacy/manage-connections-from-windows-operating-system-components-to-microsoft-services#1816-feedback--diagnostics).

A lot of the policies also seem to be privacy/security regressive (e.g no windows update, no Microsoft store - i.e. no UWP apps, etc.). Perhaps we should try to pick out what policies aren't regressive (e.g. cortana related policies) and go on from there.

I think I've been saying things that you already know so I'll leave it at that.

ghost avatar Jan 18 '22 11:01 ghost

Recommeding things, like Windows Enterprise, that are not legally available for consumers, is probably not a good idea for privacy or security. Bootleg software is pretty notorious for malware.

ilmaisin avatar Feb 13 '22 18:02 ilmaisin

You can get Windows Enterprise straight from the media creation tool.

ghost avatar Feb 13 '22 23:02 ghost

The thing with installing anything other than windows 11 pro is very minimum . Like for example if you install the workstation version and above ( the enterprise ones ) ,it doesn't come installed with the Extra bloat like Photoshop and stuff .

Another thing is we could recommend simplefirewall ( it has a custom config to block some specific windows thing iirc )

And This Essentially simplefirewall utilises this only anyways

And then above this all we can utilise winget to uninstall Microsoft teams or edge and stuff

Guardian-Dusty avatar Mar 05 '22 14:03 Guardian-Dusty

Recommeding things, like Windows Enterprise, that are not legally available for consumers, is probably not a good idea for privacy or security. Bootleg software is pretty notorious for malware.

To add to what @xibeifenghenhaohe was saying, many students are able to get Education Edition (almost identical to enterprise) for free.

0rdinant avatar Mar 11 '22 01:03 0rdinant

I would recommend using BulkCrap Uninstaller for uninstalling things such as Cortana and Many UWP apps.

IkelAtomig avatar Mar 21 '22 06:03 IkelAtomig

There is some good material here https://github.com/beerisgood/Windows11_Hardening

We should see if @beerisgood would like to contribute to this page. I know they used to hang around old PTIO back in the day.

dngray avatar Mar 26 '22 16:03 dngray

Thanks for the link to my repository 🍺 Also see https://github.com/beerisgood/Windows11_Privacy

However, I have no interest in working on this or other PTIO project(s).

beerisgood avatar Mar 26 '22 22:03 beerisgood

https://www.ghacks.net/2022/03/28/windows-defender-vulnerable-driver-blocklist-protects-against-malicious-or-exploitable-drivers/ mention this as well

ghost avatar Mar 28 '22 13:03 ghost

https://www.windowslatest.com/2022/03/30/windows-11-to-get-smart-clipboard-and-actions-features/ - Need to cut off Telemetry and Internet Connection of Clipboard.

IkelAtomig avatar Apr 02 '22 11:04 IkelAtomig

When using with MS Account, windows recommends you to use Device Encryption which is nothing but Bitlocker but Encryption keys linked to MS account. Be carefult to note that. Say a proper way to use Bitlocker Encryption in the guide.

IkelAtomig avatar Apr 03 '22 14:04 IkelAtomig

Consider using this tool : https://www.ghacks.net/2022/04/09/bloatware-removal-tool-remove-pre-installed-windows-applications-and-more/ for removing Bloatware

IkelAtomig avatar Apr 10 '22 08:04 IkelAtomig

We currently don't have any Windows-specific recommendations at the moment. @dngray are we interested in re-introducing this page, or can this issue be closed?

jonaharagon avatar Apr 24 '22 02:04 jonaharagon

@jonaharagon Seriously!? Only Linux Fanboys can have Privacy not Windows ?

I know you are writing for MacOS. But you should consider Windows too.

Privacy Guides is actually to give advice for People on Privacy.

The Thing is AFAIK, dngray do not have Windows. So, He aint' testing it out.

You can ask for Windows users to contribute.

IkelAtomig avatar Apr 24 '22 04:04 IkelAtomig

Microsoft Windows still has a significant market share and is the dominant desktop OS (73% of the desktop market)^1. IMO, creating a Windows page should be high on our list.

elitejake avatar Apr 24 '22 15:04 elitejake

It is also evident from the website statistics that most visitors use Windows OS.

elitejake avatar May 03 '22 06:05 elitejake

It is also evident from the website statistics that most visitors use Windows OS.

I guess that it uses user agent for OS detection which is not reliable since people here probably spoof it.

pm4rcin avatar May 05 '22 10:05 pm4rcin

Recommend using TPM + Pin on Boot to prevent Cold boot attacks.

More Context - https://blog.elcomsoft.com/2021/01/understanding-bitlocker-tpm-protection/

Also here - https://www.kapilarya.com/enable-bitlocker-pin-in-windows-11 (Guide for How to Set it up)

IkelAtomig avatar May 06 '22 14:05 IkelAtomig

I think that this Guide should be focused on Windows 11 mainly not 'Only' as Windows 10 will be discontinued in 3yrs. Though there are no differences between them just UI. A suggestion though.

IkelAtomig avatar May 07 '22 06:05 IkelAtomig

Configure TPM + PIN as below in Group Policy.

image

IkelAtomig avatar May 07 '22 07:05 IkelAtomig

Very important reference according to me: https://www.makeuseof.com/windows-10-11-disable-telemetry/

cryptocat8 avatar Jun 08 '22 16:06 cryptocat8

  • you can't change your default browser ( edge will always stay as the default ) . You can however install other web browsers

So had another look at S-Mode today, and found this article from 2 June 2022.

Another limitation it puts on the user includes the web browser. Windows 11 S mode makes Microsoft Edge the default browser on your system. Now, here’s how it differs from Windows 10 S. In Windows 10 S, you cannot install any browser other than Microsoft Edge. Windows 11 provides some leeway in this area.

You can install other browsers, like Chrome and Firefox as long as they’re available in the Microsoft Store, on your Windows 11 S device. But, and that’s a big but, you cannot make any of them your default browser. Edge safely takes up that mantle; it will always be your default browser, come what may.

If we do mention it, it's worth mentioning that it is not available for Windows 11 Professional.

Windows 11 in S mode is only available in the Windows 11 Home edition. If you have the Pro, Enterprise, or Education editions of Windows 10 in S mode, Windows Update will not offer Windows 11 because S mode is not available in those editions of Windows 11. Therefore, if you have the Pro, Enterprise or Education editions of Windows 10 in S mode, you'll need to switch out of S mode to upgrade to Windows 11.

This will likely change in the future:

The upgrade rollout for Windows 11 begins in October 2021 and will continue into 2022. Specific timing will vary by device. After the upgrade has been tested and validated for your specific PC, Windows Update will indicate that it's ready for installation.

Maybe we'd like to write a guide a simple SRP policy or, a more advanced guide with WDAC/AppLocker.

dngray avatar Jun 10 '22 18:06 dngray