Extremely promising Windows security hardening tool: HotCakeX

4 Likes

The colors and GIFs are a lot to take in lol. Does look interesting, however it does seem to sacrifice some privacy in the name of security for a handful of settings.

1 Like

haha that was my first reaction too.

Yes that definitely is the case as she’s basically just following all of Microsoft’s recommendations. Either way, still a great repo.

Windows by default is secure and safe

Doesn’t sandbox your apps by default

mfw. No it isn’t..

I love the design of this tool tho, very unique and pretty.

2 Likes

I disagree with that statement too lol.

1 Like

Compared to what?

It’s a security tool, not a privacy tool, so it makes sense.

2 Likes

Android/ChromeOS. An OS isn’t ‘secure by default’ if any program that is executed has full access to user data and/or can do whatever it wants to the system. Also, to my knowledge, there is no way other than virtualisation to securely sandbox windows apps. Preventing sandbox escapes require blacklisting some widely used syscalls which in turn breaks lots of common programs. Linux sandboxing is much better.

Let’s not turn this into another broad desktop OS discussion please.

4 Likes

There is also BeerIsGood who has both Windows and macOS hardening guides. It also has a link to this one and mentions that it provides more hardening and is better maintained.

2 Likes

Did you try this script?

yeah it works nicely.

Oh awesome! Did you do all the categories? It seems the script turns on a lot of potential things that would hurt privacy? Or am I mistaken?

I messed around with it in a VM and tried all the categories for the lols.

That’s true, a lot of the settings can compromise your privacy. I would recommend reading through what each option does before deciding if you should enable it or not.

1 Like

This update marks the inaugural release of the Harden System Security application, representing a comprehensive reimagining of the original module. The new application is architected for enhanced efficiency, fortified security, and superior user experience.

It seems like this tool has received quite the substantial update.

The update is nice as the app store version works for more versions of Windows (such as iot).

I still think for casual users its a bit heavy handed. For example the recommended presets disables NTLM authentication (when I tested it did so regardless if I have the “block NTLM” box checked), which for most users will mean remote desktop is blocked. I doubt most users would want that.

But it is a nice tool if you are willing to research a bit before screwing with it.

3 Likes

I wouldn’t follow any of her advice. She sounds like someone working for or paid by Microsoft to shill all their products because it’s clearly biased in their favor. Windows is not safe, nor is anything else from Microsoft.

There are situations where using VPN can provide security and privacy. For example, when using a public WiFi hotspot or basically any network that you don’t have control over. In such cases, use Cloudflare WARP which uses WireGuard protocol, or as mentioned, use Secure Network in Edge browser that utilizes the same secure Cloudflare network.

So the connection goes from you → Cloudflare WARP → Cloudflare CDN → site basically defeating the whole point of the VPN and allowing sites to identify you? Or you → Microsoft → Cloudflare → Cloudflare → site if using the so-called “secure network”? This is worse than no VPN at all. It’s like using Tor is one company controlled all the entry, middle, and exit nodes and all of the onionsites. Even if it isn’t, most VPNs nowadays use WireGuard.

Use Microsoft account (MSA) or Microsoft Entra ID to sign into Windows. Never use local administrators. Real security is achieved when there is no local administrator and identities are managed using Entra ID.

Connecting an online account to your whole system is one of the worst things you could do for privacy, security, and software freedom. What happens if Microsoft suddenly locks your account as they’ve done? Do users lose access to their own desktop?

BeerIsGood’s advice isn’t any better. But let all of this be a reminder as to what PrivacyGuides could have become if security was the only focus and the majority of users and team members were big tech advocates.

while I agree the connected account is worse on the privacy end, local accounts are laughably easy to get into. Geek Squad breaks into peoples local accounts all the time and has their own proprietary software to do so.

In nature, such vibrant displays are used to overwhelm and distract prey before moving in for the kill.

Some strong opinions on privacy from the author:

tl;dr
She failed to sync time in Whonix, because anonymity is hard. So why don’t you want Mossad spying on your devices? Do you want to live in a terrorists paradise or what?

But the tool seems nice, I would like to use something like this. If we had similar thing from a random anonymous “privacy-centered” dev, it wouldn’t be any better, I guess, because it seems like no-one seriously auditing anything open-sourced anyway.

1 Like