# Extremely promising Windows security hardening tool: HotCakeX

**URL:** https://discuss.privacyguides.net/t/extremely-promising-windows-security-hardening-tool-hotcakex/22753
**Category:** General
**Created:** 2024-11-26T15:03:10Z
**Posts:** 41

## Post 1 by @anon94009837 — 2024-11-26T15:03:11Z

> **[GitHub - HotCakeX/Harden-Windows-Security: Harden Windows Safely, Securely using Official...](https://github.com/HotCakeX/Harden-Windows-Security)**
>
> Harden Windows Safely, Securely using Official Supported Microsoft methods and proper explanation | Always up-to-date and works with the latest build of Windows | Provides tools and Guides for Personal, Enterprise, Government and Military security levels | Read The Rationale https://github.com/HotCakeX/Harden-Windows-Security/blob/main/Rationale.md

---

## Post 2 by @gregandcin — 2024-11-26T15:32:46Z

The colors and GIFs are a lot to take in lol. Does look interesting, however it does seem to sacrifice _some_ privacy in the name of security for a handful of settings.

---

## Post 3 by @anon94009837 — 2024-11-26T15:39:38Z

> [@gregandcin](#):
>
> The colors and GIFs are a lot to take in lol

haha that was my first reaction too.

> [@gregandcin](#):
>
> however it does seem to sacrifice _some_ privacy in the name of security for a handful of settings.

Yes that definitely is the case as she’s basically just following all of Microsoft’s recommendations. Either way, still a great repo.

---

## Post 4 by @asanyan — 2024-11-26T15:53:48Z

> Windows by default is secure and safe

> Doesn’t sandbox your apps by default

mfw. No it isn’t..

I love the design of this tool tho, very unique and pretty.

---

## Post 5 by @anon94009837 — 2024-11-26T15:54:39Z

> [@asanyan](#):
>
> > Windows by default is secure and safe

> [@asanyan](#):
>
> mfw. No it isn’t…

I disagree with that statement too lol.

---

## Post 6 by @anon48875053 — 2024-11-26T16:35:44Z

> [@asanyan](#):
>
> > Windows by default is secure and safe
> 
> > Doesn’t sandbox your apps by default
> 
> mfw. No it isn’t…

Compared to what?

---

## Post 7 by @anon48875053 — 2024-11-26T16:42:06Z

> [@gregandcin](#):
>
> Does look interesting, however it does seem to sacrifice _some_ privacy in the name of security for a handful of settings.

It’s a security tool, not a privacy tool, so it makes sense.

---

## Post 8 by @asanyan — 2024-11-26T17:11:19Z

Android/ChromeOS. An OS isn’t ‘secure by default’ if any program that is executed has full access to user data and/or can do whatever it wants to the system. Also, to my knowledge, there is no way other than virtualisation to securely sandbox windows apps. Preventing sandbox escapes require blacklisting some widely used syscalls which in turn breaks lots of common programs. Linux sandboxing is much better.

---

## Post 9 by @anon94009837 — 2024-11-26T17:14:41Z

Let’s not turn this into another broad desktop OS discussion please.

---

## Post 10 by @anon22773769 — 2024-11-26T20:17:35Z

There is also [BeerIsGood](https://github.com/beerisgood) who has both Windows and macOS hardening guides. It also has a link to this one and mentions that it provides more hardening and is better maintained.

---

## Post 11 by @anon54690201 — 2025-01-11T18:23:55Z

Did you try this script?

---

## Post 12 by @anon94009837 — 2025-01-11T21:21:59Z

yeah it works nicely.

---

## Post 13 by @anon54690201 — 2025-01-11T22:44:44Z

Oh awesome! Did you do all the categories? It seems the script turns on a lot of potential things that would hurt privacy? Or am I mistaken?

---

## Post 14 by @anon94009837 — 2025-01-11T23:51:00Z

> [@anon54690201](#):
>
> Oh awesome! Did you do all the categories?

I messed around with it in a VM and tried all the categories for the lols.

> [@anon54690201](#):
>
> It seems the script turns on a lot of potential things that would hurt privacy?

That’s true, a lot of the settings can compromise your privacy. I would recommend reading through what each option does before deciding if you should enable it or not.

---

## Post 15 by @HackOrSwim — 2025-08-04T20:55:49Z

> **[Release Harden System Security First Release! 🥳🎉 ·...](https://github.com/HotCakeX/Harden-Windows-Security/releases/tag/HardenSystemSecurity-v.1.0.1.0)**
>
> What's New
> This update marks the inaugural release of the Harden System Security application, representing a comprehensive reimagining of the original module. The new application is architected for...

> This update marks the inaugural release of the Harden System Security application, representing a comprehensive reimagining of the original module. The new application is architected for enhanced efficiency, fortified security, and superior user experience.

It seems like this tool has received quite the substantial update.

---

## Post 16 by @anon83428815 — 2025-08-05T13:16:01Z

The update is nice as the app store version works for more versions of Windows (such as iot).

I still think for casual users its a bit heavy handed. For example the recommended presets disables NTLM authentication (when I tested it did so regardless if I have the “block NTLM” box checked), which for most users will mean remote desktop is blocked. I doubt most users would want that.

But it is a nice tool if you are willing to research a bit before screwing with it.

---

## Post 17 by @anon11657877 — 2025-08-05T13:41:16Z

I wouldn’t follow any of her advice. She sounds like someone working for or paid by Microsoft to shill all their products because it’s clearly biased in their favor. Windows is not safe, nor is anything else from Microsoft.

> There are situations where using VPN can provide security and privacy. For example, when using a public WiFi hotspot or basically any network that you don’t have control over. In such cases, **use Cloudflare WARP** which uses WireGuard protocol, or as mentioned, **use Secure Network** in Edge browser that utilizes the same secure Cloudflare network.

So the connection goes from you → Cloudflare WARP → Cloudflare CDN → site basically defeating the whole point of the VPN and allowing sites to identify you? Or you → Microsoft → Cloudflare → Cloudflare → site if using the so-called “secure network”? This is worse than no VPN at all. It’s like using Tor is one company controlled all the entry, middle, and exit nodes and all of the onionsites. Even if it isn’t, most VPNs nowadays use WireGuard.

> **Use Microsoft account** (MSA) or Microsoft Entra ID to sign into Windows. **Never use local administrators**. Real security is achieved when there is no local administrator and identities are managed using Entra ID.

Connecting an online account to your whole system is one of the worst things you could do for privacy, security, and software freedom. What happens if Microsoft suddenly locks your account as they’ve done? Do users lose access to their own desktop?

> [@anon22773769](#):
>
> There is also [BeerIsGood](https://github.com/beerisgood) who has both Windows and macOS hardening guides. It also has a link to this one and mentions that it provides more hardening and is better maintained.

BeerIsGood’s advice isn’t any better. But let all of this be a reminder as to what PrivacyGuides could have become if security was the only focus and the majority of users and team members were big tech advocates.

---

## Post 18 by @anonymous378 — 2025-08-05T15:03:43Z

> [@anon11657877](#):
>
> Connecting an online account to your whole system is one of the worst things you could do for privacy, security, and software freedom.

while I agree the connected account is worse on the privacy end, local accounts are laughably easy to get into. Geek Squad breaks into peoples local accounts all the time and has their own proprietary software to do so.

---

## Post 19 by @anon94117004 — 2025-08-05T15:03:57Z

> [@gregandcin](#):
>
> The colors and GIFs are a lot to take in lol.

In nature, such vibrant displays are used to overwhelm and distract prey before moving in for the kill.

---

## Post 20 by @n_n — 2025-08-05T16:05:21Z

Some strong opinions on privacy from the author:

> **[GitHub - HotCakeX/Privacy-Anonymity-Compartmentalization: This GitHub repository explores the topics of...](https://github.com/HotCakeX/Privacy-Anonymity-Compartmentalization)**
>
> This GitHub repository explores the topics of privacy, anonymity and compartmentalization. These concepts are interrelated and essential for protecting one’s identity, data and online activities from unwanted surveillance, tracking and interference.

tl;dr  
She failed to sync time in Whonix, because anonymity is hard. So why don’t you want Mossad spying on your devices? Do you want to live in a terrorists paradise or what?

But the tool seems nice, I would like to use something like this. If we had similar thing from a random anonymous “privacy-centered” dev, it wouldn’t be any better, I guess, because it seems like no-one seriously auditing anything open-sourced anyway.

---

## Post 21 by @sputnik — 2025-08-05T16:15:49Z

> [@anon11657877](#):
>
> I wouldn’t follow any of her advice. She sounds like someone working for or paid by Microsoft to shill all their products because it’s clearly biased in their favor.

She isn’t “paid by Microsoft”, she is someone promoting improving basic user security without the reliance on third-party software. With that logic, you can say that the developer of secureblue is “paid by Redhat” and shilling them due to his project. It’s nonsensical.

> [@anon11657877](#):
>
> Windows is not safe, nor is anything else from Microsoft.

I don’t understand the rhetoric that “X operating system is not safe.” Your OS is only as safe as YOU make it. In my opinion, windows gives more options to its users in that regard. And undeniably, any product from big tech is SAFE but not PRIVATE of course.

---

## Post 22 by @n_n — 2025-08-05T16:42:17Z

> [@sputnik](#):
>
> She isn’t “paid by Microsoft”

Her “About me” says she’s “𝙼𝚒𝚌𝚛𝚘𝚜𝚘𝚏𝚝 𝙼𝚅𝙿” and links to a profile which states she’s a “Windows Developer”.

> [@sputnik](#):
>
> undeniably, any product from big tech is SAFE

This statement, undeniably, is not true. Doesn’t mean the complete opposite is true, of course.

---

## Post 23 by @anon11657877 — 2025-08-05T17:37:59Z

It’s only as easy as you allow it.

Use full-disk encryption. Don’t open random attachments. Don’t share passwords. Don’t run unsafe proprietary software.

> [@sputnik](#):
>
> She isn’t “paid by Microsoft”, she is someone promoting improving basic user security without the reliance on third-party software. With that logic, you can say that the developer of secureblue is “paid by Redhat” and shilling them due to his project. It’s nonsensical.

She literally promotes her own third-party software and shills products like Microsoft Authenticator which technically is third-party software on iOS and Android when there are much better TOTP authenticators out there that don’t require cloud syncing. And cloud storage like OneDrive isn’t secure. It’s better to backup data on your own external storage that doesn’t require any network. Sounds like a Microsoft shill to me.

And calling the secureblue developers Red Hat shills is as bullshit as calling PG and Techlore Mullvad shills when Mullvad doesn’t even have an affiliate program.

> [@sputnik](#):
>
> any product from big tech is SAFE

Wrong. Any product which is proprietary is NEVER safe.

---

## Post 24 by @anon22468172 — 2025-08-05T18:37:13Z

I’m unfortunately about to be obliged to use Windows for work for the next couple of years at least. I’ve spent a _lot_ of time researching Windows privacy improvements, probably more than is healthy. I looked at HotCakeX as it’s the main recommendation for advanced tweaks in Techlore’s most recent [Windows Privacy & Security Guide](https://techlore.tv/w/gMiridfL1LHsto1DnRtd5N). While it is undeniably focused on secuirity rather than privacy, I’ve still learnt a few useful things reading through the website.

---

## Post 25 by @anon83428815 — 2025-08-05T20:05:11Z

> [@anon11657877](#):
>
> It’s only as easy as you allow it.
> 
> Use full-disk encryption. Don’t open random attachments. Don’t share passwords. Don’t run unsafe proprietary software.

I think what @anonymous378 is getting at is you need to consider the target audience. These are users who “care” about privacy and security but only if its in a convenient one click format. It is highly unlikely they have gone through and enabled FDE or researched privacy / security outside of skimming recommendations on PG (maybe) and Reddit. I guarantee the vast majority who use the recommended settings do not read what those settings do beforehand and have no clue what the tradeoffs between a local and domain account are.

I think for users here, the tool is much more of a convenient dashboard to customize Windows settings how you see fit, regardless of the devs recommendations.

---

## Post 26 by @anon11657877 — 2025-08-05T20:11:00Z

Well then if they get hacked because they didn’t bother to do the basics and opened random crap then it’s their own fault they got hacked. They shouldn’t force us to do things their way thinking we don’t know any better.

And there are other tools to customize Windows with an actual focus on privacy and de-bloating Windows.

---

## Post 27 by @anon83428815 — 2025-08-05T20:13:03Z

> [@anon11657877](#):
>
> They shouldn’t force us to do things their way thinking we don’t know any better.

I am not sure anyone is being forced to do anything in this situation…

> [@anon11657877](#):
>
> And there are other tools to customize Windows with an actual focus on privacy and de-bloating Windows.

The market is full on one-click solutions. To me, what stands out, is this at least provides a one stop shop to change a lot of Windows settings without going through the Windows UX. I find that nice. To each their own :smiley:

---

## Post 28 by @anon11657877 — 2025-08-05T20:14:18Z

> [@anon83428815](#):
>
> I am not sure anyone is being forced to do anything in this situation…

Microsoft forcing everyone to use Windows with an online account for “security”

---

## Post 29 by @anon83428815 — 2025-08-05T20:15:01Z

ahh I didn’t quite understand what you were getting at.

> [@anon11657877](#):
>
> Microsoft forcing everyone to use Windows with an online account for “security”

yeah this is super annoying.

---

## Post 30 by @sha123 — 2025-08-06T07:45:18Z

> [@sputnik](#):
>
> Your OS is only as safe as YOU make it

Not how it works

---

## Post 31 by @anon94117004 — 2025-08-06T15:10:25Z

> [@n_n](#):
>
> 𝙼𝚅𝙿

This is something anyone can become if they contribute software/writeups and are nominated by a Microsoft employee. It is not a paid or volunteer position at Microsoft.

---

## Post 32 by @n_n — 2025-08-06T16:05:28Z

> [@anon94117004](#):
>
> This is something anyone can become if they contribute software/writeups and are nominated by a Microsoft employee. It is not a paid or volunteer position at Microsoft.

> [@n_n](#):
>
> Her “About me” says she’s “𝙼𝚒𝚌𝚛𝚘𝚜𝚘𝚏𝚝 𝙼𝚅𝙿” and links to a profile which states she’s a “Windows Developer”.

Does this mean Windows Developers aren’t paid by Microsoft too? Like if I just write any program that runs on Windows I can write that I’m a Windows Developer in my Bio?

Anyway, my answer was to

> [@anon11657877](#):
>
> She sounds like someone working for or paid by Microsoft to shill all their products because it’s clearly biased in their favor

so even if she volunteers for Microsoft, doesn’t change much. She develops Windows hardening tool, would be strange to expect her praising Linux security.

---

## Post 33 by @anonymous378 — 2025-08-06T21:18:24Z

> [@n_n](#):
>
> Does this mean Windows Developers aren’t paid by Microsoft too?

lol what?

MVP is an [award for professionals who contribute](https://mvp.microsoft.com/en-US/mvp/overview) to the Microsoft community that you need to be nominated for as @anon94117004 alluded too.

> Microsoft MVP Award recognizes exceptional community leadership.
> 
> Key benefits to MVPs include early access to Microsoft products and direct communication channels with our product teams. MVPs have a very close relationship with the local Microsoft teams in their area, who are there to support and empower MVPs to address needs and opportunities in the local ecosystem. Other benefits include an executive recognition letter, a Visual Studio technical subscription, and a Microsoft 365 subscription.

I think “Windows Developer” in this context just means they develop software for the Windows OS. Not that they work for Microsoft as a developer.

[MVP Profile](https://mvp.microsoft.com/en-US/MVP/profile/4edbca65-7979-4779-b7e4-d182e123259b)

---

## Post 34 by @anon11657877 — 2025-08-06T21:47:00Z

Exactly.

This is why I wouldn’t take advice from any Windows developer/MVP. They are obviously biased towards Microsoft and against open, privacy-respecting software. Regardless, her guide only focuses on security at the cost of privacy.

[Beerisgood’s Windows hardening repo](https://github.com/beerisgood/Windows11_Hardening) isn’t much better.

> avoid insecure software like 7-Zip (which lacks [Anti-Exploit](https://malwaretips.com/threads/winrar-or-7zip-whats-your-favourite.89053/page-6#post-861699) and [MOTW](https://malwaretips.com/threads/winrar-or-7zip-whats-your-favourite.89053/page-3#post-800003) support) and also [Forks](https://improsec.com/tech-blog/peazip-msi-installer-local-privilege-escalation-vulnerabilities), Open/ LibreOffice, [Firefox](https://madaidans-insecurities.github.io/firefox-chromium.html), [True/Veracrypt](https://github.com/beerisgood/Windows11_Hardening/blob/6cabfc61a075b205f326e93247949f138caef6c0/TrueCrypt-VeraCrypt), …

Doesn’t explain why LibreOffice is insecure and fails to mention any insecure proprietary software. Is he suggesting all open source software is bad?

> While DNS encryption [isn’t perfect](https://madaidans-insecurities.github.io/encrypted-dns.html) both [Quad9](https://www.quad9.net) and [Cloudflare](https://developers.cloudflare.com/1.1.1.1/setup/) are recommend.

Cloudflare recommend my ass.

> Use the only browser which provide [defense in depth](https://learn.microsoft.com/deployedge/microsoft-edge-security-browse-safer#defense-in-depth): [Edge](https://www.microsoft.com/edge)

Enjoy your mandatory Microsoft telemetry.

> instead of passwords, [use](https://support.microsoft.com/windows/passkeys-in-windows-301c8944-5ea2-452b-9886-97e4d2ef4422) [_Passkeys_](https://blogs.windows.com/windowsdeveloper/2024/10/08/passkeys-on-windows-authenticate-seamlessly-with-passkey-providers/)

> **[Are Passkeys really the beginning of the end of passwords? I certainly hope not!](https://unixdigest.com/articles/are-passkeys-really-the-beginning-of-the-end-of-passwords-i-certainly-hope-not.html)**

- [https://raw.githubusercontent.com/beerisgood/Windows11\_Hardening/master/Microsoft%20recommendations%20for%20the%20average%20home%20use](https://raw.githubusercontent.com/beerisgood/Windows11_Hardening/master/Microsoft%20recommendations%20for%20the%20average%20home%20use)

> Use a Microsoft account.  
> Use Windows Mail app as your mail client.  
> Use free versions of MS Office applications (Word, Excel, PowerPoint) already available in Windows.  
> Do not be paranoid about Microsoft telemetry.  
> Changing your web browser from Edge to Chrome requires installing third-party software or extensions to achieve the same level of security.

:face_vomiting:

Does the Windows mail app even support PGP? Because if it doesn’t, nothing else matters.

---

## Post 35 by @anonymous378 — 2025-08-06T21:51:11Z

> [@anon11657877](#):
>
> They are obviously biased towards Microsoft and against open, privacy-respecting software.

I wont disagree with you that they are “bias” towards Windows. They make it blatantly clear they have a passion for Windows. I also wont disagree that their views of privacy are quite a bit different than mine or [most on the forum](https://github.com/HotCakeX/Privacy-Anonymity-Compartmentalization).

It is clearly false that they are against open source, or even privacy enhancing software. It just so happens they have very different belief in what privacy / anonymity should be.

Regardless this persons personal views really don’t affect the tool itself, outside of their presets which you are not forced to use.

---

## Post 36 by @anon11657877 — 2025-08-06T21:56:29Z

> [@anonymous378](#):
>
> It is clearly false that they are against open source, or even privacy enhancing software.

> Privacy advertisements, advocates, tools, programs are all fundamentally flawed. All they can do at best is to change which entity or company has access to your data. They can’t prevent the data from being collected in the first place.

Even the offline/local or self-hosted programs?

> Tor network is an inherently defective privacy instrument.

> The majority of _open source_ programs are unsigned, meaning they don’t have a digital signature, their developers haven’t bought and used a code signing certificate to sign their program. Use [Azure Trusted Signing](https://azure.microsoft.com/en-us/products/trusted-signing) which is [affordable](https://azure.microsoft.com/en-us/pricing/details/trusted-signing/).

So open source programs are bad because Microsoft doesn’t approve of them?

Sounds to me like they are against open source and privacy enhancing software. The last thing we need is more Microsoft/Google/Apple propaganda.

---

## Post 37 by @anonymous378 — 2025-08-06T22:00:28Z

You are sniping bits out of context to feed your POV.

> we discuss privacy, which is the right to control what information is collected and shared about oneself. Privacy is important for maintaining personal autonomy, dignity and security.

> [@anon11657877](#):
>
> So open source programs are bad because Microsoft doesn’t approve of them?

As I said they have a different perspective but, it seems silly for you to caim they are against open source when most, if not all, of their work is literally open source apps for Windows.

It seems obvious, if you look at this person in good faith, they care about privacy and open source. You just happen to disagree with how.

---

## Post 38 by @n_n — 2025-08-07T11:45:51Z

> [@anonymous378](#):
>
> lol what?

Is it that hard to read the whole sentence?

> [@n_n](#):
>
> Her “About me” says she’s “𝙼𝚒𝚌𝚛𝚘𝚜𝚘𝚏𝚝 𝙼𝚅𝙿” and links to a profile which states she’s a “Windows Developer”.

Thank you for clarifying for the second time the thing I already knew, but I just said that “𝙼𝚒𝚌𝚛𝚘𝚜𝚘𝚏𝚝 𝙼𝚅𝙿” leads to a profile which states she’s a “Windows Developer”.

> [@anonymous378](#):
>
> I think “Windows Developer” in this context just means they develop software for the Windows OS. Not that they work for Microsoft as a developer.

> [@n_n](#):
>
> Like if I just write any program that runs on Windows I can write that I’m a Windows Developer in my Bio?

Thank you for your opinion, it is very important to know that you think so.  
How do you think, if I regularly update my Ubuntu, can I write in my Bio that I’m a Linux maintainer?

To my knowledge, developers usually write about their technology stack, something like “Python/Ruby/whatever developer” or their projects, like “Whonix/GrapheneOS/Windows hardening tool/whatever developer”.

I might be wrong. Doesn’t change anything really.

---

## Post 39 by @anonymous378 — 2025-08-07T12:30:51Z

> [@n_n](#):
>
> Is it that hard to read the whole sentence?

yeah, when its utter nonsense.

> [@n_n](#):
>
> I might be wrong. Doesn’t change anything really.

True, you just look silly…

---

## Post 40 by @anon11657877 — 2025-08-07T14:32:04Z

> [@anonymous378](#):
>
> it seems silly for you to caim they are against open source when most, if not all, of their work is literally open source apps for Windows.

Under the **permissive** MIT license. Does she enjoy writing Microsoft’s proprietary code?

---

## Post 41 by @anon94117004 — 2025-08-08T01:52:46Z

> [@n_n](#):
>
> Windows Developer

fwiw official Windows Developers, as in people who directly develop Windows, have a `@ntdev.microsoft.com` email address and use it for official work.
