Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add Windows Guide #1380

Closed
wants to merge 0 commits into from
Closed

Add Windows Guide #1380

wants to merge 0 commits into from

Conversation

IkelAtomig
Copy link
Contributor

@IkelAtomig IkelAtomig commented Jun 2, 2022

Resolves: #166

Currently Added choosing edition, post-installation, And using FDE.

To-Do :

  • Write about changing settings via settings app that are better for Privacy and Security
  • Add Group Policy Edits that reduce Telemtry increase Secuirty and Privacy
  • Do's and Dont's that increase attack surface

@IkelAtomig IkelAtomig temporarily deployed to preview June 2, 2022 14:02 Inactive
@github-actions
Copy link

github-actions bot commented Jun 2, 2022

🎊 PR Preview 76f5417 has been successfully built and deployed to https://privacyguides-privacyguides-org-preview-pr-1380.surge.sh

🕐 Build time: 115.06s

🤖 By surge-preview

@IkelAtomig IkelAtomig temporarily deployed to preview June 2, 2022 14:17 Inactive
@dngray dngray temporarily deployed to preview June 2, 2022 16:06 Inactive
@IkelAtomig IkelAtomig temporarily deployed to preview June 5, 2022 08:01 Inactive
@IkelAtomig IkelAtomig temporarily deployed to preview June 5, 2022 08:27 Inactive
@IkelAtomig IkelAtomig temporarily deployed to preview June 5, 2022 09:41 Inactive
@IkelAtomig IkelAtomig temporarily deployed to preview June 5, 2022 09:44 Inactive
@IkelAtomig IkelAtomig temporarily deployed to preview June 5, 2022 13:58 Inactive
@dngray dngray added the c:guides full-length guides and content label Jun 5, 2022
@dngray dngray temporarily deployed to preview June 5, 2022 17:19 Inactive
@dngray dngray temporarily deployed to preview June 5, 2022 17:50 Inactive
@IkelAtomig IkelAtomig temporarily deployed to preview June 6, 2022 09:02 Inactive
@IkelAtomig IkelAtomig temporarily deployed to preview June 6, 2022 11:09 Inactive
@dngray dngray temporarily deployed to preview June 6, 2022 12:00 Inactive
@IkelAtomig
Copy link
Contributor Author

IkelAtomig commented Jun 6, 2022

I need to add What are the issues present in Windows and things referencing it.

I would like to talk more about pros and cons of Windows as compared to other OSes like macOS, GNU/Linux, BSD, etc., and why. But I am an avid windows user from start and don't have a bigger taste over other OSes. So, Enlighten me here.

cc @noClaps


This PR will be ready within a month and be complete about 70% within a couple of weeks.

Just need some additional resources and Guides. If anybody could make the Windows Issue popular on Reddit, I might think of adding more info by the redditors comment.

@dngray Just don't rebase again.

@IkelAtomig IkelAtomig temporarily deployed to preview June 6, 2022 14:33 Inactive
@IkelAtomig IkelAtomig temporarily deployed to preview June 6, 2022 14:46 Inactive
@IkelAtomig IkelAtomig temporarily deployed to preview June 6, 2022 14:51 Inactive
@IkelAtomig IkelAtomig temporarily deployed to preview June 6, 2022 14:55 Inactive
@IkelAtomig IkelAtomig temporarily deployed to preview June 8, 2022 13:12 Inactive
@IkelAtomig IkelAtomig temporarily deployed to preview June 8, 2022 13:17 Inactive
@dngray dngray temporarily deployed to preview June 9, 2022 05:09 Inactive
docs/windows/hardening.md Outdated Show resolved Hide resolved
@IkelAtomig IkelAtomig temporarily deployed to preview June 9, 2022 08:22 Inactive
docs/windows/hardening.md Outdated Show resolved Hide resolved
@IkelAtomig IkelAtomig temporarily deployed to preview July 3, 2022 03:38 Inactive
@IkelAtomig IkelAtomig temporarily deployed to preview July 3, 2022 13:47 Inactive
@IkelAtomig IkelAtomig temporarily deployed to preview July 8, 2022 13:10 Inactive
@IkelAtomig IkelAtomig temporarily deployed to preview July 13, 2022 14:11 Inactive
@ghost
Copy link

ghost commented Jul 14, 2022

Hello, I think it is worth mentioning you can make BitLocker to have a stronger cipher you can make XTS-AES 128 bit (default) same but 256 bit. What do you guys think ?

https://i.imgur.com/LmG4ggf.png

@IkelAtomig
Copy link
Contributor Author

Cool Idea. Thanks, I will look on this.

docs/windows/overview.md Outdated Show resolved Hide resolved
docs/windows/overview.md Outdated Show resolved Hide resolved
docs/windows/overview.md Outdated Show resolved Hide resolved
docs/windows/overview.md Outdated Show resolved Hide resolved
docs/windows/overview.md Outdated Show resolved Hide resolved
docs/windows/overview.md Outdated Show resolved Hide resolved
docs/windows/overview.md Outdated Show resolved Hide resolved
docs/windows/overview.md Outdated Show resolved Hide resolved
docs/windows/hardening.md Outdated Show resolved Hide resolved
docs/windows/hardening.md Outdated Show resolved Hide resolved
docs/windows/hardening.md Outdated Show resolved Hide resolved
docs/windows/hardening.md Outdated Show resolved Hide resolved
docs/windows/hardening.md Outdated Show resolved Hide resolved
docs/windows/sandboxing.md Outdated Show resolved Hide resolved
docs/windows/sandboxing.md Outdated Show resolved Hide resolved
docs/windows/sandboxing.md Outdated Show resolved Hide resolved
docs/windows/sandboxing.md Outdated Show resolved Hide resolved
docs/windows/sandboxing.md Outdated Show resolved Hide resolved
docs/windows/hardening.md Outdated Show resolved Hide resolved

### Security Improvements


Copy link
Contributor

@d4rklynk d4rklynk Jul 18, 2022

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Address Space Layout Randomization

ASLR is a feature that prevents memory corruption like buffer overflow.
You can enable ASLR mandatory & Bottom-up-ASLR by going in the Defender Exploit Guard settings.

ASLR

docs/windows/sandboxing.md Outdated Show resolved Hide resolved
docs/windows/sandboxing.md Outdated Show resolved Hide resolved
@nopeitsnothing
Copy link
Contributor

nopeitsnothing commented Jul 22, 2022

Come to think of it there are a LOT of errors related to what an ESL (English as a second language) speaker would make. Please use clear and concise English. I hope you aren't offended by my saying that.

After you have installed Windows, turn on full disk encryption (FDE) using BitLocker via the Control Panel.

Detail this for the reader?

**Control Panel** > **System and Security** > **BitLocker Drive Encryption** > **Turn on BitLocker**

See: Microsoft: Writing step-by-step instructions

- Windows 11 secures it bootloader by default by using Secure boot with the usage of TPM.

Windows 11 secures its bootloader by default using Secure Boot through the TPM

@d4rklynk
Copy link
Contributor

- Windows 11 secures it bootloader by default by using Secure boot with the usage of TPM.

Windows 11 secures its bootloader by default using Secure Boot through the TPM

#1380 (comment)

@IkelAtomig
Copy link
Contributor Author

I will fix all the grammar errors today and will continue working on this further.

@IkelAtomig IkelAtomig temporarily deployed to preview July 28, 2022 15:10 Inactive
@IkelAtomig IkelAtomig temporarily deployed to preview July 28, 2022 15:12 Inactive
@IkelAtomig IkelAtomig temporarily deployed to preview July 28, 2022 15:14 Inactive
@ghost ghost added the c:os operating systems and related topics label Aug 8, 2022
Copy link

@ghost ghost left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hello, @EdwardLangdon , Thanks for the amazing PR and all of the effort that went into it, I have some small and tiny suggestions that I believe could help.

  1. We may like to comment on Windows 10 LTSC, specially since we mention Windows 10 Enterprise.
  2. We may also like to recommend the use of open-source VeraCrypt instead of proprietary (and possibly backdoored) Bitlocker.

@d4rklynk
Copy link
Contributor

d4rklynk commented Aug 12, 2022

  1. We may also like to recommend the use of open-source VeraCrypt instead of proprietary (and possibly backdoored) Bitlocker.

No, we should only use BItlocker for Windows imo. As it is native app.

And it's not bc veracrypt is foss that it is not backdoored.

@nopeitsnothing
Copy link
Contributor

For FDE I'd prefer to see listed:

  • Hardware Accelerated: AES (Rijndael) 256 Bits with HMAC-SHA-2 or HMAC-SHA-3
    • (This is what Veracrypt, Bitlocker, Filevault 2, KeepassXC, and LUKS use by default). Prefer SHA-3.
  • Non-Hardware Accelerated: Same as accelerated above or if available consider:
    • ChaCha20 or XChaCha20
    • Serpent

@IkelAtomig
Copy link
Contributor Author

@uranuspucksaxophone LTSC Edition is used in Industries such as Healthcare, hospitals, etc. cuz they don't want unstable software when helping people on their health or fail them when a New Update breaks down.

LTSC edition is mostly stability and security. Not Security Improvements, that doesn't mean security improvements don't come. It's late. I need to know about LTSC and will think on it.

This is just a PR on my own. Things might change by the PG team.


For FDE, Bitlocker is the only thing that is best in several ways compared to Veracrypt. Veracrypt is suggested when the device doesn't have Secure boot or it is a Older device.

We are going mainly for Win11 and 10 at times. So, I think sticking to the latest and telling things for the fore-seeing the future would be better idea.


I am very busy IRL. So, I can't work. I am hoping to finish this atleast within the end of this year. Contributions are welcome.

@IkelAtomig IkelAtomig temporarily deployed to preview August 13, 2022 05:40 Inactive
@IkelAtomig IkelAtomig closed this Aug 13, 2022
@IkelAtomig IkelAtomig temporarily deployed to preview August 13, 2022 05:59 Inactive
@IkelAtomig
Copy link
Contributor Author

I closed my PR due to many conflicts using git at the same time. So, I reset branch to Main which closed this PR. I will work on the guide locally and reopen this PR later at sometime.

If anybody is keen to work on the PR. Here is the copy of the Branch before it is reset.

privacyguides.org-Windows.zip

If you are gonna work, Please do tell me. I would stop working if you are more interested. I am looking forward to hand this over to an individual who has high knowledge in this.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
c:guides full-length guides and content c:os operating systems and related topics
Projects
None yet
Development

Successfully merging this pull request may close these issues.

Re-write of Windows Page
7 participants