Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

update!: Windows guide #1659

Open
wants to merge 8 commits into
base: main
Choose a base branch
from
Open

Conversation

IkelAtomig
Copy link
Contributor

@IkelAtomig IkelAtomig commented Aug 19, 2022

Closes: #1380

This is a successor to #1380 Pull request by me. Things that are there will follow here but in a paced manner with concise information.

I have stated the reason in the old one for its closure.

If you are suggesting big Changes, make a PR other than that do Code reviews.

Do not comment about your suggestions in this PR as I want it clean and don't want it confusing either for me or to the contributors. So, Suggest them in Issue #166. I am following it.

There will be no ETA for this. I will work on this in my Free time and try finish ASAP.

@IkelAtomig IkelAtomig temporarily deployed to preview August 19, 2022 14:03 Inactive
@github-actions
Copy link

github-actions bot commented Aug 19, 2022

🎊 PR Preview 6865c06 has been successfully built and deployed to https://privacyguides-privacyguides-org-preview-pr-1659.surge.sh

🕐 Build time: 74.102s

🤖 By surge-preview

@dngray dngray added c:os operating systems and related topics c:guides full-length guides and content labels Aug 20, 2022
@IkelAtomig IkelAtomig temporarily deployed to preview September 26, 2022 05:45 Inactive
@IkelAtomig IkelAtomig temporarily deployed to preview October 20, 2022 14:57 Inactive
@IkelAtomig IkelAtomig changed the title Windows hardening guide Windows guide Oct 20, 2022
@jonaharagon jonaharagon force-pushed the main branch 2 times, most recently from b5ff399 to b9612de Compare October 24, 2022 13:58
@netlify
Copy link

netlify bot commented Nov 13, 2022

Deploy Preview for privacyguides ready!

Name Link
🔨 Latest commit 0c1bddc
🔍 Latest deploy log https://app.netlify.com/sites/privacyguides/deploys/63aaee6f71e3270009f0d7e5
😎 Deploy Preview https://deploy-preview-1659--privacyguides.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify site settings.

@IkelAtomig IkelAtomig closed this Nov 13, 2022
@IkelAtomig IkelAtomig reopened this Nov 13, 2022
@IkelAtomig IkelAtomig marked this pull request as ready for review November 13, 2022 09:58
@IkelAtomig
Copy link
Contributor Author

Thanks to @d4rklynk, @noClaps, @namazso and many more who helped on this.

@jonaharagon
Copy link
Member

Please don't ping a bunch of contributors or leave multiple consecutive comments on this PR. This guide is a work in progress.

@IkelAtomig
Copy link
Contributor Author

Okay, Jonah. But in my Opinion I have finished what I could do.So, Merging is totally upto you. I could add stuff if wanted.

@privacyguides-bot
Copy link
Collaborator

This pull request has been mentioned on Privacy Guides. There might be relevant details there:

https://discuss.privacyguides.net/t/privacy-guides-should-cover-the-reasoning-behind-why-you-should-switch-from-x-to-z/10168/2

@privacyguides-bot
Copy link
Collaborator

This pull request has been mentioned on Privacy Guides. There might be relevant details there:

https://discuss.privacyguides.net/t/recommending-apple-products/10815/9

@dngray dngray marked this pull request as draft December 17, 2022 09:13
@privacyguides-bot
Copy link
Collaborator

This pull request has been mentioned on Privacy Guides. There might be relevant details there:

https://discuss.privacyguides.net/t/inclusion-of-a-basic-guide-recommendation-column-for-hardening-windows/11170/2

docs/windows/privacy.md Outdated Show resolved Hide resolved
@dngray
Copy link
Member

dngray commented Feb 15, 2023

I am at some point going to have another look at this, we should incorporate https://github.com/privacyguides/privacyguides.org/pull/1979/files into it as an tip.

@dngray
Copy link
Member

dngray commented Feb 15, 2023

This discussion https://github.com/privacyguides/privacyguides.org/discussions/1281 brought up that we should remind users to update their systems.

We should probably have some mention about BIOS updates too, https://github.com/privacyguides/privacyguides.org/discussions/1280 as not all systems this comes through Windows Update. Of course there will only be only general instructions as different vendors use different update tools on Windows.

@jonaharagon jonaharagon force-pushed the main branch 2 times, most recently from 67e4d9a to 2150385 Compare February 24, 2023 22:39
@IkelAtomig
Copy link
Contributor Author

@dngray - Not a problem. I have to rework a lot on this as I haven't updated it more than a year and I haven't made my writing visible yet on the preview. Need to add it in mkdocs.yml

If you merge the other one first, Maybe I will modify this one as some suggestions to it.

Let's see. I hope, I could start working on this before you come back to Windows section.

@oppressor1761 - Shall we two work on this together or separately - Totally your choice ?

@dngray
Copy link
Member

dngray commented Jun 13, 2024

I'm working on merging this one together, it will be based off #2606 (then when that is merged we can look at merging this one).

@dngray dngray force-pushed the Windows branch 3 times, most recently from 8714b3c to a7e8eff Compare June 13, 2024 08:02
@IkelAtomig IkelAtomig marked this pull request as ready for review June 13, 2024 11:13
@dngray
Copy link
Member

dngray commented Jun 13, 2024

I pushed to it, before, but haven't made any changes, it will require some time to go over. I haven't read it in detail

@redoomed1
Copy link
Member

redoomed1 commented Jun 13, 2024

Since #2591 added a dedicated page for Group Policies, I suggest moving the GP instructions in "Security policies for Bitlocker" to the aforementioned page, and adding an internal link to the BitLocker section of the GP page in its place.

Other group policy recommendations introduced in this PR can also be moved to the dedicated GP page.

@dngray
Copy link
Member

dngray commented Jun 14, 2024

I suggest moving the GP instructions in "Security policies for Bitlocker" to the aforementioned page

That's exactly what I had in mind in regard to #2437 (comment). I haven't yet gone over this PR and read it, in entirety just getting the structure right of what should be where as it is huge.

Copy link
Member

@redoomed1 redoomed1 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I haven't used Windows for quite a while now so, for this PR, I can offer suggestions only regarding grammar, formatting, and consistency with other parts of the Privacy Guides site.

Aside from my earlier suggestion about consolidating Group Policy recommendations, other parts of the PR caught my eye, which I commented on below.


## Security Improvements

- Use [PeaZip](https://peazip.github.io/) archiver instead of 7-zip as it disables [Mark of the Web(MoW)](https://nolongerset.com/mark-of-the-web-details/) [support by default](https://github.com/nmantani/archiver-MOTW-support-comparison#*2) leading to execution of malicious instantly after extracting.
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I don't think that this guide (which will be housed in the Knowledge Base) should include tool recommendations that are not native to the OS.

Besides, the linked resource about Mark of the Web mentions that the unzipping tool built in to Windows preserves the MOTW.

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Well, At then time, 7Zip or Windows didn't preserve MoTW. I don't remember quite well.


- Use [PeaZip](https://peazip.github.io/) archiver instead of 7-zip as it disables [Mark of the Web(MoW)](https://nolongerset.com/mark-of-the-web-details/) [support by default](https://github.com/nmantani/archiver-MOTW-support-comparison#*2) leading to execution of malicious instantly after extracting.

- Using MS edge or brave over Firefox. Edge is recommended with MDAG mode for secure browsing if security is your priority. Brave is recommeded if content blocking is important for you (Brave shields)
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

There's already a page for desktop browser recommendations on the site.

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

You are right. Will remove it since MDAG is gonna be killed by microsoft afaik.


## Apps

- Avoid any types of Cleaning software at all cost. As Microsoft is working on its own implementation specfically designed for windows.
Copy link
Member

@redoomed1 redoomed1 Jun 19, 2024

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Including a brief explanation of why people using Windows should avoid cleaning software would be useful here.


Also, is the native implementation of cleaning software you're referring to called "Microsoft PC Manager"? From these forum posts, it looks like Windows users have to download it from the Microsoft Store themselves and the software isn't available in all geographical regions.

https://answers.microsoft.com/en-us/windows/forum/all/when-will-the-pc-manager-app-be-available-to-uk/e9325c52-2f56-402e-8a5d-1c220ed00e45

https://answers.microsoft.com/en-us/windows/forum/all/microsoft-pc-manager-is-not-available-in-windows/669e4c67-eff6-46d6-9863-a5c36dedd6ba

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yeah, It is.

Copy link
Member

@redoomed1 redoomed1 Jul 28, 2024

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

A lot of the information from this page was adapted to the current Windows Overview in #2591.

Unless someone has specific suggestions on information in this drafted page that should be added to the current Windows Overview on the site, I think this page should be removed to reduce the size of this PR and make it easier for reviewers to go over the PR.

Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I haven't looked at this PR in detail, but it should be possible to create several PRs for those various sections from this one.

We can always give @IkelAtomig credit for the ones which were heavily based on this one, perhaps splitting them up would make it more workable?

@jonaharagon jonaharagon changed the title Windows guide update!: Windows guide Aug 2, 2024
@IkelAtomig
Copy link
Contributor Author

IkelAtomig commented Aug 5, 2024

Ah, Should I do anything because I kind of orphaned this PR. I would be glad if some parts of it are made into the site and my name is in the footer. That's it.

@dngray
Copy link
Member

dngray commented Aug 5, 2024

don't close it. The other one will do that when it is merged, and yes you're on it as co-author, so you'd get the same credit in your git activity.

@IkelAtomig
Copy link
Contributor Author

IkelAtomig commented Aug 5, 2024

I want it to be on the privacyguides site. Greedy me.

@dngray
Copy link
Member

dngray commented Aug 5, 2024

I want it to be on the privacyguides site. Greedy me.

Oh I was talking about #1380. Yes the intention is to merge this, it may need some refactoring to fit in with #2591 and #2606. I have not looked at it in detail (due to irl commitments right this moment but intend to do so when I get a chance).

@dngray
Copy link
Member

dngray commented Aug 5, 2024

@IkelAtomig on second thoughts, I think it might be better if we split this off onto three PRs, one for each page (sandboxing, privacy, hardening), as long as you're the author, of each it will show your name at the bottom of the page.

We need to then just check whether windows-overview.md contains anything we want to keep that isn't already in docs/os/windows/index.md. As long as the commit has you as the author it should show you as the contributor.

@IkelAtomig
Copy link
Contributor Author

Alright, just say what to do when you are ready.

@jonaharagon jonaharagon self-requested a review as a code owner September 28, 2024 07:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
c:guides full-length guides and content c:os operating systems and related topics
Projects
Status: Unreviewed
Development

Successfully merging this pull request may close these issues.

10 participants