SECURITY: Complete blackice's 2021 Security Configuration

Last updated
Feb 17, 2021
About
Personal, primary device
Additional PC users
Not shared with other users
Desktop OS
Windows 10
OS License Type
Home
Login security
    • Passwordless (PIN, Biometric, Face)
Primary sign-in
Microsoft account
Primary account rights
Administrator permissions
Other accounts rights
N/A - Single user account
Security updates
Automatic - allow all types of updates
Windows UAC
Maximum - always notify
Network firewall
Personal router w/ firewall & filtering
Real-time protection
Microsoft Defender
NoVirusThanks OSArmor
Software firewall
Microsoft Defender Firewall
Custom RTP, Firewall and OS settings
Configure Defender - High
OS Armor - a few additional items ticked in the settings
Malware research
No - malware samples are not downloaded
Periodic scanners
Malwarebytes, EEK, ESET online scanner, HitmanPro
DNS
NextDNS
VPN
IVPN
Password manager
1Password
Browsers, Search and Addons
Chrome -
Ad blocking from ControlD DNS DoH
1Password
Malwarebytes Browser Guard

Edge Chromium -
Ad blocking from ControlD DNS DoH
1Password

Firefox -
Ad blocking from ControlD DNS DoH
1Password
Malwarebytes Browser Guard
PC maintenance
HWiNFO
Process Explorer
Everything
Bandizip
Personal Files & Photos backup
File History
Personal backup routine
Automatic (scheduled)
Device recovery & backup
Macrium Reflect
Device backup routine
Automatic (scheduled)
PC activity
  1. Browsing the web. 
  2. Shopping. 
  3. Banking. 
  4. PC and cloud gaming. 
  5. Streaming. 
Computer specs
Ryzen 7 5800X
ASUS TUF Gaming X570-Pro Wifi
32GB G.Skill Trident Neo 3600 cl16
RTX 3070 DUAL OC
500GB WD SN550 NVME
1TB WD SN550 NVME
500GB WD Blue SSD
1TB WD Blue HDD
Personal changelog
DNS: Cloudflare->Quad9
2/17/21 - AVG Internet Security
2/20/21 - Removed Brave, updated PC Maintenance section
3/3/21 - Removed AVG
Added Microsoft Defender
3/22/21 - Keeping NextDNS so added it
Added Bitdefender Internet Security
4/15/21 - Removed Bitdefender IS
Added Microsoft Defender
4/19/21 - Added Malwarebyte Premium just kidding it’s broken, Defender still.
4/29/21 - Changed DNS to ControlD (by WIndscribe)
Removed adblockers in browsers, Added HitmanPro
5/10/21 - Back to NextDNS
Feedback Response

General feedback

blackice

Level 32
Verified
Apr 1, 2019
2,139
I own a Ryzen 5-5600X too but with 32GB Crucial PC 3200 CL16 KIT (2x16B) Ballistix.
As the Ryzen only run with 3200 Mhz RAM by default so i wonder at which Mhz your RAM run
Zen 3 infinity fabric runs 1:1 up to 1800mhz. Which is the speed mine runs at; and DDR makes it 3600. Just set to D.O.C.P. Settings.
E9D17F1A-94E0-4B14-BB96-E29B637F4219.jpeg
 
Last edited:

blackice

Level 32
Verified
Apr 1, 2019
2,139
How is Quad9 for your DNS working out thus far?

~Brian
Seems to be doing great. Honestly I think DNS speed is overstated (to a degree) since cache is used in browsers and routers. Most of my browsing is to frequent sites and when it’s not I don’t notice the extra 10ms. I don’t visit many sketchy places so I can’t speak to the security. I also no longer have resolution issues for my work network, and fewer failures when using DoH on the devices I have that on. Which is funny because cloudflare used to be the only DoT system that would work as an ASUS router solution because of some technical quirks.

I saw a good interview with one of their leads a while back and liked what they had to say. Also, if I recall correctly, their director, or whatever his title is, has been active on the smallnetbuilder forums and had some good insight into their operations.

Overall I’d give Quad9 a thumbs up.

Edit: I should also note I used Quad9 in the past and liked it. I switched to the fastest alternative DNS for me, because why not, but am happy to try it again.
 
Last edited:

blackice

Level 32
Verified
Apr 1, 2019
2,139
I gave Quad9 a brief test drive a week ago, it seemed to slow down my browser's opening of web pages. It was very noticeable but wasn't much of a test though, couple minutes of slowdowns and removed.
Location can definitely cause people to have differing experiences. I know we are fairly far apart so we’d definitely be pinging different servers.
 

blackice

Level 32
Verified
Apr 1, 2019
2,139
Zen 3 infinity fabric runs 1:1 up to 1800mhz. Which is the speed mine runs at; and DDR makes it 3600. Just set to D.O.C.P. Settings.View attachment 252546
@SecurityNightmares I was just reading something that brought my mind back to this post. You are 100% correct that the spec for Ryzen 5000 is DDR4 3200 (1600mhz). And anything else is considered overclocking, even XMP/DOCP. So technically it could void your warranty (though outside of messing with voltages I don’t think they do). AMD doesn’t actually make this very clear since they advertise the Infinity Fabric can actually go up to 3733 at a 1:1 ratio.
 

blackice

Level 32
Verified
Apr 1, 2019
2,139
Your config still shows Microsoft Defender as the Firewall. You may wanna change that.
BTW, you were talking about checking AVG's Firewall if it had any negative impact or something like that. Have you find anything noteworthy?
Thanks, I sleepily missed changing that. Happily it seems as invisible as ESET. Bitdefender would sometimes add odd latency that I couldn’t nail down, but it was only occasionally (I didn’t even realize it was BD until I uninstalled it). AVG hasn’t seemed to have affected my connection at all in Speedtest, downloads, or when playing games with low pings. I don’t get a lot of time for games, but pings seem the same with the little I have tried since installing.
 

SeriousHoax

Level 35
Verified
Mar 16, 2019
2,377
Thanks, I sleepily missed changing that. Happily it seems as invisible as ESET. Bitdefender would sometimes add odd latency that I couldn’t nail down, but it was only occasionally (I didn’t even realize it was BD until I uninstalled it). AVG hasn’t seemed to have affected my connection at all in Speedtest, downloads, or when playing games with low pings. I don’t get a lot of time for games, but pings seem the same with the little I have tried since installing.
Everything is great then with AVG (y)
 

SeriousHoax

Level 35
Verified
Mar 16, 2019
2,377
Went back to Defender from AVG for this rig. Started getting slightly lower CPU performance that was inexplicable. Only new thing was more recent AMD chipset drivers. But it was repeatable causing 8% performance loss by benchmarks, which was no bueno. Back to WD for this one for now.
I noticed I was getting 8 fewer FPS on average on a game with AVG. The game was even on the exclusion list. I got curious and went back to WD, and it was normal again. I already had a plan to freshly install Windows and did it last night. Now it turns out WD is even a bit faster in default settings compared to Configure Defender at high. I have 2-3 apps that used to launch with a 2-2.5 sec delay on first run after booting up the PC (fast startup is disabled). Now those apps are launching almost immediately too. I'm not sure which particular setting/settings was causing this slight delay on those apps. I think I'm gonna stay with the default settings for a while.
 
Top