Advanced Plus Security Lenny's 2021 intention: keep this setup for a year :-)

Last updated
Jul 11, 2021
How it's used?
For home and private use
Operating system
Windows 10
On-device encryption
Log-in security
    • Biometrics (Windows Hello PIN, TouchID, Face, Iris, Fingerprint)
Security updates
Allow security updates and latest features
User Access Control
Notify me only when programs try to make changes to my computer (do not dim my desktop)
Smart App Control
Network firewall
Real-time security
  1. Software Restriction Policies similar to Hard Configurator recommended settings
  2. Microsoft Defender hardened through GPO similar to ConfigureDefender on MAX
Firewall security
Microsoft Defender Firewall
About custom security
  • NextDNS (Firefox)/Quad9 (Edge)
  • Trend Micro Home Protect in TP-Link AC4000 router
  • GPO hardening (disabling remote stuff and not used features)
  • UAC deny elevation of unsigned programs
  • ACL deny execute for Download Folder and Startup folders
  • Enabled Smartscreen for Explorer (added run-by-smartscreen)
  • Removed System and Admin ACL from quick backup documents folder on old HD (ransomware often goes for max rights)
  • Tweaked exploit protection settings of Microsoft Defender
Periodic malware scanners
Microsoft Malicious Software Removal Tool only combined with periodic Microsoft Defender scan enabled
Malware sample testing
I do not participate in malware testing
Browser(s) and extensions
Edge with hardened profile running inprivate:
- Bruce blank tab (also works incognito)
- AdGuard with only my filters to deal with annoyances and Kees1958

Firefox with hardened user.js running incognito
- Etag Stoppa
- NoScript
... running in Sandboxie
Secure DNS
Next DNS - Firefox
Quad9 - Edge
Desktop VPN
Bullet VPN
Password manager
None
Maintenance tools
Process Explorer & Autoruns64
File and Photo backup
Syncback Free
System recovery
Restore points and Windows Image Backup for software.
Windows Data Backup for Documents only
Syncback for USB and Quick documents backup to old HD
Neushield daily mirrors for Quick documents backup folder
Risk factors
    • Working from home
    • Browsing to popular websites
    • Opening email attachments
    • Buying from online stores, entering banks card details
    • Streaming audio/video content from shady sites
Computer specs
Self build from parts of old PC's from relatives
- Asus motherboard
- Intel i7 950 with 8 GB RAM
- NVidia GT730 fan-less video card
- Samsung 860 SSD (250 GB for OS)
- OCZ Vortex SSD (120 GB for Documents)
- Seagate 2 TB HDD for media files
- Western Digital 1 TB HDD for image backup and windows image & data backup

USB 2TB drive connected to Router to serv as NAS (router also has TrendMicro Home protect).
USB drive is swapped with off-line second off-line backup USB every month
Notable changes
12-2-21
Added Neushield Data Sentinel Free and changed uMatrix for uBlock on Edge WDAG sandbox
16-3-21
Same extensions in Edge and WDAG sandbox: blank tab, uBlockOrigin and PopUpOff
23-3-21
Replaced uB0 with Adguard again :)
1-4-21
Only using Edge anti-tracking and NextDNS as adblocking for Edge (in normal = hardened mode)
2-4-21
Back to Adguard with Quad9 DNS and removed PopUpOff and NextDNS
22-4-21
Back to Next DNS and replaced Adguard with AddBlockPlus, disabled Edge Application Guard (I did not use it anymore).
23-4-21
Kaspersky Cloud Free stopped working for unknown reason, reverted back to Microsoft Defender
26-4-21
Replaced Adguard DNS filter with Next DNS ad & tracking blocklist
27-4-21
Added Adguard DNS filter again as only DNS level blocklist
29-4-21
Replaced AdblockPlus with SmartAdblock (which is also a popup blocker)
4-5-21
Next DNS ad filter blocked a coupon code, so back to no ad-fiters in DNS. Added Kees1958 most commen EU-US, and set Edge anti-tracking to default again
11-7-21
Added Firefox with priivacy hardened user.js an sandboxie
What I'm looking for?

Looking for maximum feedback.

Lenny_Fox

Level 22
Thread author
Verified
Top Poster
Well-known
Oct 1, 2019
1,120
Because I sort of copies @SecurityNightmares adblocking I changed from AdGuard to AdBlockPlus, because I only use ABP to block annoyances in my bookmarked websistes

Next DNS copied setup from Next DNS guide on this forum with:
- non-latin alphabet Top Level Domains blocked
- AdGuard DNS filter (AdGuard's DNS blocklist is designed to work on DNS level*)
- Allowing affilaite and tracking links (prevents AdGuard DNS filter blocking promoted links from search results)
- some domains added manually in personal blocklist (to deal with popunder ads)
- whitelisted two Dutch banks websites

Edge
- hardened mode (blocking most site permissions and cookies from Google)
- smartscreen in browser disabled (Next_DNS has Google Safe Browsing, Router has Trend Micro url filering)
- anti-tracking on strict (whitelisting two Dutch banks)
- Bruce blank tab (also works incognito)
- AdBlockPlus (it is less advanced than AG and uBO, but fits my useage better)

AdBlockPlus to deal with remaining annoyances (using my own filters)
- Extra Security for ABP/AG/uBO https://raw.githubusercontent.com/LennyFox/Blocklists/master/Extra security
- Annoyances on popular websites https://raw.githubusercontent.com/LennyFox/Blocklists/master/Popular websites ABP
- Annoyances on bookmarked sites: https://raw.githubusercontent.com/LennyFox/Blocklists/master/Bookmarked websites

*) explanation
DNS is not the best place for adfiltering, because the DNS does not semantically looks at content (like an extension or browser build-in adblocker)
 
Last edited:

Gandalf_The_Grey

Level 84
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Apr 24, 2016
7,415
Not sure if disabling SmartScreen in Edge is wise... 🤔
You have other safeguards, but for example Google Safe Browsing in third party solutions (like Next_DNS here) is always behind / not as often updatet as Google Safe Browsing in Chrome. Also, not sure of Trend Micro URL filering in your router (as I have myself), it helps, but is it as good as SmartScreen, Safe browsing or for example Bitdefender TrafficLight?

Have you compared the performance of uBlock Origin vs AdBlockPlus with your filters?
According Raymond Hill the performance of uBlock Origin is superior to anything else.
 

Kongo

Level 36
Verified
Top Poster
Well-known
Feb 25, 2017
2,597
Not sure if disabling SmartScreen in Edge is wise... 🤔
You have other safeguards, but for example Google Safe Browsing in third party solutions (like Next_DNS here) is always behind / not as often updatet as Google Safe Browsing in Chrome. Also, not sure of Trend Micro URL filering in your router (as I have myself), it helps, but is it as good as SmartScreen, Safe browsing or for example Bitdefender TrafficLight?

Have you compared the performance of uBlock Origin vs AdBlockPlus with your filters?
According Raymond Hill the performance of uBlock Origin is superior to anything else.
Actually when using NextDNS not Google Safe Browsing but "Threat Intelligence Feeds" does pretty much all the work. But I agree, there is no valid point of disabling Smart Screen imo...
 

blackice

Level 39
Verified
Top Poster
Well-known
Apr 1, 2019
2,868
Actually when using NextDNS not Google Safe Browsing but "Threat Intelligence Feeds" does pretty much all the work. But I agree, there is no valid point of disabling Smart Screen imo...
In the latest DNS testing it seemed that NextDNS was one of the best, about on par with Safe Browsing. Of course with the small sample sizes you never know the overall picture..
 
Last edited:

Kongo

Level 36
Verified
Top Poster
Well-known
Feb 25, 2017
2,597
In the latest DNS testing it seemed that NextDNS was one of the best, about on par with Safe Browsing. Of course with the small sample sizes you never know the overall picture..
The link isn't working. I just meant that within NextDNS Google Safe Browsing is blocking far less than Threat Intelligence Feeds from my experience.

You can also see it in that video:
 

blackice

Level 39
Verified
Top Poster
Well-known
Apr 1, 2019
2,868
The link isn't working. I just meant that within NextDNS Google Safe Browsing is blocking far less than Threat Intelligence Feeds from my experience.

You can also see it in that video:

Fixed, thanks! Yeah I see what you are saying. I agree with you. I use NextDNS Threat Intelligence for our home router's DNS setup.

Edit: nevermind, not fixed. It seems to be getting blocked by something even though it works before I post it.
 

Lenny_Fox

Level 22
Thread author
Verified
Top Poster
Well-known
Oct 1, 2019
1,120
Why disable SmartScreen?
I don't like the fact that SmartScreen send full URL for the check. When I tried to download malware executables, because someone on Wilders had used my AdGuard extra security blocklist in uBlock (which did not work for uBO), I only got 1 (ONE!) smartscreen block when I disabled Next_DNS and TrendMicro in the router because I was unable to download a malware link from the list that guy on Wilders had used.


Performance UBO versus ABP
With less than 200 rules, this question has little relevance. uBo has a lot of features, which means that is has much more code than ABP. Less code means lower external code dependance and less coding errors. (remember what Cruel Sister always says about extensions).


Now for something completely different
Kaspersky Cloud Security free stopped working tonight. Spend nearly an hour figuring what was worng, decided to fall back to Windows Defender (configured through GPO simular to Configire Defender on MAX). Also dropped Neushield in favor of Protected Folders. So broke my promise to keep this setup for 2021. :cry:


Bitdefender Traffic Light
@Gandalf_The_Grey do you know whether BTL only sends domain or full URL for the URL check? Website of Bitdefender still mentions old BTL which also included tracking warning (Bitdefender now has a separate extension for this : Bitdefender Anti-tracker). Edit:eek:ld BTL checks on page, so probably also full URL.
 
Last edited:
F

ForgottenSeer 85179

The link isn't working. I just meant that within NextDNS Google Safe Browsing is blocking far less than Threat Intelligence Feeds from my experience.

You can also see it in that video:

Thanks!
Nice to see that he uses OISD and have the same experience with NextDNS default vs OISD like me.
 

Gandalf_The_Grey

Level 84
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Apr 24, 2016
7,415
Why disable SmartScreen?
I don't like the fact that SmartScreen send full URL for the check. When I tried to download malware executables, because someone on Wilders had used my AdGuard extra security blocklist in uBlock (which did not work for uBO), I only got 1 (ONE!) smartscreen block when I disabled Next_DNS and TrendMicro in the router because I was unable to download a malware link from the list that guy on Wilders had used.


Performance UBO versus ABP
With less than 200 rules, this question has little relevance. uBo has a lot of features, which means that is has much more code than ABP. Less code means lower external code dependance and less coding errors. (remember what Cruel Sister always says about extensions).


Now for something completely different
Kaspersky Cloud Security free stopped working tonight. Spend nearly an hour figuring what was worng, decided to fall back to Windows Defender (configured through GPO simular to Configire Defender on MAX). Also dropped Neushield in favor of Protected Folders. So broke my promise to keep this setup for 2021. :cry:


Bitdefender Traffic Light
@Gandalf_The_Grey do you know whether BTL only sends domain or full URL for the URL check? Website of Bitdefender still mentions old BTL which also included tracking warning (Bitdefender now has a separate extension for this : Bitdefender Anti-tracker). Edit:eek:ld BTL checks on page, so probably also full URL.
I had the same problem on my son's laptop with Kaspersky Security Cloud Free.
It stopped working and without any warning or visible notification on the taskbar icon.
So I went back to Microsoft Defender, ConfigureDefender on HIGH settings and Controlled Folder Access.

I think you are right that Bitdefender TrafficLight also sent the full URL back, like SmartScreen.
 

Ink

Administrator
Verified
Jan 8, 2011
22,490
Why disable SmartScreen?
I don't like the fact that SmartScreen send full URL for the check. When I tried to download malware executables, because someone on Wilders had used my AdGuard extra security blocklist in uBlock (which did not work for uBO), I only got 1 (ONE!) smartscreen block when I disabled Next_DNS and TrendMicro in the router because I was unable to download a malware link from the list that guy on Wilders had used.
Is Reputation-based protection disabled, or "SmartScreen for Microsoft Edge" only?

Windows Security > App & browser control:
1619211964443.png
 
F

ForgottenSeer 85179

! Block third-party executable content from insecure HTTP websites
||HTTP://*$third-party,~stylesheet,~media,~image
this rule isn't for security but privacy. Anyway, it will break some sites without any advantage.

! Block downloading executable content from insecure HTTP websites
|http://*.exe^$document
...
Edge blocks all HTTP automatic downloads already by default.
 

Lenny_Fox

Level 22
Thread author
Verified
Top Poster
Well-known
Oct 1, 2019
1,120
this rule isn't for security but privacy. Anyway, it will break some sites without any advantage.
It blocks third-party scripts, subdocuments from insecure websites. Unencrypted websites are not used in western world since domain SSL certificates became free. Although the simplest SSL certificate, says nothing about the website or its owner, the registration process of a domain SSL is only issued when the person requesting the certificate has the legal right to ask for one. The data needed to get one, makes it less attractive for criminals, so most malware websites operate as HTTP. When this advantage is not clear to you I rest my case.

Since Google started to lower your ranking when using a HTTP website, all websites converted to HTTPS in the western world. So it will hardly ever break a website.
 
Last edited:
F

ForgottenSeer 85179

It blocks third-party scripts, subdocuments from insecure website
And can be done native done in Edge.
It's recommend to not block only third party http scripts but all http scripts.

Just add http://* as blocking rule in Edge Javascript permissions.
No need to make things even more complicated ;)
 

Lenny_Fox

Level 22
Thread author
Verified
Top Poster
Well-known
Oct 1, 2019
1,120
And can be done native done in Edge.
It's recommend to not block only third party http scripts but all http scripts.

Just add http://* as blocking rule in Edge Javascript permissions.
No need to make things even more complicated ;)
This only blocks first party scripts. When you are on a HTTPS website which uses HTTP scripts as third-party those insecure scriptswill be executed. The HTTP://* rule in blocking scripts does not protect you against that.

I don't get your responses. Frst you are posting that blocking third-party scipts hardly has any advantage, now you are advising to block all http-scripts.

Are you just responding to have a discussion/making fun? I dont understand why you are posting wrong information.
 
  • Like
Reactions: Venustus

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top