SECURITY: Complete Serious Hoax's Security Configuration 2020

Last updated
Dec 19, 2020
About
Personal, primary device
Desktop OS
Windows 10
Login security
    • Password (Aa-Zz, 0-9, Symbols)
Primary sign-in
Local account
Primary user
Admin user - Full permissions
Security updates
Default - allow security updates
Windows UAC
Maximum - always notify
Real-time protection
Microsoft Defender
Software firewall
Microsoft Defender Firewall
Custom RTP, Firewall and OS settings
1. ConfigureDefender with Protection Level set to High + some additional changes including Cloud Protection Level set to "Block", Cloud Check Timeout to "60s", "Block process creations originating from PSExec and WMI commands" set to "On".

2. Hard_Configurator with "Windows_10_MT_Windows_Security_hardening" profile + few custom changes.

3. Firewall Hardening with all LOLBins blocked.
Malware testing
Periodic security scanners
Emsisoft Emergency Kit
Norton Power Eraser
Browsers, Search and Addons
Browser:
Firefox (Primary)
Microsoft Edge (Rarely)

uBlock Origin Hard mode with custom changes
ClearURLs
Cookie AutoDelete
Bitwarden - Free Password Manager
Checker Plus for Gmail
Enhancer for YouTube
Minimal Scrollbar (Edge only)
TrafficLight (Occasional)
Maintenance and Cleaning
Ccleaner portable
Personal Files & Photos backup
Mega.nz
Google Drive
Google Photos
Personal backup routine
Device recovery & backup
Macrium Reflect Free
Device backup routine
PC activity
  1. Browsing the web. 
  2. Working from home. 
  3. PC and cloud gaming. 
  4. Streaming. 
  5. Malware samples. 
Computer specs
Motherboard: Gigabyte B450M S2H ULTRA Durable
CPU: AMD Ryzen 5 3400G with RX Vega 11 Graphics
Ram: Team Dark Z 2x8 GB = 16 GB DDR4 3200MHz Gaming Ram
Storage: Transcend 110S 512GB M.2 2280 NVMe SSD, 500 GB Hitachi HDD
Personal changelog
11.10.2020: Replaced motherboard "ASRock B450M-HDV R4.0" with "Gigabyte B450M S2H ULTRA Durable"
21.10.20: Upgraded to Windows 10 20H2
23.10.20: Replaced Microsoft Defender and related tools Configure_Defender, Firewall Hardening with ESET Internet Security 14.0.21.0
24.10.20: Replaced ESET IS with Microsoft Defender
27.10.20: Replaced Microsoft Defender with Kaspersky Free
30.10.20: Back to Microsoft Defender, Added Adguard Home for DNS over QUIC
01.11.20: Disabled Adguard Home
19.12.20: Freshly installed Windows 10 Enterprise 20H2

SeriousHoax

Level 37
Verified
Mar 16, 2019
2,660
Please share µBO hard mode custom changes?:unsure:
Well, maybe writing custom change is a bit misleading 😐 I mean the changes I've made are "Prevent WebRTC from leaking local IP addresses", "Block CSP reports" and added/enabled filters like, AdGuard Tracking Protection, Fanboy’s Enhanced Tracking List, Anti-Facebook, Fanboy’s Annoyance, uBlock filters – Annoyances, 1Hosts (mini). Nothing specific related to hard mode.
 

SeriousHoax

Level 37
Verified
Mar 16, 2019
2,660
Which browser did you use?
Chromium Edge mostly nowadays but also Firefox.
Also: Checker Plus for Gmail
You can add sites as PWA which use notification system so a extension isn't needed for that ;)
I tried that actually few months ago but was missing a lot of notifications. Not sure why that happened so ended up opting for the Checker Plus for Gmail extension instead.
But ok, I'll give PWA another try.
 

SeriousHoax

Level 37
Verified
Mar 16, 2019
2,660
Maybe a bit overkill with browser add-ons :unsure: ...
Each has its purpose.

uBlock Origin is obviously the adblocker,

ClearURLs is for removing tracking parameters from urls and also let me copy clear links from websites,

Cookie AutoDelete is for removing cookies, indexdb, local storage for every sites except the one I whitelist,

Bitwarden - Free Password Manager is self explanatory,

Checker Plus for Gmail is for receiving email notification on the browser,

Enhancer for YouTube is necessary for me because even though my internet connection is perfectly capable of playing videos at 1080p, it never automatically does. So I need this to make sure every video starts playing at 1080p. It also has a feature to enlarge the video player without going full screen which is far better than YouTube's theater mode.

enhanced-h264ify is something that was quite useful for my previous laptop which had to work hard to encode YouTube's VP9 codec so I used this extension to make sure YouTube always loads h.264 videos which is far easier for GPUs to encode. I may get rid of it now if I see my current PC handling VP9 codec well which I haven't checked yet.

Minimal Scrollbar is something I use on Edge only to make the scrollbar dark on every webpage because I use the force dark mode feature of Chromium and white scrollbar on dark webpages really make things look unpleasant. It's not perfect, has some flaws but I haven't found any better option yet.
 
F

ForgottenSeer 85179

AdGuard include uBlock origin and clearURLs in one extension.

Cookies and data can be cleared automatically in Edge. Even on a per site data.

Does Google know works with PWA? Else you could use Thunderbird or Windows 10 mail app which decrease your attack surface.

YouTube remember the video quality if cookie/ data isn't deleted ;)
 

TairikuOkami

Level 31
Verified
Content Creator
May 13, 2017
2,046

Attachments

  • capture_10102020_125744.jpg
    capture_10102020_125744.jpg
    227.9 KB · Views: 336
F

ForgottenSeer 85179

SeriousHoax

Level 37
Verified
Mar 16, 2019
2,660
AdGuard include uBlock origin and clearURLs in one extension.
ClearURLs clears even more and also like the ability to directly copy clean url by right clicking on links.
Cookies and data can be cleared automatically in Edge. Even on a per site data.
Ok, I'll check this out too. Tbh, I've become very lazy lately so putting this on my to do list also 😕
Does Google know works with PWA? Else you could use Thunderbird or Windows 10 mail app which decrease your attack surface.
I used to use Thunderbird but newly found love with emails on the browser as I don't need to use any external app.
YouTube remember the video quality if cookie/ data isn't deleted ;)
It doesn't on mine. I have only 8mbps internet but 30 mbps on Google related stuff like YouTube, Playstore, etc. but YouTube still plays videos at 480p/720p by default for me and like TairikuOkami said, this extension is hassle free.
 

SeriousHoax

Level 37
Verified
Mar 16, 2019
2,660
I had to replace my motherboard yesterday from "ASRock B450M-HDV R4.0" to "Gigabyte B450M S2H ULTRA Durable".

Turns out the ASRock boards have some problems with its VRM. If I ran a game, "Rainbow Six Siege" in this case, my PC would BSOD with "Thread stuck in device drivers". After googling I found out, this only happens when ASRocks's boards are used with AMD APUs like 3400G, 3200G, 2200G.
So, I went to the shop and showed them that it's a motherboard related issue and asked them to replace it with the Gigabyte one and so they did.
So, stay away from ASRock if you're planning to use an AMD APU.
Also this is perks of not purchasing a pre-built brand PC. I would never be able get a totally different branded motherboard if that was the case.
 
F

ForgottenSeer 85179

So, stay away from ASRock if you're planning to use an AMD APU.
I use a Asrock B450 Pro4 board with Ryzen 5-2600 and get some stability problems too in the past. The problem was the combination with using my Radeon 5700 and 3000Mhz XMP Profil for my RAM. After changing RAM frequency to 2933Mhz get problems get away.
Only sometimes I get a system freeze and automatic restart if using sleep mode.

You use a Apu instead of CPU & CPU but maybe this was related.
 

SeriousHoax

Level 37
Verified
Mar 16, 2019
2,660
I use a Asrock B450 Pro4 board with Ryzen 5-2600 and get some stability problems too in the past. The problem was the combination with using my Radeon 5700 and 3000Mhz XMP Profil for my RAM. After changing RAM frequency to 2933Mhz get problems get away.
Only sometimes I get a system freeze and automatic restart if using sleep mode.

You use a Apu instead of CPU & CPU but maybe this was related.
I also found a possible solution online but with a compromise. That was, I have to lower the CPU clock speed from 3.70 Ghz to 3.40 Ghz and lower the voltage from 1.45V to 1.35V. But I wasn't happy with that so when I took it back to the shop I didn't even tell them about this. They checked the problem again by reinstalling Windows, replacing the board with another same one but the problem remained. Then I suggested to test with the Gigabyte board and no more problem whatsoever. I'm running with XMP profile 2.0 at 3200 Mhz ram frequency. Everything is great now and my PC even boot slightly faster. This Gigabyte one is actually 500 taka/$5.90 cheaper. So, this is definitely some hardware related issue of the ASRock boards because they haven't managed to fix it with BIOS updates. There are no problem with a CPU+GPU setup, only with an APU. But like you said, even you had stability problem with an ASRock board so I don't think I'm buying an ASRock again.
 
Top