-
Patch Lady – 31 days of Paranoia – Day 28
Today’s paranoia topic is about hardening Windows… and specifically if Windows 7 is really more or less secure than Windows 10.
For all that people do not like about Windows 10 privacy (or lack of) settings and telemetry, Windows 10 does have much more hardware based security that can be enabled than Windows 7 has.
But therein lies the problem, many of this security goodness only kicks in if you have the right hardware, and the right operating system and the right knowledge to set it up right. Take credential guard for example… it’s only in Enterprise sku. Others like attack surface reduction rules only kick in as well with the Enterprise version. 1809 was supposed to get block suspicious behaviors but it was pulled at the last minute.
So whenever you hear that Windows 10 is the most secure version of Windows ever… it is. But…. depending on the version you have, you may not get all the features.
One thing you can do is to “harden” the operating system by uninstalling any software added by the vendor during the OEM process you don’t use, or better yet, reinstalling the operating system from scratch before you use it. Then you can use various tools to “de bloat” the games and other items from the operating system as well as possibly disable services.
But I don’t recommend following that guidance without making a solid backup of your system before you start tweaking and making changes.
So is Windows 10 the most secure operating system ever? Sure. But like most things in security, it takes work and nothing right out of the box is as secure as it can be.