Throw some ideas. I love unconventional security methods, especially ones that have little-none performance loss.
I'm using a host file from mvps combined with one from another site dedicated to malware (no duplicates, both on my router) and I use spybot to modify my computers host file.
MSE. Fully patched/ updated windows.
No office/ flash installed. Using chrome's flash + google docs.
UAC is disabled, any way to make it enabled for specific folders? I think it would be cool if nothing could run from my temp/downloads folder without admin permissions.
Other ideas?
-
-
-
Because I don't need it globally. But restricting the two folders that things download to would be nice.
-
It's an idea of the WS members Sully and Kees1958 over there.
It might just suit your needs; link -
Thanks I'll look into that.
I basically want to keep things I download "frozen" or sandboxed until I decide whether to use them or not. -
Christoph.krn Notebook Evangelist
-
I have win7 ultimate. I'll look into bitlocker.
Thank you for the links and info.
edit: Those are some really interesting links/ articles.
And UAC is disabled completely, not just the notifications. -
Christoph.krn Notebook Evangelist
-
Haha, sorry. I was reading an article on bitlocker while I posted that =p
And I've read some of your other posts about security and they're always informative and interesting (to me at least)
edit: The only apps to reinstall would be Chrome and Java. That's no problem at all, really.
edit2: Question about UAC: If I have the notifications disabled how will I manage it? -
Christoph.krn Notebook Evangelist
-
But then how will it work? From what I understood of UAC it basically just stopped programs from accessing certain parts of the computer without permission. If I don't get a prompt how do I give them permission in the case where they'd need it.
-
Christoph.krn Notebook Evangelist
-
So what's the benefit?
-
how do i enable UAC but disable notifications? I don't see it in the UAC settings.
edit: I set some rules for my temp folder, program folders, and my downloads folder using applocker.
I'm not sure if I did it properly though but I have it deny p much everything lol
edit2: Ok... having an issue. I just downloaded a .exe (coretemp) into my downloads folder and I was able to run it. I have %OSDRIVE%\Users\myname\Downloads\*
set to action "Deny" for User "Everyone"
How come I can run it? Or is it just that it won't auto-run. -
Christoph.krn Notebook Evangelist
There might be other security related benefits, however I don't know of any (and haven't looked for any in the first place). -
I think I just disabled notifications. IE9 is running in protected mode.
Also, I got applocker to work. It was good but it's not what I need really.
I don't want it to be a "yes" or "no" situation even with exceptions.
I basically want it to prompt me before anything in my temp/ downloads folder tries to run. I don't necessarily want everything in these folders to stop running altogether, I just don't want the running without permission. -
Put UAC to full. My problem with it is always because I have it on when I first install all of my programs. I haven't really run into anything yet that needs it.
-
You should very seldom see UAC prompts except when installing software or doing system-level tweaking. It's that way for a reason
Just deal with them when you're installing software, and once all that dies down you're in the clear. You can disable notifications, but I personally prefer not to. I want to know when something is asking for "root" permissions.
-
Christoph.krn Notebook Evangelist
- ...once you executed something, you already decided to trust it.
- ...malicious software running with standard privileges will not be able to modify files inside the "tempexecutable" folder if you only allow "administrators" to do this.
-
I might play around with that Christoph. UAC kind of fulfills what I was hoping for since I have it on globally.
Any other ideas?
Just got a new hard drive, help me secure it?
Discussion in 'Security and Anti-Virus Software' started by Hungry Man, Apr 16, 2011.