TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Ask HN: Current Best Practice for Securing Windows?

5 pointsby seusscatabout 1 year ago
I&#x27;m setting up a new machine with Windows on it for a family member. Since I&#x27;ve personally not used Windows in over a decade, I&#x27;m a little disconnected from its current best practices.<p>I remember setting up an antivirus back in those days. The recent article on Avast let me know that AV software is apparently not a popular thing anymore. So what should I be doing? This machine is for the exclusive use of my parents (50+). They&#x27;re kind of good at detecting scams and stuff, I haven&#x27;t really needed to give support for the old machine in 5-7 years.<p>What are the current recommendations for setting up a machine with some security?

6 comments

solardevabout 1 year ago
Can you make them a standard (non admin) user account and then either keep the admin account to yourself (with remote desktop, probably) or at least call it something really clear like &quot;this is dangerous&quot; with a hard to type password, so they really have to think twice before using it?<p>It makes it harder for them to accidentally install rootkits and certain kinds of spyware and ransomware. It also makes it harder to install some software globally, but that&#x27;s the point.<p>If you want to go a step further you can try to set it up in some kind of kiosk mode, but that&#x27;s probably too restrictive for day to day use.<p>Of course you should explain why it&#x27;s set up this way. Something like &quot;In day to day use, your standard user account lets you run the programs you already have, create new documents, send emails, etc. All the day to day stuff is taken care of and should work the same as always have. And it protects from you bad software and people trying to hack your machine. In the rare cases you need to install some new program, you should double check to make sure it&#x27;s safe and legit first, like Googling for its official source and calling me if you&#x27;re not sure. Then if you&#x27;re it&#x27;s safe, you use this other special account I left on this post it under your desk. Use it sparingly and only when you absolutely need to!&quot;
mikewarotabout 1 year ago
Set up a backblaze backup, and check the default excludes carefully, or some important home movies and things might not be backed up.<p>It&#x27;s saved my bacon more than once.
bruce511about 1 year ago
Windows out the box is pretty secure. Make sure they are behind a NAT router and sll incoming connections are blocked.<p>AV is built in and works well.<p>Of course it&#x27;s not Windows you should be worried about. It&#x27;s about programs that they download and run, or come via email. That&#x27;s best solved with education, and frankly applies to phones as well as desktop.<p>A healthy amount of fear when it comes to new software, or opening docs is no bad thing.<p>And please don&#x27;t foister things like Libre Office on them. They are a poor solution to those used to Office. It sounds like you&#x27;ve tried that before :)<p>Only techies care about mundane things like license and freedoms etc. Regular people just want working software, that they are used to, which just works. These days that means Windows or Mac, or whatever they had before.
russfinkabout 1 year ago
Must it be windows? A senior family member has a Chromebook and it works well as their daily driver.
评论 #39488970 未加载
ungreased0675about 1 year ago
This is partially a joke, but maybe use a STIG hardened image?
评论 #39488987 未加载
评论 #39488721 未加载
pestatijeabout 1 year ago
let windows auto update and backup user files to another drive regularly...that should be it