HN user

atVelocet

151 karma

meet.hn/city/50.938361,6.959974/Cologne

Socials: - atVelocet.at.hn

Interests: Art, Cybersecurity, Cycling, Hacking, Hardware, IoT, Music, Networking, Open Source, Privacy, Programming, Technology

---

[ my public key: https://keybase.io/velocet; my proof: https://keybase.io/velocet/sigs/5nhJc6azXEW-tJDDr4KsLUafNOg5JCSHhajg37qHRts ]

Posts1
Comments82
View on HN

Seems i lack a lot of professional knowledge so please enlighten me on how you would do it.

Why use ADK or SCCM for a personal install?

The custom firewall is just a frontend for the builtin firewall.

GP reg keys are used by many third party tools to alter the system. So why use extra software if you can get this directly from the vendor?

And also a rant about anti virus: What do think is the first thing malware does? How does your system get infected if you are using an updated browser, open mails in it and use it for viewing attachments like PDF? Maybe there is even malware out there that does take advantage of high jacking the anti virus and its system priviliges? But who knows… it always depends on the user and the use case.

Make the system need way less ressouces and get way more raw compute power.

There‘s a reason i wrote a hint about the security. If you keep this in mind and know what you are doing (like take such a setup as a base for VMs) this totally fine.

I am also not aware of any Spectre/Meltdown exploits ever to be found in the wild. If you are not running on a shared system i don’t see a need for those mitigations.

Regarding the third party tool: NTlite uses `dism` under the hood with which you can achieve the same results. You are already sending your DNS to a third party (like your ISP).

You also should never ever alter the hosts file and abuse it for ad blocking and such.

Microsoft supplies the latest group policies for their software. Or how else do you handle those on a local system?

I never said my post was about security but on how to alter your local system in a „more correct“ way with a clear hint about security. If you don’t know what you are doing then you should think twice when touching your system.

Since i‘ve been doing this sort of thing for many years here are some basic rules: - Get LTSC (W10) or IoT/Enterprise (W11) images to begin with - Get https://www.ntlite.com/ .. you won‘t find any other tool which does a better job at removing packages, adding drivers, etc. Worth every penny with great support. - Use GroupPolicies to configure your system. Take the time and download them for Office, Edge, Chrome, Firefox and update those that come with Windows. - Integrate drivers not only for the base image but also in the recovery and setup image. - Install a firewall (binisoft is fine) - Use NextDNS - If you don’t mind the security implications: Disable Defender, SmartScreen, BootGuard and VBS (use bcdedit) - Disable Microcode loading (delete the DLL) - Disable Spectre/Meltdown mitigations - If you need Office: Use the LTSC version

Most third party tools are outdated or do stupid stuff which isn’t needed. You can silence Windows with the right GroupPolicies quite easy.

What i never understood:

Why not use some kind of interlacing and randomly sort the lines. The result is a valid video file which could be uploaded to YouTube. Then deinterlace with a browser plugin and the random pattern used to scramble the lines. Same can be applied to the audio.

For SiLabs Si4xxx (e.g., Si4463) chips there is also this wonderful repo:

https://github.com/astuder/Inside-EZRadioPRO

There are basically four main OEMs for SubGHz radios (hobby projects): - Analog Devices (ADF7xxx) - SiLabs (Si4xxxx) - Semtech (SX1xxx) - Texas Instruments (CCxxxx)

If i remember correctly the Analog Devices and the Semtech radios share the same internal core (blackfin?). Please correct me if i am wrong. For the Semtech and ADF702x there are firmware patches and/or ROMs available. The most interesting part would be to unlock the internal test mode which some of those chips have…

There are many ESP32 boards with a SubGHz radio. But they are either ESP32 with a SX127x or ESP32S3 with a SX126x. A lot of them come with built in battery support.

The next problem with this project is the used radio: The SX12xx series from Semtech is good but lacks a lot of features like the CC1101 as used in the Flipper Zero.

I really like the idea of using an ESP32 but the choice of the used radio is a bit akward.

If you ever plan to use any of these older PCs: Disable Spectre and Meltdown mitigations! As a bonus you should also remove CPU microcodes from the BIOS/UEFI and make sure that no microcode is loaded via software.

The performance gain is huge if done correctly. There is no need for these mitigations on homelabs.