Advertisement
Guest User

Windows 10 Security / Privacy Findings

a guest
Aug 12th, 2015
1,325
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 5.17 KB | None | 0 0
  1. Since upgrading to Windows 10, I have been rather 'paranoid' about both the security and privacy of the OS. I have validated my information on several machines. I am using ESET Endpoint Security. I use a local account and have all Windows Apps Removed except Search, Store, Edge, I use the EnableLUA feature to disable the majority of these apps also. I used custom install settings and disabled all the options in privacy, I'd rather nothing got passed through to MS. Regarding ESET, I decided to take the paranoia one step further, be enabling Interactive mode. For those of you who don't know, this is where EVERY request to the outside world has to be either Allowed or Denied by the user. This means every connection to any outside source is in theory monitored.
  2. Well, unless I am doing something very wrong I am convinced the settings you enable or disable do not do anything. Let’s talk about BitLocker, I use it, yes I know it isn't perfect or anything but it's an added piece of security, mainly if I was to have my machine lost or stolen. When setting up BitLocker it asked how I wanted the recovery key stored, I decided to go for the print off option and to store it away for safe keeping. Although I specified Microsoft not to back it up I've found that the BitLocker Service is repeatedly trying to contact a machine outside, (IP lookup reveals it's owned by Akamai), well why on earth would the BitLocker service need to communicate with such when I have clearly told it not to back up the key. The worst part of it is that as I blocked the service rather than the IP it tried using different outgoing ports, it tried port 2345 all the way to 3825 I assume to try and find a port that the firewall wasn't blocking, even though it wasn't blocking ports specifically.
  3. Now if you think it's only the BitLocker service and privacy settings that are mis-shown then that's only the start. Device Setup Manager, I had turned the options of having drivers downloaded through windows update on but it seems this still decided to contact the outside world. I disabled the Service and stopped it, Task manager showed it as being stopped and the process seemed to of disappeared. But did the outgoing requests stop? Nope. It wasn't till I rebooted that the requests for that service stopped, later on when checking again it would seem it still makes 2-3 requests now and then.
  4. Little things like every time I open the start menu or search bar results in an outgoing connection are un-necessary. Yes, I have disabled Cortana and the online search, bounding it to 'Local' only. This doesn't stop it from trying to connect to Bing.
  5. The majority of stuff is done over port 443 or 80. If you disable 443 it falls back to using 993 which is interesting but better than unsecured.
  6. After in 24 hours having 6856 outgoing requests (9 of these hours the machine was off, at boot over 600 requests are made) I have a total of 129 different IPs being contacted, I did some research, some are Microsoft, some are Akamai, some are 'Edgecast' so I blocked the IP ranges which seems to of done a good job and doesn't affect the rest of the system. I allowed the Windows Update service access and that works fine although if you rather it didn't work then you can block the service easily enough.
  7. Now I have a relatively tight grasp on outgoing communication I get around 2000 outgoing requests per hour, these vary from services that try 2-3 times to others that try multiple ports over and over into the thousands. CPU usage doesn't seem affected although I suspect this is also spoofed.
  8. The next step is seeing what's being sent.
  9.  
  10. A section of log file can be found at http://pastebin.com/hF3FakL0
  11.  
  12. Below is a list of IPs that can be safely blocked, although you may not be able to access certain stuff on the Microsoft site(s). Akamai IPs have been removed due to the 'useful-ness' of them for other sides, I recommend you block the services if need be.
  13.  
  14. 104.210.212.243
  15. 104.215.146.200
  16. 104.43.140.223
  17. 104.45.11.195
  18. 104.45.214.112
  19. 104.46.1.211
  20. 104.46.1.211
  21. 104.46.50.125
  22. 104.86.110.11
  23. 104.86.110.146
  24. 104.86.110.200
  25. 104.86.110.83
  26. 131.253.61.100
  27. 131.253.61.66
  28. 131.253.61.68
  29. 131.253.61.80
  30. 131.253.61.82
  31. 131.253.61.84
  32. 131.253.61.96
  33. 131.253.61.98
  34. 134.170.115.60
  35. 134.170.185.70
  36. 134.170.30.202
  37. 137.116.242.248
  38. 137.116.81.24
  39. 137.117.235.16
  40. 137.135.204.246
  41. 157.55.129.21
  42. 157.56.106.189
  43. 157.56.121.89
  44. 157.56.149.250
  45. 157.56.77.138
  46. 157.56.77.139
  47. 157.56.91.77
  48. 157.56.96.123
  49. 168.63.108.233
  50. 168.63.52.117
  51. 191.232.139.141
  52. 191.232.139.253
  53. 191.232.139.254
  54. 191.232.139.254
  55. 191.232.139.254
  56. 191.232.139.49
  57. 191.232.193.254
  58. 191.234.72.183
  59. 191.234.72.186
  60. 191.234.72.190
  61. 191.236.155.80
  62. 191.238.177.236
  63. 204.79.197.200
  64. 204.79.197.200
  65. 207.46.194.46
  66. 207.46.223.94
  67. 207.68.166.254
  68. 23.101.14.229
  69. 23.101.30.126
  70. 23.102.4.253
  71. 23.103.189.125
  72. 23.97.139.122
  73. 23.99.10.11
  74. 23.99.116.116
  75. 23.99.121.207
  76. 64.4.54.116
  77. 64.4.54.22
  78. 64.4.54.32
  79. 64.4.6.100
  80. 65.52.100.11
  81. 65.52.100.77
  82. 65.52.100.9
  83. 65.52.100.91
  84. 65.52.100.92
  85. 65.52.100.93
  86. 65.52.100.94
  87. 65.52.108.153
  88. 65.52.129.119
  89. 65.55.108.23
  90. 65.55.136.222
  91. 65.55.252.43
  92. 65.55.252.63
  93. 65.55.252.71
  94. 65.55.252.92
  95. 65.55.252.93
  96. 65.55.252.93
  97. 65.55.29.238
  98. 65.55.29.238
  99. 65.55.39.10
  100. 66.119.144.157
  101. 66.119.144.158
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement