Live data from Hacker News

“Reclaim Windows 10” Powershell Script

gist.github.com

181–190 of 273 posts

Re: “Reclaim Windows 10” Powershell Script

#181
post #179

Earlier quoted context omitted.

Isn't W10 Enterprise available to individuals as a monthly subscription?

I think its a victim of one of those fractal product bifurcations. I think enterprise is available in at least three different editions, depending on update cadence.

https://technet.microsoft.com/en-us/itpro/windows/deploy/win...

> Devices currently running Windows 10 Pro, version 1607 can get Windows 10 Enterprise Current Branch (CB) or Current Branch for Business (CBB). This benefit does not include Long Term Service Branch (LTSB)

Re: “Reclaim Windows 10” Powershell Script

#182

Earlier quoted context omitted.

There's another category. Those of us who manually did this already, are annoyed we didn't write down all the steps, but are glad to find this posted here.

There's another category. Those of us who were so aggravated by it we ended up starting an entire open source project and now have 12k users. https://www.reddit.com/r/TronScript

As I rely on some deeper Windows features (like Storage Spaces), I'd be very wary of running a giant script instead of targeting features I dislike (such as OneDrive sync). Last I saw it breaks features like the Windows Store app.

Re: “Reclaim Windows 10” Powershell Script

#183
post #57

I seriously doubt that Windows 10 is doing anything so grave as to require you to run some arbitrary PowerShell script you found on the Internet with elevated privileges. If you do not understand every single command in this thing, you should avoid it, and if you understand every single command in this, you don't need it.

I understand pretty much everything in here (and have manually disabled most of the things this disables in the past), but the script serves as a useful checklist and shortcut. That's it's value.

Re: “Reclaim Windows 10” Powershell Script

#184

Earlier quoted context omitted.

If you do any creative work, Linux is pretty much a desert. Adobe software doesn't run on Linux, capture one doesn't either, so as a photographer I have no choice but windows (cheap hardware and malware os) or OS X (hyper expensive old generation hardware with passable os). Davinci resolve seems to have a Linux version but not enough for someone who does more than video.

Not necessarily. I've read from several who have successfully replaced Photoshop with The GIMP. (I've done this, though I still do photo work in LR). Inkscape has come a long way, and there are multiple, competing (and very competent) Lightroom replacements for digital darkroom work. I don't know how fleshed out the DTP side of things are but as a amateur photographer and graphic designer I've been able to get away w…

Anyone whose workflow is InDesign-heavy or Illustrator-heavy is shit out of luck, though; there is no reasonable replacement for either, and especially not for InDesign.

Re: “Reclaim Windows 10” Powershell Script

#185
post #127
post #125

Earlier quoted context omitted.

Do you understand every single line of code in Windows 10? No. Then you can't make the claim it's not doing anything grave. I'm not saying it is. I'm just saying your argument is illogical and inconsistent.

But that's my point. I don't understand every single line of code in Windows. When I run Windows, I'm deciding to trust it. If you've stopped deciding to trust it, then adding more untrusted code (code that relies heavily on undocumented registry flags and the behavior of Windows itself) is like trying to put out a fire with lighter fluid. And this script doesn't have to be malicious to be bad.

> When I run Windows, I'm deciding to trust it.

I run Windows because I have to for work. I don't trust it.

Re: “Reclaim Windows 10” Powershell Script

#186
post #24

I don't consider win10 telemetry that bad. You can dial it down a lot until it's just sending crash data when thing go bad. Pretty much all OSes have this. What I really don't like however is Microsoft pushing garbage like candy crush to my machine without my consent.

What's the problem with telemetry in general? For almost all of the important products I use I like to send usage info -- my expectation is that they're more likely to improve features that I use as a result. And if you use a web app, e.g., Google Apps, they get all this data plus more (and completely not anonymized).

The biggest part of the problem is not being able to turn it off. I don't think most people would be bothered by the basic telemetry if this was an option for non-enterprise / education users.

That and not being able to see what it's sending out. I recently took a close look at the Privacy control panel on my iPhone. Not only does it give the option of turning off telemetry and ad data, but it also shows you exactly what is being sent back to the mothership.

This is what Windows 10 needs.

Re: “Reclaim Windows 10” Powershell Script

#187

Being heavily involved in setting up standard developer workstations, I consider this to be the only practical approach. It's way beyond any specific config item (including telemetry). This is a sure way to get to a stable and consistent configuration. A few comments: - It is better to split such a mega-script into a set of named scripts, so admins can mix-and-match their own configuration set. - The configuration se…

This script is a good start.

I would also change the default policy in Windows Firewall to drop all outgoing traffic, and then enable access on application basis, and for basic things such as DNS and DHCP.

Windows 10 will still spam the DNS server for telemetry hostnames, and there seems to be nothing that you can do about that.

And really, if you can, you should switch to a better OS that doesnt require you to work against it.

Re: “Reclaim Windows 10” Powershell Script

#188

Earlier quoted context omitted.

"Everything just works" so long as your expectations around "everything" are essentially set by a desktop computer experience designed in 2005. Linux on desktops is fine (except from a physical security standpoint), but primitive in terms of UX. And it's still dependent on Mozilla or Google for its browsing experience. And if you want a portable computer (which by the way are demonstrably more secure in the face of p…

> And if you want a portable computer (which by the way are demonstrably more secure in the face of physical tampering) you basically relegate yourself to terrible battery life, poor display support, dicey sleep support, and the fixes for these often compromise performance. This depends a lot on how well supported your hardware is. I run Linux Mint (MATE) on a Thinkpad T430 and have had 0 issues with displays, sleep,…

I have a T520 and last year I tried to run Ubuntu, but my battery life was around 20% worse than under Windows 10 (and the Windows 10 battery life wasn't great either). You say you haven't had any batter life issues. Does that mean it isn't worse than Windows?

Re: “Reclaim Windows 10” Powershell Script

#189
post #24

I don't consider win10 telemetry that bad. You can dial it down a lot until it's just sending crash data when thing go bad. Pretty much all OSes have this. What I really don't like however is Microsoft pushing garbage like candy crush to my machine without my consent.

What's the problem with telemetry in general? For almost all of the important products I use I like to send usage info -- my expectation is that they're more likely to improve features that I use as a result. And if you use a web app, e.g., Google Apps, they get all this data plus more (and completely not anonymized).

That's fine and I have no problem with telemetry being enabled by default. But there are lots of reasons users might want to shut it off.

A big one is that some people are on metered connections and that telemetry can cost money.

Re: “Reclaim Windows 10” Powershell Script

#190

Earlier quoted context omitted.

OneDrive is also disabled, and your claim about GPO policies is blatantly nonsense, since that's what you use for Enterprise deployments. Also, if you had actually researched before publishing, you'd known that Microsoft removed the disable option from the Hamburger menu during the Anniversary Update. This is not a conspiracy theory but Microsoft blatantly crossing the line, I personally don't care since I'm not inte…

> your claim about GPO policies is blatantly nonsense, since that's what you use for Enterprise deployments. It says right in the GPO policies which operating systems they apply to. For example in your screenshot you set "Do not allow web search" to quote the policy itself that only applies to: > Microsoft Windows XP, or Windows Server 2003 with Windows Search version 3.01 or later Doesn't do anything on Windows 10.…

Your point about various GPO settings being version specific is absolutely correct.

I will say that I definitely do not want to manage options via clicky-click. Local policy editing (and domain group policies in the enterprise) have been a replicable, scalable way to manage settings in a Windows environment since at least XP/Server 2003 (the earliest Windows client + server environments I've admin'd IIRC).

Configuration outside of LP/GP doesn't scale particularly well beyond personal use, I'd say and as such I get what the other poster was driving at.

Post reply on HN