I'm just informed enough about IT security to know that I really know very very little about it. That said, I probably know ten times as much as do 99% of people. I'm an expert in my field, and while I've been a jack of all trades on many fronts, today's threats to privacy and IT security require expert knowledge to combat.
I do not have time.
The long winded point I have is that it is now just too damn much work to do it all right. I'm tired after a 10 hour workday. I've obviously taken more steps than most, but it is still leaky as hell...
I need a company/organization that I can reasonably trust to manage my information security/property, to manage my computers, manage my vpns, e.g., to isolate my web browser windows over multiple vpns, ... all of it, and it can't be GOOGLE. My data is my property, as long as I can hold it, so it needs to be a company/organization that built in privacy obligations (like lawyers and doctors supposedly do).
-Signed: A Frustrated Tired Old Nerd (with children)
[Ed's Comment: Does such a company exist? Is it even possible to provide such a service? Or have we just identified a niche in the market for some enterprising person to fill?]
(Score: 4, Interesting) by Anonymous Coward on Monday October 05 2015, @12:56PM
The best set of tweaks I've seen is here - https://github.com/WindowsLies/BlockWindows [github.com]
I did have to comment some lines out in the hosts list as it's very... Comprehensive.
(Score: 2, Informative) by Anonymous Coward on Monday October 05 2015, @02:58PM
On that note. Setup a firwall for your network. I use ipcop. Since it will also offer dhcp services and DNS. You add a 2nd 3rd 4th... Host files to protect whole network. So kids machines or wife's will be protected without a lot of worry. Yes, it is better to not load ms spyware, but they will find another vector so patching the firewall is faster.
For me I have 17000 block ad and tracking sites. In one extra host file. The was ms sites to block since my wife and daughter both use win10. Mainly school issues.
The other nice thing I also point my DNS feed on red (Internet) interface manually to a root server since my ISP runs "helpful" DNS override. DNS entry not found... Send you to their search and sales engine.