Hacking / Opsec

Is Windows without internet safe?

Started by dontdieinvain · Jul 17, 2026

#510
↳ Replying to @dontdieinvain
Before even messing around, have you tried tails?

Have you tried running linux distros off of usb drives?
#511
↳ Replying to @dontdieinvain
If it is not connected to the internet, then yes it is safe.

There would be other attack vectors though like physical possession of an unencrypted machine or an encrypted machine powered on at the time of the raid.

But nothing can "phone home" or do anything with your stuff if it doesn't have an ethernet cable plugged into it or it is not connected to any Wifi.
#512
↳ Replying to @dontdieinvain
Not how you described it, no. IP based blocking can easily be bypassed by requesting a new lease. This can even happen without your knowledge if the machine has been powered off for long enough.

If you never connected your host to the internet and just forwarded your wireless card to the vm, that would be safer. Though I don't understand the point of doing this over just running free software on your host.
#513
↳ Replying to @dontdieinvain
It has a couple identifying markers but one that would be completely unique to your machine is the GUID. All windows machines have them.
#514
↳ Replying to @dontdieinvain
Thanks for the replies, I use BitLocker for encrypting that I personally don't trust much, Windows is on the SSD some more sensitive files are on the HD that I can delete for sure, I assign the IP to the Mac of my computer to try to keep the same IP, my idea of blocking was just to try to "disable" the AMD PSP and Windows telemetry, I've used Whonix and Tails I still have Tails on a USB but I'm not using it much
#518
↳ Replying to @dontdieinvain
every OS when you make it without any WI-FI it becomes safe from attack vectors that comes from internet and use Linux like Mint or Debian it is better if you want to run Vm's. Infact Linux have better things for OPSec
#519
↳ Replying to @dontdieinvain
Turn on the PIN for BitLocker. It makes it unhackable. Google "Bitlocker TPM+PIN" and change those settings. Note PIN doesn't have to be numbers. It can be a twenty letter and number alphanumeric string with characters. You'll enter it immediately on boot. Successful BitLocker hacks require two things:

1. Private keys backed up to a Microsoft Account.

2. BitLocker installed WITHOUT the PIN protection.

Make sure both of those aren't happening and your harddrive is truly encrypted. Now, as for the software running on the machine when it's being used -- that's another story.

Members-only continuation

This discussion contains more posts.

Create an account or sign in to continue reading the full conversation. 4 additional posts await inside.

Create an accountSign in