top | item 35398294

Ameliorated: Windows 10 and 11 minus the spyware

102 points| wolfskaempf | 2 years ago |ameliorated.io

50 comments

order
[+] shaicoleman|2 years ago|reply
"Security patches are not available for AME, as this subsystem has been disabled. In order to secure the system properly, we revoke administrator privileges from all normal users, and activate the hidden administrator account. This will mediate approximately 75% of the critical attack surface, while locking down the system from most foreseeable major future threats."

https://docs.ameliorated.io/common-questions/the-case-for-ou...

[+] eviks|2 years ago|reply
Since you can do the same thing on a normal system, by what % is AME less safe vs a patched Windows?
[+] glaucon|2 years ago|reply
Anyone from amerliorated.io reading this, the word 'Rigorously' is misspelt, it appears in a headline on the homepage as "Consistently developed. Rigerously tested".

Short of joining their Telegram channel I couldn't find another way of flagging this.

[+] jrootabega|2 years ago|reply
Perhaps it's intentionally ironic, like Bugzilla's "zarro boogs" message? Equally ill-advised, though, IMO.
[+] anaisbetts|2 years ago|reply
Is this just the standard "Break my Windows install via 'decrapify scripts'", only with a marketing team?
[+] nyanpasu64|2 years ago|reply
I don't know if this is the successor to https://ameliorated.info/ or an April Fool's joke, but it got pinned in the official Ameliorated Telegram group. I'm running Ameliorated 10 21H1 right now, and when I used to use simplewall it showed that Ameliorated is very quiet in nonconsensual network traffic, which I absolutely do not expect stock Windows 10 to be. (And hopefully the prebuilt Ameliorated ISOs aren't backdoored, though it doesn't seem to have any *obvious* C&C network traffic). Hopefully the new OS builder tool is open-source and can be audited to verify it doesn't inject backdoors.

The downsides are that the current ISO injects the creator's preferences in ways which are difficult to change (lock screen image, not being an admin account, VBScript disabled which breaks Visual Studio Installer, only one user usable, etc.). Additionally, applications (Visual Studio, VS Command Prompt, C# build tools even on Linux, vcpkg, Discord) invariably exfiltrate endless amounts of information, even if you clean up the operating system.

[+] cristiioan|2 years ago|reply
They link to an LTT video, but guess what? The video links back to another website: ameliorated.info. The source code linked by the website is also hosted on there. For me it seems like someone is trying to revive an old project without approval from the owner. I'm not sure if you should trust it right now without more information
[+] stuaxo|2 years ago|reply
I'm not sure why Java would be an easier path than C#, the next paragraph is a little weird to read -

Native app

We did not take the easy path of writing our app in Java or a web-based Java-script heavy framework. Using C# and .NET allows us to craft an experience that minimizes resource use and is very fast.

[+] captainmuon|2 years ago|reply
The whole project seems misguided, but at least we finally see somebody use WinUI in the wild...
[+] MrGilbert|2 years ago|reply
Maybe writing C# is not easy for them? Idk, but I agree with your statement. Sounds strange.

//Edit: Nvm, forgot to read today's date. I won't take anything serious today.

[+] Lanrei|2 years ago|reply
Whole thing screams scam or April Fools joke. There's one commit to the source code repository.

Anyone want to try it on a VM and report back?

[+] spiorf|2 years ago|reply
Playbook files are password protected archives. Anyone cares to reverse engineer the password from the executable?
[+] supriyo-biswas|2 years ago|reply
How's this different from NTLite, and does anyone know how this plays along with the ability to update your system?
[+] iakov|2 years ago|reply
It's different because of it's a aprils fools joke I guess? Feels off to me - the password-protected playbooks, the empty git repo, and the timing is suspicious.

If so, it's a weird prank. Where's the punchline?

[+] Double_a_92|2 years ago|reply
It's garbage. It claims to make your windows better... but then it breaks updates, and installs random software. Like VLC, OnlyOffice, Firefox, random wallpapers... What if you don't want those? Or what if it installs other malicious things?
[+] alphager|2 years ago|reply
It breaks updates, so it's an absolutely no-go.
[+] femboy|2 years ago|reply
How does this compare to ShutUp10 and others?
[+] difeorleth|2 years ago|reply
The fact that 'rigorous' is spelled incorrectly on the landing page makes me doubt this somewhat
[+] KyeRussell|2 years ago|reply
> Java-script

Not the best look when you misname the technology that you’re bagging.

[+] mrwnmonm|2 years ago|reply
What a terrible website. And what in the world is a playbook?
[+] dijit|2 years ago|reply
Ops people know playbooks as either:

A set of instructions, such as documentation defining what to do.

Or, more commonly these days: Ansible "playbooks" which run a series of idempotent scripts to bring a system into a desired state. (the terminology taken from the above).

[+] mrjin|2 years ago|reply
Seriously, why bother? Windows 11 is beyond redemption.
[+] gambiting|2 years ago|reply
Because eventually Win 10 will stop being supported and we'll have to switch to win 11 whether we like it or not. It's nice that tools exist already to get rid of most spyware.
[+] timbit42|2 years ago|reply
Not only Windows 11. Windows period.
[+] cookiengineer|2 years ago|reply
This is actually quite nice!

Finally an open alternative to NTLite, I am gonna try this out for sure!

[+] wolfskaempf|2 years ago|reply
OP here. I am not affiliated with this project. Some people have questioned whether the new domain belongs to the original project or not, so here is how I confirmed that they at least cooperate or belong to the same project team.

The older .info domain also referenced by the LTT video links to a Telegram group, whose owners now link to the new .io domain of this post.

As to why the old website does not reference the new domain directly, I have no idea.

As always with scripts that modify your system in fundamental ways, please take great care and do your own research.

[+] guntherhermann|2 years ago|reply
Ok, but what does it actually do?
[+] firecall|2 years ago|reply
Exactly - what does it do?

> Completely transform your computer in minutes. Simply download a verified Playbook, or use your own, and run it in AME Wizard.

erm... no thanks.

Going to need a bit more than just a fancy home page before I do that!

[+] anon3242|2 years ago|reply
Why don't use LTSC and some additional tweaking? Would likely save a lot of time hunting down errors related to some custom iso like this.
[+] rcarmo|2 years ago|reply
Not sure why removing OneDrive is an improvement given that it’s pretty much essential for sharing files.