The better reading is that several free tools, each covering a different risk, add up to a sensible baseline. Here is what each one does and where it stops, with a Windows slant.
The setup at a glance
The article recommends seven categories:
- A password manager (Vaultwarden is the example)
- Two-factor authentication (Proton Authenticator)
- Antivirus
- Email aliases (Proton Pass)
- Breach monitoring (Have I Been Pwned)
- File encryption (Cryptomator)
- A VPN (Proton VPN's free tier)
These sit at different layers. A VPN does not stop malware. A breach lookup does not prevent anything. Encrypting cloud files does nothing if the PC holding the unlocked files is infected. Mixing them up is how people end up feeling safer than they are.
Start with what Windows already ships
On Windows, the antivirus slot may already be filled. Microsoft's Windows 11 security documentation says Microsoft Defender Antivirus is included in all versions of Windows 11, and that it also covers Windows 10 devices enrolled in Extended Security Updates. Microsoft describes its protection as real-time, behavior-based and heuristic, with automatic updates.
Two behaviors are worth knowing:
- If you install and turn on another antivirus app, Defender Antivirus switches itself off. It switches back on if you uninstall that app.
- Windows also includes SmartScreen, which checks websites and downloads for phishing and malware. Tamper protection, which keeps malware from switching off security features, and controlled folder access, which guards folders against ransomware, are also part of the platform.
So the practical advice is to open Windows Security and confirm real-time protection is on and updates are current before paying for anything that overlaps. This doesn't prove Defender beats paid suites, and I won't claim it does. It only means a paid subscription is not the only route to baseline protection.
One naming trap: Microsoft separates the built-in Windows Security and Defender Antivirus from the Microsoft Defender app. That app is bundled with Microsoft 365 Personal and Family subscriptions. They are different products with different feature sets, and the app's identity-monitoring feature is US-only.
Passwords: Vaultwarden is a trade-off, not a freebie
A password manager lets you use a unique password everywhere without memorizing any of them. The article's example is Vaultwarden. Its GitHub project describes it as an unofficial, Rust-written server that works with Bitwarden clients and suits self-hosting.
"Free" here means you run the server yourself. You take on the setup, updates, backups and security of whatever hosts it. The project also asks users to report bugs to it rather than to Bitwarden. For many Windows users, a hosted manager's free tier is the lower-maintenance choice. Vaultwarden suits people who want control and are comfortable administering a service.
2FA: authenticator apps, recovery codes and security keys
The article prefers an authenticator app over SMS codes. Proton's own guidance describes authenticator codes as six-digit, time-based one-time passwords. Proton's documentation adds the details that matter in practice:
- Save your recovery codes somewhere secure when you enable 2FA. They are your way back in if you lose the authenticator.
- You can pair more than one device or app with the same account, which reduces lockout risk.
- If sign-in fails with an "incorrect login credentials" error, check that the clocks on your devices match.
- Proton says a physical U2F or FIDO2 security key gives stronger protection against phishing than an authenticator app, though an app can be more convenient.
Not every site supports security keys, so an authenticator app remains a solid default.
Aliases and breach checks: limit exposure, then react
Proton Pass hide-my-email aliases forward mail to your real inbox without revealing your address to the sender. Proton's documentation lists a cap of 10 aliases on its free tier and Mail Plus, with unlimited aliases on Pass Plus or Proton Unlimited. You can disable an alias temporarily, or delete it permanently. A deleted alias cannot be recovered.
Aliases cut spam and keep your main address out of future leaks. They don't stop a company from being breached, and they don't make phishing sent to the alias harmless.
Have I Been Pwned answers a narrower question: has this address appeared in a known breach? Its FAQ is candid about the limits:
- It holds only a subset of all breaches ever recorded.
- Sensitive breaches are searchable only by the verified owner of the address.
- An address stays listed in a breach even after you change the password, because the exposure is a historical fact.
- It also indexes stealer-log data, which comes from malware on infected machines.
A hit is a prompt to investigate, not proof of takeover. Find which service was affected, replace any reused password, enable 2FA, and review recent activity and recovery settings.
Cryptomator: good for cloud storage, with clear boundaries
Cryptomator encrypts file contents and file and folder names before they reach a cloud provider, and it obfuscates the directory structure. Its security documentation is blunt about what it doesn't do:
- It cannot protect you if the local computer has malware that reads your password or the contents of an unlocked vault.
- Programs that create backup copies of files while you work on them can leave readable copies behind.
- It does not encrypt timestamps, file sizes, or the number of files and folders in a vault.
- It is not a replacement for full-disk encryption, timely updates and antivirus.
On Windows, treat it as a layer for sensitive documents stored in the cloud, alongside a healthy, patched PC and a separate backup. It is not a substitute for either.
VPN: narrow benefit, real limits
The article says Proton VPN's free plan has no data limit, and that checks out. Proton states that all users, even on the Free plan, have unlimited bandwidth and data. Independent write-ups of the 2026 free tier add the catches: one device connection and servers in 10 countries, selected automatically. They also note it does not include P2P, streaming-optimised servers, Secure Core, or NetShield. Proton also says the connection is likely to be slightly slower than browsing without the VPN. One source in my search claimed a 10 GB monthly cap on the free plan. It conflicts with Proton's own statements, so I'm disregarding it.
A VPN encrypts traffic between your PC and the VPN server, and it shows websites the server's IP address instead of yours. That helps on café, hotel or airport Wi-Fi. It doesn't make you anonymous, and it doesn't protect you from phishing or malware. You are also moving trust from the network operator to the VPN provider.
A sensible order of operations for Windows users
- Confirm Windows Security shows real-time protection on and that Windows Update is current.
- Put every account behind a unique password in a manager.
- Turn on authenticator-app 2FA for email, banking and your Microsoft account, and store the recovery codes.
- Check your addresses on Have I Been Pwned and act on any matches.
- Use aliases for newsletters and throwaway sign-ups.
- Encrypt sensitive cloud documents with Cryptomator, and keep a separate backup.
- Use a VPN when you're on networks you don't trust.
The verdict
The article's practical advice holds up: a layered, low-cost routine covers real risks. Its marquee claim does not. Without a named comparison and a method, "blocks more threats than paid services" is a slogan. The honest pitch is that free tools can get you a long way, provided you know what each one does and doesn't protect. A password vault can't stop ransomware, and an antivirus can't fix a reused password.
References
- I built a security setup that costs nothing and blocks more threats than most paid services XDA · 2026-10-11T11:30:18+00:00
- Set up two-factor authentication (2FA) with an authenticator app | Proton proton.me
- Hide-my-email aliases | Proton proton.me