3 ms·
Or you can just simply block outbound traffic by default and allow what you actually need. No more forced updates. No more telemetry.
by qplex 9y ago
Or you can just simply block outbound traffic by default and allow what you actually need.
No more forced updates. No more telemetry.
- z3t4 9y agoWindows telemetry will by-pass the Windows firewall. You need to run a dedicated firewall box (that is not running Windows)
- qplex 9y agoThis is incorrect. I've run packet analysis to confirm that the built-in firewall blocks, among other things, telemetry - what is your source for this?
- z3t4 9y agoHow do you analyze decrypted data !? Or did you manage to block all outgoing windows data !? It was all over the news a year or two ago. All sources seem to be gone now though.
- qplex 9y agoThere is simply no traffic on the wire other than what you actually allow. The telemetry doesn't bypass Windows firewall. Please stop spreading misinformation.
- z3t4 9y agoSome windows domains are white-listed and will bypass both firewall and hosts file unless you block all HTTPS traffic. https://superuser.com/questions/1207878/does-windows-firewall-fully-block-windows-telemetry https://superuser.com/questions/1207878/does-windows-firewal...
- qplex 9y agoAs I stated before, setting the outbound policy to drop all traffic will work. You then allow whatever you need for your trusted executables (not svchost.exe).