4 ms·
Is there any way to block connection to these sites with DNS or something?
by tmdh 4y ago
Is there any way to block connection to these sites with DNS or something?
- quaintdev 4y agoAdGuardHome or PiHole should be able to block this.
- naeq 4y agoHenry++ Simplewall https://www.henrypp.org/product/simplewall https://www.henrypp.org/product/simplewall
- terlisimo 4y agoThis looks neat, I'll check it out. I'm currently using Binisoft (now Malware Bytes) Windows Firewall Control to block unwanted traffic. I'm quite happy with it. The amount of traffic that it regularly blocks is insane. Windows and installed apps constantly want to chat with their cloud friends.
- temac 4y agoYou can probably configure the firewall to block.
- mimotomo 4y agohttps://www.bsi.bund.de/DE/Service-Navi/Publikationen/Studien/SiSyPHuS_Win10/SiSyPHuS_node.html https://www.bsi.bund.de/DE/Service-Navi/Publikationen/Studie... (in German, but some documents are in English). Not at all.
- pierrebarre 4y agoShameless plug: https://github.com/Barre/privaxy https://github.com/Barre/privaxy It can be easily configured to block any host or path.
- jve 4y agoYou don't want to block all of that. CLR checking (else your apps may become slow to start) and windows updates (else you may become vulnerable) should be enabled. Someone else has some suggestions?
- prmoustache 4y agoIf I was still using windows I would totally block everything and run a wsus server in a VM that has a vlan and firewall config. The issue is you can only control your firewall at home. Whenever you are out you are pretty sure that MS and Apple bypass any rule you'd put on the local firewall. I prefer running sane operating systems.
- jve 4y agoPretty sure your sane OS makes calls to CRL/OCSP lists to validate cert revocation. Many of the calls in that list do just that.
- pixl97 4y agoHaving CRL/OCSP getting blocked on corporate networks is one of those things I have to commonly troubleshoot. You can get some weird timeouts and failures in applications that can be fun. For example an internal app starts up fine and works, but then can't connect to github. Instead of showing cert errors, I've had ones show errors that make it appear that you may have a DNS problem or that the connection to github itself was broken.
- walkingby111723 4y agoInstall free Comodo Internet Security. Disable DNS cache service so that all your apps resolve DNS themselves (can only be done via the registry, change the service's startup type from 2 (auto) to 4 (disabled)). In CIS, create a new group for all files under c:/windows. Create a rule denying all in/out requests to that group. Create a rule allowing only DHCP and NTP requests (255.255.255.255:67 and <whatever-timeserver-you-trust>:123) for svchost.exe (place that rule above the one for c:/windows to ensure precedence). Use third-party utilities instead of the likes of ping.exe, e.g. hrping. Refer to CIS documentation in case of any troubles. Enjoy your privacy-hardened windows.
- walkingby111723 4y ago
- walkingby111723 4y ago
- Jon_Lowtek 4y agotake it with two tablespoons of salt if someone who avoids the onboard ping tool claims there are no ill effect of blocking all network connections of OS components except DHCP and NTP. This recommendation will cripple windows features and your enjoyment may vary. (breaking updates, breaking crls, breaking active directory integration, breaking office integration, breaking push notifications, breaking companion app integration, ... and so on)
- ccbccccbbcccbb 4y ago[dead]
- Jon_Lowtek 4y agoyou misunderstood the reference: "this" was meant to mean the recommendation in the parent post. I edited my post to be clearer. concerning the intentional breaking of the windows updater and then using a third party update tool: such workarounds don't make the recommendation less bad. The question is: why break the onboard updater in the first place? And all those other features? Sure you have an alternative to office365 and to onedrive and live without the companion app is possible and happy, and maybe you even have a third party crl updater as well and a workaround for the side effects of blocking oscp. But honestly if you want to replace everything because microsoft is bad and can't be trusted, then start by replacing the kernel.
- Jamie9912 4y agoI doubt you'll have a working operating system if you were to block all of those Hosts
- temac 4y agoWindows works (nearly) fine if you block all connections except those from the "Core Networking" group. Of course you won't have access to some services in that case, like Windows Update, etc. One particular weird thing I have noticed is that the process that checks CRL on behalf on others is LSASS. So basically you have some extra tuning to do to get a system to your liking if using just the Windows Firewall, after you block everything but "Core Networking" (and programs you want to authorise), but it looks reasonable. I would suggest saving the initial state before you go that route, though. If you trace connections you will find funny things, like cl.exe phoning home.
- what-the-grump 4y agoYou would be fine, Microsoft allows and supports fully air gapped deployments and no internet connectivity deployments. Yank your internet cord out and start windows.
- ok123456 4y agoIt's not a general solution for an office. I tried this and people couldn't install Office because some of the same servers for telemetry are used for activation.