3 ms·
I just have been using alternative firewall softwares such as simplewall (Windows) and Little Snitch (Mac). You can configure them such that you are alerted eve
by d11z 4y ago
I just have been using alternative firewall softwares such as simplewall (Windows) and Little Snitch (Mac). You can configure them such that you are alerted every time any process makes any form of network request, and either temporarily or permanently blacklist/whitelist as well as even have fine-grained control over specific hosts/domains/etc.
Really a must have, for me.
- criddell 4y agoDo those firewalls block all network activity? Would a DNS lookup trigger an alert? I had an application that was phoning home and after some digging I found that it was doing so through DNS. It would lookup something like $KEY.some.domain.com and the response would decode to the value.
- d11z 4y agoAs far as I can tell it’s any and every network lookup or request. Frankly, ever since I started using them (several years ago) I’ve only been feeling more and more that it may be the only way forward. My data isn’t up for grabs for profiteering/aggregating/snooping on, sorry. EDIT: Your comment made me curious so I will do more due diligence and return with an update. EDIT2: So after not that much investigation--mostly just rereading what's shown on their project page (https://github.com/henrypp/simplewall https://github.com/henrypp/simplewall) -- it confirms my belief that this adequately shields me from any and all networks without my knowledge or consent. In my opinion, it's kind of dystopian that The Industry basically operates on the assumption that most people will in fact just not care, but maybe more would care if it was presented as more of a choice than a concession. Like, I don't mind sharing for the purpose of analytics. I read through privacy policies (is this being an adult?) kind of frequently these days, and as much as I hate to say it, Apple is still probably what I consider the poster child for big tech data privacy, they are doing the absolute bare minimum by clearly and plainly disclosing what data is used for what and how, and it allows my mind some rest. EDIT3: Proof shown here https://github.com/henrypp/simplewall/issues/980 https://github.com/henrypp/simplewall/issues/980
- criddell 4y agoVery cool. Thanks for digging in to this.
- user3939382 4y agoLittle Snitch catches a lot but gives a blank check to large parts of macOS as not to cause weird behavior of the OS. Some of macOS's phone home calls don't use DNS and instead directly use random IP ranges belonging to Apple so that the only way to block them is to blackhole their ranges at the router. Unless you do that per interface, that means now iOS iMessage won't work and bunch of other things break when your phone is on wifi. Really fixing this problem is a complete PITA.
- d11z 4y agoI can't really speak to this because I no longer own or can afford a Mac, I just know it did the trick for me in the past. The reality of our tangled mess that is data privacy issues is really almost grotesque at this point.
- sneak 4y agoYou can disable these "blank check" rules; I do. You can't use iMessage if you want privacy from Apple; trying to block phone-home to Apple while still using their hardware-serial-number-linked-services is silly. You have to give up iMessage, FaceTime, Handoff, iCloud, App Store, Apple Music, all of it if you want privacy from Apple (obviously).
- zikduruqe 4y agoLulu is a great alternative also. https://objective-see.org/products/lulu.html https://objective-see.org/products/lulu.html