Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

For those on Windows, http://www.sphinx-soft.com/Vista/index.html does the same using the native firewall (so no 3rd party dependencies, services, or bloat) (though they've ~recently added paid licenses with more features to their basic offering).

I only wish it were cleaner and simpler. I don't think the Windows Firewall API is too bad, I should add this to my bucket list of open source software to write that I'll maybe get around to in the next 20 years....



https://github.com/henrypp/simplewall

> Simple tool to configure Windows Filtering Platform (WFP)

So much better than anything else I tested. Easy to import/export rules (XML) and there's also portable mode and advanced options (that goes beyond the simple UI you can see in the image).


Thanks for the recommendation. Looks like a really good app. It recommends to disable the Windows firewall - which is understandable. But, then you start getting pestered by Windows to turn it back on. Do you turn off the Windows firewall or have them both turned on?


I disabled the firewall and alerts in the control panel.

This might be outdated but it's in the Control Panel or Action Center somewhere (Security and Maintenance area?). https://blogs.technet.microsoft.com/networking/2010/12/16/di...

I'm also using this simplewall option:

> Enable boot-time filters – Prevent data leak during system startup, even before "Base Filtering Engine" (BFE) service starts.


When the native firewall in Windows blocks something, doesn't the connection attempt fail immediately?

For example while the Little Snitch popup dialog is waiting for user input the affected application just sees an unusual latency spike and it will not complain immediately that internet access in not available. Afaik, this is not the case with the Windows Firewall: The connection will fail for the application while the frontend-app is still waiting for the user's decision.


I believe by default incoming connections are "on hold" until they either timeout or the dialog is confirmed one way or the other. Note that most "real" firewalls have two different options for blocking: drop or reject. So long as the packet isn't rejected, drop and "drop unless this dialog is satisfied" aren't very different.

I'm not sure how this app gets around it (if it does at all).


Yes, that's correct. MacOS handles this better. But really it only comes up when you run a _new_ program, so it's not a major problem.


it is because one of the major use cases for an outgoing firewall is when installing new software, which is where you also want to be careful what the application connects to, which does not work very well at all compared to Little Snitch


I've had that problem with W10FC, the permission window will often only spawn after the requesting app has notified you it failed to connect.


If you want to easily block outbound connections to several countries for your entire home network read on..

https://stackoverflow.com/questions/48100009/how-to-enable-e...

My wife has an old fitbit like app that tries to connect to China every 2 seconds. Papertrail is really useful to see patterns. I blocked outbound to every single country except for the country I live in (the embattled country of Binomo). Once I allowed the US and EU, it has been interesting to learn if a site is not US or EU.

These are the domains this week that were blocked leading me to allow a few more countries.

fromdual.com - Switzerland

mysqltuner.pl/scaleway.com - France

canary.tools - Ireland

rsyslog.com - Germany


TinyWall... other LittleSnitch-like apps on windows aren't anywhere near as nice as LittleSnitch, but TinyWall gets rid of the crappy prompts firing a million times a day until you configure it (the thing that sucks is apps like ChromeUpdate and others can get around the firewall somehow, so if you're set to prompt, it will prompt you all day long, so TinyWall makes it all sane).


Unfortunately Tinywall hasn't been updated since 2016. It still works, of course, but I'm not comfortable using security software that isn't in active development.


Thanks for the link. I'm curious how it compares to https://www.binisoft.org/wfc.php although this looks to be free I don't think it's open source. Not having much luck finding license info for it.


I have not used Simplewall but I am a paid customer of Binisoft WFC and do recommend it. WFC works great and is frequently upgraded, the developer is very responsive to his users.

It does have a crude ugly UI, so just don't expect it to look like Little Snitch (which I also endorse on MacOS) or Glasswire.


As you can see in the feature comparison[1], the free edition doesn't cover Windows' system applications, it doesn't offer a lot of pre-defined rule sets, or Desktop integration. Binsoft's WFC does.

However, if you're willing to spend money, Sphinx's product seems to offer quite a bit more features, but then you might as well consider other products out there.

Also, Binsoft's WFC UI, especially that of the rules editor, slowed down for me pretty heavily with just a hundred rules.

I'm not sure how Sphinx W10FC handles it but the Binsoft WFC doesn't accept not pre-defined file types. So if you have a binary with a random suffix, like anti-cheating rootkits often do, you can only add a generic allow or deny rule. You can't configure the rule.

[1] http://www.sphinx-soft.com/Vista/order.html


Glasswire 1.x was quite a nifty firewall/network monitoring tool and you could easily see all the dozens of outbound connections Microsoft launches from Windows 10.

Unfortunately, version 2.0 is no longer free. Windows 10 Firewall Control looks pretty good functionality wise, but it would be better if it had Glasswire's interface or one that's even better.


I would recommend to just use the Advanced Gui of Windows Firewall + Group Policy.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: