Hacker News new | ask | show | jobs
by jmacpore 3320 days ago
Does anyone know a good updated firewall whitelist to allow just Windows Updates and nothing else?
3 comments

Any reason why you believe it would respect those rules? Note the one example where a rule was dynamically added to the firewall in the tweets listed here.
Presumably you would put the rules at the router level not the os.
That doesn't matter if you're using a DNS blackhole or hardware firewall. Of course, MS could hard-code some IP addresses, too.
I was deeply tempted to setup a Windows 10 Enterprise machine at work, then have my OpenBSD firewall add any IP the W10 machines tries to get to a block list.
Yes. I'm surprised it hasn't been mentioned here. https://github.com/crazy-max/WindowsSpyBlocker/tree/master/d...

Comes in several formats: hosts, firewall, openwrt, dnscrypt. You can choose telemetry, update and extra. Has ip rules aswell as DNS rules.

I am actually thinking of writing a modular openwrt luci plugin to make it easy to add to your router as it is only effective on router level as other have mentioned here.

It's updated regularly, tested and one of the best lists out there, a clean copy and paste works into firewall rules as and there is nothing to install.

Happy user. MS probably really dislikes this because they are adding new domains serving the same function almost every update.

What does a firewall help when Windows can bypass it in the kernel?

And embedded stuff aside, a system with a firewall whitelist on a separate box is unusable for daily use...