Recommended Posts

I have windows firewall enabled but that doesn't allow you to block applications from calling home (as far as i'm aware)

Windows 7/Vista firewall have this functionality. Just type Windows Firewall with Advanced Security in the start menu. From this page make a new outbound rule (Right Pane) and simply choose to block the executable of your choice.

Hello,

A software-based application firewall can be useful for screening a notebook computer from attacks when it is connected to an untrusted network, such as a public Wi-Fi hotspot. Same with on a shared private network (dorm, home, etc.).

Regards,

Aryeh Goretsky

I saw Hawk say the same thing but I think it's one of his famous "Java is good" kinda joke again. :rolleyes:

Java is good ZA is not, never was. But then I stopped taking you serious about anything that has to do with code and such anyway since you obviously don't know what you're talking about. and still don't have any arguments beyond "it's bad".

Even back when XP didn't have a decent firewall, there was far better free alternatives, like Tiny.

Zonealarm tried to get extra market share by making several versions of the firewall with differnt added features like anti virus but lost their way in the process.Many years ago it was in my opinion one of the better free products but its just lost so much ground against the competition.

I don't understand why a lot of the so called 'experts' on Neowin seem to be fixated on advising people on using the half baked Windows 7 firewall or not having a firewall at all. By default, the WIndows 7 firewall allows all outbound traffic. You can set it to block outbound traffic but then you will have to manually create a rule for each and every application which you wish to allow access to the internet (talk about tedious). Most annoying of all is that it will not prompt you when a new program wants to establish an outgoing connection.

'Experts' of Neowin, please explain to me how your NAT gateway, your beloved MSE and half baked Windows 7 firewall at default settings will protect against unknown 0-day threats or driveby's from sending out your keystrokes or personal files to the attacker?

Hello,

A software-based application firewall can be useful for screening a notebook computer from attacks when it is connected to an untrusted network, such as a public Wi-Fi hotspot. Same with on a shared private network (dorm, home, etc.).

Regards,

Aryeh Goretsky

Wouldn't Windows' built-in firewall on an up-to-date installation do the job just fine in those situations? At our school and dorm network for example all clients are isolated and can't communicate with each other.

Perhaps someone didn't noticed that the latest version of ZA offers Kaspersky Antivirus for free?

Kaspersky has turned into trash itself. I used to buy a license for it, but quit using it about 3yrs ago. I use MSE and it has only failed me once. But that was my fault, I was beta testing release 2, instead of staying on the stable version.

'Experts' of Neowin, please explain to me how your NAT gateway, your beloved MSE and half baked Windows 7 firewall at default settings will protect against unknown 0-day threats or driveby's from sending out your keystrokes or personal files to the attacker?

That's the job of your AV and heuristics. firewalls are to protect from targeted attacks or remote attacks. at the point when outbund traffic matters, it's to late and the virus will, if it's a decent one, have disabled your FW anyway.

a FW has a purpose, it's not what you think it is.

  • Like 2

I don't understand why a lot of the so called 'experts' on Neowin seem to be fixated on advising people on using the half baked Windows 7 firewall or not having a firewall at all. By default, the WIndows 7 firewall allows all outbound traffic. You can set it to block outbound traffic but then you will have to manually create a rule for each and every application which you wish to allow access to the internet (talk about tedious). Most annoying of all is that it will not prompt you when a new program wants to establish an outgoing connection.

'Experts' of Neowin, please explain to me how your NAT gateway, your beloved MSE and half baked Windows 7 firewall at default settings will protect against unknown 0-day threats or driveby's from sending out your keystrokes or personal files to the attacker?

Where do I even begin to rebuttel this? Let me start with understanding nat and you do not. If you did you wouldn't have this argument.

Nat by default stops incoming attacks against your internal network. All routers do nat. Also many routers support other firewall attributes. Even corp firewalls do not get updates and what have you as often that these pos near useless "firewalls" do.

Your internal network is controlled by you and you allow what attaches to your network so therefore is secure against your neighbors for the most part anyway. I would be more concerned with someone breaking your wireless than someone getting into your network from the Internet.

Also, in case you didn't know, your pos router, that you have no faith in what so ever, has gotten attacked about 5000 times in the time it takes you to read this post. So even though you have absolutely no faith in it, it has done its job in protecting you better than you could have even imagined.

A software firewall is good for protecting you on unsecure networks like hotels, public hot spots, library networks, etc. But on secure networks they are nothing more than unnecessary overhead.

  • Like 3

That's the job of your AV and heuristics. firewalls are to protect from targeted attacks or remote attacks. at the point when outbund traffic matters, it's to late and the virus will, if it's a decent one, have disabled your FW anyway.

a FW has a purpose, it's not what you think it is.

Nothing is flawless including AV heuristics or software firewalls. The first thing a 0-day exploit will do is try to disable any security software on a target machine. If your AV and its self defence succumbs, at least firewall will block all outbound connections if **** hits the fan.

Yes, a software firewall has a purpose. I'd suggest you read up on them instead of making blanket statements

http://en.wikipedia.org/wiki/Personal_firewall

ZA was pretty good back in the day. I would always recommend it along with Sygate and Comodo. But since ZA got brought out, it turned to ****. I think Sygate got brought out earlier too.

Only one that remains today is Comodo, but since the Windows 7 firewall is perfect. Kinda makes Comodo redundant.

ZA was pretty good back in the day. I would always recommend it along with Sygate and Comodo. But since ZA got brought out, it turned to ****. I think Sygate got brought out earlier too.

Only one that remains today is Comodo, but since the Windows 7 firewall is perfect. Kinda makes Comodo redundant.

Sygate was amazing. It's still a shame Symantec bought it and discontinued the free version completely.

Nothing is flawless including AV heuristics or software firewalls. The first thing a 0-day exploit will do is try to disable any security software on a target machine. If your AV and its self defence succumbs, at least firewall will block all outbound connections if **** hits the fan.

Yes, a software firewall has a purpose. I'd suggest you read up on them instead of making blanket statements

http://en.wikipedia....rsonal_firewall

:facepalm:

didn't read m post at all did you ?

Where do I even begin to rebuttel this? Let me start with understanding nat and you do not. If you did you wouldn't have this argument.

Nat by default stops incoming attacks against your internal network. All routers do nat. Also many routers support other firewall attributes. Even corp firewalls do not get updates and what have you as often that these pos near useless "firewalls" do.

Your internal network is controlled by you and you allow what attaches to your network so therefore is secure against your neighbors for the most part anyway. I would be more concerned with someone breaking your wireless than someone getting into your network from the Internet.

Also, in case you didn't know, your pos router, that you have no faith in what so ever, has gotten attacked about 5000 times in the time it takes you to read this post. So even though you have absolutely no faith in it, it has done its job in protecting you better than you could have even imagined.

A software firewall is good for protecting you on unsecure networks like hotels, public hot spots, library networks, etc. But on secure networks they are nothing more than unnecessary overhead.

NAT gateways stop incoming attacks, I think that's something we can agree on. A user instigates what comes in and goes out on a network, yes, but how will NAT help in a driveby malware attack where it goes under the radar of an AV's heuristics? Just so you know, malware does tend to call home.

As for firewalls being good for untrusted wireless networks, the average Neowinian with little knowledge in networking would assume simply running a firewall would protect them which is far from the truth. A software firewall is useless on untrusted networks unless you set it up to block all traffic apart from the port you are tunnelling on. Better advice would be to use a VPN instead.

Why can't you be content what you "think" and help the OP instead.

Has anyone ever thought for a second that if your computer is compromised wouldn't the software that is running in the os be compromised as well?

The way I look at it, if your computer is compromised it is already too late. Just because you get a warm and fuzzy that your software firewall is blocking all outbound communication don't believe it is. If anything that the earlier revisions of za taught me is don't believe it is disabled (because it isn't) and don't believe it is blocking things from communicating (because it isn't).

The only way to be sure is to block it on the hardware level. This has not gotten cheap enough, IMO, for the home network. You want to block outbound and know for sure what your network is doing get a firewall distro like pfsense, monowall, or smoothwall... Once your computer is compromised it is hard to know for sure that the software on it is 100% in tact.

Why don't you install Threat Management Gateway on each computer

I don't understand why a lot of the so called 'experts' on Neowin seem to be fixated on advising people on using the half baked Windows 7 firewall or not having a firewall at all. By default, the WIndows 7 firewall allows all outbound traffic. You can set it to block outbound traffic but then you will have to manually create a rule for each and every application which you wish to allow access to the internet (talk about tedious). Most annoying of all is that it will not prompt you when a new program wants to establish an outgoing connection.

'Experts' of Neowin, please explain to me how your NAT gateway, your beloved MSE and half baked Windows 7 firewall at default settings will protect against unknown 0-day threats or driveby's from sending out your keystrokes or personal files to the attacker?

Why don't you install Forefront TMG 2010 on each client computer that'll keep those nasty outbound connections at bay./s

Overkill much ? centralize all this at the edge firewall.

Not used a software firewall since the basic one introduced with XP SP2, and never been remotely hacked. Almost every ISP will supply you with a router these days and I've always found that works just fine.

NAT gateways stop incoming attacks, I think that's something we can agree on. A user instigates what comes in and goes out on a network, yes, but how will NAT help in a driveby malware attack where it goes under the radar of an AV's heuristics? Just so you know, malware does tend to call home.

As for firewalls being good for untrusted wireless networks, the average Neowinian with little knowledge in networking would assume simply running a firewall would protect them which is far from the truth. A software firewall is useless on untrusted networks unless you set it up to block all traffic apart from the port you are tunnelling on. Better advice would be to use a VPN instead.

Why can't you be content what you "think" and help the OP instead.

I am fully aware that they call home and do not rely on a infected system to tell me that it is communicating out.

A software firewall useless on an untrusted network? Wow this is funny....you clearly have absolutely no clue about anything. This made me chuckle a bit. Please tell me more.....The software firewall bocks communication from anything outside of the computer by default. No other configuration needed. You need to create rules to allow communication with other network computers. Even the windows firewall wants to believe everything other than the host pc is hostile. I am not even touching the VPN comment, it doesn't belong in this convo.

I am fully aware that they call home and do not rely on a infected system to tell me that it is communicating out.

A software firewall useless on an untrusted network? Wow this is funny....you clearly have absolutely no clue about anything. This made me chuckle a bit. Please tell me more.....The software firewall bocks communication from anything outside of the computer by default. No other configuration needed. You need to create rules to allow communication with other network computers. Even the windows firewall wants to believe everything other than the host pc is hostile. I am not even touching the VPN comment, it doesn't belong in this convo.

The irony is that one of his replies(in fact the one to me where I brought up that exact issue) is that viruses will disable your security systems so you need your software firewall to protect you ... which isn't it's purpose in the first place, and somehow it magically didn't get deactivated, which is even more interesting since most software firewalls allows local software to self allow themselves without malicious intent, and as malicious software it would most certainly disable both AV and FW among other systems.

heck even non call home malware and bad ware I clean from clients computers usually have any firewall completely disabled or usually broken. it's far more common for malware to break the firewall than the AV which is often just disabled.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • UniGetUI 2026.2.2 by Razvan Serea UniGetUI is an application whose main goal is to create an intuitive GUI for the most common CLI package managers for Windows 10 and Windows 11, such as Winget, Scoop and Chocolatey. With UniGetUI, you'll be able to download, install, update and uninstall any software that's published on the supported package managers — and so much more. UniGetUI features Install, update and remove software from your system easily at one click: UniGetUI combines the packages from the most used package managers for windows: WinGet, Chocolatey, Scoop, Pip, Npm and .NET Tool. Discover new packages and filter them to easily find the package you want. View detailed metadata about any package before installing it. Get the direct download URL or the name of the publisher, as well as the size of the download. Easily bulk-install, update or uninstall multiple packages at once selecting multiple packages before performing an operation Automatically update packages, or be notified when updates become available. Skip versions or completely ignore updates in a per-package basis. Manage your available updates at the touch of a button from the Widgets pane or from Dev Home pane with UniGetUI Widgets. The system tray icon will also show the available updates and installed package, to efficiently update a program or remove a package from your system. Easily customize how and where packages are installed. Select different installation options and switches for each package. Install an older version or force to install a 32bit architecture. [But don't worry, those options will be saved for future updates for this package] Share packages with your friends to show them off that program you found. Here is an example: Hey @friend, Check out this program! Export custom lists of packages to then import them to another machine and install those packages with previously-specified, custom installation parameters. Setting up machines or configuring a specific software setup has never been easier. Backup your packages to a local file to easily recover your setup in a matter of seconds when migrating to a new machine Devolutions UniGetUI 2026.2.2 changelog: This release marks the completion of UniGetUI's migration from WinUI to Avalonia. With the remaining WinUI components and dependencies now removed, UniGetUI is fully powered by Avalonia. This update also brings Windows 11 Snap Layouts support, refined styling throughout the application, improved log viewing, new illustrations, and significantly smaller release packages. Highlights Further refined the Avalonia user interface to better match WinUI styling and behavior across package lists, navigation elements, dialogs, and controls. Added support for Windows 11 Snap Layouts when hovering the maximize button, matching the behavior of native Windows applications. Added illustrations for empty and loading package list states, improving visual feedback throughout the application. Improved the operation log window so automatic scrolling no longer interrupts users when reviewing previous log entries. Reduced installer and application package sizes, resulting in smaller downloads and a significantly leaner Windows distribution. User Interface Improvements Improved package list styling, column headers, backgrounds, hover states, and selection indicators for a more polished and consistent experience. Refined sidebar navigation and segmented controls to better align with modern Windows design patterns. Improved package tag badges and icon presentation throughout the application. Updated several labels, placeholders, and interface elements for improved clarity and consistency. Removed the remaining WinUI-specific styling dependencies, further consolidating the application around Avalonia. Windows Improvements Added native Windows 11 Snap Layouts integration for the maximize button. Improved maximize button hover and pressed visual states to more closely match native Windows behavior. Performance & Reliability Reduced the size of Windows release packages by removing unnecessary runtime dependencies and optimizing published builds. Reduced installer size through improved compression settings. Simplified application dependencies and reduced overall maintenance complexity. Fixes Fixed log output auto-scrolling behavior when manually reviewing previous entries. Resolved various UI inconsistencies and styling issues across the Avalonia interface. Addressed several minor issues and edge cases throughout the application. Other Changes Dependency cleanup and project maintenance. Internal code refactoring and infrastructure improvements. Additional test coverage and build pipeline optimizations. Download: UniGetUI 64-bit | Portable | ~90.0 MB (Open Source) Download: UniGetUI ARM64 | Portable Links: UniGetUI Home Page | GitHub | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • The best controller for XBOX and PC is down to the lowest price by Taras Buria Image via Neowin The GameSir G7 Pro is a fantastic controller for XBOX and PC. Officially certified, it works with Microsoft's consoles, mobile devices, and PCs, giving you a universal controller for any kind of gaming machine. And right now, you can save 20% on it, thanks to the latest deal during Prime Day 2026 (purchase link below). The G7 Pro has the classic XBOX layout, complemented by a couple of extra elements, such as the M button for changing various settings and four additional remappable buttons. It also has trigger locks and TMR sticks that eliminate drifting issues, giving you a reliable, long-lasting gamepad. The controller is powered by a built-in battery, which charges via a USB Type-C cable or the bundled dock station. The G7 Pro supports wireless (XBOX Wireless, proprietary dongle, or Bluetooth) and wired connectivity. In addition to software customization (you can remap multiple buttons to different actions), it lets you personalize the look by swapping the faceplate or grips, enabling multiple design combinations. Other features include a 1,000Hz polling rate, an audio jack for your headphones, Hall Effect triggers, and a swappable D-pad (two extra are included). The controller is also available in four color variants, and all of them are now discounted. Thanks to quality materials, reliable components, rich customization, universal compatibility, and an affordable price tag, the G7 Pro received very high praise in our review. It is certainly among the best controllers you can buy. GameSir G7 Pro - $63.99 | 20% off with Prime Good to know This Amazon deal is U.S. specific, and not available in other regions unless specified. We only use first-party seller links (at the time of article publishing); ensure that you purchase from a first-party seller link only. Check out Today's Deals on Amazon | or our recent tech deals. Become a Prime member (for Students or SNAP) via Neowin Get Prime Access - Prime for half price (for qualifying Medicaid, EBT, SNAP) Subscribe to Prime Video, Audible Plus, Music Unlimited or Kindle Unlimited via Neowin As an Amazon Associate, we earn from qualifying purchases.
    • Microsoft further improving Windows 11 Taskbar with latest builds by Sayan Sen Microsoft has released new Windows 11 builds for users flighting the Experimental channels. The new builds are 26300.8758 for Windows 11 26H2, 28120.2374 for 26H1, and 29617.1000 for future platforms. There are improvements related to the Taskbar, File Explorer and more with the new update. The full changelogs are given below: First we have the build 26300.8758: Changes and improvements gradually being rolled out [Taskbar] Taskbar customization just got easier. As we continue to make improvements to the Taskbar experience mentioned last month, we've introduced a dedicated Taskbar Size setting, making it simpler to find, understand, and personalize your ideal taskbar experience. UI showing the new Taskbar Size setting in Settings. We've also made refinements to the transitions between taskbar sizes for a smoother overall experience. [File Explorer] We've improved the reliability of thumbnail previews for cloud files in the Details pane. The pane has also been reorganized so file properties are easier to find and review at a glance. Fixed an issue where the OneDrive shortcut in File Explorer stops working when File Explorer is run in administrative mode. Fixed an issue where the confirmation dialog might display an internal Recycle Bin file name instead of the original file name when permanently deleting a file. [Sounds] Improved system sounds when using Windows in dark mode. Up next we have build 28120.2374: Changes and improvements gradually being rolled out This update includes a small set of general improvements and fixes [Mobile Device Settings] You can add and manage your mobile devices in Settings under Bluetooth & Devices > Mobile Devices. On this page, you can manage features such as using your device as a connected camera or accessing your device's files in File Explorer. [Remote Recovery Management] Added a recovery remote management plug-in to extend WinRE management capabilities for MDM providers. [Input] The emoji panel (Windows key + period (.)) now uses GIPHY as the GIF provider, delivering a smoother GIF browsing and sharing experience following the deprecation of the Tenor API. Finally we have the changelog for Windows 11 build 29617.1000: Changes and improvements gradually being rolled out [Windows Update] As announced in the Windows Update announce blog, we are now bringing a new unified update experience to reduce the number of reboots you see per month. We are starting by coordinating driver, .NET, and firmware updates to align with the monthly quality update, reducing the update experience to a single monthly restart. See the blog for more information. [Windows Magnifier] Magnifier now gives you more control over how you zoom. You can type an exact zoom percentage directly in the magnifier toolbar to land on precisely the level you need. We've also added preset step increments (5%, 10%, 25%, 50%, 100%, 150%, 200%, and 400%) to the Settings dropdown, so you can jump to common levels in a single click. Whether you need a subtle boost or a dramatic close-up, Magnifier adapts to how you want to zoom. Enter an exact percentage or jump to preset steps —5% up to 400%. Feedback: Share your thoughts in Feedback Hub (WIN + F) under Accessibility > Magnifier. [Accessibility] We're introducing screen tint, a new accessibility setting that applies a color overlay across your entire display, softening its intensity so it's easier on your eyes throughout the day. If bright, saturated screens leave you with tired or sensitive eyes by the end of a long session, screen tint can help. Screenshot showing UI for screen tint in Accessibility, with color presets and a strength slider. To get started, open Settings > Accessibility (or press WIN + U) and look for screen tint under the Vision section. From there, you can: Pick from six preset colors or choose a custom color of your own. Adjust the tint strength slider from a subtle wash to full intensity. Night light warms your display to reduce blue light that can interfere with sleep. Screen tint reduces overall screen intensity to ease eye fatigue and light sensitivity during the day. They tackle different problems and you can use both at the same time, one working on warmth and the other on intensity. Note that turning on screen tint will disable color filters, and vice versa. If you currently rely on color filters, you might need to keep screen tint turned off. Feedback: Share your thoughts in Feedback Hub (WIN + F) under Accessibility > Narrator. [Voice Access] Voice Access now supports Portuguese (Portugal), Portuguese (Brazil), and Korean (South Korea). [Audio] Continuing our work on improving Sound Settings, we've made a few more updates in this build: We've adjusted the description text for the Allow option in properties for audio devices to include the current state of the device, to improve the clarity of the text and the purpose of the button actions. "Listen to this device" is now available in properties for audio devices, so you don't need to enter Control Panel for this functionality. [Multiple Desktops] Improved explorer reliability when switching between multiple desktops. [Storage] We've updated the dialog when creating a Dev Drive to now support specifying the size in GB instead of only MB. This has also been added when changing the size of volumes under Settings > System > Storage. [Personalization] This update improves color selection accuracy when adjusting your accent color to match your wallpaper when automatic accent color selection is enabled in Personalization settings. This update improves wallpaper persistence reliability across restarts and upgrades, including better support for large-resolution wallpapers and other scenarios to prevent solid color wallpaper fallback. [Display and Graphics] Improves the reliability and persistence of applying color profiles. You can view the official blog posts here (link1, link2, link3) on Microsoft's site.
    • Windows 11 is getting redesigned taskbar settings in new build by Taras Buria Microsoft is rolling out new Windows 11 preview builds in the Insider program, offering users new features and changes to try ahead of public release. In the Experimental channel (formerly Dev), Microsoft is shipping build 26300.8758, while in the Beta channel, users can download build 26220.8754. The changelogs do not contain much, but there is an important update to taskbar settings. Here is what is new in build 26220.8754: [Taskbar] Taskbar customization just got easier. As we continue to make improvements to the Taskbar experience mentioned last month, we've introduced a dedicated Taskbar Size setting, making it simpler to find, understand, and personalize your ideal taskbar experience. We've also made refinements to the transitions between taskbar sizes for a smoother overall experience. [File Explorer] We've improved the reliability of thumbnail previews for cloud files in the Details pane. The pane has also been reorganized so file properties are easier to find and review at a glance. Fixed an issue where the OneDrive shortcut in File Explorer stops working when File Explorer is run in administrative mode. Fixed an issue where the confirmation dialog might display an internal Recycle Bin file name instead of the original file name when permanently deleting a file. [Sounds] Improved system sounds when using Windows in dark mode. And here is what is new in build 26220.8754: [Smart card removal policy] Administrators can now configure Azure Virtual Desktop (AVD) and Windows 365 sessions that use Microsoft Entra ID (RDS AAD Auth) authentication to automatically disconnect when a redirected smart card is removed. This extends smart card removal policy enforcement to Microsoft Entra authenticated remote sessions, helping organizations meet security and compliance requirements. [File Explorer] Fixed an issue where the OneDrive shortcut in File Explorer stops working when File Explorer is run in administrator mode. [Taskbar] Improved reliability of loading the system tray area of the taskbar. [Sounds] Improved system sounds when using Windows in dark mode. You can find release notes for build 26300.8758 here and for build 26220.8754 here.
  • Recent Achievements

    • One Year In
      bernmeister earned a badge
      One Year In
    • Week One Done
      Scoobystu earned a badge
      Week One Done
    • Week One Done
      tuben earned a badge
      Week One Done
    • First Post
      OffsetAbs earned a badge
      First Post
    • Reacting Well
      OffsetAbs earned a badge
      Reacting Well
  • Popular Contributors

    1. 1
      +primortal
      441
    2. 2
      +Edouard
      197
    3. 3
      PsYcHoKiLLa
      156
    4. 4
      FloatingFatMan
      71
    5. 5
      Steven P.
      67
  • Tell a friend

    Love Neowin? Tell a friend!