OS Hardening and Outbound Firewall Comparison
This source-dated matrix compares five preregistered hardening paths across twelve attributes; it is not independent testing, a security verdict, or a recommendation.
/* Not legal advice. This page is research, not compliance guidance. */ /* */
What this hardening comparison can establish
This matrix establishes what cited sources stated for five preregistered paths across twelve attributes; it does not independently test the paths or issue a security verdict.
The frozen roster deliberately mixes an operating-system feature, a suite, a hardening tool, and outbound-firewall tools. Those paths can appear in one matrix only when each value retains its own product, plan, region, platform, claim type, source class, source URL, capture date, observation version, and applicability. A value documented for one kind of path is not evidence that another kind of path supplies the same function.
The evidence set contains sixty current persisted cells: one cell for each of five paths across twelve attributes. Eleven cells are typed verified absences tied to the declared documents read. Those absences remain unknowns; they are not rewritten as zero, no, unsupported, nonexistent, or an unfavorable product conclusion.
The comparison does not create accounts, run vendor tests, import unregistered third-party reviews, assign scores, rank paths, identify a preferred provider, or make a most-secure or most-private claim. Documented source text is reported as vendor-stated or public-record evidence at the scope carried by its exact cell.
The privacy-tool comparison methodology explains the evidence labels, capture boundary, neutral ordering, and correction path. There is no affiliate, referral, sponsorship, gift, preferred-access, or paid-placement relationship with a listed vendor.
Identity requirements and operating responsibility
Signup identifiers, later-verification triggers, and operating responsibility answer different questions, so an initial identifier does not establish a later check or a legal jurisdiction.
The signup column reports the identifiers, actors, requiredness, product, plan, region, and platform supported by each current cell. It describes an initial account, purchase, download, or use path only at that cell's stated scope. It does not supply a later-verification rule when the later-verification cell is unknown.
The later-verification column stays separate because a later event needs its own trigger, requested identifier, requesting actor, and scope. Two cells in this column are verified absences limited to the documents declared in those cells. They do not establish that later verification never occurs.
The operating-responsibility column names the company, project, or platform owner and prints only the jurisdictional statements supported by the exact cell. A project name is not silently converted into a corporation, and a website-governing-law statement is not extended to a product when the source limits it to the site. Hosting, incorporation, governing law, and product responsibility remain distinct fields.
The matrix therefore keeps collection stage and entity identity separate. A name or jurisdiction appearing in one record does not fill a gap in another record, even when the records concern the same path.
| Jurisdiction | Signup identifiers | Later verification | Operating responsibility |
|---|---|---|---|
| built-in firewallApple Inc. states a 2026 copyright notice.source | macOS lets a user turn on Firewall in System Settings under Network.source | macOS Firewall settings let a user turn on the firewall to prevent unwanted connections from the internet or other networks.source | Apple Inc. states a 2026 copyright notice.source |
| Little Snitch 6Little Snitch's vendor identifies Objective Development Software GmbH, states that Objective Development was founded in 2004 and is based in Vienna, and lists Commercial Court Vienna registration FN 244130 s.source | Little Snitch says checkout stores the buyer's name, address, email address, company name, VAT number, shopping cart, Internet address, and chosen payment method to issue an invoice with the applicable VAT rate.source | Little Snitch says that if the location cannot be sufficiently determined from clues in the purchase process, such as the Internet address, it will request further documents, such as a copy of an ID card; the documents are stored for 30 days and deleted if no purchase is made, or kept for the 10-year legal retention period if a purchase is made.source | Little Snitch's vendor identifies Objective Development Software GmbH, states that Objective Development was founded in 2004 and is based in Vienna, and lists Commercial Court Vienna registration FN 244130 s.source |
| LuLuFor LuLu, the cited articles name Objective-See Foundation, Inc. as a nonprofit corporation formed under Hawaii law.source | LuLu describes itself as a free, open-source firewall for macOS 10.15 and later, with version 4.5.1 listed for download.source | Unknown Verified absenceNot disclosed in the captured primary source.source | For LuLu, the cited articles name Objective-See Foundation, Inc. as a nonprofit corporation formed under Hawaii law.source |
| Objective-SeeObjective-See's 2025 IRS Form 990 lists OBJECTIVE-SEE FOUNDATION INC as the organization's name.source | Unknown Verified absenceNot disclosed in the captured primary source.source | Unknown Verified absenceNot disclosed in the captured primary source.source | Objective-See's 2025 IRS Form 990 lists OBJECTIVE-SEE FOUNDATION INC as the organization's name.source |
| privacy.sexyprivacy.sexy's package identifies undergroundwires as its author.source | privacy.sexy is available online and as offline downloads for Windows, macOS, and Linux.source | privacy.sexy is available online and as offline downloads for Windows, macOS, and Linux.source | privacy.sexy's package identifies undergroundwires as its author.source |
Source: 5 products. Each source link opens the authority for its cell. The page source record lists the capture date and snapshot for every cell.
Field definitions
- Signup identifiers
- Initial identifiers, collecting actor, requiredness, product, plan, region, and platform stated by the current cell, preserving verified absences.
- Later verification
- Later trigger, requested identifier, requesting actor, and scope stated by the current cell, preserving verified absences.
- Operating responsibility
- Company, project, or platform owner and jurisdictional details supported by the current cell.
Scope of changes and reversibility
Change scope and reversibility are separate questions: a documented way to disable, restore, uninstall, or make an exception does not establish that every prior state returns.
The change-scope column reports the components, settings, services, rules, scripts, or features that the current cell names. It does not broaden a documented change into a claim about every connection, telemetry path, operating-system setting, application, or account.
The reversibility column separately reports the rollback, disable, uninstall, restore, reset, exception, or backup mechanics supported by its cell. A documented action may apply to one setting or component without restoring a different setting, removing a retained artifact, or reversing an action taken by another actor.
Applicability remains cell-specific because the roster contains different kinds of paths. A not-applicable value is printed only when the exact current cell authorizes it. The roster label by itself does not decide whether a rule, rollback step, or system change applies.
Read the two columns together without collapsing them. The first describes what the cited source says changes; the second describes the documented path back, around, or out. Neither column supplies an effectiveness or completeness judgment.
| Jurisdiction | Scope of changes | Reversibility |
|---|---|---|
| built-in firewallApple Inc. states a 2026 copyright notice.source | Apple says macOS includes a built-in firewall to protect the Mac from network access and denial-of-service attacks, configurable in system settings or through a firewall configuration profile.source | macOS lets a user add apps or services in Firewall options and choose whether to allow or block their connections, while warning that blocking may affect software performance.source |
| Little Snitch 6Little Snitch's vendor identifies Objective Development Software GmbH, states that Objective Development was founded in 2004 and is based in Vienna, and lists Commercial Court Vienna registration FN 244130 s.source | Little Snitch runs locally as an application firewall, lets rules allow or deny connections per app, and can hold an uncovered connection while the user chooses whether to allow or deny it.source | Little Snitch says moving its app to the Trash with Finder removes associated system extensions and helper tools but preserves configuration data and traffic history unless the Little Snitch folder in Application Support and the Little Snitch preference files in user defaults are also deleted.source |
| LuLuFor LuLu, the cited articles name Objective-See Foundation, Inc. as a nonprofit corporation formed under Hawaii law.source | LuLu describes itself as a firewall that blocks unknown outgoing connections on Macs.source | LuLu says users can quit or fully uninstall it from the status-bar menu and must authenticate to do either.source |
| Objective-SeeObjective-See's 2025 IRS Form 990 lists OBJECTIVE-SEE FOUNDATION INC as the organization's name.source | Objective-See describes LuLu v4.5.1 for macOS 10.15+ as a free, open-source firewall that blocks unknown outgoing connections.source | Objective-See says BlockBlock's status-bar menu launches an uninstaller that completely removes BlockBlock.source |
| privacy.sexyprivacy.sexy's package identifies undergroundwires as its author.source | privacy.sexy describes hundreds of transparent, reversible scripts intended to give users control of their data.source | privacy.sexy documentation says an inline script can include revertCode to reverse changes made by code.source |
Source: 5 products. Each source link opens the authority for its cell. The page source record lists the capture date and snapshot for every cell.
Field definitions
- Scope of changes
- Components, settings, services, rules, scripts, or features changed at the scope stated by the current cell.
- Reversibility
- Rollback, disable, uninstall, restore, reset, exception, or backup mechanics and limits stated by the current cell.
Outbound-rule models and alerting
Observing, prompting, allowing, and blocking are different behaviors, and an alert does not by itself establish that a connection was blocked or that every outbound path was visible.
The outbound-rule column reports only the rule granularity, default behavior, matching conditions, user choice, and scope represented in the exact current cell. A rule documented for one component or direction is not generalized to every process, protocol, destination, service, or telemetry path.
The alerting column answers a different question. It records the prompt, notification, log, interface, or other alert surface supported by the cell, together with the conditions and scope the source supplies. Seeing a notice is not treated as proof that traffic was denied, and a denied connection is not treated as proof that every related connection was observed.
The distinction also prevents a feature from being compared as if it were a whole suite. Rule models and alert surfaces can be reported side by side, but only the cell establishes the relevant product, plan, region, platform, and applicability for that row.
No table entry is promoted into a claim of complete telemetry control or universal outbound coverage. The matrix describes documented behavior at capture, not a packet-level test or an assurance that an undocumented path cannot exist.
| Jurisdiction | Outbound-rule model | Alerting |
|---|---|---|
| built-in firewallApple Inc. states a 2026 copyright notice.source | macOS Firewall supports blocking all incoming connections, automatically allowing built-in or downloaded signed software, allowing or denying access by app, and preventing responses to ICMP probes and port scans.source | macOS displays an alert when a connection attempt targets an app that has not been added and allowed, and denies attempts until the user allows or denies the connection.source |
| Little Snitch 6Little Snitch's vendor identifies Objective Development Software GmbH, states that Objective Development was founded in 2004 and is based in Vienna, and lists Commercial Court Vienna registration FN 244130 s.source | Little Snitch rules match connection conditions and choose one action in each of three categories—filtering, notification, and hiding history from Network Monitor—with the most specific matching rule supplying each action.source | Little Snitch shows a connection alert when Alert Mode is active and an attempted connection is not covered by a rule, lets the user allow or deny it, and creates a matching rule for later attempts.source |
| LuLuFor LuLu, the cited articles name Objective-See Foundation, Inc. as a nonprofit corporation formed under Hawaii law.source | LuLu describes itself as a firewall that blocks unknown outgoing connections on Macs.source | LuLu says it blocks unknown outgoing connections on Macs.source |
| Objective-SeeObjective-See's 2025 IRS Form 990 lists OBJECTIVE-SEE FOUNDATION INC as the organization's name.source | Objective-See describes LuLu v4.5.1 for macOS 10.15+ as a free, open-source firewall that blocks unknown outgoing connections.source | Objective-See says BlockBlock starts automatically when the computer restarts, aims to detect installed persistent software, and displays an informative alert.source |
| privacy.sexyprivacy.sexy's package identifies undergroundwires as its author.source | privacy.sexy says its scripts are independently executable and provide visibility into what each tweak does.source | privacy.sexy says its desktop and web versions receive updates deployed from source code, while macOS desktop updates may require users to finish installation manually.source |
Source: 5 products. Each source link opens the authority for its cell. The page source record lists the capture date and snapshot for every cell.
Field definitions
- Outbound-rule model
- Rule granularity, default behavior, matching conditions, user choices, and scope stated by the current cell.
- Alerting
- Prompt, notification, log, interface, trigger, and scope stated by the current cell without inferring a block.
Retention and deletion are lifecycle questions
Disabling or uninstalling a control does not by itself establish deletion of every related file, log, preference, account record, or vendor record.
The retention column preserves the data or artifact category, responsible actor, trigger, duration, exception, product, plan, region, platform, and other scope supplied by the current cell. A duration attached to one category is not applied to every record associated with the path.
The deletion column separately reports the documented initiation path, controller or actor, local cleanup step, completion statement, timeframe, exception, and scope. An uninstall instruction may describe removal of software without establishing erasure of preferences, logs, backups, account records, or records held by a separate actor.
The same boundary applies in reverse. A retention statement does not prove that a user lacks a disable, reset, exception, or uninstall path; those mechanics belong to the reversibility cell. A deletion statement does not establish that every earlier system change has been restored.
The table therefore treats retention, deletion, and reversibility as three related but non-equivalent attributes. Each value remains limited to its cited cell rather than becoming a product-wide lifecycle promise.
| Jurisdiction | Retention | Deletion |
|---|---|---|
| built-in firewallApple Inc. states a 2026 copyright notice.source | Apple says it retains personal data only as long as necessary for the purposes for which it was collected or as required by law, and works to retain it for the shortest possible period permissible under law when retention is required.source | Apple says customers may request deletion of personal data through its Data and Privacy page, subject to exceptions including legal recordkeeping and anti-fraud or security purposes.source |
| Little Snitch 6Little Snitch's vendor identifies Objective Development Software GmbH, states that Objective Development was founded in 2004 and is based in Vienna, and lists Commercial Court Vienna registration FN 244130 s.source | Little Snitch says invoice data and VAT proof are retained for 10 years for EU customers outside Austria or seven years for others, while the license owner's name, email address, license keys, and purchase date are stored for the license-agreement term.source | Little Snitch says placing a product in the shopping cart sets a purchase-procedure cookie that enables temporary storage of entered shopping-cart and contact data, with the temporarily stored information deleted after no more than 24 hours.source |
| LuLuFor LuLu, the cited articles name Objective-See Foundation, Inc. as a nonprofit corporation formed under Hawaii law.source | LuLu says a rule can last always, for the current process lifetime, or until a future time, when an expiring rule is deleted automatically.source | LuLu says users can quit or fully uninstall it from the status-bar menu and must authenticate to do either.source |
| Objective-SeeObjective-See's 2025 IRS Form 990 lists OBJECTIVE-SEE FOUNDATION INC as the organization's name.source | Objective-See says BlockBlock logs all alert responses to `/Library/Objective-See/BlockBlock/BlockBlock.log`.source | Objective-See says BlockBlock's status-bar menu launches an uninstaller that completely removes BlockBlock.source |
| privacy.sexyprivacy.sexy's package identifies undergroundwires as its author.source | privacy.sexy says its desktop version keeps activity logs and script-execution history in operating-system-specific directories and provides scripts to securely erase both.source | privacy.sexy says its desktop version keeps activity logs and script-execution history in operating-system-specific directories and provides scripts to securely erase both.source |
Source: 5 products. Each source link opens the authority for its cell. The page source record lists the capture date and snapshot for every cell.
Field definitions
- Retention
- Retained category or artifact, responsible actor, trigger, duration, exceptions, and scope stated by the current cell.
- Deletion
- Deletion or cleanup initiation, actor, completion statement, timeframe, exceptions, and scope stated by the current cell.
Source availability, audits, and request reporting
Public source artifacts, disclosed audit records, and lawful-request reporting answer different evidence questions, so none of the three is an overall trust or security badge.
Source availability reports the component, repository or artifact locator, version or release locator, license, and scope established by the current cell. A public artifact for one component does not establish that every component, service, rule set, or infrastructure layer is public.
The audit column reports only the assessor, scope, standard, period or date, report locator, publication status, and limitation represented in the exact cell. All five audit cells are verified absences scoped to their declared documents. They do not establish that no audit, assessment, review, or private report exists.
Request reporting records the period, jurisdiction, unit, scope, counts, or process statement supplied by the cell. Three request-reporting cells are verified absences limited to the declared documents. An absence is not printed as zero requests, and a process statement is not converted into a count.
These eight verified absences, together with the two later-verification absences and the one signup-identifiers absence in the identity section, account for the evidence set's eleven typed verified absences. Each remains attached to its own cell and declared-document scope rather than becoming a conclusion about the path as a whole.
| Jurisdiction | Source availability | Audit record | Request reporting |
|---|---|---|---|
| built-in firewallApple Inc. states a 2026 copyright notice.source | Apple says macOS includes a built-in firewall to protect the Mac from network access and denial-of-service attacks.source | Unknown Verified absenceNot disclosed in the captured primary source.source | Apple says its transparency report provides information about government requests for customer data received globally.source |
| Little Snitch 6Little Snitch's vendor identifies Objective Development Software GmbH, states that Objective Development was founded in 2004 and is based in Vienna, and lists Commercial Court Vienna registration FN 244130 s.source | Objective Development says Little Snitch is proprietary software and that it thinks users should be able to test all features before buying and that a certain level of protection should be available free of charge for everyone.source | Unknown Verified absenceNot disclosed in the captured primary source.source | Unknown Verified absenceNot disclosed in the captured primary source.source |
| LuLuFor LuLu, the cited articles name Objective-See Foundation, Inc. as a nonprofit corporation formed under Hawaii law.source | LuLu describes itself as free and open source and links its source alongside the version 4.5.1 download.source | Unknown Verified absenceNot disclosed in the captured primary source.source | Unknown Verified absenceNot disclosed in the captured primary source.source |
| Objective-SeeObjective-See's 2025 IRS Form 990 lists OBJECTIVE-SEE FOUNDATION INC as the organization's name.source | Objective-See says all tools are open source and points to its GitHub page.source | Unknown Verified absenceNot disclosed in the captured primary source.source | Unknown Verified absenceNot disclosed in the captured primary source.source |
| privacy.sexyprivacy.sexy's package identifies undergroundwires as its author.source | privacy.sexy's package identifies version 0.13.8 and undergroundwires as its author.source | Unknown Verified absenceNot disclosed in the captured primary source.source | privacy.sexy invites contributions and directs contributors to its CONTRIBUTING guide.source |
Source: 5 products. Each source link opens the authority for its cell. The page source record lists the capture date and snapshot for every cell.
Field definitions
- Source availability
- Named component, repository or artifact locator, version, release locator, license, and scope stated by the current cell.
- Audit record
- Assessor, scope, standard, period or date, report locator, publication status, and limitations, preserving verified absences.
Limits, capture dates, and corrections
This matrix records what cited sources stated at each cell's capture date; it does not establish universal behavior, complete connection coverage, or comparative effectiveness.
Every displayed value is transcluded from a current persisted cell, with its source class, claim type, source URL, capture date, observation version, applicability, and typed unknowns. The page date follows the newest printed cell, but each individual claim keeps its own capture boundary.
The mixed roster remains a material limit. An operating-system feature, suite, hardening tool, and outbound-firewall tool are not treated as interchangeable products. Side-by-side placement means that the same twelve questions were asked; it does not mean every question applies in the same way or that the answers can be combined into one verdict.
Documented rule and alert behavior does not prove observation, identification, or blocking of every outbound connection or telemetry path. A rollback step does not prove complete state restoration. A deletion path does not prove completed erasure of every related artifact or record. A verified absence speaks only to the declared documents read.
Corrections should identify the row, attribute, source, and changed statement through the privacy-tool comparison methodology. The roster and ordering remain neutral: the page carries no score, rank, preferred provider, affiliate parameter, sponsorship, gift, preferred access, or paid placement.
How to read Unknown
- Unknown: Verified absence
- The captured authority was searched and shows no such rule or filing. No value is printed because the absence is the finding. The reason and the authority are printed beside the badge.
- Unknown: Not yet verified
- The captured sources did not settle this field yet. No value is printed, not even an earlier one. The reason is printed beside the badge, and an authority is linked only when one was supplied.
Frequently asked questions
What does an OS-hardening comparison measure?
This matrix measures twelve documented attributes for five preregistered paths: identity and operating responsibility, change scope and reversibility, outbound rules and alerts, lifecycle statements, and three evidence categories. It reports cell-bounded claims rather than independently tested effectiveness.
Is an outbound alert the same as a blocked connection?
No. Observing, prompting, allowing, and blocking are different behaviors. The alerting and outbound-rule cells report only the behavior and scope their cited sources establish.
Can hardening changes be reversed?
The reversibility column reports the rollback, disable, uninstall, restore, reset, exception, or backup mechanics documented for each path. A documented step does not establish that every prior state, file, log, preference, or account record is restored or erased.
What does a verified absence mean in this matrix?
A verified absence means the declared documents read did not disclose the specified fact under the recorded method. It does not mean zero, no, unsupported, nonexistent, or a negative product verdict.