Private Pierce

OS Hardening and Outbound Firewall Comparison

This source-dated matrix compares five preregistered hardening paths across twelve attributes; it is not independent testing, a security verdict, or a recommendation.

Scope: 5 products

What this hardening comparison can establish

This matrix establishes what cited sources stated for five preregistered paths across twelve attributes; it does not independently test the paths or issue a security verdict.

The frozen roster deliberately mixes an operating-system feature, a suite, a hardening tool, and outbound-firewall tools. Those paths can appear in one matrix only when each value retains its own product, plan, region, platform, claim type, source class, source URL, capture date, observation version, and applicability. A value documented for one kind of path is not evidence that another kind of path supplies the same function.

The evidence set contains sixty current persisted cells: one cell for each of five paths across twelve attributes. Eleven cells are typed verified absences tied to the declared documents read. Those absences remain unknowns; they are not rewritten as zero, no, unsupported, nonexistent, or an unfavorable product conclusion.

The comparison does not create accounts, run vendor tests, import unregistered third-party reviews, assign scores, rank paths, identify a preferred provider, or make a most-secure or most-private claim. Documented source text is reported as vendor-stated or public-record evidence at the scope carried by its exact cell.

The privacy-tool comparison methodology explains the evidence labels, capture boundary, neutral ordering, and correction path. There is no affiliate, referral, sponsorship, gift, preferred-access, or paid-placement relationship with a listed vendor.

Identity requirements and operating responsibility

Signup identifiers, later-verification triggers, and operating responsibility answer different questions, so an initial identifier does not establish a later check or a legal jurisdiction.

The signup column reports the identifiers, actors, requiredness, product, plan, region, and platform supported by each current cell. It describes an initial account, purchase, download, or use path only at that cell's stated scope. It does not supply a later-verification rule when the later-verification cell is unknown.

The later-verification column stays separate because a later event needs its own trigger, requested identifier, requesting actor, and scope. Two cells in this column are verified absences limited to the documents declared in those cells. They do not establish that later verification never occurs.

The operating-responsibility column names the company, project, or platform owner and prints only the jurisdictional statements supported by the exact cell. A project name is not silently converted into a corporation, and a website-governing-law statement is not extended to a product when the source limits it to the site. Hosting, incorporation, governing law, and product responsibility remain distinct fields.

The matrix therefore keeps collection stage and entity identity separate. A name or jurisdiction appearing in one record does not fill a gap in another record, even when the records concern the same path.

Identity requirements and operating responsibility
JurisdictionSignup identifiersLater verificationOperating responsibility
built-in firewallApple Inc. states a 2026 copyright notice.sourcemacOS lets a user turn on Firewall in System Settings under Network.sourcemacOS Firewall settings let a user turn on the firewall to prevent unwanted connections from the internet or other networks.sourceApple Inc. states a 2026 copyright notice.source
Little Snitch 6Little Snitch's vendor identifies Objective Development Software GmbH, states that Objective Development was founded in 2004 and is based in Vienna, and lists Commercial Court Vienna registration FN 244130 s.sourceLittle Snitch says checkout stores the buyer's name, address, email address, company name, VAT number, shopping cart, Internet address, and chosen payment method to issue an invoice with the applicable VAT rate.sourceLittle Snitch says that if the location cannot be sufficiently determined from clues in the purchase process, such as the Internet address, it will request further documents, such as a copy of an ID card; the documents are stored for 30 days and deleted if no purchase is made, or kept for the 10-year legal retention period if a purchase is made.sourceLittle Snitch's vendor identifies Objective Development Software GmbH, states that Objective Development was founded in 2004 and is based in Vienna, and lists Commercial Court Vienna registration FN 244130 s.source
LuLuFor LuLu, the cited articles name Objective-See Foundation, Inc. as a nonprofit corporation formed under Hawaii law.sourceLuLu describes itself as a free, open-source firewall for macOS 10.15 and later, with version 4.5.1 listed for download.sourceUnknown Verified absenceNot disclosed in the captured primary source.sourceFor LuLu, the cited articles name Objective-See Foundation, Inc. as a nonprofit corporation formed under Hawaii law.source
Objective-SeeObjective-See's 2025 IRS Form 990 lists OBJECTIVE-SEE FOUNDATION INC as the organization's name.sourceUnknown Verified absenceNot disclosed in the captured primary source.sourceUnknown Verified absenceNot disclosed in the captured primary source.sourceObjective-See's 2025 IRS Form 990 lists OBJECTIVE-SEE FOUNDATION INC as the organization's name.source
privacy.sexyprivacy.sexy's package identifies undergroundwires as its author.sourceprivacy.sexy is available online and as offline downloads for Windows, macOS, and Linux.sourceprivacy.sexy is available online and as offline downloads for Windows, macOS, and Linux.sourceprivacy.sexy's package identifies undergroundwires as its author.source

Source: 5 products. Each source link opens the authority for its cell. The page source record lists the capture date and snapshot for every cell.

Field definitions

Signup identifiers
Initial identifiers, collecting actor, requiredness, product, plan, region, and platform stated by the current cell, preserving verified absences.
Later verification
Later trigger, requested identifier, requesting actor, and scope stated by the current cell, preserving verified absences.
Operating responsibility
Company, project, or platform owner and jurisdictional details supported by the current cell.

Scope of changes and reversibility

Change scope and reversibility are separate questions: a documented way to disable, restore, uninstall, or make an exception does not establish that every prior state returns.

The change-scope column reports the components, settings, services, rules, scripts, or features that the current cell names. It does not broaden a documented change into a claim about every connection, telemetry path, operating-system setting, application, or account.

The reversibility column separately reports the rollback, disable, uninstall, restore, reset, exception, or backup mechanics supported by its cell. A documented action may apply to one setting or component without restoring a different setting, removing a retained artifact, or reversing an action taken by another actor.

Applicability remains cell-specific because the roster contains different kinds of paths. A not-applicable value is printed only when the exact current cell authorizes it. The roster label by itself does not decide whether a rule, rollback step, or system change applies.

Read the two columns together without collapsing them. The first describes what the cited source says changes; the second describes the documented path back, around, or out. Neither column supplies an effectiveness or completeness judgment.

Scope of changes and reversibility
JurisdictionScope of changesReversibility
built-in firewallApple Inc. states a 2026 copyright notice.sourceApple says macOS includes a built-in firewall to protect the Mac from network access and denial-of-service attacks, configurable in system settings or through a firewall configuration profile.sourcemacOS lets a user add apps or services in Firewall options and choose whether to allow or block their connections, while warning that blocking may affect software performance.source
Little Snitch 6Little Snitch's vendor identifies Objective Development Software GmbH, states that Objective Development was founded in 2004 and is based in Vienna, and lists Commercial Court Vienna registration FN 244130 s.sourceLittle Snitch runs locally as an application firewall, lets rules allow or deny connections per app, and can hold an uncovered connection while the user chooses whether to allow or deny it.sourceLittle Snitch says moving its app to the Trash with Finder removes associated system extensions and helper tools but preserves configuration data and traffic history unless the Little Snitch folder in Application Support and the Little Snitch preference files in user defaults are also deleted.source
LuLuFor LuLu, the cited articles name Objective-See Foundation, Inc. as a nonprofit corporation formed under Hawaii law.sourceLuLu describes itself as a firewall that blocks unknown outgoing connections on Macs.sourceLuLu says users can quit or fully uninstall it from the status-bar menu and must authenticate to do either.source
Objective-SeeObjective-See's 2025 IRS Form 990 lists OBJECTIVE-SEE FOUNDATION INC as the organization's name.sourceObjective-See describes LuLu v4.5.1 for macOS 10.15+ as a free, open-source firewall that blocks unknown outgoing connections.sourceObjective-See says BlockBlock's status-bar menu launches an uninstaller that completely removes BlockBlock.source
privacy.sexyprivacy.sexy's package identifies undergroundwires as its author.sourceprivacy.sexy describes hundreds of transparent, reversible scripts intended to give users control of their data.sourceprivacy.sexy documentation says an inline script can include revertCode to reverse changes made by code.source

Source: 5 products. Each source link opens the authority for its cell. The page source record lists the capture date and snapshot for every cell.

Field definitions

Scope of changes
Components, settings, services, rules, scripts, or features changed at the scope stated by the current cell.
Reversibility
Rollback, disable, uninstall, restore, reset, exception, or backup mechanics and limits stated by the current cell.

Outbound-rule models and alerting

Observing, prompting, allowing, and blocking are different behaviors, and an alert does not by itself establish that a connection was blocked or that every outbound path was visible.

The outbound-rule column reports only the rule granularity, default behavior, matching conditions, user choice, and scope represented in the exact current cell. A rule documented for one component or direction is not generalized to every process, protocol, destination, service, or telemetry path.

The alerting column answers a different question. It records the prompt, notification, log, interface, or other alert surface supported by the cell, together with the conditions and scope the source supplies. Seeing a notice is not treated as proof that traffic was denied, and a denied connection is not treated as proof that every related connection was observed.

The distinction also prevents a feature from being compared as if it were a whole suite. Rule models and alert surfaces can be reported side by side, but only the cell establishes the relevant product, plan, region, platform, and applicability for that row.

No table entry is promoted into a claim of complete telemetry control or universal outbound coverage. The matrix describes documented behavior at capture, not a packet-level test or an assurance that an undocumented path cannot exist.

Outbound-rule models and alerting
JurisdictionOutbound-rule modelAlerting
built-in firewallApple Inc. states a 2026 copyright notice.sourcemacOS Firewall supports blocking all incoming connections, automatically allowing built-in or downloaded signed software, allowing or denying access by app, and preventing responses to ICMP probes and port scans.sourcemacOS displays an alert when a connection attempt targets an app that has not been added and allowed, and denies attempts until the user allows or denies the connection.source
Little Snitch 6Little Snitch's vendor identifies Objective Development Software GmbH, states that Objective Development was founded in 2004 and is based in Vienna, and lists Commercial Court Vienna registration FN 244130 s.sourceLittle Snitch rules match connection conditions and choose one action in each of three categories—filtering, notification, and hiding history from Network Monitor—with the most specific matching rule supplying each action.sourceLittle Snitch shows a connection alert when Alert Mode is active and an attempted connection is not covered by a rule, lets the user allow or deny it, and creates a matching rule for later attempts.source
LuLuFor LuLu, the cited articles name Objective-See Foundation, Inc. as a nonprofit corporation formed under Hawaii law.sourceLuLu describes itself as a firewall that blocks unknown outgoing connections on Macs.sourceLuLu says it blocks unknown outgoing connections on Macs.source
Objective-SeeObjective-See's 2025 IRS Form 990 lists OBJECTIVE-SEE FOUNDATION INC as the organization's name.sourceObjective-See describes LuLu v4.5.1 for macOS 10.15+ as a free, open-source firewall that blocks unknown outgoing connections.sourceObjective-See says BlockBlock starts automatically when the computer restarts, aims to detect installed persistent software, and displays an informative alert.source
privacy.sexyprivacy.sexy's package identifies undergroundwires as its author.sourceprivacy.sexy says its scripts are independently executable and provide visibility into what each tweak does.sourceprivacy.sexy says its desktop and web versions receive updates deployed from source code, while macOS desktop updates may require users to finish installation manually.source

Source: 5 products. Each source link opens the authority for its cell. The page source record lists the capture date and snapshot for every cell.

Field definitions

Outbound-rule model
Rule granularity, default behavior, matching conditions, user choices, and scope stated by the current cell.
Alerting
Prompt, notification, log, interface, trigger, and scope stated by the current cell without inferring a block.

Retention and deletion are lifecycle questions

Disabling or uninstalling a control does not by itself establish deletion of every related file, log, preference, account record, or vendor record.

The retention column preserves the data or artifact category, responsible actor, trigger, duration, exception, product, plan, region, platform, and other scope supplied by the current cell. A duration attached to one category is not applied to every record associated with the path.

The deletion column separately reports the documented initiation path, controller or actor, local cleanup step, completion statement, timeframe, exception, and scope. An uninstall instruction may describe removal of software without establishing erasure of preferences, logs, backups, account records, or records held by a separate actor.

The same boundary applies in reverse. A retention statement does not prove that a user lacks a disable, reset, exception, or uninstall path; those mechanics belong to the reversibility cell. A deletion statement does not establish that every earlier system change has been restored.

The table therefore treats retention, deletion, and reversibility as three related but non-equivalent attributes. Each value remains limited to its cited cell rather than becoming a product-wide lifecycle promise.

Retention and deletion are lifecycle questions
JurisdictionRetentionDeletion
built-in firewallApple Inc. states a 2026 copyright notice.sourceApple says it retains personal data only as long as necessary for the purposes for which it was collected or as required by law, and works to retain it for the shortest possible period permissible under law when retention is required.sourceApple says customers may request deletion of personal data through its Data and Privacy page, subject to exceptions including legal recordkeeping and anti-fraud or security purposes.source
Little Snitch 6Little Snitch's vendor identifies Objective Development Software GmbH, states that Objective Development was founded in 2004 and is based in Vienna, and lists Commercial Court Vienna registration FN 244130 s.sourceLittle Snitch says invoice data and VAT proof are retained for 10 years for EU customers outside Austria or seven years for others, while the license owner's name, email address, license keys, and purchase date are stored for the license-agreement term.sourceLittle Snitch says placing a product in the shopping cart sets a purchase-procedure cookie that enables temporary storage of entered shopping-cart and contact data, with the temporarily stored information deleted after no more than 24 hours.source
LuLuFor LuLu, the cited articles name Objective-See Foundation, Inc. as a nonprofit corporation formed under Hawaii law.sourceLuLu says a rule can last always, for the current process lifetime, or until a future time, when an expiring rule is deleted automatically.sourceLuLu says users can quit or fully uninstall it from the status-bar menu and must authenticate to do either.source
Objective-SeeObjective-See's 2025 IRS Form 990 lists OBJECTIVE-SEE FOUNDATION INC as the organization's name.sourceObjective-See says BlockBlock logs all alert responses to `/Library/Objective-See/BlockBlock/BlockBlock.log`.sourceObjective-See says BlockBlock's status-bar menu launches an uninstaller that completely removes BlockBlock.source
privacy.sexyprivacy.sexy's package identifies undergroundwires as its author.sourceprivacy.sexy says its desktop version keeps activity logs and script-execution history in operating-system-specific directories and provides scripts to securely erase both.sourceprivacy.sexy says its desktop version keeps activity logs and script-execution history in operating-system-specific directories and provides scripts to securely erase both.source

Source: 5 products. Each source link opens the authority for its cell. The page source record lists the capture date and snapshot for every cell.

Field definitions

Retention
Retained category or artifact, responsible actor, trigger, duration, exceptions, and scope stated by the current cell.
Deletion
Deletion or cleanup initiation, actor, completion statement, timeframe, exceptions, and scope stated by the current cell.

Source availability, audits, and request reporting

Public source artifacts, disclosed audit records, and lawful-request reporting answer different evidence questions, so none of the three is an overall trust or security badge.

Source availability reports the component, repository or artifact locator, version or release locator, license, and scope established by the current cell. A public artifact for one component does not establish that every component, service, rule set, or infrastructure layer is public.

The audit column reports only the assessor, scope, standard, period or date, report locator, publication status, and limitation represented in the exact cell. All five audit cells are verified absences scoped to their declared documents. They do not establish that no audit, assessment, review, or private report exists.

Request reporting records the period, jurisdiction, unit, scope, counts, or process statement supplied by the cell. Three request-reporting cells are verified absences limited to the declared documents. An absence is not printed as zero requests, and a process statement is not converted into a count.

These eight verified absences, together with the two later-verification absences and the one signup-identifiers absence in the identity section, account for the evidence set's eleven typed verified absences. Each remains attached to its own cell and declared-document scope rather than becoming a conclusion about the path as a whole.

Source availability, audits, and request reporting
JurisdictionSource availabilityAudit recordRequest reporting
built-in firewallApple Inc. states a 2026 copyright notice.sourceApple says macOS includes a built-in firewall to protect the Mac from network access and denial-of-service attacks.sourceUnknown Verified absenceNot disclosed in the captured primary source.sourceApple says its transparency report provides information about government requests for customer data received globally.source
Little Snitch 6Little Snitch's vendor identifies Objective Development Software GmbH, states that Objective Development was founded in 2004 and is based in Vienna, and lists Commercial Court Vienna registration FN 244130 s.sourceObjective Development says Little Snitch is proprietary software and that it thinks users should be able to test all features before buying and that a certain level of protection should be available free of charge for everyone.sourceUnknown Verified absenceNot disclosed in the captured primary source.sourceUnknown Verified absenceNot disclosed in the captured primary source.source
LuLuFor LuLu, the cited articles name Objective-See Foundation, Inc. as a nonprofit corporation formed under Hawaii law.sourceLuLu describes itself as free and open source and links its source alongside the version 4.5.1 download.sourceUnknown Verified absenceNot disclosed in the captured primary source.sourceUnknown Verified absenceNot disclosed in the captured primary source.source
Objective-SeeObjective-See's 2025 IRS Form 990 lists OBJECTIVE-SEE FOUNDATION INC as the organization's name.sourceObjective-See says all tools are open source and points to its GitHub page.sourceUnknown Verified absenceNot disclosed in the captured primary source.sourceUnknown Verified absenceNot disclosed in the captured primary source.source
privacy.sexyprivacy.sexy's package identifies undergroundwires as its author.sourceprivacy.sexy's package identifies version 0.13.8 and undergroundwires as its author.sourceUnknown Verified absenceNot disclosed in the captured primary source.sourceprivacy.sexy invites contributions and directs contributors to its CONTRIBUTING guide.source

Source: 5 products. Each source link opens the authority for its cell. The page source record lists the capture date and snapshot for every cell.

Field definitions

Source availability
Named component, repository or artifact locator, version, release locator, license, and scope stated by the current cell.
Audit record
Assessor, scope, standard, period or date, report locator, publication status, and limitations, preserving verified absences.

Limits, capture dates, and corrections

This matrix records what cited sources stated at each cell's capture date; it does not establish universal behavior, complete connection coverage, or comparative effectiveness.

Every displayed value is transcluded from a current persisted cell, with its source class, claim type, source URL, capture date, observation version, applicability, and typed unknowns. The page date follows the newest printed cell, but each individual claim keeps its own capture boundary.

The mixed roster remains a material limit. An operating-system feature, suite, hardening tool, and outbound-firewall tool are not treated as interchangeable products. Side-by-side placement means that the same twelve questions were asked; it does not mean every question applies in the same way or that the answers can be combined into one verdict.

Documented rule and alert behavior does not prove observation, identification, or blocking of every outbound connection or telemetry path. A rollback step does not prove complete state restoration. A deletion path does not prove completed erasure of every related artifact or record. A verified absence speaks only to the declared documents read.

Corrections should identify the row, attribute, source, and changed statement through the privacy-tool comparison methodology. The roster and ordering remain neutral: the page carries no score, rank, preferred provider, affiliate parameter, sponsorship, gift, preferred access, or paid placement.

How to read Unknown

Unknown: Verified absence
The captured authority was searched and shows no such rule or filing. No value is printed because the absence is the finding. The reason and the authority are printed beside the badge.
Unknown: Not yet verified
The captured sources did not settle this field yet. No value is printed, not even an earlier one. The reason is printed beside the badge, and an authority is linked only when one was supplied.

Frequently asked questions

What does an OS-hardening comparison measure?

This matrix measures twelve documented attributes for five preregistered paths: identity and operating responsibility, change scope and reversibility, outbound rules and alerts, lifecycle statements, and three evidence categories. It reports cell-bounded claims rather than independently tested effectiveness.

Is an outbound alert the same as a blocked connection?

No. Observing, prompting, allowing, and blocking are different behaviors. The alerting and outbound-rule cells report only the behavior and scope their cited sources establish.

Can hardening changes be reversed?

The reversibility column reports the rollback, disable, uninstall, restore, reset, exception, or backup mechanics documented for each path. A documented step does not establish that every prior state, file, log, preference, or account record is restored or erased.

What does a verified absence mean in this matrix?

A verified absence means the declared documents read did not disclose the specified fact under the recorded method. It does not mean zero, no, unsupported, nonexistent, or a negative product verdict.