The blog post is mentioned in the first linked article. Needless to say I fundamentally disagree with Apple's decision* - If I explicitly install a firewall, I want it to actually function like a firewall and not let some packets through. The overhead explanation seems a bit like a stretch.
* It's actually not clear whether this is a feature or a bug. Apple never responded to the bug report (FB12088655).
Perhaps just VPN + little snitch is your best bet if you're still worried