Live data from Hacker News

Portmaster 1.0 – Open-Source Network Monitor and Privacy Firewall

safing.io

71–80 of 117 posts

Re: Portmaster 1.0 – Open-Source Network Monitor and Privacy Firewall

#71
post #65

> Please note that pretty much all the DNS leak detection tests by the VPN providers will be a false positive, as the only thing they check is if you are using their DNS servers. Rest assured that your DNS queries are well protected by the Portmaster and there is no need to be concerned. " [1] That's a confusing statement... does this mean they change your DNS server/provider by default, if you are using a VPN? [1] h…

Pretty much all VPNs use their own DNS servers. Their "DNS Leak Tests" just check if queries come from that DNS server. Portmaster overrides any custom DNS server and enforces the ones the user set - or are set by default. This "breaks" the VPN leak test. You'd need to use a leak test from the DNS provider for it to work. Thanks for the feedback. I will look into improving the text.

> "overrides any custom DNS server and enforces the ones the user set - or are set by default"

If Portmaster "enforces DNS servers with the ones that are set", after installing Portmaster and without the user changing anything, i'd say that's a decrease of privacy;

Your VPN provider can see your traffic in any case (even when you're not using their DNS server.) So, if Portmaster would change this to whatever your default is (Cloudflare, Google, etc.), people are then suddenly sharing their DNS requests with yet another 3th party.

Re: Portmaster 1.0 – Open-Source Network Monitor and Privacy Firewall

#72
post #65

Earlier quoted context omitted.

Pretty much all VPNs use their own DNS servers. Their "DNS Leak Tests" just check if queries come from that DNS server. Portmaster overrides any custom DNS server and enforces the ones the user set - or are set by default. This "breaks" the VPN leak test. You'd need to use a leak test from the DNS provider for it to work. Thanks for the feedback. I will look into improving the text.

> " overrides any custom DNS server and enforces the ones the user set - or are set by default " If Portmaster " enforces DNS servers with the ones that are set ", after installing Portmaster and without the user changing anything, i'd say that's a decrease of privacy; Your VPN provider can see your traffic in any case (even when you're not using their DNS server.) So, if Portmaster would change this to whatever your…

There is a welcome screen that informs you of Portmaster handling and securing DNS queries with the option to change the provider.

But especially with a VPN the privacy is increased as it effectively becomes DNS-over-TLS/HTTPS-over-VPN. The VPN still sees your destination IP addresses, so the privacy improvement is not increased by a lot, but still.

Re: Portmaster 1.0 – Open-Source Network Monitor and Privacy Firewall

#73
post #62
post #2

CTO and Co-Founder of Safing here. We're super excited to introduce version 1.0 of our network monitor and privacy firewall - Portmaster! On 1.1. this year, Portmaster was shared on HN and we hit front page [1]. With the help of our testers - many of you! - we were able to mature and develop Portmaster to hit this milestone. We're on a mission to bring privacy back to the masses. Privacy has to be easy & accessible f…

Congrats! Just one question: In the past, postmaster had problems with WSL2. I documented the issue and the solution: https://www.reddit.com/r/safing/comments/ryioj7/portmaster_b... Is it fixed now?

We still don't have first-class support for VMs, but it will come.

Re: Portmaster 1.0 – Open-Source Network Monitor and Privacy Firewall

#74
post #70
post #68

Earlier quoted context omitted.

It's a software for clients / desktops.

Can't be run network wide on kubernetes or router? Then it's not a competitor to pihole?

Well, that depends on the use case. You might call it an indirect competitor.

Re: Portmaster 1.0 – Open-Source Network Monitor and Privacy Firewall

#76
post #70
post #68

Earlier quoted context omitted.

It's a software for clients / desktops.

Can't be run network wide on kubernetes or router? Then it's not a competitor to pihole?

Right. Other use case. PiHole is setup for network normally. This solution is personal desktop firewall. So it has more access to information, but is also easier breakable (like break thru) for "bad" software on your PC.

Re: Portmaster 1.0 – Open-Source Network Monitor and Privacy Firewall

#78
post #72

Earlier quoted context omitted.

> " overrides any custom DNS server and enforces the ones the user set - or are set by default " If Portmaster " enforces DNS servers with the ones that are set ", after installing Portmaster and without the user changing anything, i'd say that's a decrease of privacy; Your VPN provider can see your traffic in any case (even when you're not using their DNS server.) So, if Portmaster would change this to whatever your…

There is a welcome screen that informs you of Portmaster handling and securing DNS queries with the option to change the provider. But especially with a VPN the privacy is increased as it effectively becomes DNS-over-TLS/HTTPS-over-VPN. The VPN still sees your destination IP addresses, so the privacy improvement is not increased by a lot, but still.

> with the option to change the provider.

Ah right, that sounds good. So the user is aware of it.

> But especially with a VPN the privacy is increased as it effectively becomes DNS-over-TLS/HTTPS-over-VPN.

I disagree; VPN providers use an internal IP as DNS server and your connection to this DNS server goes through a secured VPN tunnel anyway.

So, by sharing your DNS requests with an external 3th party you gain nothing, and it's even a decrease of your privacy since now Google/Cloudflare/etc collects all these requests.

Re: Portmaster 1.0 – Open-Source Network Monitor and Privacy Firewall

#79
post #73
post #62

Earlier quoted context omitted.

Congrats! Just one question: In the past, postmaster had problems with WSL2. I documented the issue and the solution: https://www.reddit.com/r/safing/comments/ryioj7/portmaster_b... Is it fixed now?

We still don't have first-class support for VMs, but it will come.

Did you read the link?

Just add a PowerShell script at install time to exempt the virtual network interfaces from Windows Firewall if WSL is detected and the user agrees! It's super simple and easy.

Re: Portmaster 1.0 – Open-Source Network Monitor and Privacy Firewall

#80

I remember using Postmasters (PM2E) for router serial connectivity, good times.

Yeah, the ISP I founded in 1995 (elite.net) was a PM2ER for both dialup and routing with a Pentium 90 as the shell & web server. We quickly hit the 30 line limit and went up to the PRI-based Portmaster models. Fun and exciting times, just bringing a rural community online for the first time ever.
Post reply on HN