Live data from Hacker News

NetGuard – rootless Android outbound per-app OSS firewall, like LittleSnitch

netguard.me

51–60 of 142 posts

Re: NetGuard – rootless Android outbound per-app OSS firewall, like LittleSnitch

#51
post #19

Afaik, this requires an active VPN connection. With GrapheneOS, there is a network toggle which disables the INTERNET access to any individual app so it doesn't make sense to use NetGuard

> it doesn't make sense to use NetGuard unless you use any other phone that is not a google pixel running GrapheneOS

Which is literally the meaning of "With GrapheneOS, [...] it doesn't make sense to use NetGuard", isn't it?

Re: NetGuard – rootless Android outbound per-app OSS firewall, like LittleSnitch

#53

How do you use this if you already have an always-on VPN enabled?

There's a somewhat complex way to use it together with another VPN app, with work profiles, see see https://itsignacioportal.github.io/netguard-pdnsf-any-vpn-co...

But in case the VPN app supports running as a simple proxy, without using the VPN service, you can avoid work profiles and just have NetGuard connect to it.

Re: NetGuard – rootless Android outbound per-app OSS firewall, like LittleSnitch

#56

Earlier quoted context omitted.

LineageOS doesn't really cut off the INTERNET access properly. Graphene's approach is more robust. I still wonder why such an important feature is not in the AOSP itself

> still wonder why such an important feature is not in the AOSP itself Really? Remind yourself who works on Android. Google have been removing functionalities that benefit privacy for ever, and then put half backed alternative buried under tons of settings.

I am well aware of that. AOSP still has quite a lot of contributors outside of google

Re: NetGuard – rootless Android outbound per-app OSS firewall, like LittleSnitch

#57

Earlier quoted context omitted.

Running pihole as your home DNS is far more feasible for blocking ads and other intrusive requests. The UX perspective is a valid point

But that ties you down to connecting to a vpn every single time you leave home.

You can have a remote instance of pi hole, normally renting a cheap VPS

Re: NetGuard – rootless Android outbound per-app OSS firewall, like LittleSnitch

#58

Earlier quoted context omitted.

LineageOS doesn't really cut off the INTERNET access properly. Graphene's approach is more robust. I still wonder why such an important feature is not in the AOSP itself

Hmm, I haven’t looked much into it, but I assumed they both expose the same mechanism from AOSP?

https://grapheneos.org/faq#firewall

Re: NetGuard – rootless Android outbound per-app OSS firewall, like LittleSnitch

#59

Afaik, this requires an active VPN connection. With GrapheneOS, there is a network toggle which disables the INTERNET access to any individual app so it doesn't make sense to use NetGuard

NetGuard allows you to block specific hosts. I use it on GrapheneOS for monitoring and selective host blocking.

Re: NetGuard – rootless Android outbound per-app OSS firewall, like LittleSnitch

#60

If you use a rootless firewall doesn't it act like a VPN? And then you aren't able to use VPNs unless you disable it? Useless IMO for heavy VPN users.

You can split the usage by profiles (e.g. work profile with Shelter[1]) or separate users.

1. https://f-droid.org/en/packages/net.typeblog.shelter/

Post reply on HN