Live data from Hacker News

NetGuard – rootless Android outbound per-app OSS firewall, like LittleSnitch

netguard.me

81–90 of 142 posts

Re: NetGuard – rootless Android outbound per-app OSS firewall, like LittleSnitch

#81
post #25

Installing NetGuard was revelation regarding the amount of tracking in most Android apps. You can configure it to block access by default and notify you every time an app attempts a new connection. And it rings all the time. Some software call home at 4am every day, other every hour, some send data to a dozen "analytics" services - services that I never opted-in for, which shows how few apps respect the RGPD. At leas…

> Some software call home at 4am every day

Which app?

Re: NetGuard – rootless Android outbound per-app OSS firewall, like LittleSnitch

#82
post #76
post #50

Earlier quoted context omitted.

Except that... that doesn't block anything??

Yeah, but you can just uninstall offenders

With a firewall you can keep using them, instead (and maybe only let through some of the traffic)

Re: NetGuard – rootless Android outbound per-app OSS firewall, like LittleSnitch

#83
post #77

It drains battery because of VPN service solution, which is only non-rooted solution. Also if you use VPN (like Wireguard), you cannot use both. Every app has own settings for allowing WiFi, data, VPN, background data connections natively in Android. I use custom ROM that has turned off internet connection for all apps by default and you need manually allow them to connect. Which solve mine problem with constant unwa…

> It drains battery because of VPN service solution

It doesn't really, just try it (and take actual battery duration measurements, Android misreports VPN apps battery usages)

Re: NetGuard – rootless Android outbound per-app OSS firewall, like LittleSnitch

#85

Pcapdroid is a very good alternative that allows to see which connections are made from what app to what server and at what time. You just leave it in background, check one day later and see what sneaky app you never thought of have been sending tons of data in the background. For me it helped me remove and search alternative for 4 apps, including a pill reminder (mytherapy). I would never have thought the trade-off…

Netguard does the same. You can see a per-app list of connections. Furthermore, you can many hosts either globally, or on an app level.

Re: NetGuard – rootless Android outbound per-app OSS firewall, like LittleSnitch

#86

If you use a rootless firewall doesn't it act like a VPN? And then you aren't able to use VPNs unless you disable it? Useless IMO for heavy VPN users.

You can split the usage by profiles (e.g. work profile with Shelter[1]) or separate users. 1. https://f-droid.org/en/packages/net.typeblog.shelter/

You can also have NetGuard actually go through the VPN (https://news.ycombinator.com/item?id=41933464)

Re: NetGuard – rootless Android outbound per-app OSS firewall, like LittleSnitch

#87
post #26

Earlier quoted context omitted.

I am dreaming of an open-source app that adds Wireguard capabilities to NetGuard or vice-versa. Having to switch from one to the other is very annoying.

There's no need to dream about it, it already exists: https://f-droid.org/packages/com.celzero.bravedns/ I used to use it when I wasn't on grapheneOS and needed to block internet access.

It's annoying to see so much RethinkDNS propaganda on every Netguard or Invizible Pro thread on the internet.

That gives me a bad feeling, and it's the reason I started to consider RethinkDNS scummy.

Re: NetGuard – rootless Android outbound per-app OSS firewall, like LittleSnitch

#88
post #33

Earlier quoted context omitted.

Blockada is most likely a DNS level blocker, netguard supports that. Alternatively you can configure it to point the DNS servers at NextDNS if you just want a nice UI to configure block lists (though NextDNS might track you).

NextDNS as a manual DNS server on Android is the adblocking solution I've been using for years. Is there any reason to believe they would track you, any more than any other DNS provider?

Unlike most other dns providers, they often have an account or even payment to identify you, not just your outbound IP....

Re: NetGuard – rootless Android outbound per-app OSS firewall, like LittleSnitch

#89

Earlier quoted context omitted.

> similar but open source Netguard (per HN title) is open-source GPLv3: https://github.com/M66B/NetGuard Rethink uses cloud services by default? The [DNS] resolver is deployed to Fly.io at max.rethinkdns.com and Deno Deploy at rdns.deno.dev too, apart from the default deployment on Cloudflare Workers.

rdns dev here > Rethink uses cloud services by default? There isn't anything sinister going on here with the use of "cloud services" [0][1]. Rethink, which is geared more towards anti-censorship, has its default resolver "ip-fronted" on Cloudflare (whose IPs are seldom blocked) and it works great in countries where the app is popular. Users can opt to switch to any DoH, DoT, ODoH, DNSCrypt v3 resolver of their choice…

> rdns dev here

I have a question for you about RethinkDNS:

Can you point me the link to one thread or question about Netguard on some major internet forums like HN, Reddit or similar, where you or other RethinkDNS devs did not jump in and hijacked the thread? Only one example, please?

Your spammy marketing tactics of spamming makes your product looks like a scum, and I don't even have a desire to test.

Also, why do you keep comparing one on device firewall like Netguard with a cloud first solution like RethinkDNS?

Post reply on HN