Live data from Hacker News

NetGuard – rootless Android outbound per-app OSS firewall, like LittleSnitch

netguard.me

111–120 of 142 posts

Re: NetGuard – rootless Android outbound per-app OSS firewall, like LittleSnitch

#111

Does this show anything at all without purchases? I installed it and turned on notify on access and I have gotten no notifications so far.

Looks like most of the information features require a purchase... And the price is only visible at checkout.

Re: NetGuard – rootless Android outbound per-app OSS firewall, like LittleSnitch

#112
post #25

Installing NetGuard was revelation regarding the amount of tracking in most Android apps. You can configure it to block access by default and notify you every time an app attempts a new connection. And it rings all the time. Some software call home at 4am every day, other every hour, some send data to a dozen "analytics" services - services that I never opted-in for, which shows how few apps respect the RGPD. At leas…

[flagged]

Re: NetGuard – rootless Android outbound per-app OSS firewall, like LittleSnitch

#113
post #25

Installing NetGuard was revelation regarding the amount of tracking in most Android apps. You can configure it to block access by default and notify you every time an app attempts a new connection. And it rings all the time. Some software call home at 4am every day, other every hour, some send data to a dozen "analytics" services - services that I never opted-in for, which shows how few apps respect the RGPD. At leas…

[flagged]

I'm curious, how would looking at the Microsoft MFA app convince me that android apps aren't spying on me?

Re: NetGuard – rootless Android outbound per-app OSS firewall, like LittleSnitch

#114

Earlier quoted context omitted.

There's no need to dream about it, it already exists: https://f-droid.org/packages/com.celzero.bravedns/ I used to use it when I wasn't on grapheneOS and needed to block internet access.

It's annoying to see so much RethinkDNS propaganda on every Netguard or Invizible Pro thread on the internet. That gives me a bad feeling, and it's the reason I started to consider RethinkDNS scummy.

I didn't intend for this to be propaganda, I don't even use it anymore since I'm on grapheneOS now. But I have tried all three. I need to use a VPN in split mode for certain apps, and since using Tor with apps wasn't part of my threat model, I ended up using RethinkDNS (the app only). I don't necessarily like their upstream DNS servers, but considering that I can use my own server (and do), I don't consider that to be an issue.

Re: NetGuard – rootless Android outbound per-app OSS firewall, like LittleSnitch

#115
I occasionally set up notifications when apps make requests using NetGuard and let it run for a day. The result is always depressing, lots of apps phoning home that I haven't opened in days...

I let it run today, and the worst offenders I have installed are Spotify (various requests to Facebook endpoints, I have no Facebook integration turned on) and Speedtest (constant requests to their logging endpoint and ad partners). This is all happening without me actually using those apps.

Re: NetGuard – rootless Android outbound per-app OSS firewall, like LittleSnitch

#116

Earlier quoted context omitted.

You mean, like unrestricted access to the kernel with full firewalling capabilities? ;) Yes, GNU/Linux distributions provide exactly that.

No, you have to install additional software for that.

The linux kernel has a built-in firewall, and provides iptables to configure it. Firewalld is also installed by default at least on Fedora, and UFW for debian-based.

Unless this is just a battle of semantics on the fact iptables/firewalld/ufw are user space apps.

Re: NetGuard – rootless Android outbound per-app OSS firewall, like LittleSnitch

#117
post #101

Earlier quoted context omitted.

I did, battery drains 5-10% faster.

If it's so, it's not a lot for privacy and security --- ReThink DNS uses the VPN service as well, by the way. And it is possible to use two VPN apps, see https://news.ycombinator.com/item?id=41933464 (yes, the battery usage adds up). Rethink DNS seems fine, anyhow.

(I work on rdns)

> ReThink DNS uses the VPN service as well, by the way.

Rethink (since a year ago) has had the ability forward connections per-app to multiple WireGuard upstreams at the same time.

https://old.reddit.com/r/rethinkdns/comments/15r1eq9/v055_mu... / https://archive.md/RqUPe (to us, it turned out to be a deceptively difficult thing to integrate with the rest of the firewall).

Re: NetGuard – rootless Android outbound per-app OSS firewall, like LittleSnitch

#118

Earlier quoted context omitted.

No, you have to install additional software for that.

The linux kernel has a built-in firewall, and provides iptables to configure it. Firewalld is also installed by default at least on Fedora, and UFW for debian-based. Unless this is just a battle of semantics on the fact iptables/firewalld/ufw are user space apps.

There is no clean interface to configure app-based network rules.

Re: NetGuard – rootless Android outbound per-app OSS firewall, like LittleSnitch

#119
post #101

Earlier quoted context omitted.

I did, battery drains 5-10% faster.

If it's so, it's not a lot for privacy and security --- ReThink DNS uses the VPN service as well, by the way. And it is possible to use two VPN apps, see https://news.ycombinator.com/item?id=41933464 (yes, the battery usage adds up). Rethink DNS seems fine, anyhow.

[deleted]

Re: NetGuard – rootless Android outbound per-app OSS firewall, like LittleSnitch

#120
post #101

Earlier quoted context omitted.

If it's so, it's not a lot for privacy and security --- ReThink DNS uses the VPN service as well, by the way. And it is possible to use two VPN apps, see https://news.ycombinator.com/item?id=41933464 (yes, the battery usage adds up). Rethink DNS seems fine, anyhow.

( I work on rdns ) > ReThink DNS uses the VPN service as well, by the way. Rethink (since a year ago) has had the ability forward connections per-app to multiple WireGuard upstreams at the same time. https://old.reddit.com/r/rethinkdns/comments/15r1eq9/v055_mu... / https://archive.md/RqUPe (to us, it turned out to be a deceptively difficult thing to integrate with the rest of the firewall).

Not really on topic, but is there any plan on integrating tailscale with it? There's a userspace mode for tailscale that exposes a socks proxy, but you currently have to spawn that with Termux or another terminal, then forward your traffic on Rethink.
Post reply on HN