Live data from Hacker News

NetGuard – rootless Android outbound per-app OSS firewall, like LittleSnitch

netguard.me

131–140 of 142 posts

Re: NetGuard – rootless Android outbound per-app OSS firewall, like LittleSnitch

#131
post #94
post #80

Earlier quoted context omitted.

You could put a firewall at the other end of the wireguard connection.

This doesn't tell you which app is connecting to which IP.

You'd need a local client for the VPN server firewall, to configure it, view logs, etc. Just a web client would work.

Re: NetGuard – rootless Android outbound per-app OSS firewall, like LittleSnitch

#132
post #63

Earlier quoted context omitted.

Would be curious to hear if anyone actually did (or attempted) this and have results to share. I know I have experienced VPN leaks on Android (not the one they publically fixed as it was after). A second layer wouldn't fix that properly but it should make it less likely.

Here you go, a fairly detailed blog post about it: https://itsignacioportal.github.io/netguard-pdnsf-any-vpn-co... Got this from a thread about Tracker Control, a NetGuard fork, and VPN chaining https://github.com/TrackerControl/tracker-control-android/is...

Amazing, thank you!

Re: NetGuard – rootless Android outbound per-app OSS firewall, like LittleSnitch

#133

Earlier quoted context omitted.

NetGuard does ad-blocking with a DNS blacklist, but it's a Pro feature (which I use and works great).

On NetGuard's F-Droid page it lists "Optionally block ads using a hosts file" under its "features" section and not under its "PRO Features" section Seems like I can get ad blocking for free. https://f-droid.org/en/packages/eu.faircode.netguard/ https://github.com/M66B/NetGuard/blob/master/ADBLOCKING.md

Oh you're probably right, it's been a while since I was on the free version :)

Re: NetGuard – rootless Android outbound per-app OSS firewall, like LittleSnitch

#134
post #26

Earlier quoted context omitted.

I am dreaming of an open-source app that adds Wireguard capabilities to NetGuard or vice-versa. Having to switch from one to the other is very annoying.

There's no need to dream about it, it already exists: https://f-droid.org/packages/com.celzero.bravedns/ I used to use it when I wasn't on grapheneOS and needed to block internet access.

That only uses wg for DNS queries. Everything else remains untunneled.

Re: NetGuard – rootless Android outbound per-app OSS firewall, like LittleSnitch

#135

Earlier quoted context omitted.

There's no need to dream about it, it already exists: https://f-droid.org/packages/com.celzero.bravedns/ I used to use it when I wasn't on grapheneOS and needed to block internet access.

That only uses wg for DNS queries. Everything else remains untunneled.

From what I see running the test on my phone, there's an option to tunnel DNS through Rethink here, which you can change to the VPN's DNS. Everything else is tunneled by default through wireguard. Maybe there's a configuration issue on your end?

Re: NetGuard – rootless Android outbound per-app OSS firewall, like LittleSnitch

#136

Earlier quoted context omitted.

That only uses wg for DNS queries. Everything else remains untunneled.

From what I see running the test on my phone, there's an option to tunnel DNS through Rethink here, which you can change to the VPN's DNS. Everything else is tunneled by default through wireguard. Maybe there's a configuration issue on your end?

The only place I see where wireguard can be set up is as a proxy for DNS. Perhaps that would still allow changing the default gateway?

Re: NetGuard – rootless Android outbound per-app OSS firewall, like LittleSnitch

#137
post #25

Installing NetGuard was revelation regarding the amount of tracking in most Android apps. You can configure it to block access by default and notify you every time an app attempts a new connection. And it rings all the time. Some software call home at 4am every day, other every hour, some send data to a dozen "analytics" services - services that I never opted-in for, which shows how few apps respect the RGPD. At leas…

> Some software call home at 4am every day Which app?

Not sure anymore since I removed them, it may have been BlaBlaCar and/or Tricount.

Re: NetGuard – rootless Android outbound per-app OSS firewall, like LittleSnitch

#138
post #130
post #25

Installing NetGuard was revelation regarding the amount of tracking in most Android apps. You can configure it to block access by default and notify you every time an app attempts a new connection. And it rings all the time. Some software call home at 4am every day, other every hour, some send data to a dozen "analytics" services - services that I never opted-in for, which shows how few apps respect the RGPD. At leas…

> NetGuard allows you to block connections to Google servers except for Google Apps, which network firewalls and DNS solutions can't. How do you know those connections are blocked and not merely bypassing Netguard?

I am using GrapheneOS. GrapheneOS has a compatibility layer providing the option to install and use the official releases of Google Play in the standard app sandbox.

See https://grapheneos.org/features#sandboxed-google-play

NetGuard also shows network requests from GrapheneOS itself, all proxied by the GrapheneOS project, as described here: https://grapheneos.org/faq#default-connections

Re: NetGuard – rootless Android outbound per-app OSS firewall, like LittleSnitch

#139
post #138
post #130

Earlier quoted context omitted.

> NetGuard allows you to block connections to Google servers except for Google Apps, which network firewalls and DNS solutions can't. How do you know those connections are blocked and not merely bypassing Netguard?

I am using GrapheneOS. GrapheneOS has a compatibility layer providing the option to install and use the official releases of Google Play in the standard app sandbox. See https://grapheneos.org/features#sandboxed-google-play NetGuard also shows network requests from GrapheneOS itself, all proxied by the GrapheneOS project, as described here: https://grapheneos.org/faq#default-connections

I could see how they are blocked on your system, using GrapheneOS, but that doesn't tell us if Netguard blocks them on Android systems. One reason for GrapheneOS is to close that kind of hole.

Re: NetGuard – rootless Android outbound per-app OSS firewall, like LittleSnitch

#140

Similar but open source: https://github.com/celzero/rethink-app

I tried Rethink for the day. I had previously set Android's private DNS to dns.adguard-dns.com, which didn't block anything. Rethink's battery usage is 15 - 20% on my pixel in logging mode. It definitely works, but I can't seem to associate blocked requests with apps, which renders it far less useful. Overall I think it's a very busy UI. You definitely want to exclude Firefox with uBO as elsewise Firefox behaves as t…

> Rethink's battery usage is 15 - 20% on my pixel in logging mode.

This is unusually high. It doesn't cross 3% on my Android, but I'm using a version (v055o( that's yet to launch (but will in a week or so).

If you only need DNS based blocking, tap on the down-arrow next to the STOP/START button and choose DNS-only mode. That should bring down battery use to 1% or so.

> but I can't seem to associate blocked requests with apps, which renders it far less useful.

Rethink most definitely can. Make sure to turn OFF Private DNS (instead of setting it to Opportunistic or Automatic).

Ex A: https://mastodon.social/@tuxicoman@social.jesuislibre.net/11...

Ex B: https://mastodon.social/@33dBm@lazysocial.de/112051004405969...

> ...download the block lists locally. Does that mean it no longer uses DNS blocking

If you download the blocklists locally, then you can set those on your device, and use any DNS upstream (DoH/DoT/DNS53/DNSCrypt/ODoH) and the rules should be applied, regardless.

Post reply on HN