3 ms·
I run a VM with pf firewall (example book) https://www.nostarch.com/pf3 https://www.nostarch.com/pf3 which wholesale blocks known ad server IPs from adblock/ubl
by pakled_engineer 11y ago
I run a VM with pf firewall (example book) https://www.nostarch.com/pf3 https://www.nostarch.com/pf3 which wholesale blocks known ad server IPs from adblock/ublock origin filter lists, other sources http://pgl.yoyo.org/adservers/ http://pgl.yoyo.org/adservers/ The firewall also prevents data leaks from misconfigured software phoning home or crash reports being sent, IPs being leaked over WebRTC, ect. You can also run your own DNS and email/backup server with the VM too.
Then scrubbed traffic is passed to Snort (or use Suricata), with a ruleset to look for attack signatures. You can update rulesets from mailing lists https://lists.emergingthreats.net/mailman/listinfo/emerging-sigs https://lists.emergingthreats.net/mailman/listinfo/emerging-... and make your own by following whoever on Twitter is involved in Android/iOS security like @pof (Pau Oliva). There are specific mobile "emerging threat" rulesets too https://lists.emergingthreats.net/pipermail/emerging-sigs/2011-March/012298.html https://lists.emergingthreats.net/pipermail/emerging-sigs/20...
Now you can install Ublock Origin on your phone browser and most of the work it has to do is already done saving memory and bandwidth. Here you can experiment with custom rulesets for how pages get displayed, whitelist certain objects you may wish to look at and not blindly block. To further go down the rabbit hole you can build your own mobile version of FF on your VM, ripping out all these harmful things: https://sites.google.com/a/chromium.org/dev/Home/chromium-security/client-identification-mechanisms https://sites.google.com/a/chromium.org/dev/Home/chromium-se...
You can also set up a script on the VM to update Android on AWS. If say there's a new web views critical bug, and a patch is released your VM script (Ansible/Chef) can start an AWS instance, get the latest patch(s) and completely build a new system.img automatically. This can all be done with a custom app you write with the backend hosted on your VM, or with Termux or KBOX, and automate/abstract away all the ssh key logins and tasks with a script. Open your app see all available new Android patches, then click "Build" to automate your new system.img with your own signatures.
Of course you don't have to use any of these tools, you could learn about their innards then roll your own software. If you are a javascript developer have the pf firewall dump it into your custom interpreter on the VM, that can look for unusual behaviour and just pass scrubbed js to your browser on the phone.