5 ms·
Does something like this exist for my phone, android specifically? Any good recommendations?
by orkj 2y ago
Does something like this exist for my phone, android specifically? Any good recommendations?
- Joe_Cool 2y agoSadly all real firewalls need root. I was using AFWall+ for a long time it has neat controls for every app to allow or deny Wifi, Cell or LAN (if you have). It is a iptables/nftables frontend so you can customize the rules to your heart's content: https://github.com/ukanth/afwall https://github.com/ukanth/afwall Works from Android 2+ Without root only VPN solutions like Adguard are available. EDIT: if you want neat stats: Glasswire has an Android version. I have only used the beta so I have no idea about its current state. Might be worth checking out though.
- ignoramous 2y agoex-AOSP and rethink dns+firewall dev here > Sadly all real firewalls need root What do you mean by a "real" firewall? It is very much possible to build a userspace firewall in Android using the VPN APIs. On Android, ROMs like GrapheneOS, Lineage, and CalyxOS have firewalls built-in. > Glasswire has an Android version Note though, Glasswire was recently acquired by another company: https://archive.is/KW2R3 https://archive.is/KW2R3
- yndoendo 2y agoI thought parts of the Android OS can by-pass the VPN so the firewall becomes ineffective against blocking Google, OEMs, and others that have root. Wouldn't the VPN API being used as a firewall also prevent one to use a VPN client at the same time?
- khimaros 2y agofor the latter, Rethink can be configured to work with eg. a wireguard VPN because it has a built-in wireguard client.
- Joe_Cool 2y ago> Note though, Glasswire was recently acquired by another company Ah that's why the premium stuff is now free. I was wondering. Let's hope it's not the first sign of enshittification. > What do you mean by a "real" firewall? In my experience the "block all non VPN traffic" options in Android don't work reliably. iptables does however. It's a sad state that you cannot even set a static IPv6 on Android without root.
- ignoramous 2y ago> In my experience the "block all non VPN traffic" options in Android don't work reliably. iptables does however. Both (iptables/nftables and VPN APIs) have to be enforced by the Linux Kernel, which is subject to the same "Androidisms", if that makes sense. root, in fact, opens up a gaping hole in that, it totally compromises Android's security model. IMO, it isn't worth to root Android just to run iptables (just because it seems like iptables is what makes a firewall).
- Joe_Cool 2y agoIMHO Android's security model is incredibly flawed anyways. I don't even need root to access stuff I shouldn't have access to on my Mediatek based phone because the firmware has tons of gaping security holes anyways. I think device you don't have root on isn't really yours and should be treated as a lease. But you are right, when Wifi/Data is on at boot even the -tables might not get updated fast enough so stuff might get through.
- sureglymop 2y agoThe app "Rethink: DNS + Firewall + VPN" has similar features.
- FireInsight 2y agoTrackerControl is great too. Both are FOSS and can be used in the backgroud for using a custom DNS server and blocking certain categories of domains.
- arminiusreturns 2y agoI really like Rethink DNS. I have learned many things from watching it (such as I think Signal is compromised by some five-eyes "crossing the border" fuckery.)
- codethief 2y ago> such as I think Signal is compromised by some five-eyes "crossing the border" fuckery Would you mind elaborating?
- sureglymop 2y agoI agree with the first sentence. I cannot even begin to comprehend what semantics you were trying to convey with the second sentence however. I am also lacking all context to be able to understand (compromised in what sense, by whom and to what degree? which border? what is "fuckery" defined as?). I appreciate you trying to add to the discussion but in this case you leave me with way more questions than I started out with which I personally perceive as an unwanted mental overhead.
- arminiusreturns 2y agoSorry I don't check HN very often these days. What I mean is by watching the IPs, I see a lot of cross-border ingress/egress when it shouldn't be necessary. It's not proof, but an indicator of probability to me, that echelon style mechanisms are being used. If you are unaware of echelon and related programs, essentially, since it's illegal for the US (officially at least) to spy on it's own citizens without a warrant, instead they let an "ally" country like the UK spy on Americans and then "share the data", essentially another abuse of third party doctrine. I hope that helps clarify.
- SparkyMcUnicorn 2y agoMy non-root solution is to use NextDNS or ControlD with "private DNS" (DNS over TLS). Doesn't stop direct IP connections, but it's good enough. I also have the CLI installed on OpnSense so DoH is enforced for all devices on my LAN as well.
- supriyo-biswas 2y agoThere's netguard[1], although most of the convenience features are behind a small payment. [1] https://netguard.me https://netguard.me
- butz 2y ago"Small payment" is an understatement :) "You can get all current and future NetGuard pro features (including updates) without Google Play services for the GitHub or F-Droid version by a one time donation of € 0.10 or more. If you donate 7 euros or more, you can activate the pro features on all Android devices you personally own, else you can activate the pro features one time only."
- bardan 2y agoCan confirm that after donating > 7€ I am still able to unlock pro features on new devices 8 years later
- bornfreddy 2y agoAnd it is also opensource, so you can install it by yourself. But it is worth it (for me) to pay something to support the developer.
- ggeorgovassilis 2y agoNetguard is fantastic, although it takes a while to get a safe setup working. I'm blocking traffic by default and get to see all the blocked connection attempts - the extent to which apps transmit data to various parties is depressing. Netguard should be a standard OS feature.
- cam_l 2y agoI have heard good things about this one. But i think this one of those no root firewalls that uses the vpn, so I figure this means I can't use a VPN at the same time. An alternative android root only option is afwall+ which allows blocking on lte, WiFi, lan, and VPN separately, and script access to iptables. Not sure how actively developed it is, but it seems to work ok. *edit: Seems to still be active, open source, and available on fdroid too. https://github.com/ukanth/afwall https://github.com/ukanth/afwall
- mikae1 2y agoGrapheneOS can at least block internet traffic for specific apps. But can't do it for port ranges or specific domains.
- JoosToopit 2y agoAFWall+ Switched to it from NetGuard mentioned above.