4 ms·
Sadly all real firewalls need root. I was using AFWall+ for a long time it has neat controls for every app to allow or deny Wifi, Cell or LAN (if you have). It
by Joe_Cool 2y ago
Sadly all real firewalls need root. I was using AFWall+ for a long time it has neat controls for every app to allow or deny Wifi, Cell or LAN (if you have). It is a iptables/nftables frontend so you can customize the rules to your heart's content: https://github.com/ukanth/afwall https://github.com/ukanth/afwall
Works from Android 2+
Without root only VPN solutions like Adguard are available.
EDIT: if you want neat stats: Glasswire has an Android version. I have only used the beta so I have no idea about its current state. Might be worth checking out though.
- ignoramous 2y agoex-AOSP and rethink dns+firewall dev here > Sadly all real firewalls need root What do you mean by a "real" firewall? It is very much possible to build a userspace firewall in Android using the VPN APIs. On Android, ROMs like GrapheneOS, Lineage, and CalyxOS have firewalls built-in. > Glasswire has an Android version Note though, Glasswire was recently acquired by another company: https://archive.is/KW2R3 https://archive.is/KW2R3
- yndoendo 2y agoI thought parts of the Android OS can by-pass the VPN so the firewall becomes ineffective against blocking Google, OEMs, and others that have root. Wouldn't the VPN API being used as a firewall also prevent one to use a VPN client at the same time?
- khimaros 2y agofor the latter, Rethink can be configured to work with eg. a wireguard VPN because it has a built-in wireguard client.
- Joe_Cool 2y ago> Note though, Glasswire was recently acquired by another company Ah that's why the premium stuff is now free. I was wondering. Let's hope it's not the first sign of enshittification. > What do you mean by a "real" firewall? In my experience the "block all non VPN traffic" options in Android don't work reliably. iptables does however. It's a sad state that you cannot even set a static IPv6 on Android without root.
- ignoramous 2y ago> In my experience the "block all non VPN traffic" options in Android don't work reliably. iptables does however. Both (iptables/nftables and VPN APIs) have to be enforced by the Linux Kernel, which is subject to the same "Androidisms", if that makes sense. root, in fact, opens up a gaping hole in that, it totally compromises Android's security model. IMO, it isn't worth to root Android just to run iptables (just because it seems like iptables is what makes a firewall).
- Joe_Cool 2y agoIMHO Android's security model is incredibly flawed anyways. I don't even need root to access stuff I shouldn't have access to on my Mediatek based phone because the firmware has tons of gaping security holes anyways. I think device you don't have root on isn't really yours and should be treated as a lease. But you are right, when Wifi/Data is on at boot even the -tables might not get updated fast enough so stuff might get through.