My phone is spying on me, so I decided to spy on it
abc.net.au
abc.net.au
It doesn't display the content type enough, afaik
You can use it to specify which apps are allowed to use WiFi/data, and whether they're allowed to use all the time or only if screen is active. It also allows you to set a hosts file URL and update it with a single click. It has improved my battery life, I rarely see ads (both when using the browser and when using apps), and it force me to use old.reddit.com since reddit.com is blocked by my host file.
NetGuard is a firewall which allows to allow/block traffic.
Charles proxy only allows you to see which connections are being made. They cannot be blocked, there is no firewall functionality. There is not a single app on the App Store that can behave like a firewall on an iOS device, and Apple would definitely not allow this.
So i personally think he has a point; Apple dictating what you may or may not do with your device, without giving you the possibility to opt-out, is not good. Apples "walled garden" has positive side effects of course, like for example hardly any malware on iOS devices versus a lot of malware/viruses on Android devices.
But still, there should be the ability to opt-out of this when accepting the risks. Without this ability it's much like a dictatorship...
It's an excellent app, source code is on github, eventually ended up paying for it. There's far too many apps and system binaries dialing out, it's funny to watch in realtime. What's more amazing is how nothing breaks even when you lock down everything but the few things that need it. Blocking is fine grained and you'll have to scroll through a massive list if you choose to view system apps, but quite happy overall.
Main benefit of the paid option is pcap files. Free version does everything most will want. It's on fdroid.
Useless once you take your phone off WiFi of course, but still baffling the amount of metric abuse going on, and entirely without warning (am within the EU so concerned by it!)
Would love if someone could enlighten me :)
https://blog.tendigi.com/starbucks-should-really-make-their-...
https://jeffhuang.com/extracting_my_data_from_the_hello_sens...
https://blog.dewhurstsecurity.com/2015/11/10/mobile-security...
I just had these bookmarked from when I was wondering the same thing
[1]: https://itunes.apple.com/us/app/dnscloak-dnscrypt-doh-client...
[2]: https://itunes.apple.com/us/app/dnscloak-dnscrypt-doh-client...
Do you mean your own dns server which will be accessible to (anyone on) the public internet?
DNS-over-HTTPS spec also mentioned that you can use a standard HTTP authentication if you want to run a DOH server but want to keep it private (although I've never tried this)
Use with care, as you may break things. I've been using it as-is with no disruptions/problems.
Native ad blocking only works when an app uses an obvious third party plugin for them. The native stuff all stays
(If we still had real OS vendors, it'd be handy if this were builtin to the OS, duh...)
RedHat, Canonical, and Microsoft are not "real" OS vendors?
On the topic of Ubuntu Phone, the reimplementation of Signal for it tried really hard to look exactly the same, except core features like calling and media were broken or had issues. https://github.com/janimo/textsecure-qml
What I mean was, the old OS vendor ethos just doesn't exist any more - its no longer about giving the user the tools required to get the best value out of their computer, but rather give the computer the tools required to get the best value out of the user... RedHat/Canonical are real OS vendors. Microsoft is an also-ran ad-agency wannabe. Google: same. Apple: I give them a pass, but only because they seem to be taking privacy seriously - if only they'd give the user more control over what's going on with their devices, and stop doing things designed, clearly, to just sell more hardware ..
It's not that we lack OS vendors. There's no standard mobile platform like the PC has been for general purpose computing. No hardware vendors are shipping handsets conforming to an open standard supplying open NDA-free specs and/or drivers for OS vendors to target.
We have a number of OS vendors who would almost certainly support such hardware if it was being produced, were compelling, and affordable.
People introducing new functionality need to be incentivized to focus on sand-boxing it in some way before we accept it as a web-standard tech. Barring that, limiting functionality is preferable. But business is business, so adequate measures are generally not taken, either out of cost-saving, or deliberately.
Also, these types of irresponsible practices now constitute an indispensable core of how large modern web-apps work. They exist in a moral gray area, where it can be argued that problematic practices are outweighed by their net benefit to user experience, and misuses of the technology can be blamed on malicious outside actors who have found a loophole. If you build a giant information weapon, you are also culpable for any of its misuses, no matter how unintended they might be.
I currently don't see a way of changing things without some kind of regulation, as problematic government interference can be. The incentives here are possibly too strong for the market to sort it out, at the current state of public awareness. Current efforts in the US seem to be focusing on pressuring companies to self-regulate, but they have still have little real incentive to do so.
Another complicating factor may be the rate in which innovation arises in the tech sector - most burgeoning industries spend some time in a regulatory wild-west, but as the issues become known, laws gradually catch up and a status-quo is reached. Now, its possible that by the time any technology has matured enough to have a widespread regulatory harness applied to it, another technology has already superseded it, and the regulatory void is renewed.
As RawTruthHurts stated: "Call me crazy, but I expect an icon to behave as an icon.."
I too am one of those people that draw lines in the sand, and when these lines are crossed I make it my business to kick them out (adblockers, hosts file, VPN, firewall). I do this to keep my headspace intact, or with the minimum noise.
Market (aka profit) drives things, and it is a greedy monster with infinite appetite. There are many willing to "innovate" (flash ads were considered as innovation once)(so was medicine).
Since it is a cat-mouse/bigger mousetrap game, regulation will always be 10 steps behind, meanwhile we need to maintain our sanity and find ways to keep these distractions at bay.
My time is my time, I don't want to see a movie in an icon. Glad to know the technology is there (perhaps focus on curing cancer instead???), and not everything needs to be redefined, so that <insert-ad-company-name> can display more ads.
I use a custon hodgepodge of SVG, XMLSerializer, image elements, and canvas to do a lo-fi animation for a badge in the favicon. Works for desktop browsers (including IE11, although I haven't tested Safari. B2B web app so covers what we need). A few gotchas, but wasn't too hard.
"Safari" is the app that does the browsing.
"com.apple.Webkit.networking" is the app that works in the background doing things like the icons refresh. Some other applications also use this "channel" (app) to reach out, and I usually have it on "Deny all". I like it better when apps do their own connections and don't hijack the "backroards".
The only two reasons I jailbreak ALL my idevices(s):
a. Firewall IP
b. Protect My Privacy (PMP)
You literally have no idea what goes in the background when you install and run an app if you don't spy on your phone.
The disgusting part is that even my bank's (NatWest) app, as well as LastPass talk to irrelevant companies when I fire them up, with (my) most hated being Facebook (which is of course blacklisted and added on my hosts file).
For my Android devices I always run "NoRootFirewall" which is a pretty good firewall.
Edit: Both FirewallIP (iOS) and NoRootFirewall (Android) have logging mechanisms so you can track what goes in/out and what is rejected. I am really looking forward to a NoRootFirewall-app for iOS. Something that creates an internal VPN allowing you to manage it.
Thank you
Please, do tell us more. Or write a post about it!
Also on my deny list I seek the following which do not appear in the logs right now: segment.com, fiksu.com, youtube.com, redirector.gvt1.com
Other notes:
1) I never use the LastPass browser.
2) When a service has a "lastpass.com" AND amazon/cloudfront/azure, I prefer the "lastpass.com" over the alternatives/load balancers.
Edit: if you see, these are the logs for only 10 seconds. I know that there are multiple "Denied" since the poor thing keeps trying. It is amazing to see it on many other apps (e.g. games) that talk to apjust, appsflyer, doubleclick, duaps, feeldallapps, glispa, mobileapptracking, segment, startappservice, taprica, app-measuremenet, and HUNDREDS more.
A carefully managed firewall and an extensive hosts file is a must.
The Business/Product side of the app business considers it really important to gather in-app usage information, and they like to use off-the-shelf third-party services to do it. Depending on the service, the SDK enabling use of the service is not necessarily well-behaved. This is to say nothing of SDKs for advertising.
As a developer, it grosses me out.
It is an eye opener to see how most apps behave (including the system apps).
In F-Droid there appears to be AFWall+[1] and NetGuard[2].
Does anyone have a comparison of these two apps, compared to NoRootFirewall, or indeed others (Blokada mentioned in other threads)?
AFWall+ appears to required a rooted device for iptables, but NetGuard says no root is required.
The solution I've settling on has been AFWall+ to ensure that only a limited set of apps can talk at all, and Netguard to control where those apps can talk. The interface is not as elegant as FirewallIP, but it does allow an easier ability to interactively allow and block specific destinations without firing up a text editor.
Just because some people are idiots who don't read what's in front of them, doesn't mean others should be impacted.
We all know the real reason it's not an option.