NetGuard – rootless Android outbound per-app OSS firewall, like LittleSnitch
netguard.me
netguard.me
Every once in a while I consider making the switch to KeePassXC. I trust KeePassXC but I don't really trust the mobile apps so last time around I looked into NetGuard. It's really nice but it wasn't a good fit for my use case:
> NetGuard will do its best, but it is limited by the fact it must use the Android VPN service. This is the trade-off required to make a firewall which does not require root access. The firewall can only start when Android "allows" it to start, so it will not offer protection during early boot-up (although you can disable your network before rebooting). Also, the Android VPN service needs to be restarted to apply new rules when connectivity has changed or when the screen is being turned on or off. It will, however, be much better than nothing.
I believe that also means you can't use it with Tailscale or similar.
Is "nothing" the only Android per-app outbound firewall alternative to NetGuard?
Karma Firewall https://f-droid.org/packages/net.stargw.fok/
Ideally I would use NetGuard to block the apps and Blockada to block ads and trackers for the apps that I allowed to perform network traffic in NetGuard. But Android allows only one active VPN and they can't be chained, so it's a hard choice. Actually it's not so hard: I keep blocking ads and trackers.
Seems like I can get ad blocking for free.
One quirk from what I understand of this ticket[1] is if there's a proxy set up via a separate internet allowed app it can bypass the restriction via that app. GrapheneOS' implementation is said to prevent this.
[1] https://gitlab.com/LineageOS/issues/android/-/issues/3228
It's also rootless so I assume it has the same restrictions, but it's been very helpful with apps like Uber, which I use seldomly, but prefer not to have their notifications shoved in my face every 30 minutes.
It's also helpful for disabling access to most of the bloatware that comes with e.g. Samsung phones and such.
Probably not blocking everything, but I feel like it's at least something.
You sort of can. It can route over a socks5 proxy to the work profile where you can have a second VPN running. Wouldn't be an easy solution, but it can work
I know I have experienced VPN leaks on Android (not the one they publically fixed as it was after). A second layer wouldn't fix that properly but it should make it less likely.
Got this from a thread about Tracker Control, a NetGuard fork, and VPN chaining https://github.com/TrackerControl/tracker-control-android/is...
I'm using Keepass2Android Offline. It doesn't have the network permission, which for me adds a ton of trust already.
Of course there are other ways to infiltrate data too, but you can be only so paranoid if you want to get things done.
https://play.google.com/store/apps/details?id=keepass2androi...
Even KeePassDX? That's what I use, and it's been rock solid for me.
You can configure it to block access by default and notify you every time an app attempts a new connection. And it rings all the time.
Some software call home at 4am every day, other every hour, some send data to a dozen "analytics" services - services that I never opted-in for, which shows how few apps respect the RGPD.
At least most apps still work when those are blocked, and NetGuard allows you to block connections to Google servers except for Google Apps, which network firewalls and DNS solutions can't.
Which app?
How do you know those connections are blocked and not merely bypassing Netguard?
See https://grapheneos.org/features#sandboxed-google-play
NetGuard also shows network requests from GrapheneOS itself, all proxied by the GrapheneOS project, as described here: https://grapheneos.org/faq#default-connections
You just leave it in background, check one day later and see what sneaky app you never thought of have been sending tons of data in the background.
For me it helped me remove and search alternative for 4 apps, including a pill reminder (mytherapy). I would never have thought the trade-off to be reminded to take vitamin would be to constantly spy on me and sell all my data. Had i known, I would have put a reminder in my calendar.
I want to be able to open word and excel file on my phone, but i don't want to give microsoft access to everything on my phone including dick pics, sextape, bank sheet and other personal data.
Because android allows such bad practice, blocking internet access can be usefull.
anyway, it's not the same as netguard. Pcapdroid helps to identify bad application that you can either remove, or if not possible, use netguard later on to block.
Oh, interesting, I didn't know. A pity that you have to purchase it on the Play Store
> anyway, it's not the same as netguard. Pcapdroid helps to identify bad application that you can either remove, or if not possible, use netguard later on to block.
Well, almost all closed-source apps, and especially many system applications, send data out all the time; blocklisting rather than whitelisting is not a great strategy.
NetGuard allows exporting to PCAP as well, anyhow, as a paid feature
This is an app you wanted to replace? Or this is one of the apps that you found to be a good replacement?
(I am also looking for a basic medication reminder/logging app)
i checked on the play store, all full of trackers. open source is great but always having issue, either it lacks functionalities or it's buggy.
at the end, i decided i could put a reminder on my phone and be done with that.
Kind of wish there was more discussion about solutions for rooted devices and how much unwanted traffic is already blocked by AdAway (in rooted mode).
They really don't want users to have control over this.
Yes, GNU/Linux distributions provide exactly that.
Unless this is just a battle of semantics on the fact iptables/firewalld/ufw are user space apps.
Edit: and to clarify, you can have a user space app on Android to configure a firewall but they will either require root or a VPN-based solution like NetGuard.
https://selinuxproject.org/page/NetworkStatements
https://manpages.ubuntu.com/manpages/bionic/en/man5/apparmor...
Google hasn't made a successful product in over a decade (nor have their existing products improved in any meaningful sense) - these people are not capable of anything besides hoarding power (and passing leet code I guess :P).
Every app has own settings for allowing WiFi, data, VPN, background data connections natively in Android. I use custom ROM that has turned off internet connection for all apps by default and you need manually allow them to connect. Which solve mine problem with constant unwanted connections.
If you want really control over traffic on Android and combine with VPN, try ReThing DNS.
It doesn't really, just try it (and take actual battery duration measurements, Android misreports VPN apps battery usages)
---
ReThink DNS uses the VPN service as well, by the way.
And it is possible to use two VPN apps, see https://news.ycombinator.com/item?id=41933464 (yes, the battery usage adds up).
Rethink DNS seems fine, anyhow.
> ReThink DNS uses the VPN service as well, by the way.
Rethink (since a year ago) has had the ability forward connections per-app to multiple WireGuard upstreams at the same time.
https://old.reddit.com/r/rethinkdns/comments/15r1eq9/v055_mu... / https://archive.md/RqUPe (to us, it turned out to be a deceptively difficult thing to integrate with the rest of the firewall).
I'm unsure if we'd be able to support all of Tailscale's features as easily (taildrop, exit nodes etc), we'll see.
It's not the _only_ solution. If you're on a modern (read: last 6 years or so) version of android, you can specify a DNS over TLS server to use.
If that DNS server also happens to be a PiHole, you have a good filter mechanism that doesn't hit battery life / data quotas quite like an always-on VPN does.
It's a bit old, but I put together a basic project for this here: https://github.com/kquinsland/skyhole/
I let it run today, and the worst offenders I have installed are Spotify (various requests to Facebook endpoints, I have no Facebook integration turned on) and Speedtest (constant requests to their logging endpoint and ad partners). This is all happening without me actually using those apps.
(On my phones, I use LineageOS which can manage network permissions per app right in app settings.)
Having to switch from one to the other is very annoying.
I used to use it when I wasn't on grapheneOS and needed to block internet access.
That gives me a bad feeling, and it's the reason I started to consider RethinkDNS scummy.
Perhaps the reason it gets mentioned often is simply because it's a good piece of software. Then again, perhaps not!
In any case, I'd be careful about using 3rd party DNS (and other) services, but that's for the user to decide, depending on the situation one is in.
Using one's own resolver is always a good practice, even in countries where ISPs are not selling customer's private data to anyone that comes along and where governments don't monitor and repress their citizens on every step...
We live in strange times where even EU countries misuse resolvers to censor certain web pages, while, for example, independent Balkan countries do not. Go figure...
[1] Except apps that pin their certificates. But you can exclude those or install another module[2] (not from AdGuard) which disables certificate pinning.
[2] For example: https://github.com/cryptoexpertssss/TrustMeAlready
* Shadowrocket - you can set complex rules on what hosts/connections should be routed by what, but afaik you are not able to isolate traffic on a per-app basis.
* I think you can set up per-app VPN on iOS, but you must use MDM, can’t do it on an unmanaged profile. Link: https://support.apple.com/guide/deployment/vpn-overview-depa...
Yet iOS allows Safari per-site VPN without enterprise MDM, via Apple Configurator profile.
I am pretty sure it is open source. I’ve been using it for years both for upstream DNS and blocklist filtering.
Any alternatives to Lockdown on iOS/iPadOS would be nice to know about.
But it’s more designed to be a debug tool than to block traffic from specific apps
The creator also made XPrivacyLua (hooks Android API system calls to block premissions)
Netguard (per HN title) is open-source GPLv3: https://github.com/M66B/NetGuard
Rethink uses cloud services by default?
The [DNS] resolver is deployed to Fly.io at max.rethinkdns.com
and Deno Deploy at rdns.deno.dev too,
apart from the default deployment on Cloudflare Workers.Yes rethink uses public fly resolver by default but you can self host that as well. Apologies, that's something I should have mentioned.
> Rethink uses cloud services by default?
There isn't anything sinister going on here with the use of "cloud services" [0][1]. Rethink, which is geared more towards anti-censorship, has its default resolver "ip-fronted" on Cloudflare (whose IPs are seldom blocked) and it works great in countries where the app is popular.
Users can opt to switch to any DoH, DoT, ODoH, DNSCrypt v3 resolver of their choice. In fact, we encourage users on our reddit/telegram groups to use ODoH (we also run a public-facing ODoH proxy) and DNSCrypt upstreams because of their privacy guarantees.
[0] If anything, hosting it cost us a bomb: https://old.reddit.com/r/rethinkdns/comments/17h2y6r / https://archive.md/slpZ9
[1] Our stub resolvers are open-source & "open deploy" (ie deploy straight from github actions): https://github.com/serverless-dns/serverless-dns/actions/
I have a question for you about RethinkDNS:
Can you point me the link to one thread or question about Netguard on some major internet forums like HN, Reddit or similar, where you or other RethinkDNS devs did not jump in and hijacked the thread? Only one example, please?
Your spammy marketing tactics of spamming makes your product looks like a scum, and I don't even have a desire to test.
Also, why do you keep comparing one on device firewall like Netguard with a cloud first solution like RethinkDNS?
I (try and) mostly only respond to subthreads that mention Rethink.
> why do you keep comparing one on device firewall like Netguard with a cloud first solution like RethinkDNS
Rethink isn't cloud-first.
> where you or other RethinkDNS devs
There's 2 of us. The other one isn't on HN, or reddit, or any other forum.
> spammy marketing tactics of spamming makes your product looks like a scum
I'm sorry you think that.
I had previously set Android's private DNS to dns.adguard-dns.com, which didn't block anything.
Rethink's battery usage is 15 - 20% on my pixel in logging mode.
It definitely works, but I can't seem to associate blocked requests with apps, which renders it far less useful.
Overall I think it's a very busy UI.
You definitely want to exclude Firefox with uBO as elsewise Firefox behaves as though the network is down, whereas with uBO you can interactively choose to proceed.
I see there is an option to download the block lists locally. Does that mean it no longer uses DNS blocking? I see it described as a DNS blocker but it requires a VPN.
Anyway, off to try a Adaway next.
This is unusually high. It doesn't cross 3% on my Android, but I'm using a version (v055o( that's yet to launch (but will in a week or so).
If you only need DNS based blocking, tap on the down-arrow next to the STOP/START button and choose DNS-only mode. That should bring down battery use to 1% or so.
> but I can't seem to associate blocked requests with apps, which renders it far less useful.
Rethink most definitely can. Make sure to turn OFF Private DNS (instead of setting it to Opportunistic or Automatic).
Ex A: https://mastodon.social/@tuxicoman@social.jesuislibre.net/11...
Ex B: https://mastodon.social/@33dBm@lazysocial.de/112051004405969...
> ...download the block lists locally. Does that mean it no longer uses DNS blocking
If you download the blocklists locally, then you can set those on your device, and use any DNS upstream (DoH/DoT/DNS53/DNSCrypt/ODoH) and the rules should be applied, regardless.
https://grapheneos.org/faq#firewall
Yeah there's no stats or traffic info, but until Android has a real way of using multiple VPN interfaces or exposes adding routes to users/apps, these VPN-based local tools are a no-go.
But in case the VPN app supports running as a simple proxy, without using the VPN service, you can avoid work profiles and just have NetGuard connect to it.
unless you use any other phone that is not a google pixel running GrapheneOS
Really? Remind yourself who works on Android. Google have been removing functionalities that benefit privacy for ever, and then put half backed alternative buried under tons of settings.