Join GitHub today
GitHub is home to over 20 million developers working together to host and review code, manage projects, and build software together.
Consider bundling NetGuard instead of Privacy-Friendly Net Monitor? #598
Comments
This comment has been minimized.
Show comment
Hide comment
This comment has been minimized.
Show comment Hide comment
thestinger
Feb 21, 2017
Contributor
Net Monitor is bundled because it now needs a special SELinux domain in order to access /proc/net. NetGuard is not a replacement for it, and NetGuard is not the right way to approach implementing firewall features in CopperheadOS. It's a hack depending on the VPN service conflicting with other real VPN services which doesn't make sense in CopperheadOS where it can be properly implemented with integration into the OS.
|
Net Monitor is bundled because it now needs a special SELinux domain in order to access |
thestinger
closed this
Feb 21, 2017
This comment has been minimized.
Show comment
Hide comment
This comment has been minimized.
Show comment Hide comment
thestinger
Feb 21, 2017
Contributor
If people want to work on implementing proper firewall configuration support, that's welcome. CopperheadOS isn't the place for hacks and workarounds with major security and usability limitations though.
|
If people want to work on implementing proper firewall configuration support, that's welcome. CopperheadOS isn't the place for hacks and workarounds with major security and usability limitations though. |
securesearch commentedFeb 21, 2017
I noticed you bundled SECUSO (Darmstadt)'s Privacy-Friendly Net Monitor in a recent release, which is great. Have you checked out Marcel Bokhorst's NetGuard? https://github.com/M66B/NetGuard
It is a pretty comprehensive application layer firewall (incl system applications) using the VPN API.
Supports blocking ICMP, TCP, UDP on IPv4/v6.
Separate DNS and allowed/blocked logs
Custom Hosts File which also blocks DNS requests (firewall itself does leak DNS requests)
He doesn't support the F-Droid builds since they don't support reproducible builds, which sadly means they are usually very out of date, but he does release the application bundles on Github regularly.
Documentation suggests NetGuard includes Google ads, but having used the Github releases for a while, and not seen any ads or unknown network requests from the phone during packet captures, I can only assume the ads are only in the Play Store releases.