sandbox and vpn - Security Discussion

Hello,
I use shelter since some months, and manage to get afwall+ on personnal and work profil working by creating a custom Script.
So one app running for 2 profils.
Actually my vpn work only on personnal profil, and if I want it under work profil, I have to install and run it twice.
Is there a way to get one instance of vpn for the 2 profile. If I can make it with afwall+, this may be possible for vpn?

Related

Can't make adway work.

Hello xda users.. today im facing a big problem..
I have op6 with rooted (magisk installed). oos 9.02
Ive installed latest adway 4.0.11. Everything works fine (adway gets permisions.. etc). But he does not stop the ads.
In magisk i have ticked systemless hosts same for adway in prefs. What i am doing wrong?
I am missing something?
zubyro said:
What i am doing wrong?
I am missing something?
Click to expand...
Click to collapse
I haven't routed a phone for a few years now but I seem to remember Adaway wrote its hosts file to the system partition. And isn't it the way of Magisk to not write anything to system?
I use Adguard directly from Adguard.com. It just works, (apart from the odd time Oneplus closes it ,) and I ALWAYS have Google Pay working too - so no hassle at checkouts.
Ended up using dns66.. cant make adway to work..
zubyro said:
Ended up using dns66.. cant make adway to work..
Click to expand...
Click to collapse
I have Adaway running on my rooted OP 6, but I'm not using that systemless switch you mentioned...
zubyro said:
Ended up using dns66.. cant make adway to work..
Click to expand...
Click to collapse
Use AdAway v3.3. I have it working perfectly fine.
croques said:
I haven't routed a phone for a few years now but I seem to remember Adaway wrote its hosts file to the system partition. And isn't it the way of Magisk to not write anything to system?
I use Adguard directly from Adguard.com. It just works, (apart from the odd time Oneplus closes it ,) and I ALWAYS have Google Pay working too - so no hassle at checkouts.
Click to expand...
Click to collapse
I agree with you. Adaway just doesn't do anything for me. Adguard just works, and it works very well.
On unrooted phones, the VPN adapter is used to reroute traffic. As I use a normal VPN permanently to prohibit carrier deep packet inspection, any adblocker relying on the VPN approach is a nogo for me as Android only supports one VPN connection at a time.
akxak said:
On unrooted phones, the VPN adapter is used to reroute traffic. As I use a normal VPN permanently to prohibit carrier deep packet inspection, any adblocker relying on the VPN approach is a nogo for me as Android only supports one VPN connection at a time.
Click to expand...
Click to collapse
I agree with you totally. I would much prefer your way of a permanent VPN and to block ads some other way.. However,
I need Google Pay to work all the time and not be in an arms race with Google;
I need to block ads;
I need a VPN that always has good connection speeds for downloads and not just a high burst speed for a few seconds..
That little list just won't work together. And that last point seems impossible to achieve - certainly with the many VPN services I've tried. I'm currently using Mullvad when I need security but cannot recommend it for speed
I use an OP6 with Android 9, OOS 9.0.1 routed with Madison 17.2
I have Google Pay, Adaway and my permanent VPN with OpenVPN.
I use NordVPN for which I pay but it's reliable and fast, allows multiple connections from my home router and my mobile.
Reliable and without any problems.
akxak said:
On unrooted phones, the VPN adapter is used to reroute traffic. As I use a normal VPN permanently to prohibit carrier deep packet inspection, any adblocker relying on the VPN approach is a nogo for me as Android only supports one VPN connection at a time.
Click to expand...
Click to collapse
Adguard works both in vpn or in proxy mode. But for proxy mode, root is required. Using Adguard for an year ans its always my fav adblocker.
If you're using Magisk, both Magisk and Adaway need to be set to systemless via the settings in each application.
For some reason Adaway 4.x just ignore the restart warning and then just press check for updates again and it'll start properly downloading the host files.
My Adaway has the systemless setting grayed out and not ticked. I'm using Adaway 3.3 from F-Droid which is the latest version, there's no version 4. It's not available on Google Play.
akxak said:
I use NordVPN for which I pay but it's reliable and fast, allows multiple connections from my home router and my mobile.
Reliable and without any problems.
Click to expand...
Click to collapse
Well and good for you. TrustPilot (UK) gives them only 5.8/10. There are some good and bad comments - as to be expected -but this is recent post. It chimes with my own experiences of paid VPN - more promises than delivery.
Extremely slow server
Extremely slow servers. Absolutely horrible app. They make it next to impossible to select a specific server you've used in the past and instead give you an unsorted list of thousands of servers to manually scroll through and try to find the one you want. You can search for a server but if you do it this way you can't add it to favourites.
They advertise as fast for p2p, yet my speeds are the slowest I've ever experienced with a VPN, including those lousy free vpn.
Click to expand...
Click to collapse
I'm aware this is off-topic for Adaway; apologies to OP for possible thread hi-jacking; but if you are in to ad-blocking the next step is VPN
I use the app OpenVPN which gives me more control, speed of servers vary but I am satisfied.

Shelter: Second work profile possible?

I am using shelter (from F-Droid) to separate whatsapp from my other phone.
WA runs in the work profile only.
Is it possible to generate a second work profile where some different apps can be sheltered?
These shall be sheltered from the normal phone as well as the first shelter.
nadastry said:
I am using shelter (from F-Droid) to separate whatsapp from my other phone.
WA runs in the work profile only.
Is it possible to generate a second work profile where some different apps can be sheltered?
These shall be sheltered from the normal phone as well as the first shelter.
Click to expand...
Click to collapse
Unfortunately this is not possible, android does only allow for one work profile.
If you are still using shelter or island and want more functionality and convenience (for example a simple to use file transfer or want to hide apps),
you may want to take a look at SRT Vault.

Best Adblocking solutions for rooted phone, no VPN?

I know the title is rather generic and not strictly related to OP7, but I didn't know where else to post, and as this applies to my OP7, I thought to post here.
OP7
OOS 10.0.7
Rooted, Magisk+TWRP
So far I have been using Blokada to stop ads and it's been a bliss, but the limitation of Android to only run one VPN at a time makes using another VPN a compromise.
Recently I decided to use NordVPN, but as the situation stays now, I must choose between really no ads (Blokada), or NordVPN, but rely on Nord's as filtering which isn't really doing much.
Can you recommend me some reliable Adblocking solutions for rooted phone that can work in parallel with NordVPN and do equally good job as Blokada is doing? I need to block apps across the whole system (apps, websites).
P.S. using YouTube Vanced, so that one is sorted.
Energized magisk module, energized.pro for info on which version best suits you
Adguard dns without any app
Isn't DNS ad-blocking problematic? I've been reading that apps and websites can detect ad- locking DNS and act strangely.
Also, some ISP may not like some DNS... What has been your experience with DNS Adblocking so far?
Hi
I'm using OP7T OOS Beta 7 at the moment. I've been using Blokada for a short time and liked it a lot. But a minor was indeed not being able to combine it with a VPN from another provider. So I tried Blokada VPN. I had the feeling that it was working smoother than the VPN I'm always using. And I like the way they handle accounts. So you could use Blokada and VPN together if you pay for the VPN from Blokada.
So what stopped me using it? Having a long time subscription at NordVPN. I'm not using a vpn much lately. My setup is as follows:
- setup private dns under settings-networks-private dns: dns.adguard.com
- setup Adaway from FDroid (you need root)
- setup NordVPN. Beware to use the apk from the website and not from the Play Store. Only the apk from the website has working cybersec functionality. It can be used together with Adaway.
I've no problems using a dns server that blocks ads and malware. Neither do I have problems using hosts file based blocking like Adaway. Besides that I'm using browsers like Privacy Browser, Firefox nightly, Bromite and ungoogled chromium. And I try not to use apps with ads.
SvenC said:
- setup private dns under settings-networks-private dns: dns.adguard.com
- setup Adaway from FDroid (you need root)
- setup NordVPN. Beware to use the apk from the website and not from the Play Store. Only the apk from the website has working cybersec functionality. It can be used together with Adaway.
Click to expand...
Click to collapse
Thanks, I made the same setup... Seems less strict compared to Blokada, but this I am sure is just a matter of hosts list in adaway.
Do you recommend any hosts in particular besides the ones already in Adaway?
Also, what kind of apps do you split tunnel in NordVPN? Or no need? Everything working as it should?
derei said:
Thanks, I made the same setup... Seems less strict compared to Blokada, but this I am sure is just a matter of hosts list in adaway.
Do you recommend any hosts in particular besides the ones already in Adaway?
Also, what kind of apps do you split tunnel in NordVPN? Or no need? Everything working as it should?
Click to expand...
Click to collapse
Be sure to update hosts file in Adaway regularly. I haven't changed any sources in Adaway. Just the standard setup. It blocks system wide and I don't want it to be too strict. Maybe I want to reach a domain sometimes on some site without hassle. You can start up "dns log"in Adaway and then just use your phone like you always do. It then monitors every request. After a while you can go back to Adaway to view which requests occurred. From there you can block domains that were allowed. Or allow domains that were blocked.
I'm not using vpn a lot lately as I'm in my home country. I use it especially when I'm abroad in less privacy conscious countries. That's why I haven't split anything. But I would just it more, I would split apps like Signal private messenger which are end to end encrypted, and apps that don't seem to work well going through the vpn tunnel.
If you are really concerned about your privacy/ISP, then you should setup VPN always on, or force apps to use vpn tunnel by using a firewall. Although opinions differ on this. To me that's overkill anyway. Do you have apps still showing ads? Or do you mean ads while browsing websites?
SvenC said:
Do you have apps still showing ads? Or do you mean ads while browsing websites?
Click to expand...
Click to collapse
Yes, some apps are still showing placeholders. Didn't check all apps...but with Blokada I didn't even have the placeholders. Isn't a big nuisance, but if I can find a solution for it, for the better.
As for vpn usage... i just made some network speed tests... what do you see... it was better over the vpn. For some reason my isp was throttling my mobile (weird). So, I decided to allow NordVPN to always connect to the fastest server.
About tunneling, I was interested if any app misbehaves when on vpn (for example Netflix, or banking apps, if you personally encountered some issue).
derei said:
Yes, some apps are still showing placeholders. Didn't check all apps...but with Blokada I didn't even have the placeholders. Isn't a big nuisance, but if I can find a solution for it, for the better.
As for vpn usage... i just made some network speed tests... what do you see... it was better over the vpn. For some reason my isp was throttling my mobile (weird). So, I decided to allow NordVPN to always connect to the fastest server.
About tunneling, I was interested if any app misbehaves when on vpn (for example Netflix, or banking apps, if you personally encountered some issue).
Click to expand...
Click to collapse
I keep apps with ads at a minimum, so probably that's why I haven't any problems like that. I remember having problems setting up Payconiq and Transferwise while on vpn. After finishing the setup, only Transferwise still gives problems while on vpn. I don't have streaming or social apps besides Telegram and Keybase.
That said, if I didn't have a subscription from NordVPN, I would use Blokada and pay for its vpn. Everything in one app. But in case speed is important, probably Nord is a better option.
derei said:
Isn't DNS ad-blocking problematic? I've been reading that apps and websites can detect ad- locking DNS and act strangely.
Also, some ISP may not like some DNS... What has been your experience with DNS Adblocking so far?
Click to expand...
Click to collapse
You may have the same problems you have with VPN apps, I have not had any problems for the moment and I have been using dns adguard for some time ... once there was a problem in the server and they crashed but just set '' automatic dns' 'until the problem is solved. In any case, if you don't have root the only way is vpn or dns
I tried the Magisk module Energized but couldn't make it work. I got an error that it was not compatible although I had systemless hosts installed. Otherwise it seemed promising.
I'm testing another app now: Nebulo. At first sight I like it very much. But don't download it from Google Play cause that's a very limited version. Downloading it from Aurora Droid seems the easiest way. It's like Blokada, but I like it more. You can add packages to block ads. And the choice is large. You have a lot of dns servers to choose from. You can test the speed of the servers. Not just a ping test, but a revolution test. You can use cache to avoid sending the same dns requests over and over to the server; to speed up browsing. And a lot of other settings. Worth taking a look at.
Tried Magisk module energized.pro module on another ROM with success now. Using private DNS settings in android combined with that module. My favorite setup at the moment.

Help security/privacy question GrapheneOS (noob, beginner)

Hello everybody, i am using Graphene OS and only FOSS apps and i have a question. Recently i see some Foss apps also have "trackers" like Duckduckgo browser for example. I want to choose which apps i can block the internet connection for + the communication wich each other + VPN. I tried to use a "firewall" like netguard to block internet connection from the apps whoem don't need it + trackercontrol to block the trackers from all the apps and OpenVPN to hide my IP adress. But i can't use these 3 apps at once because the phone recognize them all as an VPN. Does anyone have the solution for this for me?
Use Brave browser.
jwoegerbauer said:
Use Brave browser.
Click to expand...
Click to collapse
That is only for tracking on web browsing. I am searching to block unwanted trackers on the background from the apps also
When you are on the Internet, data such as IIP address, browser type, operating system, etc.pp, are inevitably transported with. Even a VPN service - what is superior to a Proxy - get this data transmitted. And you never will really know what the VPN service is doing with these data - at least VPN services that are free-of-charge - and whether they themselves run Man in the Middle Attacks or not.
BTW: A Firewall protects a network’s resources from intrusion by users on another network such as the Internet. All networked and online Android users should implement a Firewall solution, IMO. If you have a rooted Android smartphone, you can use AFWall+ to control your device’s Internet activities. AFWall+ also allows users to control Internet access on a per-app basis.
jwoegerbauer said:
When you are on the Internet, data such as IIP address, browser type, operating system, etc.pp, are inevitably transported with. Even a VPN service - what is superior to a Proxy - get this data transmitted. And you never will really know what the VPN service is doing with these data - at least VPN services that are free-of-charge - and whether they themselves run Man in the Middle Attacks or not.
BTW: A Firewall protects a network’s resources from intrusion by users on another network such as the Internet. All networked and online Android users should implement a Firewall solution, IMO. If you have a rooted Android smartphone, you can use AFWall+ to control your device’s Internet activities. AFWall+ also allows users to control Internet access on a per-app basis.
Click to expand...
Click to collapse
Thabk you very much for youre great advice. So if i understand it good it is VPN connection is not a top priority right? Is it also true that GrapheneOs creates every day another imei number? Is the firewall solution of AFWall+ not the same as Netguard? If no can you please tell me what the difference is. AFWall+ gives in Fdroid that it has antifunctions, also for a lot of other apps. Does that have also influence on privacy and security?
I don't
1. make use of VPNs
2. know anything about GraphenOS. Changing IMEI and/or Wi-Fi Mac Address on a per daily basis makes no sense for me
3. use NetGuard, never tried it

Question PPTP option missing in VPN menu any third party app that supports it?

I need PPTP option to connect my remote server vpn service
How can I do that? That option missing in my uptodate poco x3 pro phone
edit :
I have found a solution and prepared a tutorial guide video. Here link
If it's your remote Server it's recommended to switch to OpenVPN or Wireguard.
Wireguard works pretty well on Android, and also quite easy to setup in WG-easy docker if the root System supports it.
Still needs an additional vpn app....
Haldi4803 said:
If it's your remote Server it's recommended to switch to OpenVPN or Wireguard.
Wireguard works pretty well on Android, and also quite easy to setup in WG-easy docker if the root System supports it.
Still needs an additional vpn app....
Click to expand...
Click to collapse
ye OpenVPN is the best

Categories

Resources