Messaging App and Orbot + VPN

Hi everyone,

I’m using Proton VPN along with Orbot to secure my connections. I’ve configured Orbot to work with Signal and WhatsApp (as recommended by the app), and I’ve excluded Orbot from the VPN to avoid potential interference. My question is: could there be a conflict if both Proton VPN and Orbot are working with Signal and WhatsApp at the same time? Would it be better to exclude Signal and WhatsApp from the VPN too, so that only Orbot routes their data?

Thanks for your advice!

Android only allows one VPN connection at a time. Now if you configured Signal and Whatshapp to use a Proxy (if option is available), then that’s different. I am not sure Signal has a TOR proxy option though.

It is possible to start Orbot without VPN mode while using a VPN, by making an exclusion of Orbot of Proton VPN and by connecting Orbot in Russia, Signal asks me well I want to circumvent the censorship, things which is not required if I am in France.

I want to know if such a configuration is useful or serves a purpose

Signal, Telegram, MySudo, Cheogram, and I’m sure more, routinely attempt to bypass the VPN/DNS configuration on Android per monitoring through RethinkDNS. You have to allow them to bypass the proxy for them to function. Using the app level Orbot routing for Signal, Telegram, and presumably Whatsapp seems to be the best option I’ve found for getting them to function without leaking or bypassing their routing.

1 Like

@Rasta Okay, I didn’t know there were leaks and that some applications like Signal would try to bypass the VPN.
With this info, it’s better to exclude Signal and Whatsapp from Proton VPNs like Orbot to avoid possible conflicts or not?

@Anon47486929 Thanks for the info, but I can’t use Proton VPN with killswitch, I use LocalSend regularly and I have to exclude it for it to work, same for Orbot.

How does this work?

You simply need to activate the “Power user mode” in Orbot and exclude Orbot from the VPN so that it works without the VPN mode.

I understood that, I just don’t see how it can bypass the Android restrictions. I never saw this before.

OK, so if I understand correctly, whether I’m using Proton VPN or Orbot, I’m obliged to activate the kill switch to prevent Signal and Whatsapp leaks and bypasses?

I saw that Rethink had an option to prevent DNS leaks. Wouldn’t a Rethink configuration without a kill switch + WireGuard from Proton VPN be the best solution, if the option to prevent DNS leaks works correctly? And do I also need to activate the kill switch with Rethink?

I runultiple wireguard configs through rethink and have the kill switch enabled. Signal and other apps like it break if i dont allow them to bypass the proxies because they attempt to bypass the dns and rethink blocks them internally. I cant speak to their behavior with other vpn apps, but if theyre attempting to bypass the config inside of rethink even with kill switch enabled on GOS, it doesn’t scream to me that they aren’t bypassing the dns with a different setup.

I’m using advanced as I’m running three concurrent wireguard configs for different apps/services.

1 Like

I’ve been using Rethink with kill switch and WireGuard with Proton VPN for 2 days and Signal and Whatsapp are working fine, how do you check for DNS leakage, proxy bypass etc?

In the logs section it will show you that signal is being blocked for attempting to bypass the dns config. I have the firewall enabled to prevent dns bypass attempts. The way i figured out the issue was because i was intermittently missing calls, and messages in signal, or the messages would show up hours later with no notifications. I did some digging in logs and spoke to a few people in the SR and Techlore Signal groups (while switched back to just proton vpn) to narrow down the issue. Allowed the app to bypass the proxy and everything started working flawlessly again

I see it worked for me because I hadn’t activated the option to block apps that try to bypass DNS, so for the return, I’ll leave this option unchecked.

hello

I am trying to use orbot without vpn too but to me it doesn’t work

it’s saying that it’s connected I choose the apps that I want to use (Firefox) but when I try to check if I have tor the site shows me that I don’t so what else have you do so the apps use the orbot?

thanks for your time

@RodifFire
You must use the VPN mode OR all the apps you want must have proxy support.