# What is your Network threat model?

**URL:** https://discuss.privacyguides.net/t/what-is-your-network-threat-model/21130
**Category:** Questions
**Created:** 2024-09-26T10:49:14Z
**Posts:** 22

## Post 1 by @ikelatomig — 2024-09-26T10:49:14Z

What is your threat model for your Internet connection (and LAN when running NAS or local server) ?

Do you use Encrypted DNS only or VPN all the time or Split tunnelled VPN or Tor over VPN or Tor all time ?

I have my own. Just trying to know what’s out there in the wild to sulk in better.

---

## Post 3 by @anon94009837 — 2024-09-27T01:32:07Z

No but seriously I try to use a VPN all the time on all my devices with separately set Encrypted DNS. Don’t really care about the “standing out from the other VPN users” aspect of this.

---

## Post 4 by @flarmo — 2024-09-27T01:44:11Z

Somewhat same here. Although I don’t have an always-on VPN for my mobile device I use it whenever I can. When in public I tend to use mobile data and limit my phone use unless absolutely necessary. I use an encrypted DNS.

---

## Post 5 by @ikelatomig — 2024-09-27T03:09:23Z

I am currently with NextDNS but soon switching to ControlD because they can spoof my IP to the destination server via Proxy. I don’t care about ISP since things are encrypted via TLS and I use sites that an average internet user uses. So, not a problemo.

Because of the above, I uninstalled official VPN apps and just using ProtonVPN’s free server configs on my devices whenever I need (for the most part, I don’t).

---

## Post 6 by @Chingelton — 2024-09-27T11:45:33Z

Pretty much the same as @ikelatomig, currently using NextDNS and sometimes use ProtonVPN for downloading linux iso’s but I don’t even have ProtonVPN installed on my phone, just on my pc and laptop.

---

## Post 7 by @atori — 2024-09-27T13:31:24Z

I use a VPN double hop, some apps / browsers are split tunneled out, mostly when interacting with services that have my true identity / address.  
I also use Tor Browser sometimes outside the VPN tunnel, and some apps run behind Tor proxy (Telegram / bitcoin / monero stuff)

---

## Post 8 by @ignoramous — 2024-09-27T22:47:59Z

> [@ikelatomig](#):
>
> What is your threat model for your Internet connection

I personally think[[1]](#footnote-60329-1) per-app _network sandbox_ is a good way to think about it: [iOS apps should be inside a network sandbox · Felix Krause](https://krausefx.com/blog/ios-app-network-sandboxing) ([mirror](https://archive.fo/P6mCB)).

Such drastic measures isn’t possible for all apps, but for frequently-used, task-specific, non-browser apps (like email/messaging/social media), setting up a _network sandbox_ (using tools like _LuLu Firewall_ / _Little Snitch_ / _OpenSnitch_) makes me feel better about it all.

* * *

1. I co-develop an Android-only firewall app, so I may be biased towards solns similar to it. [↩︎](#footnote-ref-60329-1)

---

## Post 9 by @asanyan — 2024-09-27T23:04:32Z

VPN always except for a specific browser that requires my identity, which is split tunnelled (whatsapp, email, government sites). Tor on top whenever possible.

> [@ignoramous](#):
>
> _network sandbox_

Yeah, this is cool.

Firejail has a netlock feature, which scans the hosts that the app connects to in the first minute when you launch it, and builds a whitelist of hosts based on this that is enforced afterwards. Not as good or convenient as something set up out of the box by the developer or packager, but still good.

---

## Post 10 by @ikelatomig — 2024-09-28T07:56:55Z

A network sandbox is cool when you want to block internet access for certain apps which we can do in Graphene OS via native apps or in normal android via Rethink (or just block trackers via something like Next DNS).

* * *

I am into PC networks primarily.

I am considering Split Tunnelling and do all the casual browsing via Tor too, but it would create a lot of Suspicion.

Currently thinking of,

- Thinking of running it over VPN would be better to spoof TOR traffic. Problem : connection would be too slow.
- Using Mullvad Browser but with ProtonVPN. Problem, Split Tunnel not yet implemented in Linux client, and it’s even a Pro feature in Android App. So, I doubt it.

---

## Post 11 by @anon48875053 — 2024-09-28T08:12:47Z

> [@ikelatomig](#):
>
> A network sandbox is cool when you want to block internet access for certain apps which we can do in Graphene OS via native apps or in normal android via Rethink (or just block trackers via something like Next DNS).

RethinkDNS, NetGuard, etc. can only block direct internet access. GrapheneOS network permission blocks both direct and indirect internet access and is a lot more robust.

As for blocking trackers using NextDNS:

> **[Badness Enumeration](https://privsec.dev/posts/knowledge/badness-enumeration/#dns-filtering)**
>
> Badness enumeration is the concept of making a list of known bad actors and attempting to block them. While it seems intuitive at first glance, badness enumeration should not be relied on for privacy or security. In many cases, it actually does the...

> DNS filtering solutions. while not having any negative impact on security, are trivially bypassable by just hosting the advertisement and trackers under the apex domain instead of a subdomain. For example, instead of hosting advertisement and trackers under [ads.example.com](http://ads.example.com), the webmaster can move them to be under [example.com/ads](http://example.com/ads) and it would be impossible for DNS filters to block. Other bypasses include an application implementing its own DNS resolution instead of relying on the DNS servers set by the operating system, or connecting directly to certain IP addresses without any DNS resolution at all.
> 
> It should also be noted that websites can detect which DNS servers a visitor uses. You can look at [DNSLeakTest](https://www.dnsleaktest.com/) as an example. Using non-network provided DNS servers adds to the fingerprint and make you more identifiable.
> 
> The best way to do DNS filtering is to use a VPN provider which has this feature built in like [ProtonVPN](https://protonvpn.com/), [Mullvad](https://mullvad.net/), and [IVPN](https://www.ivpn.net/) in order to not standout from other users of the same VPN provider. Even then, DNS filtering is purely a convenience feature and cannot be relied on for privacy and security.

---

## Post 12 by @anon48875053 — 2024-09-28T08:16:04Z

> [@ikelatomig](#):
>
> Thinking of running it over VPN would be better to spoof TOR traffic. Problem : connection would be too slow.

Are you living in a country where Tor is illegal? If not, then I’m not sure what’s the problem with using Tor directly.

---

## Post 13 by @ikelatomig — 2024-09-28T08:41:42Z

It is legal. I just don’t want to be under suspicion. Simply because I am avoiding trackers and having anonymity during Casual browsing (Even when I haven’t done anything).

I just don’t want to be under the radar.

* * *

Regarding DNS, the paragraph you highlighted does introduce some valid points. Problem.

I like Next DNS because it has robust filtering and I have configured every device on my home to use it (including family) so that they can have a good web experience.

Yeah, the subpage thing is valid but not a concern when ad blocker is used in browser or using Brave browser.

Even though, it fingerprints me, it does give a lot of convenience. And why does website know the DNS server instead of only the IP address ?

* * *

To be honest, I am into Windscribe VPN, it’s robust, but I am in no situation to purchase a premium at the moment, and it’s R.O.B.E.R.T is not as powerful as ControlD. So, I might need to wait for that to happen or use Both Windscribe + ControlD when it is sold as a combo like AdGuardVPN + AdGuard DNS.

It may or may not happen. It’s up to @yegor. Would be great to know some insights on that though.

---

## Post 14 by @ignoramous — 2024-09-28T13:02:14Z

> [@anon48875053](#):
>
> GrapheneOS network permission … lot more robust

Interesting. I’d have thought it is the same _INTERNET_ permission AOSP Android checks for. What changes has Graphene made to it, if you’re aware?

> [@anon48875053](#):
>
> direct and indirect internet access

Can this _indirect_ access be used to upload things?

---

## Post 15 by @anon48875053 — 2024-09-28T13:16:57Z

One of the examples:

1. Install Molly.
2. Block access to the internet for Molly using RethinkDNS or NetGuard.
3. Install Orbot and enable proxy mode.
4. Configure Molly to use Orbot.

Result: You will have internet access in Molly even though it’s blocked using RethinkDNS or NetGuard.

---

## Post 16 by @PrivacyEnthusiast — 2024-09-28T14:12:49Z

That sounds pretty dangerous. Is there anyway to get rid of this (for non-graphene devices)?

---

## Post 17 by @anon48875053 — 2024-09-28T14:15:02Z

You could also use DivestOS, it also has network permission.

---

## Post 18 by @ignoramous — 2024-09-28T18:35:10Z

> [@anon48875053](#):
>
> You will have internet access in Molly even though it’s blocked using RethinkDNS or NetGuard.

My guess is, this happens because Android doesn’t route _localhost_ traffic into the VPN tunnel. If Rethink or NetGuard are setup to _block_ the proxy app, Orbot, it _should_ block Molly, as well.

Would you know if _localhost_ traffic bypasses even when _Block connections without VPN_ is turned ON? If so, I’d want to ask Graphene/Divest/Calyx to shore that one up, even if AOSP may not.

---

## Post 19 by @anon48875053 — 2024-09-28T18:38:22Z

Using something like RethinkDNS or NetGuard with “Block all connections without VPN” will prevent direct network access via sockets, but the internet can still be accessed via OS networking APIs.

---

## Post 20 by @ignoramous — 2024-09-28T21:02:29Z

> [@anon48875053](#):
>
> but the internet can still be accessed …

Nothing to do with _sockets_ or networking APIs. On Android, a VPN app _cannot_ prevent apps from using either of those.

The extent of a VPN-based firewall like Rethink or NetGuard is… iff the OS routes traffic into the VPN tunnel, it may either forward it or block it. It cannot act on traffic flowing outside of its tunnel (like ESP for VoWiFi, Hotspot, built-in AOSP Connectivity Checks, built-in HTTP Connect Proxy, localhost).

In case of Molly+Orbot, it is effectively _Orbot_ that’s connecting to the _Internet_ to forward Molly’s traffic. Installed apps using APIs from the _Download Manager_ or _Google Play services_ to connect (which still pass through the VPN tunnel) has _similar_ effect.

As for Molly+Orbot, my guess is… AOSP _not_ routing _localhost_ traffic to the VPN tunnel is why the _bypass_ happens. I’d imagine this holds true even when _Block connections without VPN_ is turned ON, but I’m unsure.

As for _Download Manager_ / _Google Play services_, the _bypass_ is because the original app identity is _lost_ by the time the traffic reaches the VPN tunnel.

---

## Post 21 by @anon48875053 — 2024-09-28T21:13:32Z

Found some information on GOS forum.

> **[Arguement against GOS firewall makes no sense to me - GrapheneOS Discussion...](https://discuss.grapheneos.org/d/4113-arguement-against-gos-firewall-makes-no-sense-to-me/12)**
>
> GrapheneOS discussion forum

> It would be possible to split up the INTERNET permission to an extent by making it possible to disable some sockets but not others, such as splitting out `localhost` access into a separate toggle. However, the permission enforced by the permission system will need to be denied if network access is partially denied. Otherwise, an application could bypass the direct traffic filtering with indirect access. This is something missed by other projects trying to make finer grained firewall toggles, including every firewall app implemented as a VPN service which do not really work properly.

---

## Post 22 by @ignoramous — 2024-09-28T23:33:16Z

> [@anon48875053](#):
>
> … `localhost` access … This is something missed by other projects trying to make finer grained firewall toggles, including every firewall app implemented as a VPN service which do not really work properly

I don’t follow. How do they conclude “a VPN service is not working properly” when _localhost_ traffic isn’t even sent to it?

One could definitely say that Android’s _VPN services_ won’t block _localhost_ traffic… but to say that _VPN services_ don’t work properly when Android itself isn’t routing _localhost_ traffic to it (among other bits of traffic as noted in my previous reply), is bit of a head-scratcher. Or, may be I misunderstand.

Though, if Android’s _Block connections without VPN_ toggle is turned ON, I’d _want_ hyper security-focused Android forks like Graphene, if not AOSP itself, to block ALL traffic _not_ flowing through _VPN services_.
