Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Some firewalled apps can still access internet sometimes? #370

Closed
ignoramous opened this issue Sep 10, 2021 · 9 comments
Closed

Some firewalled apps can still access internet sometimes? #370

ignoramous opened this issue Sep 10, 2021 · 9 comments
Assignees
Labels
P0 Priority: 0 (urgent and important)

Comments

@ignoramous
Copy link
Collaborator

A user says,

Hello there, some system apps can still access internet sometimes even I have never disconnected from Rethink dns firewall. Here is the image showing those apps' network usage

I have also noticed that apps that I've blocked have, according to Android, sent meager traffic (within 100 KBs). May be Always-on VPN is critical to prevent any such leaks? Or, may be Android's accounting for the app's DNS / ICMP traffic (RethinkDNS does not block ICMP celzero/firestack#3 and cannot know which app sent DNS request #270 though it can block them if it knew it was sent from a firewalled-app).

Interesting.

@ignoramous ignoramous self-assigned this Sep 10, 2021
@ignoramous ignoramous added the P0 Priority: 0 (urgent and important) label Sep 10, 2021
@ignoramous
Copy link
Collaborator Author

ignoramous commented Sep 10, 2021

Unrelated, but also see: #364

screenshot

20210403_150405

@pukkancsanyo
Copy link

pukkancsanyo commented Aug 3, 2022

Hi, I think I have the same issue. I keep getting new mails through Huawei’s default e-mail app, although it’s fully blocked. I cannot figure out why.

screenshots

Screenshot_20220803_114941_com celzero bravedns

Screenshot_20220803_115159_com huawei systemmanager

@ignoramous
Copy link
Collaborator Author

The Huawei email app is a system app. If so, it can bypass the VPN Rethink sets up (and thus the firewall) See: #224

@pukkancsanyo
Copy link

Thanks for the reply. OK, so that's why it seems to be blocked in the logs (every connection by it listed in the log is red), while it keeps getting new messages. It can make some other connections which are not logged and not blocked either, which is pretty unfortunate in the case of spying system apps.
Thanks for all the info.

@ignoramous
Copy link
Collaborator Author

ignoramous commented Sep 13, 2022

It can make some other connections which are not logged and not blocked either

Yes, but let me clarify: If the Huawei Email app wanted to bypass the VPN firewall, it could. But, does it? That's unclear.

OK, so that's why it seems to be blocked in the logs (every connection by it listed in the log is red), while it keeps getting new messages. It can make some other connections which are not logged and not blocked either, which is pretty unfortunate in the case of spying system apps.

So: The notifications are usually driven by some other System component (on Google-blessed devices, it is Firebase Messaging Service via the Google Framework Services app) and not the actual app (in this case, the Huawei Email app) itself.

@ignoramous
Copy link
Collaborator Author

Also see #544

@aykirito
Copy link

aykirito commented Jul 15, 2023

hi, i was about to report issue about firewall but i found this thread so i didn't. was wondering how firewall in rethinkdns actually work? i using firewall only mode and was doing some testing if internet connection actually blocked so i looked at dns logs (from nextdns that i set router level) it still sending request despite internet access
for those apps already been blocked by rethinks. i felt like this is causing by rethink stats log that look for ip countries, is there a way to disable this?

i already check the app it show no internet connection but somehow dns logs show different.

should i worried about this? it look like leak to me

@aykirito
Copy link

i did some more testing this time with netguard. it give similar behaviour like rethink. seems like it normal behaviour from read on-demand explained in README rethink#firewall i guess.

@hussainmohd-a
Copy link
Collaborator

Closing this issue as no changes are required.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
P0 Priority: 0 (urgent and important)
Projects
None yet
Development

No branches or pull requests

4 participants