Ch4t4r / Nebulo

Mirror of https://git.frostnerd.com/PublicAndroidApps/smokescreen. Feel free to contribute here as well.
https://nebulo.app
GNU General Public License v3.0
197 stars 24 forks source link

Non-VPN section may require clarification regarding Android's Private DNS functionality #21

Open zer0def opened 7 months ago

zer0def commented 7 months ago

Considering that built-in "Private DNS" (actually DoTLS over port 853/tcp) has become an opt-out feature among numerous vendors by default, the non-VPN section may require additional steps remarking on either settling for that or disabling for the sake of using Nebulo. Not addressing this leads to suggested configuration never matching on DNS traffic, as it is never sent over 53/udp.

zer0def commented 7 months ago

One additional remark regarding non-VPN mode is that the user can also use it with VPN-based firewalls and Block connections without VPN turned on, improving leak handling at boot or when said firewall gets killed by the system for whatever reason.

For the case of NetGuard, Nebulo has to be configured with all of the following:

This may constitute a vaguely associated issue, however considering the amount on needle-threading for this particular case, it may warrant extending server addition options to cover specifying (likely through QR code, since we are talking about a mobile device case) either of the following for authenticity purposes: