Applications "profile" export, import, sharing with others (allowed, blocked ips and domains) outside of rdns Generic backup/restore #1982
Closed
onetimecontributor
started this conversation in
Ideas
Replies: 1 comment
-
Thanks. Not sure when we get to working on this, but: #1987 |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
-
Hi. I would like to bring up a discussion around potential feature.
Environment: I have rdns with wireguard, on-device blocklists and upstream dns resolver (with blocklists).
I would like to be able to export/import user applications config - like mode (allowed/denied/isolated), ip/domain rules. This needs to be done outside of rdns generic backup/restore, so I can sync my different devices without affecting other rdns configurations and restore app config after app re-installation (now rdns doesn't preserve settings).
Greater possibility - allow community to share predefined profiles so others can import them and don't bother figuring out.
Reasoning:
Though blocklists (on-device and upstream) address a lot of privacy concerns for well-known trackers, there is still a set of application-specific addresses that those doesn't block though they are app-specific trackers and are not required for (controversial) basic app functioning.
So there is still a noticeable area of privacy leaks that, at the moment, can be addressed only manually by blocking particular domains in per-app settings.
Let's take Waze navigation app as an example. For my basic usage, it seems I only need 3 domains for it to work: ctilesgcs-row.waze.com, rt-xlb-row.waze.com and rt.waze.com
However, there are 16 other domains (also including clearly non-waze domains) that are reached by waze.
Though all of them do smth useful, there is also a great possibility that data will leake for profiling etc.
So I have isolated Waze with 3 domains whitelisted.
Another example is phone manufacturer system apps. I have system apps in isolation mode, keeping only OTA update servers whitelisted.
I understand the will be risks or downsides, like:
What do you think?
Beta Was this translation helpful? Give feedback.
All reactions