2026-09-24 17:32 UTC
When I don't have a laptop with me, I sometimes do server admin stuff using my smartphone. It's a reasonably secure phone because it runs a hardened Android distribution called #GrapheneOS. Or so I thought. Shoddy apps can of course violate your security and privacy on any operating system.
As a matter of fact, I once set up a Mastodon server via SSH using my smartphone as a terminal. My terminal app of choice is @termux@fosstodon.org – it almost feels like Debian Gnu/Linux.
Today I found out that the #Termux developers do not care about their users' privacy: They put Google's DNS resolvers as defaults into their app and do tell their users about it. Which means that until today, Google learnt about each hostname I resolved in Termux, although I had configured my smartphone to use a different DNS resolver. The Termux developers were alerted to this bug ten years ago by @rugk@chaos.social but chose not to do anything about it.
Someone wrote a shell script to correct this. But it requires special permissions you can only grant via ADB. So I just used a text editor to replace Google's DNS resolvers with privacy-respecting ones gleaned from @kuketzblog@social.tchncs.de's recommendations in my first link: editor /data/data/com.termux/files/usr/etc/resolv.conf
#TIL #dnsleak #terminal #android #app #privacy
Replies (0)
No replies.