AI summary
A privacy-focused VPN that routes device traffic through the Tor network. It features an interactive firewall with domain threat filtering, DNSCrypt support, and a kill switch. This version introduces an Arti SOCKS shim for improved OpenVPN-over-Tor stability and standardized authentication handling.
Generated by AI. May contain inaccuracies.
About this app
Privacy-focused Android VPN that routes all device traffic through Tor, with DNSCrypt for app DNS (over Tor SOCKS by default; FakeDNS / SOCKS5A as a settings fallback). Inspired by InviZible and Mullvad-style leak protection.
What it does
- Feature: Tor tunnel Description: Full-device VPN via hev-socks5-tunnel -> Tor SOCKS; kill switch blocks traffic when the tunnel is down
- Feature: DNSCrypt Description: App DNS resolved through DNSCrypt (upstream via Tor); TunDnsMux on 10.8.0.1
- Feature: Interactive firewall Description: OpenSnitch-style Accept / Deny for new outbound connections (notification + prompt, FIFO queue, permanent / session / temporary rules)
- Feature: Domain threat lists Description: HaGeZi lists colour destinations on prompts: safe (unlisted), ads/tracking/telemetry, malware/C2 — updates prefer Tor when the tunnel is up
- Feature: App lock Description: Lock the UI without stopping the tunnel or kill switch
- Feature: Tor tuning Description: Circuit rotation presets, stream isolation modes, editable torrc / dnscrypt-proxy.toml
- Feature: Tor engine Description: Dual backend: C Tor (libtor.so, default) or Arti (arti-mobile and/or onionmasq TUN)
- Feature: TUN data plane Description: hev-socks5 (C Tor / Arti fallback) or onionmasq (Arti preferred when libonionmasq_mobile.so is present)
- Feature: Circuit UI Description: Onionmasq path: per-app hops, NEWNYM-per-app, exit directory from NewDirectoryEvent
License
Proprietary / OnionPhone family
What's new
OpenVPN-over-Tor via Arti SOCKS: added a SOCKS5 shim that handles authentication between ics-openvpn and Arti, resolving auth and socks-error storms that previously blocked nested OpenVPN TLS connections. - Fail-closed protection: the shim now stops after repeated unexpected auth errors to avoid endless reconnect loops. - Added "remote-cert-tls server" automatically when a profile includes a CA but no server certificate verification method — closes an OpenVPN MitM warning. - Standardized authentication handling across all profiles: imports only from inline <auth-user-pass>; no default credentials are invented; retries with empty credentials once after an AUTH_FAILED. - DNSCrypt: default Tor-friendly fallback servers are now cs-de and cs-nl (removed adguard-dns to avoid non-standard provider warnings at boot).
About this version
- Version
- 0.3.72 (79)
- Size
- 53.45 MB
- Requires Android
- 8.0
- Target SDK
- 26
- Architecture
- arm64-v8a
- Downloads
- 13
- Updated
- Aug 26, 2026
- Package
- ltechnologies.onionphone.onionvpn
Similar apps
Ratings & reviews
- 50
- 40
- 30
- 20
- 10