Tier-1 paranoid hardening: privacy_lan.py disables LLMNR/NetBIOS/mDNS with reversible snapshot; service rotates MAC on every chain rotation when enabled; leak_audit.py probes every leak surface (IP, DNS, IPv6, WPAD, GPO, ProxySettingsPerUser, LAN broadcast, VPN, WebRTC) and renders pass/fail in Privacy tab.
Co-authored-by: Cursor <cursoragent@cursor.com>
On Server / GPO baselines, ProxySettingsPerUser=0 makes WinINet ignore HKCU entirely. When elevated, force the flag to 1 and mirror proxy values to HKLM root + Connections blob. Detect Group Policy proxy locks and surface them so the user knows browsers will keep the policy value. Add diagnose_system_proxy() logged on every chain engage.
Co-authored-by: Cursor <cursoragent@cursor.com>
Adds VPN-aware leak handling, chain testing UX improvements, hardened Firefox launch/profile management, privacy/device hardening modules, and tray/status upgrades so the app is production-ready as the new baseline.
Co-authored-by: Cursor <cursoragent@cursor.com>
- _is_same_network: /16 subnet comparison catches NordVPN IP rotation
(exit_ip != real_ip exact-match missed same-VPN exits on rotated IPs)
- Leak now blacklists the entire dead chain, not just rotate
- GOST stderr/stdout -> gost.log (file, never deadlocks vs pipe)
with 512KB rotation; last 8 lines shown in UI when GOST dies
- read_gost_log_tail helper for live debugging
- Health check uses same subnet check for consistency
- 5 new subnet tests
Made-with: Cursor
httpx.AsyncClient.get() does not accept proxy= per-request.
Shared client caused every check_one call to raise TypeError,
silently caught as False, so 0/N proxies ever passed.
Reverted to per-proxy AsyncClient(proxy=url) in _check_one.
Semaphore concurrency + wall-clock cap preserved.
Also re-adds _check_one helper that was accidentally removed.
Made-with: Cursor