Skip to content
itsPremkumarPublic

About

No description, website, or topics provided.

Resources

Code of conduct

Contributing

Security policy

Stars

2 stars

Watchers

0 watching

Forks

Latest commit

Β 

History

146 Commits

Folders and files

NameName
Last commit message
Last commit date
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 

Repository files navigation

Amnos β€” Privacy-First Hardened Android Browser

Ultra-secure, ephemeral, and anti-fingerprinting browsing for Android.

AI Discovery (llms.txt)

Amnos is a privacy-first hardened Android browser built on a Modular Cluster Architecture. Every componentβ€”from the configuration to the UIβ€”is categorized into seven logical security clusters for maximum forensic isolation and "zero-trust" engineering. It prioritizes privacy over compatibility: no persistent cookies, no cache retention, aggressive tracker blocking, and deterministic fingerprint silos.

Amnos is not Tor, not a VPN, and not a custom browser engine. It reduces exposure inside Android WebView constraints; it does not provide network-layer anonymity against every observer.

Security, Privacy & Anonymity Comparison

Amnos is engineered for Forensic Zero-Trace and Identity Consistency, filling a critical gap in the mobile browser landscape. Below is the ultimate breakdown of the privacy browser landscape as of 2024–2025.

πŸ† The Ultimate Executive Comparison Matrix

Feature Dimension Amnos (Titan) Tor Browser Brave Browser Firefox (Hardened) DuckDuckGo
Primary Use Case Forensic Sandbox High-Risk Anonymity Daily Privacy Power Users Quick Simplicity
Major Strength Forensic Amnesia Multi-Hop IP Ad-Block Speed Gecko Ecosystem Ease of Use
Core Engine Hardened WebView Gecko (Hardened) Chromium (Custom) Gecko Platform WebView
Net Anonymity Rotating DoH + Proxy 3-Hop Onion Standard / DoH Standard / DoH Standard
Persistence Zero-Disk (RAM) Ephemeral Stateful Stateful Manual Wipe
RAM Scrambling Yes (Secure Noise) None None None None
Anti-Debugging Nuclear Exit (ADB) None None None None
Fingerprinting Consistent Spoofing Uniformity Random Noise Block / Resist Basic
Ad-Block Engine Dual Multi-List Extension Mode Rust-Based Engine ETP / uBlock Tracker Filter
Ext. Support None Internal Only None Full (uBlock) None
Web Compatibility Moderate Low (Breaks) High (Chromium) High (Gecko) High (WebView)
Account Sync None (Isolated) None Brave Sync Firefox Account None

πŸ›‘οΈ Comparative Strengths: When to use what?

  • Choose Tor Browser if your goal is hiding your IP address and physical location from the network itself. It is the absolute gold standard for Network Anonymity and evading state-level surveillance of your traffic.
  • Choose Brave if you want the fastest possible browsing experience and bulletproof compatibility. Its Rust-based ad-block engine is the best-in-class for performance, making it the perfect daily driver for most users.
  • Choose Firefox if you believe in an Independent Open Web and want to use specialized extensions like uBlock Origin or Decentraleyes. It offers the most customization for users who want to build their own "wall of security."
  • Choose DuckDuckGo if you want privacy that requires zero effort. Its "Fire" button and clean UI make it the best choice for non-technical users who want a high-quality private browsing experience without touching a single setting.
  • Choose Amnos if you need a Forensic Sandbox that guarantees Local Device Amnesia. It is the only choice if you are concerned about physical device inspection, memory-dump forensics, or identity fingerprinting consistency on Android.

πŸ” Advanced Technical Comparison

1. Forensic & Physical Isolation

Feature Amnos (Titan) Tor Browser Brave Browser DuckDuckGo
Storage Model Pure RAM (Zero-Disk) Ephemeral (Session) Stateful Manual Wipe
RAM Scrambling Yes (Secure Noise) No No No
ADB Detection Nuclear Exit (Auto-Kill) No No No
Recents Cloaking Yes (Cluster 1) No No No
Clipboard Purge Proactive Sentinel Manual None None

2. Anti-Fingerprinting & Identity

Feature Amnos (Titan) Tor Browser Brave Browser Firefox (Hardened)
General Strategy Generative Consistent Spoofing Uniformity (Sameness) Noise Injection Request Blocking
UA/GPU Matching Synchronized Templates Generic Standard Randomized Static
Timezone/Locale Deterministic (Fixed UTC) Standardized Standard Standard
Timing Noise Multi-Layer Jitter Standard (100ms) Basic None
Canvas/Audio Deterministic Seeds Standardized Randomization Blocking

3. Network Architecture & Hardening

Feature Amnos (Titan) Tor Browser Brave Browser Firefox (Hardened)
Routing Local Loopback Proxy Onion (3-Hop) Direct / Tor Tab Direct
DNS Strategy Rotating DoH (Dynamic) Onion Resolution Standard DoH Standard DoH
WebSocket Control JVM-Level Wrapper Blocked Standard Standard
Header Purifier Stripping ETag/L-Mod Standard Basic Basic
IPv6 Leakage Active Blocking Forced IPv4 Standard Standard

4. Hardware & API Surface Reduction

Feature Amnos (Titan) Tor Browser Brave Browser DuckDuckGo
Sensor APIs Auto-Jitter/Undefined Blocked Basic Noise Basic Block
Permissions Silent Auto-Denial Gated Prompt Gated Prompt Gated Prompt
Media/WebGL Locked Templates Standardized Shielded Standard
Service Workers Strict Isolation Blocked Standard Standard

Deep Dive: Why Amnos is Different

πŸ›‘οΈ The "Nuclear Exit" Mechanic (Integrity)

Unlike other browsers, Amnos monitors its own integrity via the RiskEngine. If an Android Debugger (ADB) is attachedβ€”a common first step in forensic extractionβ€”Amnos triggers a SuperWipe. This process physically nukes the RAM buffers, wipes all session identifiers, and terminates the process (System.exit(0)) within milliseconds, leaving zero forensic debris for an attacker.

πŸ‘€ Generative Identity Consistency

Most "private" browsers randomize your User-Agent or GPU fingerprints. However, randomness itself is a signal (a "Randomized Profile" is often unique). Amnos uses a High-Entropy Generative Engine that synthesizes a logically consistent device profile. If your UA says you are a Pixel 8 Pro, your GPU, screen specs, battery discharge curve, and even your CPU core count will perfectly match a real Pixel 8 Pro.

🧹 Forensic RAM Scrambling

Clearing data is not enough. Amnos implements Forensic RAM Scrambling during its PURGE sequence. Before zero-filling memory, it saturates sensitive buffers with cryptographically secure noise. This prevents "Cold Boot" attacks and ensures that even if physical RAM is extracted immediately after a wipe, the data remains unrecoverable.

Production posture

  • Cleartext traffic disabled in the manifest and network security config
  • User-installed CAs trusted only through debug-overrides
  • Release builds no longer fall back to debug signing
  • Release APK generation is stable by default; optional shrinking enabled with -Pamnos.release.minify=true
  • Remote WebView debugging and relaxed diagnostics locked behind debug-build guards
  • Navigation routes through a tested resolver that applies the Search Dog heuristic before load
  • Address bar updates commit on successful top-level navigation instead of transient load state
  • Set-Cookie headers are stripped and WebView cookies are disabled
  • Session startup and teardown both purge WebView storage to limit crash-leftover persistence
  • Diagnostic logging is centralized through AmnosLog and surfaced in the in-app dashboard
  • Screenshot protection enforced via FLAG_SECURE when policy requires it
  • Root detection on launch β€” automatically escalates to STRICT fingerprint mode if rooted device is detected
  • Global crash resilience engine prevents force-close and wipes clipboard on fatal exceptions
  • Task Removal Cloaking β€” automatically purges the app from Android "Recents" upon close or wipe to prevent forensic residue
  • Forensic RAM Scrambling β€” saturates sensitive memory buffers with cryptographically secure noise before zero-filling
  • Absolute Proxy Lock β€” forces all JVM-level traffic through the internal secure loopback tunnel

Privacy features

Network security

  • HTTPS-only enforcement β€” all HTTP requests are blocked or upgraded; loopback proxy rejects non-CONNECT requests
  • DNS-over-HTTPS (DoH) β€” all DNS resolution routes through Cloudflare DoH (1.1.1.1 / 1.0.0.1) via OkHttp; no system resolver leakage
  • IPv6 blocking β€” optional IPv4-only resolution to prevent IPv6 address leakage
  • Loopback proxy β€” a local 127.0.0.1 CONNECT proxy intercepts all WebView traffic, enforces tunnel policy, and routes DNS through DoH
  • Tracking parameter stripping β€” utm_*, fbclid, gclid, wbraid, gbraid, msclkid, mc_eid, yclid, _hsenc, _hsmi, mkt_tok removed from every URL before load
  • Referrer stripping β€” Referer and Origin headers suppressed; Referrer-Policy: no-referrer injected into responses
  • Cookie blocking β€” WebView cookies disabled globally; Set-Cookie response headers stripped before reaching WebView; session and all cookies purged on wipe
  • Third-party request blocking β€” cross-site subresource requests blocked by policy
  • Third-party script blocking β€” cross-origin <script> loads blocked independently of full third-party blocking
  • WebSocket blocking β€” ws:// and wss:// connections blocked at both the network layer and via JS wrapper; attempts reported to the Security Cockpit
  • Local network access blocking β€” requests to localhost, *.local, RFC-1918 ranges (10.x, 172.16–31.x, 192.168.x), and loopback are blocked
  • Unsafe method blocking β€” only GET and HEAD are proxied; POST/PUT/DELETE fall through or are blocked
  • Intent jail β€” only http:// and https:// schemes are allowed in navigation; intent://, tel:, mailto:, market://, javascript:, file:, data:, content: are all blocked
  • DNT and Sec-GPC headers β€” DNT: 1 and Sec-GPC: 1 injected on every proxied request
  • Cache disabled β€” Cache-Control: no-cache, no-store on requests; Cache-Control: no-store, no-cache, max-age=0 on responses; WebView cache mode set to LOAD_NO_CACHE

Ad and tracker blocking

  • Dual blocklist engine β€” loads blocklist.txt and blocklist_comprehensive.txt from assets at startup in a background thread
  • Domain-based blocking β€” hierarchical subdomain matching against a ConcurrentHashMap of blocked domains
  • Regex pattern blocking β€” compiled patterns for ad/tracker URL structures (/ads/, /tracking/, /analytics/, /pixel/, /beacon/, etc.)
  • Keyword blocking β€” path and query keyword matching for pagead, doubleclick, googlesyndication, facebook.net/tr, UTM parameters, fbclid, gclid
  • Whitelist support β€” per-domain allow-list to exempt specific hosts from blocking
  • YouTube functional resource exemption β€” media, image, and font resources from googlevideo.com, ytimg.com, and youtube.com are exempted from tracker blocking to preserve playback

Fingerprint protection

  • Deterministic session silos β€” each session gets a UUID session ID; each tab gets a UUID tab ID; profiles are seeded from these IDs so the same session always produces the same fingerprint
  • Three protection levels β€” BALANCED (rotates across device templates per session), STRICT (fixed minimal profile, UTC timezone), DISABLED
  • Device template spoofing β€” three real-device templates (Pixel 8, Samsung S23, OnePlus) with matching user agents, screen specs, GPU vendor/renderer strings
  • User-Agent spoofing β€” spoofed at both the HTTP header level (via SecurityHeaderFactory) and the JS level (navigator.userAgent, navigator.appVersion)
  • Navigator API spoofing β€” platform, language, languages, hardwareConcurrency, deviceMemory, maxTouchPoints, webdriver, doNotTrack, plugins, mimeTypes, vendor, vendorSub, productSub, cookieEnabled, onLine, globalPrivacyControl
  • Screen spoofing β€” screen.width/height/availWidth/availHeight/colorDepth/pixelDepth, devicePixelRatio, outerWidth/Height, innerWidth/Height, screenX/Y, screenLeft/Top, screen.orientation.type/angle
  • Timezone spoofing β€” Intl.DateTimeFormat.prototype.resolvedOptions and Date.prototype.getTimezoneOffset overridden; STRICT mode forces UTC
  • Timing noise β€” Date.now, performance.now, and requestAnimationFrame timestamps quantized and jittered using a per-tab noise seed (16ms / 3ms jitter in BALANCED; 100ms / 12ms in STRICT)
  • Performance API scrubbing β€” performance.getEntries/getEntriesByType/getEntriesByName return empty; PerformanceObserver filtered; performance.timing frozen to a single base timestamp; performance.memory spoofed
  • Canvas fingerprinting β€” getImageData pixel data XOR-noised with session seed; toDataURL and toBlob inject a 1Γ—1 near-invisible noise pixel; OffscreenCanvas.convertToBlob similarly noised; measureText.width rounded in STRICT mode
  • WebGL spoofing / blocking β€” GPU vendor and renderer strings spoofed via getParameter; WebGL disabled entirely in STRICT mode
  • Audio fingerprinting β€” AudioBuffer.getChannelData noise-injected; AudioContext.createAnalyser frequency data noised; baseLatency and outputLatency spoofed; OfflineAudioContext.startRendering result noised
  • Font fingerprinting β€” document.fonts.check always returns false; document.fonts.load returns empty; FontFace undefined in STRICT mode; CSS forces sans-serif, Arial, Helvetica
  • Storage isolation β€” localStorage and sessionStorage replaced with in-memory noop stores (max 100 entries, session-scoped); indexedDB undefined; openDatabase undefined; Cache API blocked
  • WebRTC blocking β€” RTCPeerConnection, webkitRTCPeerConnection, RTCSessionDescription, RTCIceCandidate replaced with fake implementations that report attempts to the Security Cockpit and never leak IP addresses; RTCDataChannel and MediaStreamTrack undefined
  • WebSocket JS wrapper β€” native WebSocket wrapped; blocked connections throw SecurityError; allowed connections report open/close/error state to the Security Cockpit
  • Sensor blocking β€” DeviceMotionEvent, DeviceOrientationEvent, Accelerometer, Gyroscope, Magnetometer, AbsoluteOrientationSensor, RelativeOrientationSensor, LinearAccelerationSensor, GravitySensor, AmbientLightSensor, ProximitySensor all set to undefined
  • Hardware API blocking β€” USB, Bluetooth, HID, Serial, MIDI, Presentation API, XR/WebXR all blocked or return empty
  • Geolocation blocking β€” navigator.geolocation.getCurrentPosition and watchPosition call the error callback with PERMISSION_DENIED; Permissions.query returns denied for camera, microphone, geolocation, clipboard, accelerometer, gyroscope, magnetometer
  • Media device blocking β€” getUserMedia blocked and reported; enumerateDevices returns empty array
  • Battery API spoofing β€” getBattery returns a fixed profile (charging: true, level: 0.76)
  • Network Information API spoofing β€” effectiveType: "4g", downlink: 10, rtt: 50, type: "wifi"
  • Beacon API interception β€” navigator.sendBeacon intercepted; blocked when tracker blocking is active
  • CSS media query spoofing β€” prefers-color-scheme forced to light; prefers-reduced-motion forced to false; prefers-contrast forced to no-preference; inverted-colors forced to false
  • Pointer/Touch event normalization β€” PointerEvent pressure/tilt/twist normalized; Touch force/rotation/radius normalized
  • Error stack sanitization β€” in STRICT mode, file paths in stack traces replaced with <sanitized>
  • History length spoofing β€” history.length returns 2 in STRICT mode
  • Notification API β€” Notification.permission always "denied"; requestPermission resolves to "denied"
  • Vibration API β€” navigator.vibrate returns false
  • Wake Lock API β€” navigator.wakeLock.request and screen.keepAwake blocked
  • Idle Detection API β€” IdleDetector set to undefined
  • Gamepad API β€” navigator.getGamepads returns empty array
  • Keyboard Lock API β€” navigator.keyboard.lock blocked
  • Speech Synthesis β€” speechSynthesis.getVoices returns at most one voice
  • Scheduling API β€” navigator.scheduling.isInputPending always returns false
  • Service worker blocking β€” navigator.serviceWorker.register blocked (except on search engines); getRegistration/getRegistrations return empty
  • eval / Function constructor blocking β€” window.eval and window.Function throw SecurityError; WebAssembly.compile/instantiate blocked
  • DNS prefetch / preconnect scrubbing β€” <link rel="dns-prefetch|preconnect|prefetch|prerender|modulepreload"> elements removed by MutationObserver
  • Inline script blocking β€” dynamically injected <script> tags without src removed by MutationObserver when policy requires
  • Referrer JS spoofing β€” document.referrer returns "" when referrer stripping is active
  • Storage quota spoofing β€” navigator.storage.estimate returns { usage: 0, quota: 0 }; persisted/persist return false
  • Clipboard JS blocking β€” navigator.clipboard.readText/writeText/read/write all blocked

Session and storage security

  • Zero persistent state β€” domStorageEnabled and databaseEnabled disabled in WebView settings; cacheMode = LOAD_NO_CACHE
  • Physical storage nuke β€” StorageService.purgeGlobalStorage deletes cookies, WebStorage, form data, HTTP auth credentials, client cert preferences, and physically deletes the app_webview_amnos_session directory
  • Volatile downloads β€” downloads stored in cacheDir/volatile_downloads with UUID-prefixed filenames; directory wiped on session end
  • Clipboard wipe β€” ClipboardSentinel uses clearPrimaryClip() on API 33+; falls back to empty sensitive clip with IS_SENSITIVE extra on API 31+
  • Background wipe β€” onStop triggers killAll when not rotating; onTrimMemory triggers wipe at TRIM_MEMORY_UI_HIDDEN
  • Session timeout β€” configurable inactivity timeout (default 2 minutes) triggers automatic wipe and session reset
  • GHOST wipe β€” kill switch destroys all tabs, clears logs, wipes clipboard, purges storage, rotates session ID, and optionally calls Process.killProcess
  • Strict first-party isolation β€” cross-site top-level navigations recreate the WebView tab with a fresh fingerprint profile
  • Identity reset on refresh β€” tab profile can be regenerated on page refresh

WebView hardening

  • Ghost Keyboard β€” custom in-app Compose keyboard (alpha + symbol layouts).
    • Premium Feedback β€” real-time key popups and Material 3-grade haptics.
    • Sanitization Shortcuts β€” "Long-press to Clear All" on the backspace key for instant field zeroing.
    • High-Density Adaptive β€” automatically reduces height in landscape to preserve browsing visibility.
  • Interactive UI & Safety
    • Sandbox Mode Selector β€” toggle between PARANOID (Silent zero-trust) and BALANCED (Gated confirm) modes.
    • Navigation Safety Dialogs β€” explicit user confirmation required to leave the secure sandbox for external apps.
    • Threat Alert Banner β€” real-time detection and HUD warning if Accessibility Scrapers are active on the device.
  • Autofill disabled β€” IMPORTANT_FOR_AUTOFILL_NO_EXCLUDE_DESCENDANTS
  • Password/form save disabled β€” savePassword = false, saveFormData = false
  • File access disabled β€” allowFileAccess, allowContentAccess, allowFileAccessFromFileURLs, allowUniversalAccessFromFileURLs all false
  • Geolocation disabled β€” setGeolocationEnabled(false)
  • Mixed content blocked β€” MIXED_CONTENT_NEVER_ALLOW
  • Safe Browsing β€” enabled; onSafeBrowsingHit intercepted to show Amnos blocked page instead of Google's interstitial
  • SSL error handling β€” all SSL errors cancel navigation and log to diagnostics
  • Pop-up blocking β€” setSupportMultipleWindows(false); onCreateWindow returns false
  • File chooser blocked β€” onShowFileChooser returns null to the callback
  • Hardware permission denial β€” PermissionSentinel silently denies all PermissionRequest resources (camera, microphone, etc.)
  • Geolocation permission denial β€” onGeolocationPermissionsShowPrompt always denies
  • Long-press disabled β€” setOnLongClickListener { true } suppresses context menus
  • Over-scroll disabled β€” OVER_SCROLL_NEVER
  • Haptic feedback disabled β€” isHapticFeedbackEnabled = false
  • Media autoplay blocked β€” mediaPlaybackRequiresUserGesture = true
  • Document-start script injection β€” fingerprint obfuscation script injected via WebViewCompat.addDocumentStartJavaScript before any page JS runs
  • Security bridge β€” WebMessageListener (amnosBridge) validates HTTPS origin and host match before accepting messages from page JS
  • Service worker hardening β€” ServiceWorkerControllerCompat sets LOAD_NO_CACHE, disables content/file access
  • WebView data directory isolation β€” WebView.setDataDirectorySuffix("amnos_session") isolates storage from other WebView users

Content security

  • Permissions-Policy header β€” injected on document responses: blocks accelerometer, ambient-light-sensor, autoplay, battery, camera, clipboard-read/write, geolocation, gyroscope, magnetometer, microphone, payment, USB, XR
  • Content-Security-Policy β€” dynamically built per-request: default-src https:, object-src 'none', base-uri 'none', frame-ancestors 'none', upgrade-insecure-requests; script/connect sources tightened based on active policy flags
  • X-DNS-Prefetch-Control: off β€” injected on all document responses
  • Referrer-Policy: no-referrer β€” injected on all responses

UI security

  • Screenshot protection β€” FLAG_SECURE applied to the window when blockScreenshots policy is active
  • Security Cockpit β€” bottom-sheet dashboard with three tabs:
    • SHIELDS β€” toggles for HTTPS-only, tracker blocking, third-party blocking, inline scripts, WebSockets, JavaScript mode, WebGL, fingerprint level, first-party isolation, identity reset on refresh
    • INSPECTOR β€” live request log (last 100 entries) with URL, method, type, disposition (ALLOWED / BLOCKED / PASSTHROUGH), third-party flag, and block reason
    • IDENTITY β€” session ID, fingerprint level, proxy status, DoH status, WebRTC status, WebSocket status, attempt counters, active connections
  • Tracker badge β€” live counter of blocked trackers in the browser toolbar
  • Burn session button β€” animated kill-switch button with burn overlay animation
  • Internal diagnostics log β€” last 100 internal log entries surfaced in the dashboard

Amnos is organized into seven identifiable security clusters:

  • πŸ‘» STEALTH: Cloaking and camouflage orchestration (NavigationGuard, ResourceGuard).
  • 🧹 PURGE: Forensic sanitization and wipe agents (SuperWipeEngine, ForensicFileSystemNuke).
  • ⚑ NETWORK: Encrypted transport and loopback proxy (NetworkTrafficConfigurator, LoopbackProxyServer).
  • πŸ›‘ FILTER: Request filtering and tracking suppression (AdBlocker, FilterRegistry).
  • πŸ‘€ IDENTITY: Profile spoofing and session siloing (FingerprintManager, SecureVault).
  • βš™οΈ HARDWARE: API restriction and sensor masking (PolicyController, TabManager).
  • πŸ› οΈ DEBUG: Integrity monitoring and forensic auditing (RiskEngine, ForensicAuditLog).

Validation commands

Windows:

.\gradlew.bat clean testDebugUnitTest lintDebug assembleRelease

Project verification script:

powershell -ExecutionPolicy Bypass -File .\scripts\verify_build.ps1

Documentation map


Honest limits

  • Some sites will break by design because Amnos disables cookies, strips tracking state, and blocks invasive browser capabilities.
  • Real leak validation still requires device or emulator testing against live WebRTC, DNS, and fingerprint test sites.
  • WebView and Android system behavior still define the ultimate trust boundary.
  • Amnos does not provide network-layer anonymity β€” it is not Tor and does not route traffic through an anonymizing network.
  • DoH protects DNS from local observers but does not hide DNS queries from the upstream resolver (Cloudflare).

About

No description, website, or topics provided.

Resources

Code of conduct

Contributing

Security policy

Stars

2 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages