Open Source · Linux · MIT License
Entropy Shield

Privacy, layered.
One interface.

A modern Linux desktop privacy stack combining Tor, DNSCrypt, I2P, and Onion Server — controlled through a single polished GUI.

Tor Transparent Proxy DNSCrypt I2P Network Onion Server nftables / iptables Multi-distro
Entropy Shield UI
4
Privacy Layers
5+
Distros Supported
0
Footprint on Exit
1
Click to Connect
Why Entropy Shield

Everything you need,
nothing you don't

Stop wrestling with configs. Entropy Shield orchestrates your entire privacy stack with zero residue.

Layered Privacy

Combine Tor, DNSCrypt, I2P, and Onion Server in any combination. Each layer adds a dimension of anonymity — use one or all four simultaneously.

Firewall Integration

nftables and iptables rules are applied at connect and cleanly removed at disconnect. Your firewall state is always consistent and predictable.

IPv6 Leak Protection

Separate ip6 table rules block all IPv6 traffic under Tor, preventing leaks through a protocol Tor's TransPort cannot handle.

Built-in Onion Server

Publish any local directory as a Tor hidden service. Choose a folder, click connect, and your .onion address appears in the activity log.

Privacy Browsers

Launch isolated Firefox instances pre-configured for Tor or I2P with WebRTC disabled. Your normal browser profile is never touched.

Zero Footprint

All config changes are backed up before modification and restored on disconnect. Entropy Shield leaves your system exactly as it found it.

5 Themes

OLED, Pixel, Circuit, Binary, and Light — each with a unique visual identity and matching logo. Switch in one click.

System Tray

Minimize to tray and keep Entropy Shield running in the background. Disconnect or quit directly from the notification area icon.

NixOS Native

Declarative NixOS module with no mutable config patching. Services are on-demand systemd units — they never auto-start at boot.

Themes

Five identities,
one tool

Every theme ships its own logo and color palette. Click to apply — the whole page transforms.

OLED Theme
OLED
Pixel Theme
PIXEL
Circuit Theme
CIRCUIT
Binary Theme
BINARY
Light Theme
LIGHT
Privacy Layers

Four layers of anonymity,
one control panel

Each layer is independent and configurable. Stack them for maximum anonymity or use only what you need.

Tor
Transparent Proxy

Routes all TCP traffic through the Tor network using nftables REDIRECT rules. DNS queries are redirected to Tor's DNSPort. All IPv6 is blocked to prevent leaks. Supports custom exit nodes and StrictNodes.

DNSCrypt
Encrypted DNS

Encrypts DNS queries via dnscrypt-proxy. Redirects both IPv4 and IPv6 DNS traffic through the proxy. Enforces no-log and no-filter server requirements. Integrates with systemd-resolved via resolvectl.

I2P
Anonymity Network

Starts i2pd and configures HTTP/SOCKS proxies. With redsocks installed, enables full transparent proxy mode for all TCP. Combined with Tor, I2P traffic tunnels through Tor's SOCKS port for extra anonymity.

Onion Server
Hidden Service

Starts a built-in HTTP file server and publishes it as a Tor hidden service. Choose any directory to serve — its contents become accessible at a .onion address shown in the activity log. Requires Tor (enforced automatically).

Installation

Up and running
in seconds

Universal installer auto-detects your distribution and handles everything — packages, polkit, desktop entry, and more.

bash
# Recommended — auto-detects your distro
git clone https://github.com/berk-kucuk/entropy-shield.git
cd entropy-shield
bash installers/install.sh

# Override distro detection if needed:
# DISTRO_ID=arch bash installers/install.sh
bash
# Arch Linux — install from AUR with paru
paru -S entropy-shield

# Or with yay:
yay -S entropy-shield
About AUR Installation
The AUR package installs all dependencies automatically and integrates with your system. After installation, run entropy-shield from your terminal or application menu.
bash
# Arch Linux · Manjaro · EndeavourOS · Garuda
git clone https://github.com/berk-kucuk/entropy-shield.git
cd entropy-shield
bash installers/install-arch.sh

# To install via AUR → see the "AUR (Paru / Yay)" tab
bash
# Debian · Ubuntu · Linux Mint · Kali · Pop!_OS
git clone https://github.com/berk-kucuk/entropy-shield.git
cd entropy-shield
bash installers/install-debian.sh
bash
# Fedora · RHEL · AlmaLinux · Rocky Linux
git clone https://github.com/berk-kucuk/entropy-shield.git
cd entropy-shield
bash installers/install-fedora.sh
bash
# NixOS — generates declarative module
git clone https://github.com/berk-kucuk/entropy-shield.git
cd entropy-shield
bash installers/install-nixos.sh

# Automatically added to /etc/nixos/configuration.nix:
# imports = [ ./entropy-shield.nix ];
bash
# Manual / development install
git clone https://github.com/berk-kucuk/entropy-shield.git
cd entropy-shield
pip install PyQt6
sudo python3 main.py
After installation
Run entropy-shield from your application menu or terminal. The app requests elevated privileges via pkexec on first launch — subsequent launches authenticate transparently without a password dialog.
Architecture

Clean, modular design

Each privacy service has its own module. The GUI is fully decoupled from the core logic.

entropy-shield/
entropy-shield/
├── main.py                  # entry point — pkexec privilege escalation
├── core/
│   ├── config.py            # JSON config with deep-merge defaults
│   ├── connection.py        # orchestrates all layers (connect/disconnect)
│   ├── tor.py               # torrc patching, DNS redirect, systemd control
│   ├── dnscrypt.py          # dnscrypt-proxy config, IPv6, resolved
│   ├── i2p.py               # i2pd config, redsocks transparent proxy
│   ├── onion_server.py      # hidden service + built-in HTTP file server
│   ├── browser.py           # isolated Firefox launcher (Tor / I2P)
│   ├── firewall.py          # nftables / iptables, IPv6 leak prevention
│   ├── tray_helper.py       # system tray subprocess (runs as real user)
│   └── platform.py          # NixOS detection, firewall backend selection
├── gui/
│   ├── main_window.py       # main window, animated glow border, worker thread
│   ├── settings_panel.py    # slide-in settings overlay
│   ├── themes.py            # 6 themes: oled/dark/pixel/circuit/binary/light
│   └── widgets.py           # ServiceCard, StatusRing, Spinner, ToggleSwitch
├── logos/
│   └── *.png                # per-theme logo assets
└── installers/
    ├── install.sh           # universal distro-detecting installer
    ├── install-arch.sh
    ├── install-debian.sh
    ├── install-fedora.sh
    └── install-nixos.sh
Supported Distributions

Works everywhere you do

One installer, five ecosystems, zero headaches.

Arch Linux
Manjaro · EndeavourOS · Garuda
pacmanAUR
Debian
Ubuntu · Mint · Kali · Pop!_OS
apt
Fedora
RHEL · AlmaLinux · Rocky Linux
dnf
openSUSE
Leap · Tumbleweed
zypper
NixOS
Declarative module · No mutable configs
nixos-rebuild
How It Works

One click, full stack

Entropy Shield orchestrates every service in the correct order — connect and disconnect are fully atomic operations.

1
Select Layers

Toggle the service cards you want: Tor, DNSCrypt, I2P, Onion Server — any combination works.

2
Click CONNECT

Configs are patched, services are started via systemctl, and firewall rules are applied atomically.

3
DNS Redirected

systemd-resolved is pointed at the active proxy via resolvectl — no manual resolv.conf editing.

4
Traffic Routed

nftables REDIRECT rules transparently route all TCP through your chosen layers. IPv6 is blocked under Tor.

5
Click DISCONNECT

Rules flushed, services stopped, all config files restored from backup. Zero residue on your system.

CONNECT flow
  • →Original config files backed up with .entropy-shield.bak suffix
  • →If Onion Server enabled, hidden service block appended to torrc and HTTP file server started
  • →Services started via systemctl restart in dependency order
  • →systemd-resolved pointed at active proxy via resolvectl
  • →FirewallManager applies nftables rules — TCP redirect, DNS redirect, IPv6 drop (Tor mode)
  • →Status ring turns green, animated border glow activates
DISCONNECT flow
  • →DNS settings restored via resolvectl
  • →Firewall rules flushed — both table ip and table ip6
  • →HTTP file server shut down in background thread (non-blocking)
  • →All started services stopped via systemctl stop
  • →Config files restored from .entropy-shield.bak backups
  • →System proxy environment variables cleared
Privacy Browsers

Isolated Firefox,
zero contamination

Launch pre-configured Firefox instances for Tor or I2P. Your normal profile is never touched, never contaminated.

TOR BROWSER

Isolated Firefox instance routed through Tor's SOCKS5 proxy with remote DNS resolution.

ProxySOCKS5 → 127.0.0.1:9050
Remote DNSsocks_remote_dns=true
WebRTCdisabled
DNS Prefetchdisabled
DoHdisabled
Profile/tmp/entropy-shield-ff-tor/
Note: Browsers with DNS-over-HTTPS (DoH) bypass nftables rules entirely — DoH is disabled here. Disable DoH in your normal browser if relying on DNSCrypt.
I2P BROWSER

Isolated Firefox instance routed through I2P's HTTP and SOCKS proxies with the router console as homepage.

HTTP Proxy127.0.0.1:4444
SOCKS5127.0.0.1:4447
HomepageI2P router console
DNS Prefetchdisabled
DoHdisabled
Profile/tmp/entropy-shield-ff-i2p/
Note: Media peer connections and HTTPS prefetch are also disabled to prevent any DNS or IP leaks through browser-level protocols.
DNS Leak Prevention

No DNS, no leak

Every scenario is covered — IPv4 and IPv6 DNS traffic is locked down regardless of which layers are active.

ScenarioIPv4 DNSIPv6 DNSDirect IPv6
Tor active→ Tor DNSPortStack blockedBlocked (ip6 DROP)
DNSCrypt active→ dnscrypt-proxy→ [::1]:portUnrestricted
I2P activeSystem defaultSystem defaultUnrestricted
Tor + DNSCrypt→ dnscrypt-proxyStack blockedBlocked (ip6 DROP)
Tor + I2P→ Tor DNSPortStack blockedBlocked (ip6 DROP)
All layers→ dnscrypt-proxyStack blockedBlocked (ip6 DROP)
Configuration

Every detail,
under your control

Settings stored at ~/.config/entropy-shield/config.json — editable via the in-app Settings panel or directly.

Tor
TransPort9040
DNSPort5300
SOCKSPort9050
ExitNodes{us},{de},{nl}
StrictNodesfalse
DNSCrypt
Port5353
Require DNSSECfalse
Require no-logtrue
Require no-filtertrue
I2P
HTTP Port4444
SOCKS Port4447
Max Bandwidth0 (unlimited)
Onion Server
Local HTTP Port8080
Onion Port80
Serve Directory~ (home)
~/.config/entropy-shield/config.json
{
  "theme": "oled",
  "tor": {
    "trans_port":  9040,
    "dns_port":    5300,
    "socks_port":  9050,
    "exit_nodes":  "",
    "strict_nodes": false
  },
  "dnscrypt": {
    "port":             5353,
    "require_dnssec":   false,
    "require_nolog":    true,
    "require_nofilter": true
  },
  "i2p": {
    "http_port":     4444,
    "socks_port":    4447,
    "max_bandwidth": 0
  },
  "onion_server": {
    "local_port": 8080,
    "hs_port":    80,
    "serve_dir":  ""
  }
}
Legal Disclaimer / Sorumluluk Reddi

Entropy Shield is a general-purpose privacy and anonymity tool intended for legitimate use cases such as protecting personal data, bypassing censorship in restrictive regions, security research, and educational purposes.

You are solely responsible for how you use this software. The author and contributors do not endorse, encourage, or support any illegal activity. Use of Entropy Shield to violate any applicable law — including but not limited to unauthorized access to computer systems, distribution of illegal content, or circumvention of lawful restrictions — is strictly prohibited.

This software is provided "as is", without warranty of any kind, express or implied. The author makes no guarantee of anonymity or security. Network anonymity tools reduce exposure but cannot guarantee complete protection against all adversaries. Always assess your own threat model.

By downloading or using Entropy Shield, you confirm that you are in compliance with all laws applicable to your jurisdiction and that you accept full legal responsibility for your actions.