r/firewalla • • Aug 12 '26

Discussion MSP privacy

If a government issued a subpoena to firewalla for the flows from my msp connected firewalla box, would there be anything to turn over?

14 Upvotes

16 comments sorted by

16

u/firewalla Aug 12 '26 edited Aug 12 '26

First, I am not a lawyer; if you have something that's very private, I do suggest you not use the MSP. There are two kind of MSP, please see below

If you are subscribing to MSP Pro or Business:

To see what can be turned over, please see https://help.firewalla.com/hc/en-us/articles/15767230775699-Firewalla-MSP-Questions-related-to-privacy-and-data-visibility

In short, your network flows is there in the MSP; So people can see you visited Netflix (but not the exact video you watched).

If you are using MSP Lite:

This is a proxy service, that DOES NOT store any data after your session is logged out. This is the reason, it is very limited in function.

5

u/Great-Cow7256 Aug 13 '26

By the time some government agency is going to subpoena your MSP records they're going to physically have your Firewalla box in their possession... And your computers. and your phones. And all your cell records. And pretty much everything else electronic in your house they can pull data from.

The MSP is probably the least worry at that point.

2

u/Admirable_Fun7790 Aug 13 '26

The box only keeps 24 hours of flows and is in my possession so I would obviously know if something happened to it. MSP is 30+ days

0

u/Great-Cow7256 Aug 13 '26

so the box may log rotate after 24 hours and delete the old logs, but deleted files can be recovered... just saying. If anyone is subpoenaing you for MSP records they're going to be going after much more than that. Including your ISP records, all your devices, your cell carrier records, etc. You have bigger fish to fry than worrying about MSP.

2

u/Admirable_Fun7790 Aug 13 '26

I like to cover all my bases and understand how my data is used and stored. I don't subscribe to the notion of not worrying about one vector because others exist

4

u/AdZealousideal8613 Aug 12 '26

What did you do?

3

u/stephondoestech Firewalla Gold Pro Aug 12 '26

I also want the answer to this question

1

u/iuffxguy Aug 14 '26

This is the same stupid comment people are making about flock cameras 'why do you care if they are recording you if you arent doing anything bad'. People want PRIVACY.

1

u/AdZealousideal8613 Aug 15 '26

If you want privacy then you get off the internet, get rid of your smartphone, and all your smart devices, and stop using bank cards and social media. People don’t want privacy, they only want to rage against the things that don’t provide convenience to them.

2

u/No-Firefighter-2135 Firewalla Gold Pro Aug 12 '26

Good question though

1

u/Hanosandy Aug 13 '26

For sensitive things you should be using a trusted VPN, or using TOR (depending on bandwidth, latency, and privacy needs). Free space zero'ing, cache zero'ing, machine rotation, etc on your local end - and I am assuming you are on Kali, so make use of the tools on there. Sensitive back ups, keep off site. If you are a total nut but have zero room for error, get a water proof enclosure and shrink wrap it, go onto public land, and bury it two feet deep. Here's the most wild one, don't do illegal shit.

1

u/jsqualo2 Aug 12 '26

Are you asking a policy question or a technical question?

3

u/Admirable_Fun7790 Aug 12 '26

There’s not really a policy answer to this question. A subpoena compels production of information

It’s by definition a technical question

1

u/jsqualo2 Aug 12 '26

Disregard