Custom OS · Raspberry Pi 4 / 5
MSNet
A hardened custom operating system that turns a Raspberry Pi 4 or 5 into a multi-tunnel privacy router — per-device VPN routing, OS-fingerprint spoofing, encrypted DNS and zero-leak by design.
__ __ ___ _ _ _ | \/ / __| \| |___ | |_ | |\/| \__ \ .` / -_)| _| |_| |_|___/_|\_\___| \__| MSNet v1.0.0 “Umbra” Anti-fingerprint router · privacy by design
Everything the box does
One appliance. Every layer of network privacy, controlled per device.
Anti-fingerprint engine
Per-device OS profiles rewrite each client's TCP/IP signature in-path — TTL, window size, MSS, option order, DF and ECN bits — so every device on your LAN looks like a different machine to the outside world. An optional zapret DPI-desync layer plugs in where deep packet inspection blocks tunnels.
Modern tunnels
SOCKS5, WireGuard, OpenVPN, DPI-resistant AmneziaWG, ZeroTier mesh, plus sing-box protocols: VLESS-Reality, VMess, Trojan, Shadowsocks, Hysteria2 and TUIC.
VPN chaining
Stack tunnels into multi-hop routes — send one VPN through another so your exit IP is two networks away from your uplink.
Per-device routing
Pin any device (by MAC) to its own bridge and tunnel. Phone through Germany, laptop through Japan, TV direct — all from one box, at the same time.
Encrypted DNS · no leaks
DNS-over-HTTPS per tunnel with the client subnet stripped, WebRTC/STUN leak blocking, IPv6 leak guard, ICMP-timestamp and mDNS filtering, NTP pinned to the box, and a kill-switch that drops all client traffic the instant a tunnel goes down.
Wi-Fi APs & LAN bridges
Broadcast multiple SSIDs, each bound to its own tunnel. Clients land on isolated bridges over Wi-Fi or Ethernet — pick your exit by which network you join.
Live control panel
A web UI and a native desktop app (Linux) with mDNS auto-discovery, live client list, real-time traffic graph and one-click leak tests.
Signed OTA updates
Apply new firmware straight from the panel — update bundles are Ed25519-signed and verified on-device before they install, so the box upgrades in place without re-flashing.
REST API & tokens
Everything the UI does is a REST call. Mint and revoke bearer tokens for headless, scripted control — automate tunnels, bridges and device routing from your own tooling.
Telegram control
Run a local Telegram bot to check status and drive the box from your phone. A chat allowlist locks it to you, and it authenticates back over loopback — no ports exposed.
Phone Mirror
Mirror and drive a USB-connected Android phone straight from the panel — live screen over the phone's own H.264 encoder, tap, swipe and type from the browser. No app on the phone, just USB debugging; a license-gated addon.
In-panel console
A real PTY-backed shell right in the browser over a secure WebSocket — full terminal access to the appliance without SSH, gated for locked-down deployments.
Privacy by design
Secrets encrypted at rest, a sealed appliance and signed over-the-air updates. No cloud account, no telemetry — it runs entirely on your own LAN.
Phone tethering as uplink
Plug in an Android or iPhone over USB and MSNet uses it as the WAN — as your primary link or an automatic failover when the wired/Wi-Fi uplink drops. iPhone pairing is handled on hotplug.
WAN MAC spoofing
Present a random, stable or explicit MAC on the WAN uplink — so the upstream network can't fingerprint or track the box by its hardware address. Permanent mode restores the real one.
Wi-Fi RF survey
Scan the local RF environment: every access point around you, per BSSID — SSID, channel, band, signal and security, hidden networks included. Fully on-device; nothing is sent to any positioning service.
See every tunnel at a glance
Live status, per-tunnel traffic and one-click device routing — from the web UI or the native desktop app.
Dashboard
3 tunnels upIllustration of the MSNet panel — layout and data are representative.
How the box is built
A coordinator orchestrates isolated network namespaces — one per tunnel — each with its own engine, DNS and fingerprint rewriter.
One engine, every protocol
Paste a config and MSNet routes it. VPNs, mesh, proxies and censorship-resistant transports — side by side.
| Protocol | Category | Highlights |
|---|---|---|
| WireGuard | VPN | Kernel-fast, modern crypto |
| AmneziaWG | VPN · anti-censorship | DPI-resistant WireGuard fork |
| OpenVPN | VPN | Broad compatibility, TCP/UDP |
| ZeroTier | Mesh | Peer-to-peer virtual LAN |
| SOCKS5 | Proxy | Any host:port, optional auth |
| VLESS-Reality | sing-box | TLS camouflage, no cert needed |
| VMess | sing-box | Classic V2Ray transport |
| Trojan | sing-box | Looks like plain HTTPS |
| Shadowsocks | sing-box | Lightweight encrypted proxy |
| Hysteria2 | sing-box | QUIC, high throughput on lossy links |
| TUIC | sing-box | QUIC-based, low latency |
Three steps to private
No cloud, no account. Flash the card, connect, and route.
Flash the image
Write the MSNet OS image to an SD card and boot your Raspberry Pi 4 or 5. The whole stack comes baked in.
Connect & discover
Open the desktop app or web panel — it finds the box on your LAN automatically over mDNS. No IP typing.
Route each device
Paste a proxy or VPN, spin up an SSID, assign devices and OS profiles. Traffic flows through the tunnel, fingerprint-spoofed and leak-free.
Who runs an MSNet box
One appliance, many shapes of privacy.
Travel & public Wi-Fi
Carry your own trusted exit. Every device that joins the box's SSID rides an encrypted tunnel — no matter how sketchy the café or hotel network is.
A household with mixed needs
Kids' tablet goes direct, the work laptop exits through the corporate region, the TV lands in another country for its catalog — all at once, all from one box.
Research & OSINT
Give each device its own exit IP and OS fingerprint. Run parallel investigations without cross-contaminating identities or leaking your real signature.
Self-hosted privacy
No monthly VPN app, no vendor lock-in. Bring your own tunnels and proxies, keep the keys, and run the whole thing on hardware you physically own.
What you need
Off-the-shelf hardware. Flash and boot — no installer, no cloud.