Another way to leak traffic on Android has been discovered
Posted by mhitza 17 hours ago
Comments
Comment by brinepot 4 hours ago
Comment by grapheneos 31 minutes ago
Comment by exceptione 8 minutes ago
> We plan to heavily overhaul the VPN implementation to make most forms of leaks nearly impossible rather than continuing to use the current system prone to it.
Thanks, great to hear. Given the slew of bugs you uncovered it seems the Android implementation has some rough edges. Would `pasta` be helpful to you? It allows you to unshare netns and then pass a user-space network adapter inside. https://passt.top/passt/about/ Podman leverages this one as well in more recent versions.Comment by exceptione 6 hours ago
Comment by exceptione 6 hours ago
> A proper fix would require changes in the Android system. The researcher who discovered the leak has reported the issue to the Android Vulnerability Reward Program, but according to the researcher the issue was closed without action. This issue is not public, but based on this information we deem it unlikely that Google will do anything about it. GrapheneOS is aware of the issue and are working on a fix.
If the account given by the researcher is correct, we cannot rule out that Google deliberately introduced or wanted to keep the leak in place.Comment by jjav 6 hours ago
I'd say a lot stronger than "cannot rule out". Regardless of how it was introduced, if it is now known and the issue was closed without action, they are actively choosing to keep it.
Comment by grapheneos 46 minutes ago
Comment by gib444 4 hours ago
N.B. I don't disagree there is a possibility of foul play on Google's part, but I think more evidence / better argument is required.
[0] https://github.com/GrapheneOS/os-issue-tracker/issues/8617#i...
Comment by exceptione 4 hours ago
Google just closed the ticket, without communicating their plan to deal with it. I just stated that we cannot rule out a possibility of foul play, thereby keeping other options open. Keeping that thing in mind which is better known as "the reality" I would be a little bit more wary about Google's stance towards privacy than I would be about GOS though. The difference in how these parties are handling this issue is already a tell.
Comment by nvme0n1p1 4 hours ago
Comment by gib444 3 hours ago
Comment by kennethkl 2 hours ago
a person walks up to you, punches you in the face, and leaves.
it could have been an accident, an AI bot, or a misunderstanding. definitely not deliberate.
Comment by gib444 2 hours ago
By your logic, the GOS lack of reply was deliberate too.
Comment by grapheneos 24 minutes ago
Comment by grapheneos 47 minutes ago
Comment by nonamesleft 6 hours ago
Comment by exceptione 6 hours ago
I have a hunch this leak is bound to wifi hardware only, for details: https://supuk.ch/papers/android-natt-keepalive-vpn-bypass
Comment by aucisson_masque 9 hours ago
Good guy Google, as usual.
Comment by grapheneos 16 minutes ago
Comment by potatoproduct 4 hours ago
Comment by TutleCpt 4 hours ago
Comment by gib444 4 hours ago
Do any similar leaks exists on iOS currently?
Comment by xicolo 8 hours ago
Comment by arunvpp 17 hours ago
Comment by lsaferite 14 hours ago
Comment by gib444 1 hour ago
Comment by tosti 4 hours ago
Comment by gib444 2 hours ago
An individual: you're a pedo if you use a VPN
Give over.
Comment by tosti 1 hour ago