[HN Gopher] Android leaks some traffic even when 'Always-on VPN'...
       ___________________________________________________________________
        
       Android leaks some traffic even when 'Always-on VPN' is enabled
        
       Author : godelski
       Score  : 27 points
       Date   : 2022-10-14 17:39 UTC (5 hours ago)
        
 (HTM) web link (www.bleepingcomputer.com)
 (TXT) w3m dump (www.bleepingcomputer.com)
        
       | 4oo4 wrote:
       | I'm curious whether this is an AOSP or Google Play Services
       | thing, and whether de-Googled LineageOS would also be affected.
       | 
       | EDIT: Looks to be AOSP according to this
       | https://issuetracker.google.com/issues/249990229?pli=1
        
         | h4waii wrote:
         | I hate to come across as someone who just responds with the
         | equivalent of "Simpsons did it", but GrapheneOS has mitigated
         | this for quite some time.
         | 
         | The main AOSP derivatives, including LineageOS don't address it
         | at all.
        
       | Melatonic wrote:
       | I wonder if this also applies if you use their in house app
       | "intra" which is made for journalists and whistleblowers (part of
       | the Google Jigsaw project) to avoid getting exposed?
        
       | metadat wrote:
       | A similar story, except for iOS, was discussed two days ago:
       | 
       | https://news.ycombinator.com/item?id=33177629
       | 
       | (154 points, 76 comments)
        
       | woojoo666 wrote:
       | Looks to be a duplicate of a post from yesterday
       | https://news.ycombinator.com/item?id=33194105
       | 
       | Anyways reposting my comment from that thread:
       | 
       | Seems like even if you enable the option to block connections
       | outside a VPN, Android is designed to still do connectivity
       | checks for special cases like identifying captive portals (like
       | hotel WiFi).
       | 
       | From the article:
       | 
       | > "Even if the content of the message does not reveal anything
       | more than "some Android device connected", the metadata (which
       | includes the source IP) can be used to derive further
       | information, especially if combined with data such as WiFi access
       | point locations."
       | 
       | > Mullvad is still debating the significance of the data leak
       | with Google, calling them to introduce the ability to disable
       | connectivity checks and minimize liability points.
       | 
       | > Notably, GrapheneOS, Android-based privacy and security-focused
       | operating system that can run on a limited number of smartphone
       | models, provides this option with the intended functionality.
        
       | josephcsible wrote:
       | It seems like every week it's another OS where a problem like
       | this is discovered. If it's critical that your traffic goes over
       | a VPN, you really need to be using something like Whonix.
        
         | woojoo666 wrote:
         | Or GrapheneOS, which as mentioned in the article, already
         | addressed this issue
        
       ___________________________________________________________________
       (page generated 2022-10-14 23:02 UTC)