[HN Gopher] Android leaks some traffic even when 'Always-on VPN'...
___________________________________________________________________
Android leaks some traffic even when 'Always-on VPN' is enabled
Author : godelski
Score : 27 points
Date : 2022-10-14 17:39 UTC (5 hours ago)
(HTM) web link (www.bleepingcomputer.com)
(TXT) w3m dump (www.bleepingcomputer.com)
| 4oo4 wrote:
| I'm curious whether this is an AOSP or Google Play Services
| thing, and whether de-Googled LineageOS would also be affected.
|
| EDIT: Looks to be AOSP according to this
| https://issuetracker.google.com/issues/249990229?pli=1
| h4waii wrote:
| I hate to come across as someone who just responds with the
| equivalent of "Simpsons did it", but GrapheneOS has mitigated
| this for quite some time.
|
| The main AOSP derivatives, including LineageOS don't address it
| at all.
| Melatonic wrote:
| I wonder if this also applies if you use their in house app
| "intra" which is made for journalists and whistleblowers (part of
| the Google Jigsaw project) to avoid getting exposed?
| metadat wrote:
| A similar story, except for iOS, was discussed two days ago:
|
| https://news.ycombinator.com/item?id=33177629
|
| (154 points, 76 comments)
| woojoo666 wrote:
| Looks to be a duplicate of a post from yesterday
| https://news.ycombinator.com/item?id=33194105
|
| Anyways reposting my comment from that thread:
|
| Seems like even if you enable the option to block connections
| outside a VPN, Android is designed to still do connectivity
| checks for special cases like identifying captive portals (like
| hotel WiFi).
|
| From the article:
|
| > "Even if the content of the message does not reveal anything
| more than "some Android device connected", the metadata (which
| includes the source IP) can be used to derive further
| information, especially if combined with data such as WiFi access
| point locations."
|
| > Mullvad is still debating the significance of the data leak
| with Google, calling them to introduce the ability to disable
| connectivity checks and minimize liability points.
|
| > Notably, GrapheneOS, Android-based privacy and security-focused
| operating system that can run on a limited number of smartphone
| models, provides this option with the intended functionality.
| josephcsible wrote:
| It seems like every week it's another OS where a problem like
| this is discovered. If it's critical that your traffic goes over
| a VPN, you really need to be using something like Whonix.
| woojoo666 wrote:
| Or GrapheneOS, which as mentioned in the article, already
| addressed this issue
___________________________________________________________________
(page generated 2022-10-14 23:02 UTC)