Live data from Hacker News

GrapheneOS fixes Android VPN leak Google refused to patch

cyberinsider.com

11–20 of 142 posts

Re: GrapheneOS fixes Android VPN leak Google refused to patch

#11
post #7

> Because system_server operates with elevated networking privileges and is exempt from VPN routing restrictions So a VPN isn't a VPN on Android? Regardless of this bug. Do other locked down operating systems act the same?

Ios does the same, only way around it is if you have an ?enterprise? licence (250+ devices)

Mullvad and others reported on that one ages ago

Re: GrapheneOS fixes Android VPN leak Google refused to patch

#12
post #7

> Because system_server operates with elevated networking privileges and is exempt from VPN routing restrictions So a VPN isn't a VPN on Android? Regardless of this bug. Do other locked down operating systems act the same?

MacOS has had instances where their own apps could bypass always-on VPN. I'm not sure if there have been exploits or gaps where traffic could go to arbitrary destinations directly.

Re: GrapheneOS fixes Android VPN leak Google refused to patch

#13
post #5
post #3

Earlier quoted context omitted.

That assumes there is pride they have to bother to keep.

Interestingly GrapheneOS being so good brings more money to Google as only Pixel phones are supported.

Sadly, Verizon Pixel phones, even after carrier unlocking, seem to be forever blocked from using GrapheneOS.

Re: GrapheneOS fixes Android VPN leak Google refused to patch

#14
post #5

Earlier quoted context omitted.

Interestingly GrapheneOS being so good brings more money to Google as only Pixel phones are supported.

First motorola grapheneos phone i am buying to get fully off the google pain train. Grapheneos tides me over until a real linux smart phone shows up or i die of old age. Now if home assistant could get thread network join*ng working without an android phone with a google account i could ve fully ris of those eh holes.

I am patiently waiting for that one. I have been willing to move to GrapheneOS for a while, but I don't feel like buying Google hardware.

Re: GrapheneOS fixes Android VPN leak Google refused to patch

#15
post #5

Earlier quoted context omitted.

Interestingly GrapheneOS being so good brings more money to Google as only Pixel phones are supported.

First motorola grapheneos phone i am buying to get fully off the google pain train. Grapheneos tides me over until a real linux smart phone shows up or i die of old age. Now if home assistant could get thread network join*ng working without an android phone with a google account i could ve fully ris of those eh holes.

> Now if home assistant could get thread network join*ng working without an android phone with a google account

There is already a way to do this. It's fiddly, but not by much. Once set up it's a much better experience, though.

https://www.matteralpha.com/how-to/how-to-use-home-assistant...

Re: GrapheneOS fixes Android VPN leak Google refused to patch

#16
post #7

> Because system_server operates with elevated networking privileges and is exempt from VPN routing restrictions So a VPN isn't a VPN on Android? Regardless of this bug. Do other locked down operating systems act the same?

How hard would it be to fix the system_server (and any other) bypass?

Re: GrapheneOS fixes Android VPN leak Google refused to patch

#18
post #5
post #3

Earlier quoted context omitted.

That assumes there is pride they have to bother to keep.

Interestingly GrapheneOS being so good brings more money to Google as only Pixel phones are supported.

I don't see a problem with supporting their legitimate hardware or cloud business models. But of course I see a problem supporting their illegitimate adware and spyware business models.

Re: GrapheneOS fixes Android VPN leak Google refused to patch

#19

I know there are bad business reasons, but how can someone classify a VPN leak as "not a security issue" and keep their pride?

Corporations have no pride. They are soulless, psychopathic accountability sinks.

What planet are you from?

Re: GrapheneOS fixes Android VPN leak Google refused to patch

#20

I know there are bad business reasons, but how can someone classify a VPN leak as "not a security issue" and keep their pride?

At some point digital security turns into physical security, and there are national security interests that have fine-tuned their detection logic on these kinds of "buggy" behavior.

If you patch it, you'd need to find another way to de-anonymize those users.

Post reply on HN