> Because system_server operates with elevated networking privileges and is exempt from VPN routing restrictions So a VPN isn't a VPN on Android? Regardless of this bug. Do other locked down operating systems act the same?
MacOS has had instances where their own apps could bypass always-on VPN. I'm not sure if there have been exploits or gaps where traffic could go to arbitrary destinations directly.
GrapheneOS fixes Android VPN leak Google refused to patch
21–30 of 142 posts
Re: GrapheneOS fixes Android VPN leak Google refused to patch
#22Earlier quoted context omitted.
Interestingly GrapheneOS being so good brings more money to Google as only Pixel phones are supported.
Sadly, Verizon Pixel phones, even after carrier unlocking, seem to be forever blocked from using GrapheneOS.
Your best bet for now is to buy a new Pixel direct from Google, or a used one from eBay that the seller advertises as already having GrapheneOS on it (or otherwise guarantees that the bootloader is unlockable). These ones are worth a lot more than the ones that can only run Google/carrier Android.
https://grapheneos.org/install/web#prerequisites
I own two GrapheneOS Pixel 7 units, which should get any Google blob security updates (which GrapheneOS incorporates) through October 2027, and GrapheneOS may still support it with source updates after that. So in a year or so, I might get the GrapheneOS Motorola if it's available, or a later Pixel. (I never buy these new, since I don't want to carry a several hundred dollar phone when a 2 gen old one is still great, thanks to GrapheneOS.)
Re: GrapheneOS fixes Android VPN leak Google refused to patch
#23I know there are bad business reasons, but how can someone classify a VPN leak as "not a security issue" and keep their pride?
At some point digital security turns into physical security, and there are national security interests that have fine-tuned their detection logic on these kinds of "buggy" behavior. If you patch it, you'd need to find another way to de-anonymize those users.
I feel like this should be toward the top of the terms of service for the phone, even above the mandatory arbitration clause.
Re: GrapheneOS fixes Android VPN leak Google refused to patch
#24I know there are bad business reasons, but how can someone classify a VPN leak as "not a security issue" and keep their pride?
Re: GrapheneOS fixes Android VPN leak Google refused to patch
#25I'm surprised they honored the embargo at that point, and delayed the fix until May. Why not just release immediately?
Re: GrapheneOS fixes Android VPN leak Google refused to patch
#26Earlier quoted context omitted.
Interestingly GrapheneOS being so good brings more money to Google as only Pixel phones are supported.
I don't see a problem with supporting their legitimate hardware or cloud business models. But of course I see a problem supporting their illegitimate adware and spyware business models.
Re: GrapheneOS fixes Android VPN leak Google refused to patch
#27Earlier quoted context omitted.
Interestingly GrapheneOS being so good brings more money to Google as only Pixel phones are supported.
Sadly, Verizon Pixel phones, even after carrier unlocking, seem to be forever blocked from using GrapheneOS.
I also did the math and determined buying a new unlocked phone outright on this plan was far cheaper than paying Verizon monthly for one.
Re: GrapheneOS fixes Android VPN leak Google refused to patch
#28> Because system_server operates with elevated networking privileges and is exempt from VPN routing restrictions So a VPN isn't a VPN on Android? Regardless of this bug. Do other locked down operating systems act the same?
It's a concern to me, because humans often extend their trust to computer trust based upon misunderstanding of the identically spelled words and lack of recognition of differing context.
Re: GrapheneOS fixes Android VPN leak Google refused to patch
#29Earlier quoted context omitted.
That assumes there is pride they have to bother to keep.
Interestingly GrapheneOS being so good brings more money to Google as only Pixel phones are supported.
Google's Pixel hardware division likely operates at a loss - or breaks even.
and even if every active HN user bought $100-$400 used Pixels from Swappa, meaningless money to them.
Re: GrapheneOS fixes Android VPN leak Google refused to patch
#30I know there are bad business reasons, but how can someone classify a VPN leak as "not a security issue" and keep their pride?