Live data from Hacker News

Android NAT-T keepalive offload bypasses VPN lockdown

supuk.ch

31–40 of 68 posts

Re: Android NAT-T keepalive offload bypasses VPN lockdown

#31

'Closed without action' is the tell. A leak that Google knows about and leaves in place isn't a bug anymore, it's a feature they're comfortable with.

Google considers VPN leaks to be valid bugs but unfortunately doesn't consider them security bugs. Internal issues are created for any issue report considered valid. The external one is only used to communicate with people. If it was filed as a security bug, they'll close it if it isn't considered within the scope of the bounty program. See https://news.ycombinator.com/item?id=49672677 .

I am not sure why all your comments are flagged, but here is my response to your other comment:

  > We plan to heavily overhaul the VPN implementation to make most forms of leaks nearly impossible rather than continuing to use the current system prone to it.
Thanks, great to hear. Given the slew of bugs you uncovered it seems the Android implementation has some rough edges. Would `pasta` be helpful to you? It allows you to unshare netns and then pass a user-space network adapter inside. https://passt.top/passt/about/ Podman leverages this one as well in more recent versions.

Re: Android NAT-T keepalive offload bypasses VPN lockdown

#32
post #22

Earlier quoted context omitted.

your logic would assert a similar conclusion with this scenario: a person walks up to you, punches you in the face, and leaves. it could have been an accident, an AI bot, or a misunderstanding. definitely not deliberate.

[flagged]

[flagged]

Re: Android NAT-T keepalive offload bypasses VPN lockdown

#33

Earlier quoted context omitted.

Google considers VPN leaks to be valid bugs but unfortunately doesn't consider them security bugs. Internal issues are created for any issue report considered valid. The external one is only used to communicate with people. If it was filed as a security bug, they'll close it if it isn't considered within the scope of the bounty program. See https://news.ycombinator.com/item?id=49672677 .

I am not sure why all your comments are flagged, but here is my response to your other comment: > We plan to heavily overhaul the VPN implementation to make most forms of leaks nearly impossible rather than continuing to use the current system prone to it. Thanks, great to hear. Given the slew of bugs you uncovered it seems the Android implementation has some rough edges. Would `pasta` be helpful to you? It allows yo…

> I am not sure why all your comments are flagged

The past couple weeks of our replies were maliciously flagged. We've made a post about it on social media as we've had to do before when this happens. This happens very regularly to posts by GrapheneOS or posts which simply support GrapheneOS. There are a bunch of malicious accounts which show up to each thread about GrapheneOS to make personal attacks towards our team, baselessly claim it's a honey pot, promote non-hardened products reducing privacy/security compared to AOSP and to make a bunch of disingenuous attacks towards it. The attacks towards our team often involve fabricated stories about us and harassment content. There's an account active in many of these recent threads making disingenuous replies and spreading Kiwi Farms harassment content in their profile:

https://archive.ph/JAunG

That account should clearly be banned rather than a subset of their posts getting flagged. The same applies to several other blatant ones.

Re: Android NAT-T keepalive offload bypasses VPN lockdown

#34

Earlier quoted context omitted.

There's a big difference between "the issue was closed" and "received no acknowledgment". The former is a deliberate action. The latter could be a case of SMTP-ate-my-email.

This is the email we received: Hello Check: https://news.ycombinator.com/item?id=49096839 Please upvote/comment/share/mitigate We passed it along to our developer working on solving VPN leaks. We didn't feel it was necessary to reply to a post linking to a public article. The article was shared with us by our users before we checked out emails. We have a bunch of internally discovered VPN leaks which are already bein…

Yep, that's a reasonable response. Thanks for your work.

Re: Android NAT-T keepalive offload bypasses VPN lockdown

#35

Earlier quoted context omitted.

I am not sure why all your comments are flagged, but here is my response to your other comment: > We plan to heavily overhaul the VPN implementation to make most forms of leaks nearly impossible rather than continuing to use the current system prone to it. Thanks, great to hear. Given the slew of bugs you uncovered it seems the Android implementation has some rough edges. Would `pasta` be helpful to you? It allows yo…

> I am not sure why all your comments are flagged The past couple weeks of our replies were maliciously flagged. We've made a post about it on social media as we've had to do before when this happens. This happens very regularly to posts by GrapheneOS or posts which simply support GrapheneOS. There are a bunch of malicious accounts which show up to each thread about GrapheneOS to make personal attacks towards our tea…

[deleted]

Re: Android NAT-T keepalive offload bypasses VPN lockdown

#36

Earlier quoted context omitted.

I am not sure why all your comments are flagged, but here is my response to your other comment: > We plan to heavily overhaul the VPN implementation to make most forms of leaks nearly impossible rather than continuing to use the current system prone to it. Thanks, great to hear. Given the slew of bugs you uncovered it seems the Android implementation has some rough edges. Would `pasta` be helpful to you? It allows yo…

> I am not sure why all your comments are flagged The past couple weeks of our replies were maliciously flagged. We've made a post about it on social media as we've had to do before when this happens. This happens very regularly to posts by GrapheneOS or posts which simply support GrapheneOS. There are a bunch of malicious accounts which show up to each thread about GrapheneOS to make personal attacks towards our tea…

[deleted]

Re: Android NAT-T keepalive offload bypasses VPN lockdown

#37

Earlier quoted context omitted.

I am not sure why all your comments are flagged, but here is my response to your other comment: > We plan to heavily overhaul the VPN implementation to make most forms of leaks nearly impossible rather than continuing to use the current system prone to it. Thanks, great to hear. Given the slew of bugs you uncovered it seems the Android implementation has some rough edges. Would `pasta` be helpful to you? It allows yo…

> I am not sure why all your comments are flagged The past couple weeks of our replies were maliciously flagged. We've made a post about it on social media as we've had to do before when this happens. This happens very regularly to posts by GrapheneOS or posts which simply support GrapheneOS. There are a bunch of malicious accounts which show up to each thread about GrapheneOS to make personal attacks towards our tea…

[flagged]

Re: Android NAT-T keepalive offload bypasses VPN lockdown

#38
post #37

Earlier quoted context omitted.

> I am not sure why all your comments are flagged The past couple weeks of our replies were maliciously flagged. We've made a post about it on social media as we've had to do before when this happens. This happens very regularly to posts by GrapheneOS or posts which simply support GrapheneOS. There are a bunch of malicious accounts which show up to each thread about GrapheneOS to make personal attacks towards our tea…

[flagged]

Asking for support is not brigading. The vouch button exists for a reason.

Re: Android NAT-T keepalive offload bypasses VPN lockdown

#40
post #37

Earlier quoted context omitted.

> I am not sure why all your comments are flagged The past couple weeks of our replies were maliciously flagged. We've made a post about it on social media as we've had to do before when this happens. This happens very regularly to posts by GrapheneOS or posts which simply support GrapheneOS. There are a bunch of malicious accounts which show up to each thread about GrapheneOS to make personal attacks towards our tea…

[flagged]

The past several weeks of our replies were wrongly flagged. None of our posts were in any way inappropriate and it's entirely appropriate to ask for help getting it undone. On the other hand, you're repeatedly making personal attacks on our team, engaging in doxxing and spreading harassment content. You're directly pointing people to Kiwi Farms harassment content with blatant libel and doxxing. There have been years of this harassment on Hacker News without it being addressed by the moderators. We're not going to be tolerating it anymore. Hacker News actively engages in moderation and therefore has no excuse to be permitting this harassment and leaving up years of it across many threads.
Post reply on HN