Live data from Hacker News

GrapheneOS fixes Android VPN leak Google refused to patch

cyberinsider.com

71–80 of 142 posts

Re: GrapheneOS fixes Android VPN leak Google refused to patch

#71

[flagged]

You make a lot of claim yet gives no source or material to back up your claim.

Beside, what would be a great distribution beyond grapheneos. iOS isn't, stock Android is much worst, calyxos ? Lineageos ? They are much worst on the security.

Re: GrapheneOS fixes Android VPN leak Google refused to patch

#74
post #52

Earlier quoted context omitted.

I'm really glad calyxos is starting up again. Grapheneos has a lot of cool technical implementation but there are a lot of things that Calyx seems to do in a simpler, more vanilla Android manner.

CalyxOS claims releases are paused[1] and the best you can get is Android 15. How recent are security patches you're getting? Can you even lock the bootloader on your device? [2] [1] https://calyxos.org/ [2] calyxos.org/lock

Not using it currently but they recently released some test builds of android 16. And yeah aiui bootloader relocking is supported for devices that are compatible.

https://old.reddit.com/r/CalyxOS/comments/1t3tdt6/calyxos_pr...

Re: GrapheneOS fixes Android VPN leak Google refused to patch

#75
post #17

Stock Android is spyware and adware, back in the day we called such software malicious and removed it, now it's the default.

We all agree. But what's the solution? We know 99% of the users don't care. So, the only pressure point is phone manufacturers. I don't have any power to influence anybody significant in this space. I feel helpless.

The truly independent solution is GNU/Linux. Sent from my Librem 5.

Re: GrapheneOS fixes Android VPN leak Google refused to patch

#77

I know there are bad business reasons, but how can someone classify a VPN leak as "not a security issue" and keep their pride?

Depends on how you see the role of a VPN.

VPNs, at least originally, were designed to provide access to private/business networks across another network. Office to office, home to office, that sort of thing. VPNs were only later turned into some kind of (supposed) security tool.

If your take on VPN code is "as long as your phone can reach the office printer over 5G" then this is a tiny bug. QUIC connections aren't being shut down properly, like they weren't before the introduction of the feature.

If your take on VPN code is "this wireguard tunnel must keep my identity safe no matter what" or "my security relies on this wireguard tunnel being an exact copy of all traffic exchanged over the internet" then this is a massive problem.

I don't think Android VPNs, or any VPN to be honest, were ever designed as a privacy or security measure. Especially not against apps with code execution on the device. The device itself will do all kinds of network interactions, some happening from within the modem chip itself.

Closing the bug was a mistake on Google's part, but I can see why they don't consider this a security bug in their bug bounty programme.

Re: GrapheneOS fixes Android VPN leak Google refused to patch

#78
post #47

Earlier quoted context omitted.

10a will get longer support, so why not (unless 9a is significantly cheaper)?

Isn’t part of the point of wanting GrapheneOS is that the official support periods don’t matter?

GrapheneOS will stop releasing updates when Google stops supporting a device. They put an emphasis on security and unpatched drivers or firmware (which they can't/won't/don't have the resources to patch) are a major security risk.

Luckily, Google's support periods are actually quite long, and very clear (stated on the website on launch date, unlike iOS or even Windows these days).

Re: GrapheneOS fixes Android VPN leak Google refused to patch

#79
post #68

[flagged]

> a governamental VPN and honeypot, a.k.a. Tor. Why is tor a honeypot?

I wouldn't call it a honeypot, but it's probably compromised by the feds.

It was shown a few years back that if you control enough of the exit nodes (more than some specific % that I don't remember off the top of my head) then you can associate traffic across most/all of the Tor network. Since running exit nodes is relatively cheap the assumption was that the feds (or some other state actor) were already doing so.

I'd call that materially different than a honeypot though since it wasn't designed for that purpose.

Post reply on HN