Live data from Hacker News

Android NAT-T keepalive offload bypasses VPN lockdown

supuk.ch

71–73 of 73 posts

Re: Android NAT-T keepalive offload bypasses VPN lockdown

#71
post #60

Earlier quoted context omitted.

Can you report this to GrapheneOS?

It has been reported to Google (as a security bug) and to GrapheneOS as a comment in one of the very similar VPN leak issue on github. GrapheneOS has deleted my comment, probably because they assumed it was AI-generated or something, I've copied the report I sent to Google there.

[deleted]

Re: Android NAT-T keepalive offload bypasses VPN lockdown

#72
post #60

Earlier quoted context omitted.

Can you report this to GrapheneOS?

It has been reported to Google (as a security bug) and to GrapheneOS as a comment in one of the very similar VPN leak issue on github. GrapheneOS has deleted my comment, probably because they assumed it was AI-generated or something, I've copied the report I sent to Google there.

It was believed to be an AI generated comment and the issue is already known. We solved it as part of VPN lockdown mode which means it isn't solved for profiles not using a VPN in lockdown mode yet. We could expand our already working approach to always be active but we were concerned about compatibility so we scoped it to VPN lockdown mode.
Post reply on HN