ES version is available. Content is displayed in original English for accuracy.
Advertisement
Advertisement
⚡ Community Insights
Discussion Sentiment
14% Positive
Analyzed from 594 words in the discussion.
Trending Topics
#issues#issue#vpn#security#google#android#leak#considered#closed#leaks

Discussion (22 Comments)Read Original on HackerNews
See https://news.ycombinator.com/item?id=49672677.
A security issue being closed means you aren't getting a bounty and it won't be fixed for existing Android releases. It doesn't mean it won't be fixed in a future Android release. They do track VPN leaks as issues internally and regularly ship fixes in new major releases. They unfortunately don't consider those security issues so they don't get prioritized. If they were considered security issues, then they'd likely consider them Low or Moderate severity. Only a large subset of patches for High and Critical severity issues are backported to older releases of Android.
GrapheneOS has had to fix a bunch of VPN leak issues and we're in the process of fixing more of the issues. We plan to heavily overhaul the VPN implementation to make most forms of leaks nearly impossible rather than continuing to use the current system prone to it.
I'd say a lot stronger than "cannot rule out". Regardless of how it was introduced, if it is now known and the issue was closed without action, they are actively choosing to keep it.
See https://news.ycombinator.com/item?id=49672677.
I have a hunch this leak is bound to wifi hardware only, for details: https://supuk.ch/papers/android-natt-keepalive-vpn-bypass
Good guy Google, as usual.
Do any similar leaks exists on iOS currently?
An individual: you're a pedo if you use a VPN
Give over.