Back to News
Advertisement
Advertisement

⚡ Community Insights

Discussion Sentiment

14% Positive

Analyzed from 594 words in the discussion.

Trending Topics

#issues#issue#vpn#security#google#android#leak#considered#closed#leaks

Discussion (22 Comments)Read Original on HackerNews

brinepotabout 4 hours ago
'Closed without action' is the tell. A leak that Google knows about and leaves in place isn't a bug anymore, it's a feature they're comfortable with.
grapheneos8 minutes ago
Google considers VPN leaks to be valid bugs but unfortunately doesn't consider them security bugs. Internal issues are created for any issue report considered valid. The external one is only used to communicate with people. If it was filed as a security bug, they'll close it if it isn't considered within the scope of the bounty program.

See https://news.ycombinator.com/item?id=49672677.

exceptioneabout 6 hours ago
This paper goes into much more detail: https://supuk.ch/papers/android-natt-keepalive-vpn-bypass
exceptioneabout 7 hours ago

  > A proper fix would require changes in the Android system. The researcher who discovered the leak has reported the issue to the Android Vulnerability Reward Program, but according to the researcher the issue was closed without action. This issue is not public, but based on this information we deem it unlikely that Google will do anything about it. GrapheneOS is aware of the issue and are working on a fix.
If the account given by the researcher is correct, we cannot rule out that Google deliberately introduced or wanted to keep the leak in place.
grapheneos24 minutes ago
Security issues considered outside the scope of what they consider a security vulnerability are closed regardless of what they plan to do about the issue. Google primarily uses internal issues to track issues with Android. Public issues and security issues filed by external parties are only used to communicate externally and an internal issue is created for their actual issue tracking.

A security issue being closed means you aren't getting a bounty and it won't be fixed for existing Android releases. It doesn't mean it won't be fixed in a future Android release. They do track VPN leaks as issues internally and regularly ship fixes in new major releases. They unfortunately don't consider those security issues so they don't get prioritized. If they were considered security issues, then they'd likely consider them Low or Moderate severity. Only a large subset of patches for High and Critical severity issues are backported to older releases of Android.

GrapheneOS has had to fix a bunch of VPN leak issues and we're in the process of fixing more of the issues. We plan to heavily overhaul the VPN implementation to make most forms of leaks nearly impossible rather than continuing to use the current system prone to it.

jjavabout 6 hours ago
> we cannot rule out that Google deliberately introduced or wanted to keep the leak in place

I'd say a lot stronger than "cannot rule out". Regardless of how it was introduced, if it is now known and the issue was closed without action, they are actively choosing to keep it.

grapheneos23 minutes ago
Google considers VPN leaks to be valid bugs but unfortunately doesn't consider them security bugs. Internal issues are created for any issue report considered valid. The external one is only used to communicate with people. If it was filed as a security bug, they'll close it if it isn't considered within the scope of the bounty program.

See https://news.ycombinator.com/item?id=49672677.

nonamesleftabout 6 hours ago
As a quick kludge use an USB-C wlan network adapter that lacks the functionality for this type of connection (albeit that won't help you with a cellular connection)?
exceptioneabout 6 hours ago
Regarding cellular connection, the proof of concept presented here only works on wifi: https://github.com/GrapheneOS/os-issue-tracker/issues/8617

I have a hunch this leak is bound to wifi hardware only, for details: https://supuk.ch/papers/android-natt-keepalive-vpn-bypass

aucisson_masqueabout 9 hours ago
> This issue is not public, but based on this information we deem it unlikely that Google will do anything about it. GrapheneOS is aware of the issue and are working on a fix.

Good guy Google, as usual.

potatoproductabout 4 hours ago
Surprised this hasn't blown up more!
TutleCptabout 4 hours ago
Mullvad did a really good job writing up this blog post. And yet again GrapheneOS to the rescue.
gib444about 5 hours ago
I guess the best advice remains to only use wifi to connect to a router which forces traffic over a VPN and never use mobile data?

Do any similar leaks exists on iOS currently?

tostiabout 4 hours ago
You're definately not hiding something if all your traffic goes out to a single IP address and a single pair of source and destination ports.
gib444about 2 hours ago
A business: hiding everything is expected. To do otherwise is negligence

An individual: you're a pedo if you use a VPN

Give over.

tostiabout 1 hour ago
Most people I know use a VPN do it to bypass geo restrictions and/or get a discount with cheaper currencies. (But hey, our "representatives" seem to disagree.)