Android leaks some traffic even when 'Always-on VPN' is enabled
bleepingcomputer.com
bleepingcomputer.com
From the article:
> “Even if the content of the message does not reveal anything more than "some Android device connected", the metadata (which includes the source IP) can be used to derive further information, especially if combined with data such as WiFi access point locations.”
> Mullvad is still debating the significance of the data leak with Google, calling them to introduce the ability to disable connectivity checks and minimize liability points.
> Notably, GrapheneOS, Android-based privacy and security-focused operating system that can run on a limited number of smartphone models, provides this option with the intended functionality.
Having an accurate clock is a requirement for some VPN protocols and IMO doing a connectivity check to see if a captive portal needs to opened is reasonable.
This doesn't seem like a big deal or a privacy risk, seems overblown. I don't think 99% of people should be worried of these "leaks" if you could call them that.