Android leaks some traffic even when 'Always-on VPN' is enabled
bleepingcomputer.com
bleepingcomputer.com
Anyways reposting my comment from that thread:
Seems like even if you enable the option to block connections outside a VPN, Android is designed to still do connectivity checks for special cases like identifying captive portals (like hotel WiFi).
From the article:
> “Even if the content of the message does not reveal anything more than "some Android device connected", the metadata (which includes the source IP) can be used to derive further information, especially if combined with data such as WiFi access point locations.”
> Mullvad is still debating the significance of the data leak with Google, calling them to introduce the ability to disable connectivity checks and minimize liability points.
> Notably, GrapheneOS, Android-based privacy and security-focused operating system that can run on a limited number of smartphone models, provides this option with the intended functionality.
EDIT: Looks to be AOSP according to this https://issuetracker.google.com/issues/249990229?pli=1
The main AOSP derivatives, including LineageOS don't address it at all.
That being said, it's a shame that LOS doesn't borrow more from Graphene.
Magisk and other tools are a prime target.
A LOT of the concerns I had with losing control can be worked around. I've been using/building LineageOS/CM for many years and can highly recommend GrapheneOS.
That doesn't suffice for me since then I'm limited by Android only allowing one VPN at a time and would then have to choose between having adblocking or hiding my public IP. Yes, I can (and do) use a custom DoH like NextDNS for blocking as well, but I also like having a static hosts file so I have a baseline blocklist on my phone itself. However that's just my personal preference, any of those approaches are valid.
Having the ability for logcat would be nice too, since I depend on that to audit apps and track down strange bugs occasionally.
My main defense in limiting my attack surface is just not installing very many apps in general, and preferring apps from F-Droid that are as simple as possible and offline only, or that are connecting to a self-hosted service that I control. Which I'm sure helps but is obviously not as thorough as Graphene's hardening.
Verified boot is an awesome feature though, I think the ideal for me would be using my own custom keys to have verified boot, so I can include and sign whatever I want in my ROM. Though, I know there are the hardware backed keys you can't change and at that point I'd essentially just have my own custom ROM. I might just be spoiled from what I get with the Pureboot firmware on my Librem laptop and being able to verify firmware with my own GPG key.
I also think it's awesome that we have enough privacy-focused ROM choices on Android to be having this discussion :)
https://news.ycombinator.com/item?id=33177629
(154 points, 76 comments)