The leak involves telling Android to create a keep-alive UDP connection that is offloaded to the hardware Wi-Fi or cellular chip.

GOS fix in progress. Google has reportedly declined the bug report/bounty.

  • Mirror Giraffe@piefed.social
    link
    fedilink
    English
    arrow-up
    0
    ·
    15 hours ago

    Why are we still letting mullvad be relevant? Until they oust their nazi founder they shouldn’t get a penny or any shared articles.

  • one_old_coder@piefed.social
    link
    fedilink
    English
    arrow-up
    0
    ·
    5 days ago

    Google has reportedly declined the bug report

    Yet another proof that preventing stores like F-droid is a good security choice /s

        • notSys@lemmy.cafe
          link
          fedilink
          English
          arrow-up
          0
          ·
          16 hours ago

          Fdroid can be a security hole. They might not awarded security bounty for some reason. Those 2 things are not connected

    • CosmicTurtle0 [he/him]@lemmy.dbzer0.com
      link
      fedilink
      English
      arrow-up
      0
      ·
      4 days ago

      In other words, Google prefers security researchers to immediately share vulnerability findings publicly immediately. That way users can properly mitigate their risks appropriately while Google decides whether fixing the vulnerability will affect their bottom line.

  • pulsewidth@lemmy.world
    link
    fedilink
    English
    arrow-up
    0
    ·
    5 days ago

    Google sure seems to not care about VPN leak bugs that easily enable user apps to track real-world IP addresses without any kind of special permissions, even while the user thinks they’re safe in ‘lock traffic to VPN only mode’.

    I wonder why

    Via Graphene issue tracker.

    Author: ArminShupuk

    @thestinger As I see that you, Daniel, have picked this one up, I want to add that I was just in touch with Yusuf, who found the registerQuicConnectionClosePayload VPN leak. He informed me today that they didn’t pay him and closed the report as “won’t fix.” He had no success with his appeal. Mine seems to be “won’t fix” too, with no success reasoning with them either.

    So there are currently already two arbitrary ways for any user app with internet permission to leak the IP address in VPN lockdown mode that won’t be fixed upstream.

    Side note, the main GrapheneOS dev being his usual abrasive self (this is his only contribution to the thread).

    Author: thestinger

    That’s not the spelling of my name.

    • frongt@lemmy.zip
      link
      fedilink
      English
      arrow-up
      0
      ·
      4 days ago

      I don’t see that comment in the linked issue. I do see them triaging and assigning it, though.

        • Rekhyt@lemmy.world
          link
          fedilink
          English
          arrow-up
          0
          ·
          3 days ago

          The original comment called him “Danielle” and then edited to fix it to “Daniel”. Given that it’s the feminine version of the name, I think asking for a correction is reasonable, and deleting that request when it is fixed is also reasonable.

          That being said, he could have been more polite about it. Everyone in that thread comes across to me at grumpy, though.