- cross-posted to:
- tech@piefed.world
- cross-posted to:
- tech@piefed.world
The leak involves telling Android to create a keep-alive UDP connection that is offloaded to the hardware Wi-Fi or cellular chip.
GOS fix in progress. Google has reportedly declined the bug report/bounty.



Google sure seems to not care about VPN leak bugs that easily enable user apps to track real-world IP addresses without any kind of special permissions, even while the user thinks they’re safe in ‘lock traffic to VPN only mode’.
I wonder why…
Via Graphene issue tracker.
Side note, the main GrapheneOS dev being his usual abrasive self (this is his only contribution to the thread).
Yes, very typical
I don’t see that comment in the linked issue. I do see them triaging and assigning it, though.
Lol wtf he deleted it. Maybe he lurks here.
The original comment called him “Danielle” and then edited to fix it to “Daniel”. Given that it’s the feminine version of the name, I think asking for a correction is reasonable, and deleting that request when it is fixed is also reasonable.
That being said, he could have been more polite about it. Everyone in that thread comes across to me at grumpy, though.
I enjoy his abrasiveness.
You do you (no downvote for me), but abrasiveness doesn’t help build community support in general, and context matters a lot.
In the context of some random user demanding a niche feature be added to a free project to suit their needs: abrasiveness warranted.
In the context here, of a security researcher very politely notifying them of a bug critical to the focus of their project (security and privacy), attempting private channels first, providijg deep details of the issue, adding discussion notes regarding upstream provider being unlikely to fix, and even including code to fix the problem for them - abrasiveness is counter-productive.