4 ms·
Android leaks some traffic even when 'Always-on VPN' is enabled
- DerekBickerton 4y agoGet a VPN router with OpenWRT (which supports OpenVPN). Case closed.
- eimrine 4y agoGet a VPN router, and a keyboard, and a decent monitor, and not Android. Case closed.
- MasterYoda 4y agoUnrelated but could also be interesting to know for those who use vpn + internet-sharing/wifi-hotspot that if you turn on vpn on your android (maybe ios too?) and connect another device like a laptop to you mobile phone that traffic from you laptop will not go through the VPN, but directly thru the cellular network. So that traffic will see your real ip.
- rany_ 4y agoThe Android issue has Mulvad mentioning connectivity checks and NTP which seems reasonable to me. Having an accurate clock is a requirement for some VPN protocols and IMO doing a connectivity check to see if a captive portal needs to opened is reasonable. This doesn't seem like a big deal or a privacy risk, seems overblown. I don't think 99% of people should be worried of these "leaks" if you could call them that.
- woojoo666 4y agoSeems like even if you enable the option to block connections outside a VPN, Android is designed to still do connectivity checks for special cases like identifying captive portals (like hotel WiFi). From the article: > “Even if the content of the message does not reveal anything more than "some Android device connected", the metadata (which includes the source IP) can be used to derive further information, especially if combined with data such as WiFi access point locations.” > Mullvad is still debating the significance of the data leak with Google, calling them to introduce the ability to disable connectivity checks and minimize liability points. > Notably, GrapheneOS, Android-based privacy and security-focused operating system that can run on a limited number of smartphone models, provides this option with the intended functionality.