24 ms·
DNS traffic can leak outside the VPN tunnel on Android
- nazgulsenpai 2y agoI don't use Mullvad, but I respect the shit out of them. This is a good, information dense explanation of the problem, their short term workaround and potential workarounds for others, as well as what will need to be fixed in Android. Good stuff.
- pqdbr 2y agoBlog posts like this (instead of endless YouTube sponsorships like their competitors do) are what made me choose them as my VPN service.
- bloopernova 2y agoI use and recommend Mullvad. However I'm worried that their goodwill and values will become more valuable to some private equity corp that buys them to asset strip and squeeze their customers.
- input_sh 2y agoWhy do you think they'd accept an offer? They openly said it's not for sale: https://mullvad.net/en/blog/2021/9/16/ownership-and-future-mullvad-vpn https://mullvad.net/en/blog/2021/9/16/ownership-and-future-m... Not everyone's in it for the money. Assuming they're not operating at a loss, even less so.
- Groxx 2y agoNot everyone telegraphs if they're in it for the money. In some lines of business, like (purely hypothetically) security, it might actually be a bad thing for your business if you do. I also use mullvad because I don't really think this is the case, but bad actors are generally hard to conclusively identify by design. And VPNs are pretty far out in the "just trust me bro" realm of handing over all your browsing habits with no ability to check their real behavior.
- reaperman 2y agoI think legally they would have to change their ownership directive document in Switzerland to allow the board of directors to allow the two founders to sell more than 50% of their shares. So you might get a heads up!
- blowfish721 2y agoThey arent based in Switzerland but in Sweden.
- yencabulator 2y agoMullvad is trying pretty darn hard to be as far from "just trust me bro" as is feasible. If you do take their word for how they run their systems (/are working toward), their servers are diskless (what logs?), will only run software signed by their infrastructure team, and will remotely attest that their software has not been tampered with. This is so very, very, far away from the typical VPN company that any such comparison sounds ridiculous to me. Just the pretense of doing all this work costs so much that a greedy biz bro simply wouldn't. https://github.com/mullvad/system-transparency https://github.com/mullvad/system-transparency https://www.system-transparency.org https://www.system-transparency.org https://news.ycombinator.com/item?id=29903695 https://news.ycombinator.com/item?id=29903695
- kfreds 2y agoThank you for noticing! System Transparency is taking way longer to figure out, design and build than I expected. On the other hand the project is quite ambitious, and our work on ST has sprouted two additional OSS projects: - https://www.sigsum.org https://www.sigsum.org (a transparency log with witness cosigning) - https://tillitis.se https://tillitis.se (an open-source hardware FPGA-based security key with measured boot)
- fragmede 2y ago> a greedy biz bro simply wouldn't. On the other hand, if it were an NSA honeypot, doing all that work would easily be worth the cost. Personally, I don't think they are, so I'm merely pointing out that there are angles other than totally above-board honest legitimate reasons, and "greedy biz bro".
- selectodude 2y agoThere are billboards for Mullvad all over Chicago which kind of weird me out.
- ziddoap 2y agoThey do traditional advertising (billboards being one example) instead of paid reviews, affiliate/influencer advertising, etc. https://mullvad.net/en/help/policy-reviews-advertising-and-affiliates https://mullvad.net/en/help/policy-reviews-advertising-and-a...
- neuronexmachina 2y agoOh wow, I wish more companies had pages like that summarizing what sort of marketing/advertising they do/don't use.
- ziddoap 2y agoI’m fanboying at this point, but I honestly believe Mullvad should be the poster child for a lot of things other companies should be doing. Transparency, accountability, data minimization, thorough documentation, publicly available audits, etc.
- hughesjj 2y agoI've been a happy expressvpn customer since dec 2016 but I'm sincerely considering switching to mullvad at this point
- nick238 2y ago[flagged]
- ziddoap 2y agoHoly unsubstantiated accusations, batman. This can be instantly disproved by examining the cases where valid warrants were presented to them by LEAs and they were unable to provide any user data.
- wepple 2y agoThey’re in it for the money. They’ve made some claims that are downright lies, I chuckle at the idea anyone would trust them. The NYC subway ads state that they save you from online web ad systems; blatantly false. I’ll take a photo next time I see the ad to store away.
- cjaybo 2y ago> They’ve made some claims that are downright lies Which claims are you referring to?
- Rastonbury 2y agoWhat were the lies?
- wepple 2y agoFrom my above post: > The NYC subway ads state that they save you from online web ad systems; blatantly false.
- fooqux 2y agoA very cursory search online shows that it's actually your statement which is blatantly false. They've offered ad blocking for years. While it's true they've not always offered this, it's on you when making such claims to ensure you're still factual.
- 2y ago
- ph0ny 2y agoThey are making bank. Thank you open Swedish data: https://www.allabolag.se/5592384001/mullvad-vpn-ab https://www.allabolag.se/5592384001/mullvad-vpn-ab
- radicality 2y agoI’ve been using and still using Mullvad but also getting worried. I live in nyc and in the last few months I’ve seen a _lot_ of ads from them. Huge billboards in high-traffic areas. Full-sized ads on a side of a bus. A whole subway car just with mullvad ads. Some of the ads also felt deceptive making it seem like it will prevent all your online tracking, even though we know that’s not the case.
- fernandotakai 2y agothey do advertise, but they try to keep traditional (instead of influencers) https://mullvad.net/en/help/policy-reviews-advertising-and-affiliates https://mullvad.net/en/help/policy-reviews-advertising-and-a...
- kfreds 2y ago> Some of the ads also felt deceptive making it seem like it will prevent all your online tracking, even though we know that’s not the case. I'm sorry to hear that. For what it's worth our marketing colleagues make a big effort to minimize the risk of such interpretations. Sometimes a really snappy string of words can be interpreted multiple ways. There's also only so many words we can put on an ad before it gets messy. We do try hard to make the nuances clear on our website, which ultimately is where any new users will have to go in order to buy the service.
- woodruffw 2y agoI’m a big fan of your service, but I agree with GP. I rode the subway yesterday and saw a Mullvad ad that strongly implied that a VPN is adequate protection against data brokers and data collection on websites. It certainly wasn’t the most egregious VPN ad I’ve ever seen, but it was disappointing to see Mullvad imply privacy properties for VPNs knowing that ordinary people don’t understand cookies, sessions, fingerprinting, or JavaScript.
- kfreds 2y agoDid the ad in fact talk about the VPN by itself, or in conjunction with the Mullvad Browser? In any case we make the most important nuances clear on our landing page, and in other places on our website.
- 2OEH8eoCRo0 2y agoI was an extremely happy user until they removed port-forwarding. That forced me to switch unfortunately :(
- Gormo 2y agoHow were you using port forwarding with an external VPN?
- fullspectrumdev 2y agoA lot of VPN’s allow you to forward a port from local to “listening” on one of their servers, to make it easier to use P2P filesharing and such. Mullvad and a few others have had to disable this feature because it turns out it’s super useful for hosting malware C&C servers, phishing pages, etc
- deleted 2y ago[deleted]
- Gormo 2y agoI sort of understand their reasoning, then, because acting as a reverse proxy for externally-initiated inbound connections is not typically within the scope of VPN services per se, and especially outside the scope of Mullvad's particular mission of offering VPN services for the purposes of protecting privacy and suppressing censorship. There are other solutions for your use case, with or without a third-party VPN, that wouldn't require port forwarding. There are also other VPN services that do offer this functionality.
- epcoa 2y agoIt’s typically for BitTorrent.
- nicce 2y agoWhat was the reasoning for removal?
- 2y ago
- uneekname 2y agoI was a bit surprised to walk onto a DC Metro car last weekend to find the walls plastered with ads for Mullvad. Just wanted to note that Mullvad is spending money on traditional advertising, as well as blog posts like this.
- watermelon0 2y agoFYI they are transparent about buying outdoor ads: https://mullvad.net/en/help/policy-reviews-advertising-and-affiliates https://mullvad.net/en/help/policy-reviews-advertising-and-a...
- deleted 2y ago[deleted]
- bragr 2y agoI was surprised this week to see a big yellow Mullvad ad on LA Metro bus. They must be on an advertising push.
- SpaceManNabs 2y agoI saw mullvad vpn ads on the L train (nyc) this week!
- deleted 2y ago[deleted]
- zevra 2y agoI saw them on metro north going into nyc
- 2y ago
- sli 2y agoThey don't do YouTube sponsors but they sure plastered their ads all over Chicago. Literally everywhere.
- dkga 2y agoGood points. By the way, how do they compare with the likes of ProtonVPN?
- rmdes 2y agoSimply the best VPN around, in terms of values, mindset, loyalty to their core beliefs and the relentless proof to stick to their moto over the last decades.
- stoniejohnson 2y agoonly bummer is that due to their strong respect of user anonymity a lot of their IPs are blocked by major platforms like Reddit
- spxneo 2y agohow are platforms like reddit able to get complete list of mullvad IPs and other vpns but not residential proxies?
- stoniejohnson 2y agopeople use mullvad IPs maliciously -> those IPs end up on blocklists
- adamomada 2y agoIt’s an industry now e.g. https://ipinfo.io https://ipinfo.io
- spxneo 2y agodamn this is crazy, how did they even compile all the residential proxies im seeing it detect!!
- fragmede 2y agoNet flows. A residential proxy should have a residential amount of traffic coming from it. If one IP has 1000x the usual traffic one household could reasonably account for, then mark it as a residential proxy. It won't be 100% accurate, but it's sufficiently accurate for reddit to go on a blocking spree.
- utensil4778 2y agoHow does one even get access to that kind of information? Are ISPs just selling this stuff or what?
- colordrops 2y agoWhat VPN do you use, if any?
- godelski 2y agoIf you don't use a VPN I'll note that they have a DNS service that is free. I think this demonstrates some support, at least in the way that increased traffic/usage can be support (and should help make Mullvad VPN users stand out less WRT DNS requests). The only downside I'll say is that the ping time for me is quite a bit higher than quad9 or cloudflare. I wrote some info about it in this thread[0], including how you can do ad blocking at the DNS level (and cloudflare info for the same). [0] https://news.ycombinator.com/item?id=40056162 https://news.ycombinator.com/item?id=40056162
- bjoli 2y agoI AM a user of mullvad, and I am extremely satisfied. I once mailed support with a payment question and added a small iptables question regarding a problem I had. I got back a swift reply which solved the payment question, and a detailed iptables reply with pros and cons of different solutions. In short: they are great.
- chadsix 2y ago[flagged]
- ibizaman 2y agoIt does because on the server you can’t distinguish the IPs from different clients anymore. But indeed, you have other means of tracking.
- chadsix 2y agoI agree, but IP addresses haven't been used as the main source of tracking for some time. Advertisers learned how to use much better data points a long time ago due to AOL proxies much like the Mobile proxies a significant amount of mobile providers use today. > Depending on your threat model this might mean that you should avoid using Android altogether for anything sensitive, or employ other mitigations to prevent the leaks. We aim to partially mitigate these problems in our app, so make sure to keep the app up-to-date. I don't think companies should give false hopes to people, and that is what is exactly happening here (e.g., "fixing a DNS leak will make you private and that's the only reason you're not!").
- ziddoap 2y ago>"fixing a DNS leak will make you private and that's the only reason you're not! This is not said or implied anywhere in Mullvad literature. In fact, they say the opposite. "A VPN isn’t the entire solution for privacy. Here’s the kind of monitoring it can’t protect you against." From https://mullvad.net/en/vpn/what-is-vpn https://mullvad.net/en/vpn/what-is-vpn
- chadsix 2y ago> Depending on your threat model this might mean that you should avoid using Android altogether for anything sensitive, or employ other mitigations to prevent the leaks. We aim to partially mitigate these problems in our app, so make sure to keep the app up-to-date." This statement clearly implies this is the reason that Android is currently not safe.
- gregoryl 2y agoThat's unfortunate, they only recently rolled out prompts to push Android users away from their in-app always-on functionality to the built in version.
- tiagod 2y agoI guess the safest setup is to have mobile data off on your phone and carry an OpenWRT hotspot to do the VPN bit upstream from the phone.
- nickburns 2y agoit's true. even bigger nightmare on iOS where 'always-on VPN' can only be configured on devices 'supervised' by an Apple-approved (documented application and telephone call with current employee required) organization's MDM solution—or you otherwise need a Mac to use the Apple Configurator app to even create a Configuration Profile containing the 'always-on VPN' key.
- fullspectrumdev 2y agoMaking a simple OSS tool to generate valid configuration profile files seems like a potentially useful way to spend a weekend sometime. The format cannot be that complex, right?
- nickburns 2y agolol, hit me up with your rate. my only term is that i get to be watching over your shoulder the whole time.
- jasomill 2y agoLooks like it’s just XML .plist format, and (at least partially) publicly documented: https://developer.apple.com/business/documentation/Configuration-Profile-Reference.pdf https://developer.apple.com/business/documentation/Configura...
- yonatan8070 2y agoUntil you get to the bit where I'm guessing you need Apples private keys to sign it or whatever
- walterbell 2y agoWeb page for offline generation of iOS VPN configuration profile: https://mobileconfig.app https://mobileconfig.app
- ignoramous 2y agorethinkdns dev here > these issues should be addressed in the OS in order to protect all Android users regardless of which apps they use. Android's paranoid networking has always had an exception for System and OEM apps (which include Google apps). Most such bugs fixes are unlikely to fix that core assumption. Some code refs: https://github.com/celzero/rethink-app/issues/224 https://github.com/celzero/rethink-app/issues/224 > The leak during tunnel reconnects is harder for us to mitigate in our app. We are still looking for solutions. Android supports seamless handover between two TUN devices (on reconfiguration). It is tricky to get it right, but implementable.
- cma 2y agoThey don't even allow disabling internet permissions on a flashlight app, the OS is run by an internet ad company so it makes sense.
- switch007 2y agoFWIW GrapheneOS does (it asks you before installing any app)
- codedokode 2y agoAs I understand, it installs a pseudo-VPN and passes traffic through it. I remember using similar app (NoRoot Firewall), and it worked poorly and couldn't block everything I wanted.
- switch007 2y agoGrapheneOS is totally different to having an app on stock android > GrapheneOS adds a Network permission toggle for disallowing both direct and indirect access to any of the available networks. The device-local network (localhost) is also guarded by this permission, which is important for preventing apps from using it to communicate between profiles. Unlike a firewall-based implementation, the Network permission toggle prevents apps from using the network via APIs provided by the OS or other apps in the same profile as long as they're marked appropriately. >The standard INTERNET permission used as the basis for the Network permission toggle is enhanced with a second layer of enforcement and proper support for granting/revoking it on a per-profile basis. > To avoid breaking compatibility with Android apps, the added permission toggle is enabled by default. However, the OS app installation UI has been extended to show the toggle as part of the installation confirmation page so users can disable it when installing an app. > when the Network permission is disabled, GrapheneOS pretends the network is down. It shows the network as down in various APIs, returns errors showing a network connectivity issue rather than a revoked permission and avoids running scheduled jobs depending on the network. This results in apps handling it as if the network is down rather than crashing or showing errors from trying to use the network and being unable to do it.
- ar-jan 2y agoI think this finding originates with the GrapheneOS community [0]. Edit: I guess that may be the same user reporting both. 0: https://twitter.com/GrapheneOS/status/1782477984156311814 https://twitter.com/GrapheneOS/status/1782477984156311814
- strcat 2y agoIt's worth noting that the built-in VPN support doesn't have these leaks. We don't agree with how Mullvad is presenting this because it is not yet clear if the leaks with their app and other apps are because of bugs in these apps or the OS. Their own post says they've resolved part of these DNS leaks through changing their app to avoid not having a DNS configuration. Android supports many use cases of the VPN service API including not handling DNS and this may be a side effect of that flexibility. It's not necessarily a bug. If it's possible to set up the apps in a way that they don't leak without OS changes, then it was probably an app issue all along. We're aware of a separate issue unrelated to DNS leaks where multicast packets can leak to the local network with VPN apps. This appears to be an OS bug, but that's not confirmed yet. It will likely only be determined if it's a bug when we find a fix for it. This multicast leak doesn't happen with the built-in VPN support either. There have been plenty of VPN leaks on other platforms including issues that are still not really fixed without setting up custom netfilter or eBPF rules similar to what Android is trying to do on platforms where that's not done for you by the OS. On Android, the responsibility for preventing leaks is partially taken on by the OS which promotes a standard leak blocking feature which has gotten much better in the past few years. Each app trying to do this themselves is not a recipe for success. It's not as if Mullvad was aware of these issues for a long time and asking Android to fix it without action.
- exabrial 2y agoAny system where you don't have root access in insecure by it's very definition. Android and ios are hilarious.
- nickburns 2y agoa point as salient as it is germane. this is exactly why open-source software and hardware mobile device projects[0] will only continue to proliferate. [0] https://en.wikipedia.org/wiki/PinePhone_Pro https://en.wikipedia.org/wiki/PinePhone_Pro
- autoexec 2y agoAs much as I want to support those kinds of devices they're all insanely priced and have earned a reputation for failing at the most basic tasks. Maybe after it's been more than 3-5 years since the last forum post titled "can make/receive calls" I'll give pine phones another look.
- nickburns 2y agoi agree the whole concept is not too far past proof at present.
- fifteen1506 2y agoMost are happy to outsource root to the OS manufacturer. And while I demand having root on Desktop, I don't see it happening on mobile for the majority.
- autoexec 2y agoMost phone users are oblivious to what root even is and yet still hate it when changes are pushed to their devices without notice, with no ability to revert to how things were or prevent unwanted changes in the future. This isn't acceptance but rather learned helplessness.
- 2y ago
- jerry1979 2y agoThis can also be detected by using the NetGuard firewall which acts as a vpn. Even in full lockdown mode, some kinds of newwork traffic gets through.
- strcat 2y agoNetGuard doesn't support the standard OS leak blocking like Mullvad and doesn't try to filter DNS so it inherently has leaks. There are no known remote leaks on Android 14 when a VPN app supporting is already active or when it's down. The DNS leaks in this post were partially caused by an app bug that's not fixed and also happen when the VPN is in the process of connecting. The issue with leaks when the VPN is in the process of connecting may be an app bug or an OS bug. It's not clear that it's an OS bug at this point. It was reported to us for GrapheneOS earlier and we've been looking into it. There's also leak issue which was reported where multicast packets leak outside of the VPN tunnel to the local network. This is highly likely to be an OS bug, unlike the DNS leak issue where it's not yet clear if the OS or the app is the problem. The OS can likely prevent those DNS leaks even if apps don't get fixed but it wasn't necessarily supposed to be responsible for it. From the OS perspective, a VPN app is supposed to set a DNS configuration and not setting that configuration results in partially using the OS DNS.
- Valery91 2y agoIf you don't mind clarifying, currently GOS uses ASYMMETRIC MTE for the low overhead and to close the soft time constraint in ASYNC MODE. I was having a read though https://googleprojectzero.blogspot.com/2023/08/mte-as-implemented-part-1.html?m=1 https://googleprojectzero.blogspot.com/2023/08/mte-as-implem... Where I had come accross possible MTE bypasses in ASYNC mode and I quote: 'Since SIGSEGV is a catchable signal, any signal handlers that can handle SIGSEGV become a critical attack surface for async MTE bypasses'. Moreover, "The concept is simple - if we can corrupt any state that would result in the signal handler concluding that a SIGSEGV coming from a tag-check failure is handled/safe, then we can effectively disable MTE for the process", hence having MTE as ineffective. Paradoxically, I don't believe this issue is faced regarding SYNC MODE. As you obviously know, 'in asymmetric mode, read memory accesses are processed as SYNC, while write memory accesses are processed as ASYNC'. does this mean that the signal handlers in write memory are exploitable? If this be true, does GOS offer a mitigation for this, or can it be possible to simply allow all users to have the option to pick SYNC MTE to bypass this attack surface? Furthermore, MTE is not enabled for the kernel, would it be possible to have it enabled by choice as well? Finally, regarding the OS processes to which GOS recently enabled MTE for as an option for its users, does it also include the cellular firmware, IOMMU/SMMU and the software stack that communicates between the isolated chip and the OS? I address this point because, GAL Beniamini stated that: " That said, up until now we’ve only considered the high-level attack surface exposed to the firmware. In effect, we were thinking of the Wi-Fi SoC and the application processor as two distinct entities which are completely isolated from one another. In reality, we know that nothing can be further from the truth. Not only are the Wi-Fi SoC and the host physically proximate to one another, they also share a physical communication interface". Nonetheless he further states: "For example, by going over the IOMMU bindings in the Linux Kernel, we can see that apparently both Qualcomm and Samsung have their own proprietary implementations of an SMMU (!), with it’s own unique device-tree bindings. However, suspiciously, it seems that the device tree entries for the Broadcom Wi-Fi chip are missing these IOMMU bindings". Despite that the research is from a couple years, it remains viable evidence that IOMMU although provides adequate protection, it remains an insufficient mechanism on its own and requires further hardening on the software stack. Does GOS address this profound attack vector? I hope to get your perspective on the matter. Thank you in advance.
- lloydatkinson 2y ago> Depending on your threat model this might mean that you should avoid using Android altogether for anything sensitive I once worked with someone who worked with someone that had previously been a major Android fanboy, but after doing some work that required a security clearance, they became an iPhone user and insisted their family get iPhones too.
- nickburns 2y agoApple is no less culpable of the same, they just put it behind the garden walls (which, in fairness, would appear to be just barely more trustworthy than Alphabet).
- bongodongobob 2y agoApple does the exact same shit. I discovered it when I first set up a home DNS server.
- lloydatkinson 2y agoThey switched to iPhone not for DNS reasons, but overall security.
- bastard_op 2y agoThis has been a long-standing issue with android, that no matter how much you want it to use internal dns servers only, it'll decide to flip to cell and use those as it needs/wants. I've observed adb debugs for times recently to see why/when wireless was disconnecting, and it comes down to liveliness checks that if it can't see or resolve something, it'll simply bring up and try the cell data to do so. It's especially frustrating when using internal dns records that only live internal will randomly not work on a phone. I can see that the device is on wifi that is feeding internal dns servers with the records, but it's resolving externally still for some android reason. This happens on my SO's phone when using things all the time, but I really don't use my phone in the house except to read books and rarely notice. No idea how apple is about this, but the fact they try to proxy everything you do via their "privacy" vpn by default including dns as DOH, I can't imagine it is any better trying to use what they'd see as a competing product, and we know how apple feels about those.
- edward28 2y agoHave you tried disabling "mobile data always active" in developer options?
- gruez 2y ago>it'll decide to flip to cell and use those as it needs/wants Are you sure you don't have wifi assist enabled? That's explicitly designed to switch to cellular when wifi signal is poor.
- callalex 2y agoiOS absolutely does not use Private Relay (iCloud branded VPN) by default. Even when it is included in a subscription, you must explicitly opt in.
- kccqzy 2y agoThe Limit IP Address Tracking feature is turned on by default and Apple makes it more annoying because it is turned on or off for each WiFi network. And a simple search shows definitely people annoyed by the exact same symptom of redirected DNS queries and inability to use internal-only DNS entries. https://www.reddit.com/r/ios/comments/uurkqr/limit_ip_address_tracking_issue/ https://www.reddit.com/r/ios/comments/uurkqr/limit_ip_addres...
- the8472 2y agoLinux has network namespaces, which can be used to isolate programs so they don't see any external networking when no VPN is available. Does android not use this for its VPN feature?
- dyingkneepad 2y agoLol. On the other hand, I use Linux network namespaces to make programs run outside the VPN on a specific machine that has the whole system configured to go through the VPN. So yeah if you get namespaces you can use them to both isolate programs and also bypass the VPN.
- ranger_danger 2y agoI have also noticed that when using the FoxyProxy addon under Firefox, even with a SOCKS5 proxy in use, it will leak DNS requests through the direct connection unless you also set a manual proxy in the regular Firefox settings as well.
- yjftsjthsd-h 2y agoI don't suppose you can set a nonexistent manual proxy and then use the addon for everything?
- moose44 2y agoApologies if this is a dumb question—could a service like NextDNS help prevent this?
- nickburns 2y agonope. no DNS service, not even a self-hosted one, can mitigate what's happening here. the matter at-hand considers Android (and iOS both) operating system- and kernel-level insecurities by-design. the operating system (together with all root-level or otherwise authorized system activity), under certain conditions—e.g. connectivity change, hard-coded system function, apps with permission to hardcode their own network functions, etc.—will refuse to use any NIC, whether physical or virtualized, except the one containing the cellular carrier's connection/routes. that traffic might then necessarily include DNS queries and any/all other private but now-leaked data.
- moose44 2y agoInteresting. Thank you for this.
- raggi 2y agoNextDNS _does help_ though by way of being DoH, so while your packets might be traversing a less desirable path they’re not readable.
- nickburns 2y agofair point. but that assumes: 1.) the system strictly respects user-configured DNS; and 2.) that the leak of some private data is acceptable. leaked traffic is still leaked even if otherwise encapsulated by some other encryption mechanism outside of an otherwise properly-configured VPN tunnel. #1 is of course a much larger risk assumption to swallow.
- throwaway2037 2y agoI don't VPNs, nor Mullvad, but I do appreciate the transparency here. We need to support more companies like this.
- kop316 2y agoI've sort of suspected this the case for a while. On VPN, MMS and Visual Voicemail still work on Android. Both of these require direct mobile access or they will get rejected (sometimes they are only on the mobile network, or else they requests get rejected if they don't come from within the mobile network). I suspect the same is true of VoLTE. If there is a VPN, that would mess things up. I found this out since on Mobile Linux, if you enable VPN, the VPN breaks all of those. I don't think there is a clear way to fix this on Android without breaking a lot of expected functionalty.
- nickburns 2y agoironically SMS/MMS and VVS are two of maybe a few other operations/functions (system updates maybe? maybe?) that are justifiably 'hard-coded' to the carrier connection. i've done the dance re: VVS with advanced AT&T support on VPN'ed iOS—so can confirm your point is not limited to Android.
- bestham 2y agoNo VoLTE uses a dedicated bearer (network interface) in the LTE stack. Not the one used for data. Different bearers can have different priorities/QCI (like QoS). In a congested LTE network VoLTE should provide a better experience than VOIP on a lower priority bearer.
- mise_en_place 2y agoLuckily WireGuard doesn't have this issue on desktop peers. Although I did run into DNS leaking due to my peer config having an exception for my local network address range. The way I resolved that is to setup dnsmasq on the server and set that as my primary DNS. I will say that I wish there was a DisallowedIPs directive. It's fun having to subtract a /24 from 0.0.0.0/0, although there are calculators you can use.
- rkagerer 2y agoWe have reported the issues and suggested improvements to Google Isn't Android open source? Can they not fix it for them and submit a PR?
- nickburns 2y agoMullvad's not really in the business of developing for Alphabet. but any of us could though, sure.
- GrantMoyer 2y agoAndroid is open source, but the codebase is massive and unapproachable. I managed to make some tweaks to Android, and compiled my own custom version (for one, I removed the stupid blur from lock screen album art), but I'm fairly confident I wouldn't be able to even find all the relevant code for DNS and VPN interactions in any reasonable amount of time.
- robertritz 2y agoI noticed this with my Android TV. Sometimes my location would leak and certain streaming sites stopped working (I'm outside the US). Got an AppleTV and this issue stopped.
- resource_waste 2y agoNo one is going to say Apple has acceptable levels of Security. I am a bit shocked when I see politicians with iPhones, most are unaware that Pegasus can take over at any point.
- NotYourLawyer 2y agoYes, iOS is the only software with 0 days.
- eviks 2y agoThat's why it has 0 in its name!
- _8j50 2y agoI gave on trusting phones to secure data a long time ago. But my approach is, at least when on wifi, to allow access to the internet only if the device connects to a local vpn gateway. 100% leak proof and prevents almost all wifi/lan/mitm attacks.
- nickburns 2y agowhat if a system-level (read: root) process doesn't respect your user-configured routing table? that's the real issue here. only mitigation would be to physically remove the undesirable NIC/s from the system, which is obviously impossible on SoC hardware.
- _8j50 2y agoIt won't make a difference, the other end (gateway) will only accept vpn connections, nothing more or less. Devices that can't establish a connection with your wg/openvpn won't be able to communicate with any other device anywhere in any way period.
- nickburns 2y agowe're talking here about the ability to control what NIC localhost traffic egresses a device with multiple NICs—even when some of said NICs may be be virtualized, like a TUN interface for example. anything and everything else is upstream.
- _8j50 2y agoWhy would localhost traffic be routed via non-loopback nic's. I think you are talking about something else and I am not following. Sorry.
- nickburns 2y agoby "localhost traffic" i've meant literally any traffic generated by a given device, its operating system, and any applications running on it, no matter the destination.
- Asmod4n 2y agoThe Problem with Android in regards to DNS: you just can't set your own IPv6 DNS Server on that platform, it gets changed anytime anything happens to your wifi. There is no app, even for rooted android, which can disable the operating system from changing it. When you are stuck with a router that always hands out IPv6 Adresses and doesn't let you turn that off you are just screwed. I don't even know if you could install a firewall appliance behind that router and strip out the IPv6 DNS Servers it advertises.
- stainablesteel 2y agoso that's what happens on when the phone is the main interface does this happen with wifi tethering too? if i have a vpn set up on a laptop that i connect through the phone's wifi will that leak in the same way?
- jsheard 2y agoWhat if you use the system-level support for DNS-over-TLS instead of setting the DNS server IP addresses? That's a global setting so it should apply regardless of which network you're on, or what happens on it. If you care about DNS requests leaking you should be using DoT or DoH anyway.
- nickburns 2y agodoesn't matter. plenty of elaboration elsewhere in the discussion.
- aritashion 2y agoDoesn't rethink let you change ipv6 dns?
- bobbob1921 2y agoA few years ago, when I was testing various VPN set ups for a project, one thing I would do is have a MikroTik firewall device (hardware) sit between my computer and my main router, it’s only purpose would be to block any traffic, not dst for the IP address of the VPN server that the pc was connecting to. This worked great to ensure that no traffic was leaked from pc to vpn server. The IP address of the VPN server you’re making use of rarely changes or if it does it’s easy enough to change on the MikroTik firewall. Another method is to block all traffic not to the port/protocol pair being used by the VPN server if you don’t know the servers IP address (or if it changes). As an example drop any traffic not dst UDP 1194 (based on the type of VPN, of course). MikroTik routers also have a great little tool called torch that allows you to quickly and easily watch traffic (in addition to of course, supporting packet captures. Mikrotik routers are very reasonably priced and range from as low as $30 up to $3000 - all with no software licenses, and they are very powerful and capable if you know what you’re doing.
- nickburns 2y agoThis worked great to ensure that no traffic was leaked from pc to vpn server. The IP address of the VPN server you’re making use of rarely changes or if it does it’s easy enough to change on the MikroTik firewall. Another method is to block all traffic not to the port/protocol pair being used by the VPN server if you don’t know the servers IP address (or if it changes). As an example drop any traffic not dst UDP 1194 (based on the type of VPN, of course). outbound filtering by source and/or destination address and/or port is both a fundamental firewalling concept and standard configuration on all firewall-routing platforms. (policy-based routing[0], i.e. filtering by gateway, is the same.) generally speaking, only the con/prosumer products allow everything out by default. just curious, what was your "main router" in this setup? ISP-supplied? [0] https://en.wikipedia.org/wiki/Policy-based_routing https://en.wikipedia.org/wiki/Policy-based_routing
- bobbob1921 2y agoIt was also a mikrotik - so of course, I could’ve done everything on that one. however, I had to show / prove to a client that the set up could be easily duplicated at other locations (and moved around) where everything else on the network was unknown (only known / controlled parts were to be a Windows laptop, and the mikrotik router connecting ethernet from that laptop to whatever network also via eth. For some of the configurations that needed to be very portable, the (very low end) MikroTik was powered via USB from the laptop Customer also wanted the router to log any dropped/leaked traffic (which we did on the mikrotik to it’s internal memory, or a usb stick with a txt file log)
- aftbit 2y agoAlso apparently tethering traffic doesn't go via the VPN? That's a silly choice too.
- marc_ranieri 2y agoBlock connections without VPN is turning out to be as reliable as my self-control at an all-you-can-eat buffet…if I'm not mistaken, these DNS leaks can very much expose where you browse and even your location, which kinda defeats the whole purpose of a VPN (and yes, even with VPNs, Android might still leak your DNS info. If you're really privacy-conscious, you might need to look beyond just using Android or keep your sensitive stuff off your phone)
- wolverine876 2y agoMullvad's security team should have found this problem on their own, and as soon as it appeared: Inspect security empirically - you might think that your security must work, but that means nothing; you must investigate empirically: All data going to the Internet must pass through the gateway. Collect the packets on the gateway, not on the device, and inspect them for leaks. Finding leaks should be trivial at that point. The only trick might be cellular connections: We don't know that leaks aren't unique to cellular connections. I know cellular gateways can be setup, but are the packets inspectable at a level that will reveal leaks?
- kerhackernews 2y agoCan't you just use a DNS provider that encrypts the traffic?
- spxneo 2y agotoy with me for a bit, couldn't Mullvad be another "Encrochat" in the making? Encrochat was similarly marketed as absolutely trustable complete with experts covering "we fixed this vulnerability/exploit and you can trust us" vibes (https://www.manchestereveningnews.co.uk/news/uk-news/dads-secret-criminal-life-unmasked-29089865 https://www.manchestereveningnews.co.uk/news/uk-news/dads-se...) Isn't Mullvad the same thing? Do you really think they would allow terrorists like Hamas use Mullvad to coordinate attacks? Coincidentally, Hamas does not trust any sort of VPN, opting for underground land lines.
- generalizations 2y ago> Hamas does not trust any sort of VPN, opting for underground land lines. I mean, duh. Like everyone always says around here, all bets are off when your threat model includes nation states. Timing attacks, meta data, and total access to the internet backbones means it’s a reasonable bet that the Big Boys can track anything on the public internet, regardless of encryption or redirection. And if you’re Hamas, you’re probably on their radar.
- spxneo 2y agoSo your narrative is that they have complete access but choose not to act on anything they find on VPNs and other "privacy focused" tech? Makes sense as there has been no cases involving terrorist using Mullvad and such. So Mullvad is not good enough for terrorists but good enough for the rest? This makes no sense to me.
- pavi2410 2y agoWhat's the point for a terrorist certified VPN?
- generalizations 2y agoWhat’s not to understand? Nation states (read: their 3 letter agencies) probably don’t care if you’re torrenting movies.
- 2y ago
- Remzi1993 2y agoSometimes you wonder if those "bugs" are intentionally well placed or not. Especially since big tech has been known that they work together with a kinds of intelligence agencies. I just can't believe that so many bugs like this in Android are there "not intentionally" at this point since this is not the first time I have heard about these kinds of bugs in Android.
- sneak 2y ago"Once is happenstance. Twice is coincidence. Three times is enemy action." —Ian Fleming, Goldfinger
- Rastonbury 2y agoWhat if I have private dns set up on my phone?
- seany 2y agoI really _really_ want to love mullvad, but they still don't ignore DMCA requests.
- chrisjj 2y agoBut why should they ignore DMCA requests?
- sneak 2y agoAPNS traffic leaks outside of the VPN on iOS as well (except possibly OS-supported VPNs installed with a provisioning profile). Apple doesn’t seem to care, as they don’t care about preserving your privacy wrt themselves.
- haisin1982 2y agoI like Mullvad. Just wish they used less shitty providers - all of them are super dodgy from xtom (super unhinged owner) to m247. Mullvad presents a great image but their providers would probably sell netflow traffic for $7 a month to any interested party. They really do use the scum of the earth providers instead of investing in their own infra
- taxesTaxi 2y agoSo, a closed source operating system can do things the user can't control? I don't know what's more impressive, the fact people don't apprehend this reality, or the fact people still rely on VPNs (especially a third party) for privacy or whatever.
- beefnugs 2y agoIf google wasn't evil: then the default for all permissions would be to mock fake data that the app could never recognize as fake. Then you pick and choose which apps get REAL data.
- mik09 2y agoused an exploit to get vpn working on router...