Hacker Newsnew | past | comments | ask | show | jobs | submit | exceptione's commentslogin

Imho, the interface should not even be in the namespace to begin with. Unshare netns, then using pasta allows you to pass a user-space network adapter inside. https://passt.top/passt/about/

Caveat: I am no expert on Android.


I think any HN'er who previously voted republican has experienced enough disappointment; I doubt there would be anyone left.

The most important point for every political faction however is to realize that the problems aren't solved when the current president steps down. The real power that pushes the agenda rest in the hands of a loosely connected network of 'think tanks', religious organizations, tech billionaires and media moguls. They are hidden from the public discourse, simply because they are able to manage it, and as such are a formidable opponent.


There's this weird thing where HN users seem to think for some reason they are better than other people and users of this site wouldn't do X. It all seems incredibly silly with zero foundation in reality. This site has tons of morons. Just like every other publicly accessible website with free sign ups. You can see examples of this spread all throughout the comments on this post as an easy example.

I am not sure why all your comments are flagged, but here is my response to your other comment:

  > We plan to heavily overhaul the VPN implementation to make most forms of leaks nearly impossible rather than continuing to use the current system prone to it.
Thanks, great to hear. Given the slew of bugs you uncovered it seems the Android implementation has some rough edges. Would `pasta` be helpful to you? It allows you to unshare netns and then pass a user-space network adapter inside. https://passt.top/passt/about/ Podman leverages this one as well in more recent versions.

> I am not sure why all your comments are flagged

The past couple weeks of our replies were maliciously flagged. We've made a post about it on social media as we've had to do before when this happens. This happens very regularly to posts by GrapheneOS or posts which simply support GrapheneOS. There are a bunch of malicious accounts which show up to each thread about GrapheneOS to make personal attacks towards our team, baselessly claim it's a honey pot, promote non-hardened products reducing privacy/security compared to AOSP and to make a bunch of disingenuous attacks towards it. The attacks towards our team often involve fabricated stories about us and harassment content. There's an account active in many of these recent threads making disingenuous replies and spreading Kiwi Farms harassment content in their profile:

https://archive.ph/JAunG

That account should clearly be banned rather than a subset of their posts getting flagged. The same applies to several other blatant ones.


This comment specifically was also auto-collapsed for me, without being marked as flagged or dead.

It might help to ask moderation about this. Could be an artefact of brigarding or something similar.

I also wouldn't worry about individual accounts so much. Asking for others to be banned, linking mirrored profiles, etc. That is just not the stuff many users like to read on HN. I think your technical content is truly amazing on its own already.


[flagged]


The past several weeks of our replies were wrongly flagged. None of our posts were in any way inappropriate and it's entirely appropriate to ask for help getting it undone. On the other hand, you're repeatedly making personal attacks on our team, engaging in doxxing and spreading harassment content. You're directly pointing people to Kiwi Farms harassment content with blatant libel and doxxing. There have been years of this harassment on Hacker News without it being addressed by the moderators. We're not going to be tolerating it anymore. Hacker News actively engages in moderation and therefore has no excuse to be permitting this harassment and leaving up years of it across many threads.

Perhaps this is a stupid question, but have you emailed the moderators (rather than assuming they're aware of the issue) ?

We've previously emailed them with no result. This time around we got a reply about this specific account targeting us but it isn't resolved. We don't have much optimism about getting the many past threads with personal attacks based around fabricated stories and harassment content addressed without doing more than asking via email.

Asking for support is not brigading. The vouch button exists for a reason.

Regarding cellular connection, the proof of concept presented here only works on wifi: https://github.com/GrapheneOS/os-issue-tracker/issues/8617

I have a hunch this leak is bound to wifi hardware only, for details: https://supuk.ch/papers/android-natt-keepalive-vpn-bypass



The tool recommends you to use this skill <https://github.com/zachsaw/graphify-csharp/blob/main/.agents...>, but I wonder if this is the right approach if one just want to use this as a consumer in a .net project. It seems very wordy, but wording like these

  "Read the relevant design documents under docs/ before changing architecture."
makes me think that developing 'graphify the tool' and using 'graphify as a tool' are mixed up in the same document? How does an LLM keep track of both this gigantic skill and the user development problem at the same time?

Very good point! the graphify the tool and using graphify AS A tool have definitely beed mixed up! I'll fix this up. Thanks again and appreciate you looking into it!

Great, looking forward to it!

  > A proper fix would require changes in the Android system. The researcher who discovered the leak has reported the issue to the Android Vulnerability Reward Program, but according to the researcher the issue was closed without action. This issue is not public, but based on this information we deem it unlikely that Google will do anything about it. GrapheneOS is aware of the issue and are working on a fix.
If the account given by the researcher is correct, we cannot rule out that Google deliberately introduced or wanted to keep the leak in place.

Security issues considered outside the scope of what they consider a security vulnerability are closed regardless of what they plan to do about the issue. Google primarily uses internal issues to track issues with Android. Public issues and security issues filed by external parties are only used to communicate externally and an internal issue is created for their actual issue tracking.

A security issue being closed means you aren't getting a bounty and it won't be fixed for existing Android releases. It doesn't mean it won't be fixed in a future Android release. They do track VPN leaks as issues internally and regularly ship fixes in new major releases. They unfortunately don't consider those security issues so they don't get prioritized. If they were considered security issues, then they'd likely consider them Low or Moderate severity which means those wouldn't be backported.

Only a large subset of patches for High and Critical severity issues are backported to older releases of Android. Low and Moderate severity issues stopped having patches backported years ago due to volume. High and Critical severity patch backporting is now being scaled down too due to AI accelerated vulnerability discovery. You need the latest yearly or QPR2 release to get full updates.

GrapheneOS has had to fix a bunch of VPN leak issues and we're in the process of fixing more of the issues. We plan to heavily overhaul the VPN implementation to make most forms of leaks nearly impossible rather than continuing to use the current system prone to it.


The GrapheneOS team did not respond to an email report either [0]. Does that mean we can draw similar conclusions from the GrapheneOS team? I don't think that would be fair or correct, so why assume malice from Google just based on the (lack of) response to the report?

N.B. I don't disagree there is a possibility of foul play on Google's part, but I think more evidence / better argument is required.

[0] https://github.com/GrapheneOS/os-issue-tracker/issues/8617#i...


GOS explicitly stated that they work on a fix, also for other issues and they keep this on their radar.

Google just closed the ticket, without communicating their plan to deal with it. I just stated that we cannot rule out a possibility of foul play, thereby keeping other options open. Keeping that thing in mind which is better known as "the reality" I would be a little bit more wary about Google's stance towards privacy than I would be about GOS though. The difference in how these parties are handling this issue is already a tell.


There's a big difference between "the issue was closed" and "received no acknowledgment". The former is a deliberate action. The latter could be a case of SMTP-ate-my-email.

This is the email we received:

    Hello

    Check: https://news.ycombinator.com/item?id=49096839

    Please upvote/comment/share/mitigate
We passed it along to our developer working on solving VPN leaks. We didn't feel it was necessary to reply to a post linking to a public article. The article was shared with us by our users before we checked out emails.

We have a bunch of internally discovered VPN leaks which are already being worked on and this was added to that workload. We've already shipped a bunch of fixes and will ship more soon. We plan to eventually overhaul the whole system to prevent leaks in a much more systemic way.


Yep, that's a reasonable response. Thanks for your work.

Issue could have been closed by a mis-click, an AI bot gone wrong, a misunderstanding of the issue etc. You can't assert it was deliberate unless e.g. you work in the team that handled it and have inside knowledge. Agree GOS should have benefit of the doubt (too)

your logic would assert a similar conclusion with this scenario:

a person walks up to you, punches you in the face, and leaves.

it could have been an accident, an AI bot, or a misunderstanding. definitely not deliberate.


> we cannot rule out that Google deliberately introduced or wanted to keep the leak in place

I'd say a lot stronger than "cannot rule out". Regardless of how it was introduced, if it is now known and the issue was closed without action, they are actively choosing to keep it.


Google considers VPN leaks to be valid bugs but unfortunately doesn't consider them security bugs. Internal issues are created for any issue report considered valid. The external one is only used to communicate with people. If it was filed as a security bug, they'll close it if it isn't considered within the scope of the bounty program.

See https://news.ycombinator.com/item?id=49672677.


Using python or any other stone-age approach for search and replace is stupid when your language provides you with a complete, fully typed AST, like .NET does.

  >  i demonstrated replacing _all_of them at once, not replacing them each by hand.
Not really, that is search and replace. IDE's do typesafe refactoring. If you change the Find method in class A, you should only change occurences of x.foo(), where x has type A. You shouldn't accidentally change all B.find()'s.

That is my advice for everyone completing their first Python tutorial: learn a typed language next if you aspire to do serious work. It also saves you writing many manual tests that you had to make otherwise, as the compiler makes that superfluous. Plus your IDE becomes a superpower.


  > complaining about LLM-assisted writing.
I urge you to read the article. "assisted" is doing a lot of load-bearing work here. The problem is not just the writing style, but rather that it doesn't make sense at all.

Take the example for PGQ. "Two ordinary tables, one graph on top of them:" The example makes zero sense, because the fucking tables aren't even there. You can't be lazier than writing a prompt: "please make a blog post about the new PostgreSQL release, and give code examples for each new feature", then ctrl-c, ctrl-v the output.

You can write articles with the most horrible style if you want, but this level of disdain for readers is beyond belief.


You can add the following statements in the first example and click "Run" button in order to understand the underlying tables' structure and contents mentioned in the example:

    SELECT * FROM person;

    SELECT * FROM follows;
You can explore the database used in this example with any valid PostgreSQL statements.

Okay, that is better than I thought, can confirm it works.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: