Elektrine lite

← Feed

@icon_of_computational_sin@mstdn.starnix.network

2026-05-02 13:22 UTC

From: https://lowlevel.fun/posts/tiny-udp-cannon-android-vpn-bypass/ The fact that this pretty stupid VPN circumvention exists isn't a big surprise, given how bloated and over-engineered Android (and probably any other L'Eunuchs system) is. The surprising part is these words here: Asked If I am free to disclose With some uncanny rituals, not at all dissimilar from cults or MLM schemes, big tech corpos have managed to guilt trip a huge crowd of nerds that said corpos are owed the honour of being asked permission to do things. Not because these nerds are paid to do this--most bug bounty programs offer scraps, you can sell these 0days and other secrets to Mossad or CIA for 10x the amount--but because it's somehow "ethical". In quotation marks, because nobody can even tell what ethics system here is usually referred to (deontologists can suck a dingus). All while the same corpos have NO WARRANTY clauses in every single software licence they employ, even in EULAs. And where this isn't possible, they limit the maximum possible compensation to a laughable sum. Remember, boys and girls. You don't owe corpos anything. And you certainly owe their customers even less than that. Full and immediate disclosure is the only way. Let them deal with the consequences of pushing shit code into prod, this isn't your problem. SEE SOMETHING, SAY SOMETHING

Replies (3)

  • @phnt@fluffytail.org 2026-05-02 13:26

    @icon_of_computational_sin@mstdn.starnix.network >Let them deal with the consequences of pushing shit code into prod, this isn't your problem. As I've said on IRC, you only say this because you don't have to deal with the chaos and panic in the aftermath of disclosing high severity issues before a fix is released. You never had to sit down and try to figure out which of your possibly hundreds or thousands of systems is affected and how to fix it.

    Open ##1885124

  • @icon_of_computational_sin@mstdn.starnix.network > First, nobody checks the payload is actually a QUIC CONNECTION_CLOSE frame. The bytes are whatever you want. who comes up with these ideas.

    Open ##2686530

  • @m0xEE@breloma.m0xee.net 2026-05-02 14:49

    @icon_of_computational_sin@mstdn.starnix.network > pretty stupid VPN circumvention exists Android is as lax as it can possibly be with such things. There is a http(s) proxy configured for this network, but it doesn't respond in a timely manner? Let's send all traffic directly — software has to be able to phone home at all cost! Then there is this switch in VPN settings: "Block connections without VPN" :marseysigh: What happens if VPN connection goes down, does the traffic get dropped? From the phone it does — or at least so it seems. But what if you've been sharing your VPN connection wirelessly, can wireless clients still connect to the outside world? They sure do! NAT just switches to sending all their traffic directly over your cellular connection.

    Open ##2686533