5/9/2026 at 4:08:15 PM
> Because system_server operates with elevated networking privileges and is exempt from VPN routing restrictionsSo a VPN isn't a VPN on Android? Regardless of this bug. Do other locked down operating systems act the same?
by nottorp
5/9/2026 at 4:43:55 PM
Ios does the same, only way around it is if you have an ?enterprise? licence (250+ devices)Mullvad and others reported on that one ages ago
by Paradigm2020
5/9/2026 at 6:05:10 PM
Is this really true? The Mullvad report a year or so ago was that they didn’t want to turn on no exceptions mode because it breaks network connectivity until reboot if you don’t pause it when updating the app, not that the feature doesn’t exist. They also recently shipped it anyway, opt in and behind a warning.by kqp
5/12/2026 at 5:34:12 PM
As a quick chatgpt check and following the links to apple's own site that still seems to be the case...Force “most” traffic through VPN using includeAllNetworks Yes, but imperfect (normal) Yes (supervision)
stronger controls are tied to device management / supervision, usually for organization-owned devices.
https://developer.apple.com/documentation/NetworkExtension/N...
by Paradigm2020
5/9/2026 at 10:57:58 PM
a VPN enabled wifi router would suffice as a fallback tho right?by pyaamb
5/12/2026 at 5:29:34 PM
You could get one of those hotspots https://www.gl-inet.com/products/gl-mifi/Haven't bought one (yet - but did quite a bit of research but again outdated by 2 years...)
by Paradigm2020
5/10/2026 at 9:25:52 AM
For the very specific case where you are connected to that router, yes.by ranguna
5/9/2026 at 4:44:13 PM
MacOS has had instances where their own apps could bypass always-on VPN. I'm not sure if there have been exploits or gaps where traffic could go to arbitrary destinations directly.by unethical_ban
5/9/2026 at 5:14:39 PM
this is not an ocassional bug this is still the system design today. privacy gateways upstream of big tech are the way to go on this because privacy isn't their profit centerby spr-alex
5/9/2026 at 5:30:12 PM
Terminology like "private" and "trust" differ in meaning from computer land to human convention.It's a concern to me, because humans often extend their trust to computer trust based upon misunderstanding of the identically spelled words and lack of recognition of differing context.
by ncr100
5/9/2026 at 4:58:52 PM
How hard would it be to fix the system_server (and any other) bypass?by mmooss