hn.today

I captured 72 hours of idle Android packets behind pfSense

praveentechworld.com42 points21 comments
Screenshot of I captured 72 hours of idle Android packets behind pfSense

A 72-hour external packet-capture experiment recorded every wireless packet from factory Google Pixel 8 phones left idle and plugged in behind an enterprise pfSense firewall running Wireshark. The phones were isolated on a private WPA3-Enterprise Wi‑Fi network with no other clients; an independent hardware wiretap ensured operating-system traffic could not be hidden by on-device monitoring. The complete raw CSV (timestamps, device build, destination domains and IPs, ASN 15169, ports, and payload sizes) is published under CC BY 4.0 for reanalysis.

The measurement shows stock Android phones never truly idle: an average of 348.4 outbound requests per hour (≈8,920 daily), with the top background leaks being Wi‑Fi BSSID uploads (84.2 req/hr), hardware and SIM fingerprint hashes (48.0 req/hr), Google Cloud Messaging heartbeats (14.8 req/hr), Google Photos sync tokens (28.5 req/hr), and search-widget prefetches (22.1 req/hr). Per-service breakdown lists Google Play Services (~142.6 req/hr, 7.8 MB/day), Location/Maps (~84.2 req/hr, 4.2 MB/day), Device Provisioning (~48/hr, 2.4 MB/day), Photos (~28.5/hr, 1.9 MB/day), and others. Replacing OS and Google services (e.g., GrapheneOS) or blocking known Google endpoints via Pi‑Hole/AdGuard/NextDNS dramatically reduces or eliminates these background connections.

Read on praveentechworld.com21 comments on Hacker News

Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.

More in Security

The daily digest

Today's best Hacker News stories, summarized and screenshotted, one email a day.