FINDING · DEPLOYMENT

ShieldShare demonstrates that an Android application can route all hotspot-client traffic through a VPN tunnel without root access by using a SOCKS5/HTTP/HTTPS proxy layer between the hotspot and the VPN, with per-client traffic accounting and quota management. The system works because Android's native hotspot does not forward VPN routing tables to connected clients; ShieldShare interposes a proxy that handles this. Released as open-source.

From 2026-edorh-shieldshareShieldShare: Building a VPN-backed Android Hotspot for Secure Internet Sharing with Per-User Traffic Accounting · §Abstract · 2026 · arXiv preprint

Implications

Tags

censors
generic
techniques
ip-blocking
defenses
tunneling

Extracted by claude-sonnet-4-6 — review before relying.