Live data from Hacker News

Apple's iCloud+ “VPN”

metzdowd.com

261–270 of 413 posts

Re: Apple's iCloud+ “VPN”

#261
post #24

Props to Apple for the design of this service. It doesn't hit all the privacy targets that long-time personal VPN users might be looking for, and it doesn't get into the game of trying to circumvent region locked content*, but otherwise it's likely to be a solid privacy improvement for almost all users in a careful and deliberate way. I use a VPN for other reasons (downloading Ubuntu ISOs mostly) but I'll probably tu…

> I use a VPN for other reasons (downloading Ubuntu ISOs mostly). This made me smile. Good one. For context, copyright trolls recently tried to extort torrent users for downloading and sharing Ubuntu ISOs.

"Linux ISOs" has been slang for a very long time:

https://www.urbandictionary.com/define.php?term=Linux+ISO&am...

Re: Apple's iCloud+ “VPN”

#263
post #203
post #92

Earlier quoted context omitted.

I wish I could pay for bbc iPlayer service outside old blighty. But they don't allow it.

You still can in some places if I recall correctly. Notably not in US due to licensing disagreements (of course).

Like, commonwealth nations? Or just countries too small to bother with the legal fees?

Re: Apple's iCloud+ “VPN”

#264
post #216

Earlier quoted context omitted.

Let's be really frank about it - no large company is going to offer end-to-end encryption of photos because of what kind of photos might end up on their infrastructure if they do. And honestly I don't blame them at all . I'd just like to see Apple be more transparent with this one particular issue because it undermines so much of what they're advertising to the consumer. A transparency label for iCloud backup showing…

Are you really arguing that because child pornography exists, no large company should offer ETE photos? Despite there been reasonable solutions like bloom filters and client sided hash detection, so that known child abuse material can be detected, without it needing to compromise the privacy of 99.99999% of users? And that photos present some of the most sensitive materials on your device: - geo-IP location showing b…

> Despite there been reasonable solutions like bloom filters and client sided hash detection, so that known child abuse material can be detected, without it needing to compromise the privacy of 99.99999% of users?

This is not a good argument. “Known child abuse material” is the tip of the iceberg. There’s nothing stopping people from creating new “child abuse material”, and the people who are doing that sort of thing are the ones who are more important to catch.

Re: Apple's iCloud+ “VPN”

#265
> The routing uses two hops; Apple provides the first, and "independent third parties" (not yet specified) provide the second.

This isn’t true though, they have specified who the independent third parties will be: CloudFlare Warp, Fastly, and Akamai. See here: https://www.barrons.com/articles/fastly-stock-outage-think-a...

Re: Apple's iCloud+ “VPN”

#266

Earlier quoted context omitted.

Google does end-to-end encryption of Android backups. And Apple knows how to do it too, but they intentionally restricted their implementation to only cover backups of Keychain passwords and a few other things, apparently because they don't have the courage to stand up to the FBI, according to Reuters. Strange considering their public stance against the FBI in the San Bernardino case and on privacy issues in general.…

Yes, backups, and Apple should get on that. However, your photos in Google Photos, your location data, your uploads in Google Drive (equivalent to iCloud Drive OP is talking about), not end to end encrypted and no option for it. I think market share is another sign. Does anyone use actual Android Backup, or do they use the unencrypted “backups” in G Photos and elsewhere? For that reason should the FBI care? Maybe I’m…

There are encryption options, just not with the software provided by the storage providers.

Re: Apple's iCloud+ “VPN”

#267

Interesting. I thought I recalled talking about this on HN previously: https://news.ycombinator.com/item?id=10355868 _-__--- on Oct 8, 2015 | parent | favorite | on: Verizon revives "zombie cookie" device tracking on... Tor as an OS-level feature may not spark the best reaction. It's been given a bad name ("deep web," silk road, etc) in mass media and many people don't understand it enough to think of it as anything…

Your prediction of it being called Apple Undercover is significantly more 80’s though. And I like it. So much so that I would accept Apple using something other than Helvetica this one time for a Miami Vice typeface and a Michael Knight and Kitt intro at WWDC. I cannot stress enough that Hasselhoff needs to stay in character the entire time or the whole concept doesn’t work.

> I would accept Apple using something other than Helvetica

At this point, Helvetica itself would give a retro feeling if used by Apple. They’ve been all in on San Francisco for several years.

Re: Apple's iCloud+ “VPN”

#268

> All in all, a very Apple approach: They deny themselves any knowledge of a customer's DNS queries and Web traffic, so if served with a subpoena they have very little to respond with. Maybe I am missing something but I view this is a rather genius move. They have plausible deniability + actually introduce some protection for their users. Not sure how to read the original post though. Is it praising Apple? Is it mock…

Apple has claimed this shtick several times (as well as many other VPN companies), but it actually requires a pretty intricate software setup to pull off. The best VPN services won't even have hard drives to store logs in: that way, even individuals with a court-issued warrant can't get your info. I'd imagine there's sufficient pressure on Apple from PRISM and other governments to keep some level of rudimentary logs.

> The best VPN services won't even have hard drives to store logs in: that way, even individuals with a court-issued warrant can't get your info

Courts can compel them to log this information, so all claims about not keeping logs are just theater. The second they're ordered to by a court in the US, they will.

Re: Apple's iCloud+ “VPN”

#269
post #250

Earlier quoted context omitted.

Because Google is definitely the most trustworthy company when it comes to data governance and respecting user privacy. No chance they'd use it to put you into a FLoC-type thing, benefiting their own advertising business while shutting out competitors. Google, the engineering company, always plays second fiddle to Google, the advertising company.

I trust Google and Apple 100x more (low estimate) than I do Comcast/Verizon, AT&T, etc.

I don’t trust google and apple equally. I trust google about the same level as comcast/etc.

apple having less advertising influence is more trustworthy, I think, in terms of privacy. don’t lump google in with them.

Meanwhile apple has many many anti consumer anti competitive policies so while I may trust my privacy with them more, I wouldn’t trust them to fight for my privacy rights in the long run.

Re: Apple's iCloud+ “VPN”

#270
post #24

Earlier quoted context omitted.

> I use a VPN for other reasons (downloading Ubuntu ISOs mostly). This made me smile. Good one. For context, copyright trolls recently tried to extort torrent users for downloading and sharing Ubuntu ISOs.

"Linux ISOs" has been slang for a very long time: https://www.urbandictionary.com/define.php?term=Linux+ISO&am...

Anecdote from my MSc year in 2003. In the dorm room I had 10Mbps Internet connection via the University's network which was quite amazing for the time. So among the real Linux ISOs, I tormented also the other kind of ISOs. At some point the Uni NOC reached out telling me that I'm consuming lots of BW for torrents which is against the policy, at which I replied that I download Linux ISOs and I'm happy to schedule it for after midnight, outside of peak hours. After some days I get a reply that please do so from another guy who forgot to remove the quote from his previous colleague which went something like "hey we have a problem with this guy's answer"

So yes, Linux ISOs is an old thing indeed

Post reply on HN