Earlier quoted context omitted.
The issue in the article isn't that the VPN is sometimes inactive, it's that when the VPN is active, some traffic escapes the VPN. As far as I can see the linked page doesn't say that your VPN will leak unless you're using Always On. Plus, that page documents the VPN features built in to iOS itself, not VPNs provided by apps.
The ProtonMail article said it only applies to pre-existing connections, because iOS doesn't force them to close when an app enables its VPN. I'd be reluctant to call that a leak, unless it contradicts Apple's documented behaviors, which as far as I can tell make no mention of a systemwide VPN except for corporate "always on" ones. Besides, is there any reason why you can't just toggle airplane after enabling a consu…
VPNs on iOS are a scam
51–60 of 260 posts
Re: VPNs on iOS are a scam
#52I remember recently using Cloudflare Warp and using one of those webpages that tell you your IP address and it showed my real IP address. It was a bit weird.
Warp is not designed to hide your address. If website is behind cloudflare, it'll know your IP address. If website is not behind cloudflare, your address will not be available.
Re: VPNs on iOS are a scam
#53Earlier quoted context omitted.
That doesn’t sound right. https://blog.cloudflare.com/warp-for-desktop/ > WARP was built on the philosophy that even people who don’t know what “VPN” stands for should be able to still easily get the protection a VPN offers.
> From a technical perspective, WARP is a VPN. But it is designed for a very different audience than a traditional VPN. WARP is not designed to allow you to access geo-restricted content when you’re traveling. It will not hide your IP address from the websites you visit. If you’re looking for that kind of high-security protection then a traditional VPN or a service like Tor are likely better choices for you. See: htt…
Re: VPNs on iOS are a scam
#54Re: VPNs on iOS are a scam
#55I don’t care for VPNs but I do want an adblocker. What are my options aside from using a public pihole dns or a vpn to a private dns server?
Tailscale + Pihole works well, https://tailscale.com/kb/1114/pi-hole/
Using iOS's built in support for browser adblockers is largely as effective and doesn't come with the battery life hit.
Re: VPNs on iOS are a scam
#56Earlier quoted context omitted.
That Apple documents that 'normal' VPNs are broken on iOS doesn't change the fact that they're broken.
VPNs were always meant to carry internal traffic to a private network, not the public internet (hence the name Virtual Private Network). The fact that a VPN server can send you a route for 0.0.0.0/0 always was and always will be a happy accident.
what people expect, and what is being sold, is an encrypted tunnel that all traffic goes through, to an endpoint. That this is called "VPN" is irrelevant.
I have a GL-iNet Mango that i have setup to provide "always on wireguard" to a computer in a datacenter i control the public IP for. I haven't tested, but i expect all data sent to and from any devices connected to that Device's SSID to be tunneled via wireguard to the computer in the DC, and therefore, to all outside observers the DC is where my device is. Obviously the ISP can see the session, but since they have no say over the DC endpoint, they have no way of knowing what the traffic is or where it's going. It could just be me doing SSH or video streaming or backups to and from the datacenter, or i could be watching netflix or youtube.
In that circumstance, an iOS device shouldn't be able to leak my local network's ostensible "public IP", since the actual transport layer is outside of the iOS device's control.
With all of this being said, i don't think there's any way to guarantee that leaks are impossible without literally air-gapping your devices and forcing all traffic through something that cannot communicate with anything but the remote endpoint - that is, if the wireguard connection fails, all pings fail, all TCP/UDP/etc traffic times out, and so on. In this manner, probably all things sold as "secure VPN" or as a service that does that are scams. This is the issue that TFA is complaining about.
in a situation where it's life and death - i would find an open wifi access point and connect a wireless bridge device (e.g. tp link TL-WR802N), with an STP ethernet cable to something similar to the gl-iNET mango, with 100% forced wireguard connectivity. I'd only consider this viable after doing tshark or tcpdump on the server i control log access to, to verify that my (local) MAC address and/or stuff like webrtc or whatever are blocked/dropped.
sorry for the length, but i didn't want to make multiple comments all over the threads.
Re: VPNs on iOS are a scam
#57Earlier quoted context omitted.
That Apple documents that 'normal' VPNs are broken on iOS doesn't change the fact that they're broken.
VPNs were always meant to carry internal traffic to a private network, not the public internet (hence the name Virtual Private Network). The fact that a VPN server can send you a route for 0.0.0.0/0 always was and always will be a happy accident.
To be clear, is what you're saying that it is ok for VPNs to be broken (or at least less bad) because their most popular usage isn't what they were originally intended for?
If that wasn't your point, what was?
Re: VPNs on iOS are a scam
#58Re: VPNs on iOS are a scam
#59Earlier quoted context omitted.
I hope Wireguard makes it into iOS/macOS at some point. Still early days relative to other protocols of course but it's so much simpler and more reliable (even beyond the security benefits). I use it extensively on both platforms for access to my own networks and services nowadays.
Quoted post unavailable.
It used to be a huge issue, but thankfully that’s been fixed. I can’t tell you how many times my Mac crashed due to faulty “enterprise” security kexts.
Re: VPNs on iOS are a scam
#60Earlier quoted context omitted.
VPNs were always meant to carry internal traffic to a private network, not the public internet (hence the name Virtual Private Network). The fact that a VPN server can send you a route for 0.0.0.0/0 always was and always will be a happy accident.
[flagged]
What are VPN services SOLD AS? If they promise something and do not do that thing, then this is a problem. They should be sued or regulated or similar, and they shouldn't be able to get around that, even based on techinical definitions.