Live data from Hacker News

VPNs on iOS are a scam

michaelhorowitz.com

121–130 of 260 posts

Re: VPNs on iOS are a scam

#121
post #104
post #39

Earlier quoted context omitted.

> You are wrong on this, the private part indicates the privacy it provides not the destination. I remember using VPNs long before, to my knowledge, people were using them in the way you describe, and I was always under the impression that the "P" in VPN meant "connecting private networks" together over the Internet. This document from 2001 agrees with me: https://docs.microsoft.com/en-us/previous-versions/windows/i.…

Yes, too bad about the downvotes but let me add on that and ask those who disagree what P stands for in WEP and WPA? lol. Wep is wired equivalent privacy. A connection that does not provide privacy like a GRE tunnel for example is called a tunnel never a VPN or more and GRE specifically connects networks which are typically private. You can also have VPN between two ASes on on the internet which are public networks.…

The P in WPA stands for Protection, the P in WEP stands for Privacy, the P in VPN stands for Private. Private and privacy don't have the same meaning, and one does not imply the other. I've cited an RFC from 1999 (RFC2547) in another reply to you that strongly suggests (to my reading, at least) that privacy was not necessarily implied in the notion of "private" (although of course a VPN could provide privacy). "Private IP addresses" in the form of "not publicly routable", but not necessarily with any privacy-providing encryption in the mix, seem closer in meaning in this case, and were often (but not always) part of it.

The same RFC also pretty clearly calls the network spanned by the tunnel, not the tunnel itself, a VPN.

By now, the meaning has shifted.

That being said, I think this is my last message on the topic, since, well... it's quite a lot of wasted time on pedantry (which is totally my fault).

Re: VPNs on iOS are a scam

#122

"Data is leaving my iPad and not traveling through the VPN tunnel." It is is interesting how the iPad purchaser refers to "my iPad". He owns the computer. But how much control does he have over it. He runs an OS controlled by a HW manufacturer turned trillion dollar tracking and data collection company. (Apple computers are extremely chatty on any network and phone home 24/7. Apple is fervent about its need to collec…

https://knowyourmeme.com/memes/we-should-improve-society-som...

This comment is a gish-gallop RMS-y soapboxing which is largely irrelevant-to-the-article points: that iPads (possibly all iOS devices) only pass some of their traffic over a VPN connection.

Re: VPNs on iOS are a scam

#123
mac/iOS still needs to do subnet local stuff like renew the DHCP lease and discover other link-local devices using mDNS/Bonjour. The system also periodically makes sure interfaces are “up” so it can seamlessly route traffic between cell and wifi. I would not assume that the presence of traffic where DST != VPN tunnel endpoint means that application traffic is leaking over the VPN. I only skimmed the article so someone correct me if there was a case of that observed. The “bug” where existing connections aren't terminated when you bring a VPN up sounds annoying but I can also see why the system wouldn't force terminate existing connections. The connection to the router’s public IP sounds like a hairpin. I also wouldn't be surprised if user-space VPN is outside of the scope of the APNS connection that the system maintains through sleep states.

Re: VPNs on iOS are a scam

#124
Can someone clarify this better than the author?

Trying to read through the whole thing, I can't tell if if this is claiming:

a) When a VPN is activated, pre-existing connections will continue communicating outside the VPN, but all new connections happen via the VPN

b) Apple services like the app store and/or certain other apps leak outside the VPN because of a) more than you would expect

c) Apple services like the app store and/or certain other apps leak outside the VPN for other reasons totally unrelated to a)

The author's tl;dr just says "data leaks" but I really just can't follow what that actually means.

It seems like a) is not entirely unexpected or necessarily a problem -- you probably turn on a VPN before initiating activities/apps you want routed through the VPN, so not usually problematic? But b) means it might be more serious than that, while c) would be even scarier?

Re: VPNs on iOS are a scam

#125
post #119

Earlier quoted context omitted.

I took it to mean a private network connecting two end points, not necessarily connecting two private networks, just that the tunnel (the network between them) was virtual and secure so the traffic exchanged couldn't be eavesdropped on, or modified, by every random node as it passed though the untrusted internet. I might have been influenced by the product we were selling though. These were dial up users on workstati…

Fair, it does seem that "privacy" VPNs are a lot older than I thought and possibly as old as the "VPN" moniker. (Assuming that your project was in the 90s, which it sounds like.) At this point it just seems like arguing for arguing's sake, but I was rejecting the notion that VPNs were always intended for privacy (along with saying others are wrong for suggesting otherwise). It still seems to me that VPNs did not alwa…

I agree, VPNs were absolutely not always used to hide internet activity, but sometimes they were. Early on they were certainly most often used by companies to connect networks or to connect to resources on their intranet, the need (and the money) was primarily there, but I'm not surprised that using VPNs for privacy reasons got more popular as time went on. Even back then I thought it was pretty cool/useful tech and I had no LAN to speak of.

Re: VPNs on iOS are a scam

#127
post #119

Earlier quoted context omitted.

Fair, it does seem that "privacy" VPNs are a lot older than I thought and possibly as old as the "VPN" moniker. (Assuming that your project was in the 90s, which it sounds like.) At this point it just seems like arguing for arguing's sake, but I was rejecting the notion that VPNs were always intended for privacy (along with saying others are wrong for suggesting otherwise). It still seems to me that VPNs did not alwa…

I agree, VPNs were absolutely not always used to hide internet activity, but sometimes they were. Early on they were certainly most often used by companies to connect networks or to connect to resources on their intranet, the need (and the money) was primarily there, but I'm not surprised that using VPNs for privacy reasons got more popular as time went on. Even back then I thought it was pretty cool/useful tech and…

I agree with all of that, too! And yeah, I think by now the meaning of "VPN" has well shifted, likely because of the privacy enhancement getting to popular (and I think I've also noticed that terms like "Intranet" and "Extranet" have somewhat fallen out of favor, too, but maybe that's just in my environments).

Re: VPNs on iOS are a scam

#128
post #5

I think Apple is transparent about Always on VPN (blocking traffic except over the tunnel) requiring provisioning using MDM tools. Apple Configurator is free and allows anyone to set this up. Any other VPN is just best effort. https://support.apple.com/guide/deployment/vpn-overview-depa...

[deleted]

Re: VPNs on iOS are a scam

#129

Earlier quoted context omitted.

> VPNs were always meant to carry internal traffic to a private network, not the public internet This. And the idea that these so called ‘VPN’ services somehow improve your security and privacy on the internet is laughable. All they do is let you get onto the public, untrusted, internet through a different on-ramp. There is no point to them. The internet is just as untrustworthy through a VPN service as it is through…

Thing is, if you ping experts in the privacy field (like Mike Bazzell, the former FBI OSINT guy who billionaires and celebs hire to keep their personal info off the internet), they will all say the VPNs are a very important tool to create a layer of privacy between you and the site you are visiting and also a good tool to prevent said sites from easily profiling you. No, they are not a panacea -- much like the securi…

> who billionaires and celebs hire to keep their personal info off the internet

I also do this type of work on the side. When it matters a device level VPN is never the correct option, because every OS leaks to some extent. They get a device where the cellular components have been disabled and it can only connect to a fixed wifi AP carried by one of their EP guys that tunnels the traffic back to a datacenter.

Re: VPNs on iOS are a scam

#130
post #62

It's also worth pointing out that tethered/hotspot data shared to the iPhone with a VPN enabled at the iPhone level will not travel through the VPN, but will rather leak your phone's IP: https://apple.stackexchange.com/questions/266871/is-there-a-...

this happens with android too. Which sucks. Although it is possible with root, which shows the benefit of having full control over your device
Post reply on HN