Earlier quoted context omitted.
Because if you used a central cert, every device would have to whitelist that cert, and just clocking the lock icon in your browser would reveal it.
Many consumer VPNs install a client, and it would be trivial to ship a new trusted certificate with it.
Apple's iCloud+ “VPN”
101–110 of 413 posts
Re: Apple's iCloud+ “VPN”
#102Earlier quoted context omitted.
But also, and mostly, in reverse. The BBC is the producer and license owner of a ton of programming, and rather than offer that to the world for a subscription fee, they choose to offer it to select partners (previously mainly PBS, now Netflix and Amazon) for a licensing fee, or sometimes in a coproduction arrangement. This is big money, up-front, with no need to build out a global delivery system or deal with millio…
The BBC aren't allowed to. There are very strict terms in which the BBC can operate. So what they have to do is sell to subsidiaries like BBC America. And there in lies the licensing issues described in the GPs post. This is one of those classic examples of something that looks really simple from an outsiders perspective but once you have to deal with the details you realise it's anything but simple. And through no f…
Hell, I thought the practice would die (or at least slow down) when Netflix started transitioning away from syndicated TV and movies; this never happened. Netflix will totally geoblock their own shows so they can, say, release a cartoon on a weekly basis in Japan but in binge-watchable chunks in America.
You will continue to see anything more premium than a high-subscriber-count YouTube channel be geoblocked until and unless one of two things happens:
- Geoblocking gets so heinous that it starts to push people away from shows and services, beyond ordinary subscriber churn. This is unlikely - the US is the biggest market for a lot of this stuff, and that's a market full of people who have no desire to watch foreign media ahead of an official release. Hell, most of us don't even have passports, and think that you can just move to another country by asking politely.
- Some country or trading bloc gets enough of a bug up their butt about getting releases late that they start amending copyright law to ban the practice. AFAIK, I've heard Australia was considering banning region locked DVD players at one point; and that the EU was considering forcing online video providers to license content on an EU-wide basis.
Re: Apple's iCloud+ “VPN”
#103Earlier quoted context omitted.
That’s the beauty of this. Party 2 only knows Apple’s IP. Apple doesn’t know what site you’re visiting. So how do you assemble “all traffic to this site” even by subpoenaing both parties?
To party 1: "Give us a netflow log of all of this user's traffic." To party 2: "Give us a list of all outbound connections matching this netflow list of inbound proxying requests." It would work the other way around as well (going from visited sites to a given Apple id). If you can monitor all nodes in an onion routing network, you can deanonymize everybody.
This means that Apple’s logs would say this user authenticated and passed some encrypted stuff to Fastly, and Fastly would say that it received requests from Apple, without an identifier to match it up against the first request.
Once this scales and Apple has millions of requests incoming, there will be no way to conclusively prove that two requests are the same.
In which case a double subpoena is again useless. And this assuming they keep logs - if they don’t keep logs, which is more likely, it’s even more useless.
This also aligns with something we currently know. Apple says they can’t see your requests. This implies that they just pass data along in an encrypted format to their partners. So all Apple does is make it so their partners don’t know your device, and the partners ensure Apple doesn’t know your request.
Ultimately, even if logs were kept, there would have to be a unique identifier of some sort that was passed on to the second server from the first server to break the system. You decide the odds that they did that. Sounds a lot like an IP Address, in which case why not just build a classic VPN?
Re: Apple's iCloud+ “VPN”
#104Props to Apple for the design of this service. It doesn't hit all the privacy targets that long-time personal VPN users might be looking for, and it doesn't get into the game of trying to circumvent region locked content*, but otherwise it's likely to be a solid privacy improvement for almost all users in a careful and deliberate way. I use a VPN for other reasons (downloading Ubuntu ISOs mostly) but I'll probably tu…
I wish I could pay for bbc iPlayer service outside old blighty. But they don't allow it.
Re: Apple's iCloud+ “VPN”
#105Props to Apple for the design of this service. It doesn't hit all the privacy targets that long-time personal VPN users might be looking for, and it doesn't get into the game of trying to circumvent region locked content*, but otherwise it's likely to be a solid privacy improvement for almost all users in a careful and deliberate way. I use a VPN for other reasons (downloading Ubuntu ISOs mostly) but I'll probably tu…
I wish I could pay for bbc iPlayer service outside old blighty. But they don't allow it.
Re: Apple's iCloud+ “VPN”
#106Expected this to take the top spot right after the keynote.
Re: Apple's iCloud+ “VPN”
#107Earlier quoted context omitted.
Because if you used a central cert, every device would have to whitelist that cert, and just clocking the lock icon in your browser would reveal it.
Many consumer VPNs install a client, and it would be trivial to ship a new trusted certificate with it.
Re: Apple's iCloud+ “VPN”
#108Earlier quoted context omitted.
Apple has sort of addressed this with only having it work with Safari and other apps that implement the API, rather than system-wide as something you can connect to. It’s probably going to take a lot of reverse engineering before hackers figure out the API and how to get third party devices to connect and authenticate, if at all. If you can’t get third party devices to connect, you are missing the first D in DDOS.
There is also almost certainly an authentication mechanism in place, even if you were to reverse engineer the API. You'd need a bunch of paid iCloud accounts to have a DDoS be at all feasible with this service. Additionally, Cloudflare themselves, one of Apple's third party partners, offer DDoS protection services. Because they see all the exit traffic, they'd be able to detect the DDoS and block it.
I can't see Cloudflare putting themselves in the position of needed to protect their clients from themselves ...
Re: Apple's iCloud+ “VPN”
#109I've been trying to point this out to people but YouTube personalities have a louder voice than anyone else so you end up with bad information. Props to Apple for offering an (albeit low entropy) onion router on their own infrastructure. I can't imagine this is going to win them any friends in government circles but it's definitely a step in the right direction. I'd also really like to see Apple come clean about the…
re: non-encrypted iCloud storage: I agree with you. I keep medical and financial data encrypted (e.g., their Pages app supports encrypting documents, and you can encrypt PDFs, etc.) but I would rather they did this for me. That said, for the 90% of my files that I would post on a street corner, I find iCloud storage across my devices is handy.
Re: Apple's iCloud+ “VPN”
#110Interesting. I thought I recalled talking about this on HN previously: https://news.ycombinator.com/item?id=10355868 _-__--- on Oct 8, 2015 | parent | favorite | on: Verizon revives "zombie cookie" device tracking on... Tor as an OS-level feature may not spark the best reaction. It's been given a bad name ("deep web," silk road, etc) in mass media and many people don't understand it enough to think of it as anything…