Live data from Hacker News

Apple's iCloud+ “VPN”

metzdowd.com

101–110 of 413 posts

Re: Apple's iCloud+ “VPN”

#101
post #89

Earlier quoted context omitted.

Because if you used a central cert, every device would have to whitelist that cert, and just clocking the lock icon in your browser would reveal it.

Many consumer VPNs install a client, and it would be trivial to ship a new trusted certificate with it.

This is true, but note that, for example, on iOS an application can't do that without prompting. Now, most people would probably hit “Approve” if one of their security products said it was necessary.

Re: Apple's iCloud+ “VPN”

#102
post #49

Earlier quoted context omitted.

But also, and mostly, in reverse. The BBC is the producer and license owner of a ton of programming, and rather than offer that to the world for a subscription fee, they choose to offer it to select partners (previously mainly PBS, now Netflix and Amazon) for a licensing fee, or sometimes in a coproduction arrangement. This is big money, up-front, with no need to build out a global delivery system or deal with millio…

The BBC aren't allowed to. There are very strict terms in which the BBC can operate. So what they have to do is sell to subsidiaries like BBC America. And there in lies the licensing issues described in the GPs post. This is one of those classic examples of something that looks really simple from an outsiders perspective but once you have to deal with the details you realise it's anything but simple. And through no f…

More generally, geographic licensing maximizes revenue without damaging brand goodwill for the vast majority of customers, so pretty much everyone is going to do it.

Hell, I thought the practice would die (or at least slow down) when Netflix started transitioning away from syndicated TV and movies; this never happened. Netflix will totally geoblock their own shows so they can, say, release a cartoon on a weekly basis in Japan but in binge-watchable chunks in America.

You will continue to see anything more premium than a high-subscriber-count YouTube channel be geoblocked until and unless one of two things happens:

- Geoblocking gets so heinous that it starts to push people away from shows and services, beyond ordinary subscriber churn. This is unlikely - the US is the biggest market for a lot of this stuff, and that's a market full of people who have no desire to watch foreign media ahead of an official release. Hell, most of us don't even have passports, and think that you can just move to another country by asking politely.

- Some country or trading bloc gets enough of a bug up their butt about getting releases late that they start amending copyright law to ban the practice. AFAIK, I've heard Australia was considering banning region locked DVD players at one point; and that the EU was considering forcing online video providers to license content on an EU-wide basis.

Re: Apple's iCloud+ “VPN”

#103
post #83
post #65

Earlier quoted context omitted.

That’s the beauty of this. Party 2 only knows Apple’s IP. Apple doesn’t know what site you’re visiting. So how do you assemble “all traffic to this site” even by subpoenaing both parties?

To party 1: "Give us a netflow log of all of this user's traffic." To party 2: "Give us a list of all outbound connections matching this netflow list of inbound proxying requests." It would work the other way around as well (going from visited sites to a given Apple id). If you can monitor all nodes in an onion routing network, you can deanonymize everybody.

Well, here’s the catch. Even if logs were kept, the 2nd party as far as we know does not have a unique identifier passed onto it.

This means that Apple’s logs would say this user authenticated and passed some encrypted stuff to Fastly, and Fastly would say that it received requests from Apple, without an identifier to match it up against the first request.

Once this scales and Apple has millions of requests incoming, there will be no way to conclusively prove that two requests are the same.

In which case a double subpoena is again useless. And this assuming they keep logs - if they don’t keep logs, which is more likely, it’s even more useless.

This also aligns with something we currently know. Apple says they can’t see your requests. This implies that they just pass data along in an encrypted format to their partners. So all Apple does is make it so their partners don’t know your device, and the partners ensure Apple doesn’t know your request.

Ultimately, even if logs were kept, there would have to be a unique identifier of some sort that was passed on to the second server from the first server to break the system. You decide the odds that they did that. Sounds a lot like an IP Address, in which case why not just build a classic VPN?

Re: Apple's iCloud+ “VPN”

#104
post #92

Props to Apple for the design of this service. It doesn't hit all the privacy targets that long-time personal VPN users might be looking for, and it doesn't get into the game of trying to circumvent region locked content*, but otherwise it's likely to be a solid privacy improvement for almost all users in a careful and deliberate way. I use a VPN for other reasons (downloading Ubuntu ISOs mostly) but I'll probably tu…

I wish I could pay for bbc iPlayer service outside old blighty. But they don't allow it.

This is as much to do with their content license agreements as it is BBC being disinterested. Material BBC licenses to distribute, they are limited to the UK, and content BBC licenses to foreign TV presumably can't be also distributed to that same region. There is a service BBC run which allows those outside the UK to stream some content (https://www.britbox.com/us/).

Re: Apple's iCloud+ “VPN”

#105
post #92

Props to Apple for the design of this service. It doesn't hit all the privacy targets that long-time personal VPN users might be looking for, and it doesn't get into the game of trying to circumvent region locked content*, but otherwise it's likely to be a solid privacy improvement for almost all users in a careful and deliberate way. I use a VPN for other reasons (downloading Ubuntu ISOs mostly) but I'll probably tu…

I wish I could pay for bbc iPlayer service outside old blighty. But they don't allow it.

smartdnsproxy.com - 2 weeks, no credit card needed. Works perfectly and you don't need to use a VPN, just one of their DNS servers.

Re: Apple's iCloud+ “VPN”

#107
post #89

Earlier quoted context omitted.

Because if you used a central cert, every device would have to whitelist that cert, and just clocking the lock icon in your browser would reveal it.

Many consumer VPNs install a client, and it would be trivial to ship a new trusted certificate with it.

That wouldn’t change that clicking the lock icon in your browser would show the same certificate on every website, and that this certificate was universally valid. Pretty obvious…

Re: Apple's iCloud+ “VPN”

#108
post #93

Earlier quoted context omitted.

Apple has sort of addressed this with only having it work with Safari and other apps that implement the API, rather than system-wide as something you can connect to. It’s probably going to take a lot of reverse engineering before hackers figure out the API and how to get third party devices to connect and authenticate, if at all. If you can’t get third party devices to connect, you are missing the first D in DDOS.

There is also almost certainly an authentication mechanism in place, even if you were to reverse engineer the API. You'd need a bunch of paid iCloud accounts to have a DDoS be at all feasible with this service. Additionally, Cloudflare themselves, one of Apple's third party partners, offer DDoS protection services. Because they see all the exit traffic, they'd be able to detect the DDoS and block it.

That's why this concern seemed weird to me; the exit nodes ARE the DDoS protection services.

I can't see Cloudflare putting themselves in the position of needed to protect their clients from themselves ...

Re: Apple's iCloud+ “VPN”

#109

I've been trying to point this out to people but YouTube personalities have a louder voice than anyone else so you end up with bad information. Props to Apple for offering an (albeit low entropy) onion router on their own infrastructure. I can't imagine this is going to win them any friends in government circles but it's definitely a step in the right direction. I'd also really like to see Apple come clean about the…

I am running APple's betas for iOS, iPadOS, and macOS right now - I really appreciate their implementing yet more privacy.

re: non-encrypted iCloud storage: I agree with you. I keep medical and financial data encrypted (e.g., their Pages app supports encrypting documents, and you can encrypt PDFs, etc.) but I would rather they did this for me. That said, for the 90% of my files that I would post on a street corner, I find iCloud storage across my devices is handy.

Re: Apple's iCloud+ “VPN”

#110

Interesting. I thought I recalled talking about this on HN previously: https://news.ycombinator.com/item?id=10355868 _-__--- on Oct 8, 2015 | parent | favorite | on: Verizon revives "zombie cookie" device tracking on... Tor as an OS-level feature may not spark the best reaction. It's been given a bad name ("deep web," silk road, etc) in mass media and many people don't understand it enough to think of it as anything…

An even more impressive prediction in 2015, a time when Apple was not positioned as some type of savior of user privacy.
Post reply on HN