Live data from Hacker News

Apple's iCloud+ “VPN”

metzdowd.com

121–130 of 413 posts

Re: Apple's iCloud+ “VPN”

#121
post #7

I think this is great, if only as a way to kill the bullshit consumer VPN business, which sells snake oil.

Doesn't a consumer VPN keep my ISP from building a data profile on me?

Yes, I get that now my VPN provider can build that data profile, but I am certain that my ISP is a vile monopoly that has corrupted the regulators that are supposed to represent me.

Re: Apple's iCloud+ “VPN”

#122

Earlier quoted context omitted.

If you want to give context, a link to the story would be nice: https://arstechnica.com/gadgets/2021/05/fake-dmca-takedown-n... Importantly, OpSec (the company doing this torrent-dmca-for-hire stuff) says the DMCA itself was spoofed > OpSec Security’s DCMA notice sending program was spoofed on Wednesday, May 26, 2021, by unknown parties across multiple streaming platforms.

...who names their company "OpSec"? Are they actively wanting to be made fun-of at the next defcon?

I mean, they're willing to work for ISPs doing torrent detection, which has been a scummy business from the start. Somehow, I would imagine they would be even less respected than the feds at defcon, since the feds actually do technically challenging things occasionally.

Re: Apple's iCloud+ “VPN”

#123
> All in all, a very Apple approach: They deny themselves any knowledge of a customer's DNS queries and Web traffic, so if served with a subpoena they have very little to respond with.

Maybe I am missing something but I view this is a rather genius move. They have plausible deniability + actually introduce some protection for their users.

Not sure how to read the original post though. Is it praising Apple? Is it mocking them? We don't have to be polar of course, I am just wondering.

Re: Apple's iCloud+ “VPN”

#124
post #71

Earlier quoted context omitted.

> I'd also really like to see Apple come clean about the iCloud backup encryption debacle Are you referring to this article?: https://www.reuters.com/article/us-apple-fbi-icloud-exclusiv... It's why I only use my Apple ID for grabbing apps from the app store. I have disabled all the `cloud storage` features of iCloud. iCloud is a privacy nightmare.

By that logic though, Google Drive, OneDrive, AmazonS3, they are all privacy nightmares. And you might agree, but Apple is hardly alone. And like the article says, they didn’t want to poke the bear anymore. Of course the FBI has congressional friends. It is possible that Apple saw the risk of it backfiring and making things worse as too great.

Google does end-to-end encryption of Android backups. And Apple knows how to do it too, but they intentionally restricted their implementation to only cover backups of Keychain passwords and a few other things, apparently because they don't have the courage to stand up to the FBI, according to Reuters. Strange considering their public stance against the FBI in the San Bernardino case and on privacy issues in general. Especially since iCloud backup totally defeats the highly touted end-to-end encryption in iMessage.

Re: Apple's iCloud+ “VPN”

#125
post #119

What's are the differences between a VPN and an onion router approach? Could anyone explain or link to an article?

A VPN is a middleman that accepts your traffic and forwards it, hiding who you are to servers. An onion router is like a VPN but instead of 1 middleman, the middleman is a whole random network of middlemen, and those middlemen also hand off to other middlemen.

Re: Apple's iCloud+ “VPN”

#126
post #3

My experience with this so far was... mixed. - This breaks DNS resolution for company-internal domains. - This routes all my traffic through CloudFlare or another CDN I might or might not trust (yes, the IP is hidden, but not the data) - it significantly slows down my internet access on my location. - it tends to turn itself on again without my intervention especially the last point is very problematic for me

To use it you're clearly using early beta software. Clearly it isn't going to "turn itself on again". I turned it on and actually forgot I did. Performance is decent here. I mean of course it's going to be worse than native, but that's the compromise. As to trusting Cloudflare -- what do you mean? You understand your connection is still TLS end-to-end encrypted (presuming that's what we're talking about), right? I me…

[Clearly not turn itself on.]

Funny story, I was shocked and quite annoyed that an iPhone automatically turns on Wifi and stuff every day by itself - even if you turn it off...

Still dont know how to actually turn it off

Re: Apple's iCloud+ “VPN”

#127
post #110

Interesting. I thought I recalled talking about this on HN previously: https://news.ycombinator.com/item?id=10355868 _-__--- on Oct 8, 2015 | parent | favorite | on: Verizon revives "zombie cookie" device tracking on... Tor as an OS-level feature may not spark the best reaction. It's been given a bad name ("deep web," silk road, etc) in mass media and many people don't understand it enough to think of it as anything…

An even more impressive prediction in 2015, a time when Apple was not positioned as some type of savior of user privacy.

[deleted]

Re: Apple's iCloud+ “VPN”

#128

Earlier quoted context omitted.

By that logic though, Google Drive, OneDrive, AmazonS3, they are all privacy nightmares. And you might agree, but Apple is hardly alone. And like the article says, they didn’t want to poke the bear anymore. Of course the FBI has congressional friends. It is possible that Apple saw the risk of it backfiring and making things worse as too great.

Google does end-to-end encryption of Android backups. And Apple knows how to do it too, but they intentionally restricted their implementation to only cover backups of Keychain passwords and a few other things, apparently because they don't have the courage to stand up to the FBI, according to Reuters. Strange considering their public stance against the FBI in the San Bernardino case and on privacy issues in general.…

Yes, backups, and Apple should get on that. However, your photos in Google Photos, your location data, your uploads in Google Drive (equivalent to iCloud Drive OP is talking about), not end to end encrypted and no option for it.

I think market share is another sign. Does anyone use actual Android Backup, or do they use the unencrypted “backups” in G Photos and elsewhere? For that reason should the FBI care? Maybe I’m wrong but I believe actual Android Backup is much less used than iCloud and confusingly named alternative “backups” within Google apps.

Re: Apple's iCloud+ “VPN”

#129
post #119

What's are the differences between a VPN and an onion router approach? Could anyone explain or link to an article?

A VPN is a middleman that accepts your traffic and forwards it, hiding who you are to servers. An onion router is like a VPN but instead of 1 middleman, the middleman is a whole random network of middlemen, and those middlemen also hand off to other middlemen.

This is a great summary, thanks

Re: Apple's iCloud+ “VPN”

#130
post #69

Earlier quoted context omitted.

What would the logs contain? I believe everything is encrypted on device before being sent to Apple.

Timestamp, source and destination ip addresses, username. In the case of the exit node, url.

Only the timestamp and username would be available from Apple.
Post reply on HN