Live data from Hacker News

Apple's iCloud+ “VPN”

metzdowd.com

131–140 of 413 posts

Re: Apple's iCloud+ “VPN”

#131
post #89

Earlier quoted context omitted.

Many consumer VPNs install a client, and it would be trivial to ship a new trusted certificate with it.

That wouldn’t change that clicking the lock icon in your browser would show the same certificate on every website, and that this certificate was universally valid. Pretty obvious…

> show the same certificate on every website

Not really, because, you can use on-demand certificate issuance.

Hell, if you really want to, you can even name your certificates the same as existing certificates and the only way to detect the forgery would be to compare the actual public keys (and who does THAT).

I feel like I'm writing an evil roadmap here, but, you can even do multiple root certs with different names and trust them all, do a whole "fake" PKI infrastructure which would be impossible to detect unless you were comparing the actual keys.

Re: Apple's iCloud+ “VPN”

#132
post #58

Earlier quoted context omitted.

But also, and mostly, in reverse. The BBC is the producer and license owner of a ton of programming, and rather than offer that to the world for a subscription fee, they choose to offer it to select partners (previously mainly PBS, now Netflix and Amazon) for a licensing fee, or sometimes in a coproduction arrangement. This is big money, up-front, with no need to build out a global delivery system or deal with millio…

GP wanted to watch BBC News in particular. I don’t think there’s any licensing issue with that, surely?

> GP wanted to watch BBC News in particular. I don’t think there’s any licensing issue with that, surely?

Ha! There's SO SO MUCH. More than you can imagine.

Re: Apple's iCloud+ “VPN”

#133
post #87

> An big tradeoff for some is that the exit node is always chosen to be in the same geo location as the entry node. You can view this as a sop to the various on-line video providers How could it be a "sop" to video services, isn't it exactly what they want, no more no less?

What video services really want is for each user to be identifiable by IP address. This doesn't quite give them that, but it does region-lock them.

Re: Apple's iCloud+ “VPN”

#134
post #105
post #92

Earlier quoted context omitted.

I wish I could pay for bbc iPlayer service outside old blighty. But they don't allow it.

smartdnsproxy.com - 2 weeks, no credit card needed. Works perfectly and you don't need to use a VPN, just one of their DNS servers.

this is showing up as a malicious site.

Re: Apple's iCloud+ “VPN”

#135
post #7

I think this is great, if only as a way to kill the bullshit consumer VPN business, which sells snake oil.

I think that's painting with a pretty broad brush. What's wrong with Mullvad, for example?

The issue here preference falsification:

>Preference falsification is the act of communicating a preference that differs from one's true preference. The public frequently conveys, especially to researchers or pollsters, preferences that differ from what they truly want, often because they believe the conveyed preference is more acceptable socially.

The reason why the VPN business is booming is to avoid those pesky content infringement letters, and to workaround geo restrictions.

OP is upset that they advertise themselves as privacy tools, but that's just marketing.

Re: Apple's iCloud+ “VPN”

#137

Props to Apple for the design of this service. It doesn't hit all the privacy targets that long-time personal VPN users might be looking for, and it doesn't get into the game of trying to circumvent region locked content*, but otherwise it's likely to be a solid privacy improvement for almost all users in a careful and deliberate way. I use a VPN for other reasons (downloading Ubuntu ISOs mostly) but I'll probably tu…

> It would be nice if the BBC didn't block like this, but UK residents do typically pay for the content whereas those outside the UK are unable to.

As an exiled Londoner, I would love to be able to pay to access BBC programmes. Unfortunately I can’t, so a VPN is often the only solution (well, I guess torrenting would be another one, but it’s not really better).

Re: Apple's iCloud+ “VPN”

#138

Props to Apple for the design of this service. It doesn't hit all the privacy targets that long-time personal VPN users might be looking for, and it doesn't get into the game of trying to circumvent region locked content*, but otherwise it's likely to be a solid privacy improvement for almost all users in a careful and deliberate way. I use a VPN for other reasons (downloading Ubuntu ISOs mostly) but I'll probably tu…

[deleted]

Re: Apple's iCloud+ “VPN”

#139
Potentially, this provides troves of data to the exit node operators (CloudFlare, Fastly, Akamai, ...). Yes, it's the same with all VPNs and ISPs, but I think users should be made aware that now instead of your ISP analyzing the data, an even bigger and more capable corporation is. And if Apple is controlling the entire onion chain (I would be surprised if they weren't), they have even more data available, mainly with a corresponding IP of yours. In the net sum, you are hiding the transmitted data from your ISP and the IP from the sites you visit, but you are handing over all this information to a centralized place - Apple and exit node providers. Potentially, they can use the information to connect the dots more easily and fully than any ISP or site ever could.

Re: Apple's iCloud+ “VPN”

#140
post #79
post #47

My guess is one of the major reasons for having the exit nodes in the same geo location as entry nodes is to have continuous operations in China. Without this constraint, they would have allowed chinese consumers to access the free web, which would ban them instantaneously. I don't think Apple cares as much about video content providers, though.

> I don't think Apple cares as much about video content providers, though. Not being able to watch Netflix, Amazon Video etc. in Safari seems like something Apple would in fact care about.

Not if it gets them banned in those countries.
Post reply on HN