Live data from Hacker News

Apple's iCloud+ “VPN”

metzdowd.com

141–150 of 413 posts

Re: Apple's iCloud+ “VPN”

#141

I've been trying to point this out to people but YouTube personalities have a louder voice than anyone else so you end up with bad information. Props to Apple for offering an (albeit low entropy) onion router on their own infrastructure. I can't imagine this is going to win them any friends in government circles but it's definitely a step in the right direction. I'd also really like to see Apple come clean about the…

I have very little respect for Youtube personalities (thinking of LTT in particular) when it comes to talking about Apple in particular. They are so wedded to their "everyone, except us, is evil" perspective that their knee-jerk reaction to almost anything from Apple, privacy or otherwise is negative. (LTT spent the first bit trashing Apple for making marketing claims about the M1, instead of letting them do, then refused to back off when numbers backed up their claims, continue to trash anything with Apple and privacy, etc).

Apple is not without sin. If we get out of this entire epic lawsuit (another company not without sin) with consumers winning the ability to side-load, it's a win. But for the most part, Apple has a multi-decade history of usually working for customers in above-board ways, as opposed to Facebook, Googles and other(s).

Re: Apple's iCloud+ “VPN”

#142
post #130

Earlier quoted context omitted.

Timestamp, source and destination ip addresses, username. In the case of the exit node, url.

Only the timestamp and username would be available from Apple.

Source IP address and next-hop IP address would be as well.

Re: Apple's iCloud+ “VPN”

#143
post #52

Earlier quoted context omitted.

what is bullshit about it

Have you noticed all the ads say “Hackers can spy on your connection when you log into your bank at Starbucks.” That’s complete FUD. HTTPS completely avoids this issue ( especially with a bank). Very few websites use HTTP now. While VPNs do have their valid use (preventing your ISP from spying, changing geolocation, and private networks for eg, work), most of the marketing is spreading misinformation.

I've seen stats for a couple of the biggest VPNs. Massive majority of their traffic is just switching geolocation restrictions (US Netflix and similar).

They don't tend to advertise that. Some do, but it's not their main message, because "prevent ISPs from spying" is cleaner.

iCloud+ does not solve this, so there will be a sustained need for VPNs, particularly those that invest effort into into avoiding Netflix blacklists.

Re: Apple's iCloud+ “VPN”

#144
post #79
post #47

My guess is one of the major reasons for having the exit nodes in the same geo location as entry nodes is to have continuous operations in China. Without this constraint, they would have allowed chinese consumers to access the free web, which would ban them instantaneously. I don't think Apple cares as much about video content providers, though.

> I don't think Apple cares as much about video content providers, though. Not being able to watch Netflix, Amazon Video etc. in Safari seems like something Apple would in fact care about.

HBO is blocking Private Relay regardless.

Re: Apple's iCloud+ “VPN”

#145

Earlier quoted context omitted.

I think that's painting with a pretty broad brush. What's wrong with Mullvad, for example?

The issue here preference falsification: >Preference falsification is the act of communicating a preference that differs from one's true preference. The public frequently conveys, especially to researchers or pollsters, preferences that differ from what they truly want, often because they believe the conveyed preference is more acceptable socially. The reason why the VPN business is booming is to avoid those pesky co…

Yea you don't legally market your product as a tool to commit a crime but 'privacy' is pretty broad term and partially true so it works.

Re: Apple's iCloud+ “VPN”

#146
post #22
post #6

Earlier quoted context omitted.

> This breaks DNS resolution for company-internal domains. Is this not the case for any VPN or proxying service? In fact, it could even be a security flaw if your internal domains were accessible on external VPN style endpoints?

> Is this not the case for any VPN or proxying service? No, it's not. > In fact, it could even be a security flaw if your internal domains were accessible on external VPN style endpoints? It would be, but then this is not something that happens on a network configured in the way you describe.

It is for any VPN client that routes DNS traffic through the VPN as well as HTTP and other web traffic. It's not out of the ordinary for this to happen.

Re: Apple's iCloud+ “VPN”

#147

I've been trying to point this out to people but YouTube personalities have a louder voice than anyone else so you end up with bad information. Props to Apple for offering an (albeit low entropy) onion router on their own infrastructure. I can't imagine this is going to win them any friends in government circles but it's definitely a step in the right direction. I'd also really like to see Apple come clean about the…

> I can't imagine this is going to win them any friends in government circles but it's definitely a step in the right direction. Quite the opposite. Governments probably already have taps to decrypted traffic. Otherwise how come that would even be legal to run? If someone commits a crime and government cannot find evidence, because Apple gives shielding, then isn't that making them hypothetically an accomplice?

> If someone commits a crime and government cannot find evidence, because Apple gives shielding, then isn't that making them hypothetically an accomplice?

We have recent and specific case law around this. The cherry on top is it was Apple on the other side.

No, this is not how being an accomplice works in the U.S. It’s not how it works anywhere with the rule of law.

Re: Apple's iCloud+ “VPN”

#148

Props to Apple for the design of this service. It doesn't hit all the privacy targets that long-time personal VPN users might be looking for, and it doesn't get into the game of trying to circumvent region locked content*, but otherwise it's likely to be a solid privacy improvement for almost all users in a careful and deliberate way. I use a VPN for other reasons (downloading Ubuntu ISOs mostly) but I'll probably tu…

Why do you use a VPN to download free and publicly available iso images? (Ubuntu). Just curious. Do you download directly from a mirror or use BitTorrent for this? (If the latter I think I kind of understand the rationale for the VPN)

Until a few months ago, I had never really used BitTorrent to do anything - save for about 20 minutes back in HS almost 20 years ago (!)

(I think I was running uTorrent on Windows, it was weird and I really didn't know how to use it.)

However, in order to "acquire" [this][1], torrenting was realistically the only sensible option I had. A direct download from the Internet Archive would have taken roughly 7 hours @ 100 Mb/s. The torrent file was done in an hour.

To my great surprise, the link isn't dead, so...yeah :)

Transmission CLI FTW.

[1]: https://www.caseyliss.com/2021/2/14/a-concert-for-charlottes...

Re: Apple's iCloud+ “VPN”

#149

Earlier quoted context omitted.

Does Apple preserve the client source IP in the request (similar to Cloudflare's VPN) or will the server only see the IP of the exit node?

The whole point of the service is to hide the client source IP.

Not necessarily. I thought it was mainly about encrypting traffic in untrusted networks. Cloudflare already does it like this in their VPN service.

Re: Apple's iCloud+ “VPN”

#150
This could also mean now major companies security teams have even more incentive to track onion routing users and to check their pattern of traffic to ensure they are legitimate Apple users and not some tor user instead of just blanket-blocking every tor user. This could make tor less secure in the long term if more open source/closed source projects (NSA notwithstanding) are started and dedicated to analyzing and delayering tor traffic.
Post reply on HN