Live data from Hacker News

Apple's iCloud+ “VPN”

metzdowd.com

151–160 of 413 posts

Re: Apple's iCloud+ “VPN”

#151

Props to Apple for the design of this service. It doesn't hit all the privacy targets that long-time personal VPN users might be looking for, and it doesn't get into the game of trying to circumvent region locked content*, but otherwise it's likely to be a solid privacy improvement for almost all users in a careful and deliberate way. I use a VPN for other reasons (downloading Ubuntu ISOs mostly) but I'll probably tu…

> It would be nice if the BBC didn't block like this, but UK residents do typically pay for the content whereas those outside the UK are unable to. As an exiled Londoner, I would love to be able to pay to access BBC programmes. Unfortunately I can’t, so a VPN is often the only solution (well, I guess torrenting would be another one, but it’s not really better).

If only there was a way to store a user's information so that they could be identified with some sort of a login process that would indicate that they are a current valid member. It would also be impressive if this same system would allow the user to indicate that they are currently abroad to allow a temporary exemption of geofencing.

Obviously, this is something licensing agreements do not allow for, but it seems like such an obvious user friendly concept that it will never be allowed.

Re: Apple's iCloud+ “VPN”

#152

Interesting. I thought I recalled talking about this on HN previously: https://news.ycombinator.com/item?id=10355868 _-__--- on Oct 8, 2015 | parent | favorite | on: Verizon revives "zombie cookie" device tracking on... Tor as an OS-level feature may not spark the best reaction. It's been given a bad name ("deep web," silk road, etc) in mass media and many people don't understand it enough to think of it as anything…

Hey there, can I call you? I have some questions about the future!

Re: Apple's iCloud+ “VPN”

#153
This is interesting. I think overall I approve as it benefits people by default.

It does mean you now have to trust Apple since that's the first hop. However you're already doing this when you spin up your AWS Lightsail Wireguard instance, say. AWS can see ingress and egress traffic and so you just need AWS to not be part of your threat model. Same here. Though I dont see this as too much of a problem since it applies to devices and services where you've already made this explicit choice.

The app limitation thing is a shame and hopefully there will be an API at a later date.

The exit node choice based on exit-locality kinda makes me think Apple either:

- Want to restrict this service being (ab)used for geolocked content (Netflix etc)

- Want to speed up the service by providing the closest exit node (Performance)

Of course given all the FBI cases, you also have to consider other possibilties for the creation of this service.

Re: Apple's iCloud+ “VPN”

#154

I've been trying to point this out to people but YouTube personalities have a louder voice than anyone else so you end up with bad information. Props to Apple for offering an (albeit low entropy) onion router on their own infrastructure. I can't imagine this is going to win them any friends in government circles but it's definitely a step in the right direction. I'd also really like to see Apple come clean about the…

> I can't imagine this is going to win them any friends in government circles but it's definitely a step in the right direction. Quite the opposite. Governments probably already have taps to decrypted traffic. Otherwise how come that would even be legal to run? If someone commits a crime and government cannot find evidence, because Apple gives shielding, then isn't that making them hypothetically an accomplice?

> Otherwise how come that would even be legal to run?

Why wouldn’t it be? I was under the impression that what isn’t forbidden by law was legal by default. AFAIK, running a VPN platform isn’t illegal.

> If someone commits a crime and government cannot find evidence, because Apple gives shielding, then isn't that making them hypothetically an accomplice?

I hate this argument. It’s lazy and can be used to accuse anybody in any context, and shut down discussions that we should be having. By that standard we are all accomplices for some crimes.

Re: Apple's iCloud+ “VPN”

#155
post #3

My experience with this so far was... mixed. - This breaks DNS resolution for company-internal domains. - This routes all my traffic through CloudFlare or another CDN I might or might not trust (yes, the IP is hidden, but not the data) - it significantly slows down my internet access on my location. - it tends to turn itself on again without my intervention especially the last point is very problematic for me

> This breaks DNS resolution for company-internal domains.

Why would it? The WWDC developer video clearly states that it’s only for public domains.

Re: Apple's iCloud+ “VPN”

#156

Interesting. I thought I recalled talking about this on HN previously: https://news.ycombinator.com/item?id=10355868 _-__--- on Oct 8, 2015 | parent | favorite | on: Verizon revives "zombie cookie" device tracking on... Tor as an OS-level feature may not spark the best reaction. It's been given a bad name ("deep web," silk road, etc) in mass media and many people don't understand it enough to think of it as anything…

Apple is in crossfire:

(a) There is pressure from many governments to give backdoor for surveillance. Or just comply with subpoenas that are against human rights.

(b) Complying with local laws generates PR damage. It makes privacy and ethics as a brand strategy look disingenuous.

The solution is, of course, to generate truly secure system where Apple can't make backdoors. Those services may not be available in some countries, but then it's just missing service, not a compromised system.

Re: Apple's iCloud+ “VPN”

#157
post #74

I'm curious how they are securing the feature that keeps you in the same region. Since that feature encourages content providers to not block, it would be a desirable target to work around.

yeah I was thinking about how difficult it might be to spoof your location prior to the Apple Router, and have it come out the other side nicely laundered

Re: Apple's iCloud+ “VPN”

#158

Earlier quoted context omitted.

> I can't imagine this is going to win them any friends in government circles but it's definitely a step in the right direction. Quite the opposite. Governments probably already have taps to decrypted traffic. Otherwise how come that would even be legal to run? If someone commits a crime and government cannot find evidence, because Apple gives shielding, then isn't that making them hypothetically an accomplice?

> If someone commits a crime and government cannot find evidence, because Apple gives shielding, then isn't that making them hypothetically an accomplice? We have recent and specific case law around this. The cherry on top is it was Apple on the other side. No, this is not how being an accomplice works in the U.S. It’s not how it works anywhere with the rule of law.

Would you have a link?

Re: Apple's iCloud+ “VPN”

#159

Earlier quoted context omitted.

Google does end-to-end encryption of Android backups. And Apple knows how to do it too, but they intentionally restricted their implementation to only cover backups of Keychain passwords and a few other things, apparently because they don't have the courage to stand up to the FBI, according to Reuters. Strange considering their public stance against the FBI in the San Bernardino case and on privacy issues in general.…

Yes, backups, and Apple should get on that. However, your photos in Google Photos, your location data, your uploads in Google Drive (equivalent to iCloud Drive OP is talking about), not end to end encrypted and no option for it. I think market share is another sign. Does anyone use actual Android Backup, or do they use the unencrypted “backups” in G Photos and elsewhere? For that reason should the FBI care? Maybe I’m…

Look at the Reuters article they linked. iCloud backup is the issue. Usage of iCloud backup and Android backup are probably very similar (in percentage terms), why would you expect that Android backup is used less? They are pretty much equivalent features, except that one is end-to-end encrypted and the other is not. In both cases, photos are handled separately.

Re: Apple's iCloud+ “VPN”

#160
post #71

I've been trying to point this out to people but YouTube personalities have a louder voice than anyone else so you end up with bad information. Props to Apple for offering an (albeit low entropy) onion router on their own infrastructure. I can't imagine this is going to win them any friends in government circles but it's definitely a step in the right direction. I'd also really like to see Apple come clean about the…

> I'd also really like to see Apple come clean about the iCloud backup encryption debacle Are you referring to this article?: https://www.reuters.com/article/us-apple-fbi-icloud-exclusiv... It's why I only use my Apple ID for grabbing apps from the app store. I have disabled all the `cloud storage` features of iCloud. iCloud is a privacy nightmare.

Yep, exactly that.

I utterly agree that other direct-to-consumer options are in the same boat - but Apple is quite heavy-handed in it's messaging about, well, messaging being encrypted and private and no-one (including Apple) being able to read your messages. That's only true if you don't backup to iCloud.

I would expect most people on HN to be aware of all of this of course but when you're so strongly selling your privacy protections as part of your brand, it's a pretty glaring window to leave wide open.

Post reply on HN