Live data from Hacker News

Apple's iCloud+ “VPN”

metzdowd.com

161–170 of 413 posts

Re: Apple's iCloud+ “VPN”

#161
post #119

What's are the differences between a VPN and an onion router approach? Could anyone explain or link to an article?

A VPN is a middleman that accepts your traffic and forwards it, hiding who you are to servers. An onion router is like a VPN but instead of 1 middleman, the middleman is a whole random network of middlemen, and those middlemen also hand off to other middlemen.

What I don’t get is why people don’t regard Onion Routers as a form of VPN. It’s still uses a virtual private network, just more of them. a network of networks.

Surely TOR is a type of VPN?

Maybe there’s some details I’m missing. I’m no expert

Re: Apple's iCloud+ “VPN”

#162
post #15

Earlier quoted context omitted.

> but UK residents do typically pay for the content whereas those outside the UK are unable to. In essence, what you're saying boils down to "it's already paid for, but nobody else can have it anyway". It's unreasonable and there is no need to make excuses for this behaviour.

totally agree. I had no end of shit trying to watch BBC News channel from abroad. I'm a UK national, I own a house in the UK, I pay UK taxes, I pay your stupid TV licence fee, you're broadcasting live over 3 separate CDNs, just let me watch the fucking news. I eventually subscribed to an illegal IPTV service for that one sodding channel. I don't even need the other 17,000 channels. the BBC drove me to it

It may be worth looking at the AAISP L2TP Service[1].

They are a domestic ISP, so I guess iplayer should work over the service.

[1]: https://www.aa.net.uk/broadband/l2tp-service/

Re: Apple's iCloud+ “VPN”

#163
post #126

Earlier quoted context omitted.

To use it you're clearly using early beta software. Clearly it isn't going to "turn itself on again". I turned it on and actually forgot I did. Performance is decent here. I mean of course it's going to be worse than native, but that's the compromise. As to trusting Cloudflare -- what do you mean? You understand your connection is still TLS end-to-end encrypted (presuming that's what we're talking about), right? I me…

[Clearly not turn itself on.] Funny story, I was shocked and quite annoyed that an iPhone automatically turns on Wifi and stuff every day by itself - even if you turn it off... Still dont know how to actually turn it off

if you disable from quick menu, it turns back on. if you disable from settings, it doesn’t

Re: Apple's iCloud+ “VPN”

#164

Earlier quoted context omitted.

Google does end-to-end encryption of Android backups. And Apple knows how to do it too, but they intentionally restricted their implementation to only cover backups of Keychain passwords and a few other things, apparently because they don't have the courage to stand up to the FBI, according to Reuters. Strange considering their public stance against the FBI in the San Bernardino case and on privacy issues in general.…

Yes, backups, and Apple should get on that. However, your photos in Google Photos, your location data, your uploads in Google Drive (equivalent to iCloud Drive OP is talking about), not end to end encrypted and no option for it. I think market share is another sign. Does anyone use actual Android Backup, or do they use the unencrypted “backups” in G Photos and elsewhere? For that reason should the FBI care? Maybe I’m…

Let's be really frank about it - no large company is going to offer end-to-end encryption of photos because of what kind of photos might end up on their infrastructure if they do. And honestly I don't blame them at all.

I'd just like to see Apple be more transparent with this one particular issue because it undermines so much of what they're advertising to the consumer.

A transparency label for iCloud backup showing what is and is not E2E before enabling would do. Most people (myself included) would be quite happy with photos being encrypted by an Apple-held key (I'm not worried about the police seeing my boring lunch pics, I just don't want photos of my kids being readily accessible to everyone else).

It should be made clear if they're offering E2E for some features that other settings will render it pointless is all I'm saying.

Re: Apple's iCloud+ “VPN”

#165
Apple in a few months to VPN's: give us 30% share if you want to serve as exit node to Apple iCloud+ VPN.

Two part strategy as always:

1. Get yourself in-between of an already functioning system, by force if needed 2. Abuse your market position to gain millions of users, make it super easy to use this as default, and make existing players compete for their 70% share of what they already were earning.

- Enjoy new billions on top of existing trillions

Re: Apple's iCloud+ “VPN”

#166

Props to Apple for the design of this service. It doesn't hit all the privacy targets that long-time personal VPN users might be looking for, and it doesn't get into the game of trying to circumvent region locked content*, but otherwise it's likely to be a solid privacy improvement for almost all users in a careful and deliberate way. I use a VPN for other reasons (downloading Ubuntu ISOs mostly) but I'll probably tu…

Which vpn do you use?

Re: Apple's iCloud+ “VPN”

#167
post #156

Interesting. I thought I recalled talking about this on HN previously: https://news.ycombinator.com/item?id=10355868 _-__--- on Oct 8, 2015 | parent | favorite | on: Verizon revives "zombie cookie" device tracking on... Tor as an OS-level feature may not spark the best reaction. It's been given a bad name ("deep web," silk road, etc) in mass media and many people don't understand it enough to think of it as anything…

Apple is in crossfire: (a) There is pressure from many governments to give backdoor for surveillance. Or just comply with subpoenas that are against human rights. (b) Complying with local laws generates PR damage. It makes privacy and ethics as a brand strategy look disingenuous. The solution is, of course, to generate truly secure system where Apple can't make backdoors. Those services may not be available in some c…

This is something Apple is increasingly working on. For example, in Fall 2020 they actually revised their CPU designs (including older CPUs) with a new Secure Enclave design that uses mailboxes to more securely store the number authentication attempts inside the secure enclave.

The goal of this is to make it so that even if the FBI had an incident similar to 2016, Apple would not be able to fulfill their request to make a backdoor, and the FBI wouldn't be able to make a backdoor even if they had the power to sign and run any code they wanted on the phone.

That's how you make a secure system these days. You can't just make it secure to everyone but yourself and fight the government - you need to secure it from yourself as well.

Re: Apple's iCloud+ “VPN”

#169
post #94

Earlier quoted context omitted.

To clarify: port 80 and 443 (TLS connections), right? Or is TLS traffic only routed through the private relay in Safari, not other apps?

All traffic in Safari goes through relay. However, in 3rd party apps, all traffic over 80 goes through relay and traffic over 443 is exempt. There is going to be an API though for if you want your 3rd party app’s 443 to go over the relay if you desire.

Not in beta1. I tcpdump'ed traffic from Firefox. HTTP/80 traffic is perfectly visible and not pushed to mask.icloud.com

Re: Apple's iCloud+ “VPN”

#170

This is interesting. I think overall I approve as it benefits people by default. It does mean you now have to trust Apple since that's the first hop. However you're already doing this when you spin up your AWS Lightsail Wireguard instance, say. AWS can see ingress and egress traffic and so you just need AWS to not be part of your threat model. Same here. Though I dont see this as too much of a problem since it applie…

Craig Federighi, on the most recent episode of The Talk Show with John Gruber [0] about 47 minutes into the episode, talked about this and I think both your assumptions are correct. For the first one I'm sure they didn't want to deal with the complexity of picking an exit location nor did they want to be a party to getting around geo-locking and so this gave them the best of both worlds, no UI and no issue with geo-blocking. For the second point I think that is also the reason as well as it's often helpful if a website knows your general location (For relevant recommendations, CDN routing, etc) but we'd prefer if the website didn't know exactly where we are coming from (IP-wise) which can be used for tracking/ads.

[0] https://daringfireball.net/thetalkshow/2021/06/11/ep-316

Post reply on HN