Live data from Hacker News

Apple's iCloud+ “VPN”

metzdowd.com

171–180 of 413 posts

Re: Apple's iCloud+ “VPN”

#171

Earlier quoted context omitted.

> If someone commits a crime and government cannot find evidence, because Apple gives shielding, then isn't that making them hypothetically an accomplice? We have recent and specific case law around this. The cherry on top is it was Apple on the other side. No, this is not how being an accomplice works in the U.S. It’s not how it works anywhere with the rule of law.

Would you have a link?

https://en.m.wikipedia.org/wiki/FBI–Apple_encryption_dispute

Re: Apple's iCloud+ “VPN”

#172

Apple in a few months to VPN's: give us 30% share if you want to serve as exit node to Apple iCloud+ VPN. Two part strategy as always: 1. Get yourself in-between of an already functioning system, by force if needed 2. Abuse your market position to gain millions of users, make it super easy to use this as default, and make existing players compete for their 70% share of what they already were earning. - Enjoy new bill…

This goes against my general distrust of giant corporations, but I trust Apple a lot more than I do the extremely shady VPN companies infesting the internet

Re: Apple's iCloud+ “VPN”

#173
post #7

I think this is great, if only as a way to kill the bullshit consumer VPN business, which sells snake oil.

> I think this is great, if only as a way to kill the bullshit consumer VPN business, which sells snake oil.

Having a US megacorporation kill a whole market segment and pull it into their monopolized walled garden sure seems like an improvement. After all, they pinky promise they will not ever abuse that! /s

Re: Apple's iCloud+ “VPN”

#174
post #139

Potentially, this provides troves of data to the exit node operators (CloudFlare, Fastly, Akamai, ...). Yes, it's the same with all VPNs and ISPs, but I think users should be made aware that now instead of your ISP analyzing the data, an even bigger and more capable corporation is. And if Apple is controlling the entire onion chain (I would be surprised if they weren't), they have even more data available, mainly wit…

This is not quite correct though - entry side and exit side are specifically and intentionally not operated by same entities. So Apple knows who you are but doesn’t know what you’re looking for or where you’re going - your traffic is passed straight through to the exit layer. Exit layer operator knows what you’re looking for and where you are going but doesn’t know who you are or where you’re coming from.

Re: Apple's iCloud+ “VPN”

#175
post #110

Earlier quoted context omitted.

An even more impressive prediction in 2015, a time when Apple was not positioned as some type of savior of user privacy.

I’m not so sure. If you read back up that thread, the thought that triggered it was from qzervaas: Apple's already shown they don't like this behaviour with their randomised MAC addresses in iOS 8+. And elsewhere in the thread people called out the fact apple had already introduced support for ad blocking. So Apple’s privacy-positive posture was already in the air. I think there is a sense in which privacy was alread…

Steve Jobs talking about this at D8 in 2010, and of course the privacy features he talks about were baked into the OS APIs from the start.

Apple's rift with Google over user data collection in Google Maps goes back to 2009 when Google held Apple to ransom for the user data in return for turn-by-turn directions. Apple refused and started building their own maps service, buying Placebase in July that year.

https://www.youtube.com/watch?v=39iKLwlUqBo

Re: Apple's iCloud+ “VPN”

#177

Does anyone have pointers to info/articles about the countries that are on the "no VPN" capability list? Some of them make sense to me, i.e. China which has a long history of censoring their citizens. But in particular, I'm trying to find out why South Africa is on that list seeing as I live there. Edit: In [1], Apple is quoted as saying, "We respect national laws wherever we operate" but did not elaborate further. […

Apple said it also will not offer "private relay" in Belarus, Colombia, Egypt, Kazakhstan, Saudi Arabia, South Africa, Turkmenistan, Uganda and the Philippines.

https://www.reuters.com/world/china/apples-new-private-relay...

Re: Apple's iCloud+ “VPN”

#178
> or you can view it as a concession to reality: If Apple didn't do this, the video providers would block their exit nodes, as they do with any VPN provider that gets large enough for them to notice.

I seriously doubt any reasonable video streaming service would cut off such a huge chunk of their user base just because they are using an iPhone.

Re: Apple's iCloud+ “VPN”

#179
post #89

Earlier quoted context omitted.

Because if you used a central cert, every device would have to whitelist that cert, and just clocking the lock icon in your browser would reveal it.

Many consumer VPNs install a client, and it would be trivial to ship a new trusted certificate with it.

> Many consumer VPNs install a client, and it would be trivial to ship a new trusted certificate with it.

A lot of browsers have their own root chain, and also now do certificate pinning, so will (IIRC) only accept specifically designated certs for particular sites (doesn't Google/Chrome/Gmail do this?).

Post reply on HN