Live data from Hacker News

Apple's iCloud+ “VPN”

metzdowd.com

201–210 of 413 posts

Re: Apple's iCloud+ “VPN”

#201

> All in all, a very Apple approach: They deny themselves any knowledge of a customer's DNS queries and Web traffic, so if served with a subpoena they have very little to respond with. Maybe I am missing something but I view this is a rather genius move. They have plausible deniability + actually introduce some protection for their users. Not sure how to read the original post though. Is it praising Apple? Is it mock…

>In one move, Apple has taken onion routing from a specialized tool for hackers to something that will be in daily use on billions of devices.

Sounds like praise to me.

Re: Apple's iCloud+ “VPN”

#202
post #15

Props to Apple for the design of this service. It doesn't hit all the privacy targets that long-time personal VPN users might be looking for, and it doesn't get into the game of trying to circumvent region locked content*, but otherwise it's likely to be a solid privacy improvement for almost all users in a careful and deliberate way. I use a VPN for other reasons (downloading Ubuntu ISOs mostly) but I'll probably tu…

> but UK residents do typically pay for the content whereas those outside the UK are unable to. In essence, what you're saying boils down to "it's already paid for, but nobody else can have it anyway". It's unreasonable and there is no need to make excuses for this behaviour.

> what you're saying boils down to "it's already paid for, but nobody else can have it anyway"

This is already paid for but the next show isn’t.

If the BBC were sold to the public as a soft dollar expenditure, it would be one thing. But it wasn’t. I’m not sure it could be in today’s Britain. Ignoring the freeloader problem threatens the support on which the BBC’s funding depends.

This is a debate with reasonable arguments on both sides.

Re: Apple's iCloud+ “VPN”

#203
post #92

Props to Apple for the design of this service. It doesn't hit all the privacy targets that long-time personal VPN users might be looking for, and it doesn't get into the game of trying to circumvent region locked content*, but otherwise it's likely to be a solid privacy improvement for almost all users in a careful and deliberate way. I use a VPN for other reasons (downloading Ubuntu ISOs mostly) but I'll probably tu…

I wish I could pay for bbc iPlayer service outside old blighty. But they don't allow it.

You still can in some places if I recall correctly. Notably not in US due to licensing disagreements (of course).

Re: Apple's iCloud+ “VPN”

#204

I've been trying to point this out to people but YouTube personalities have a louder voice than anyone else so you end up with bad information. Props to Apple for offering an (albeit low entropy) onion router on their own infrastructure. I can't imagine this is going to win them any friends in government circles but it's definitely a step in the right direction. I'd also really like to see Apple come clean about the…

iClouds lack of encryption basically invalidates all other promises they make.

Re: Apple's iCloud+ “VPN”

#205
post #15

Props to Apple for the design of this service. It doesn't hit all the privacy targets that long-time personal VPN users might be looking for, and it doesn't get into the game of trying to circumvent region locked content*, but otherwise it's likely to be a solid privacy improvement for almost all users in a careful and deliberate way. I use a VPN for other reasons (downloading Ubuntu ISOs mostly) but I'll probably tu…

> but UK residents do typically pay for the content whereas those outside the UK are unable to. In essence, what you're saying boils down to "it's already paid for, but nobody else can have it anyway". It's unreasonable and there is no need to make excuses for this behaviour.

[deleted]

Re: Apple's iCloud+ “VPN”

#206

Correct me if I’m wrong, but as I understand it a two-hop onion network is still trivially breakable with (two) warrants, especially since both Apple and Cloudflare/etc., are US companies. Which would make it a VPN in the duck-type sense.

If your threat model includes state level actors, there is no commercially available solution that will make you 100% safe. This is about privacy from private corporations and making it more difficult and more costly for governments to get your data. But the latter is always possible when you use the web.

Re: Apple's iCloud+ “VPN”

#207

Props to Apple for the design of this service. It doesn't hit all the privacy targets that long-time personal VPN users might be looking for, and it doesn't get into the game of trying to circumvent region locked content*, but otherwise it's likely to be a solid privacy improvement for almost all users in a careful and deliberate way. I use a VPN for other reasons (downloading Ubuntu ISOs mostly) but I'll probably tu…

> It would be nice if the BBC didn't block like this, but UK residents do typically pay for the content whereas those outside the UK are unable to. As an exiled Londoner, I would love to be able to pay to access BBC programmes. Unfortunately I can’t, so a VPN is often the only solution (well, I guess torrenting would be another one, but it’s not really better).

BritBox is a neflix-like service that has UK shows from the BBC and ITV. Decent catalog.

Re: Apple's iCloud+ “VPN”

#208
post #126

Earlier quoted context omitted.

To use it you're clearly using early beta software. Clearly it isn't going to "turn itself on again". I turned it on and actually forgot I did. Performance is decent here. I mean of course it's going to be worse than native, but that's the compromise. As to trusting Cloudflare -- what do you mean? You understand your connection is still TLS end-to-end encrypted (presuming that's what we're talking about), right? I me…

[Clearly not turn itself on.] Funny story, I was shocked and quite annoyed that an iPhone automatically turns on Wifi and stuff every day by itself - even if you turn it off... Still dont know how to actually turn it off

If you disable it from the control center thingie overlay it even states that is only for this day ...

If you disable it from settings, it stays off.

Re: Apple's iCloud+ “VPN”

#209

Earlier quoted context omitted.

Well, here’s the catch. Even if logs were kept, the 2nd party as far as we know does not have a unique identifier passed onto it. This means that Apple’s logs would say this user authenticated and passed some encrypted stuff to Fastly, and Fastly would say that it received requests from Apple, without an identifier to match it up against the first request. Once this scales and Apple has millions of requests incoming,…

Surely some "unique" identifier is required for each TCP session between Apple and the exit node so that Apple knows where to send the data it gets back, even if it's just the port on which Apple connect to the exit node as with standard TCP session management.

How would that help you identify all of a particular users interactions (rather than one)? Why would you expect them to log it?

Re: Apple's iCloud+ “VPN”

#210
post #180

Earlier quoted context omitted.

Source on the next hop address? Apple doesn’t know where you’re going.

They shouldn't know about the end destination, but they'll know your traffic was sent to eg. Cloudflare or whatever.

I would think they batch together all the IPs and pass it off.

It's in Apple's best interest to keep the bare minimum information they need from their end-user.

Post reply on HN