I think Apple is transparent about Always on VPN (blocking traffic except over the tunnel) requiring provisioning using MDM tools. Apple Configurator is free and allows anyone to set this up. Any other VPN is just best effort. https://support.apple.com/guide/deployment/vpn-overview-depa...
VPNs on iOS are a scam
201–210 of 260 posts
Re: VPNs on iOS are a scam
#202Earlier quoted context omitted.
VPNs were always meant to carry internal traffic to a private network, not the public internet (hence the name Virtual Private Network). The fact that a VPN server can send you a route for 0.0.0.0/0 always was and always will be a happy accident.
> VPNs were always meant to carry internal traffic to a private network, not the public internet This. And the idea that these so called ‘VPN’ services somehow improve your security and privacy on the internet is laughable. All they do is let you get onto the public, untrusted, internet through a different on-ramp. There is no point to them. The internet is just as untrustworthy through a VPN service as it is through…
I recommend VPN services in regions where legislation of your home country might difficulties getting data.
Re: VPNs on iOS are a scam
#203Earlier quoted context omitted.
> VPNs were always meant to carry internal traffic to a private network, not the public internet This. And the idea that these so called ‘VPN’ services somehow improve your security and privacy on the internet is laughable. All they do is let you get onto the public, untrusted, internet through a different on-ramp. There is no point to them. The internet is just as untrustworthy through a VPN service as it is through…
> This. And the idea that these so called ‘VPN’ services somehow improve your security and privacy on the internet is laughable. Actually, they do: Neither your ISP nor the government (assuming the VPN provider is in a "hostile" jurisdiction) can intercept, analyze or modify your Internet traffic when you are using a VPN to mask your Internet access. There have been multiple instances of this in the past [1][2] and o…
No, you're just delegating those capabilities to some completely unregulated random actors instead.
> which means any sort of shady bullshit would be a virtual death sentence
This assumes that their shady bullshit is discovered by someone. I would bet good money that the vast majority of it isn't. They could be sampling traffic and selling it to other companies without modifying it and users would never be any the wiser.
Honestly, I wish we could get past this broken narrative that VPNs are a panacea.
Re: VPNs on iOS are a scam
#204Earlier quoted context omitted.
That Apple documents that 'normal' VPNs are broken on iOS doesn't change the fact that they're broken.
That's the Apple Way though isn't it? Apple says "Do it exactly how we tell you" and you shouldn't expect anything to work if you deviate from the One True Path that Apple has laid out for you. "Think Different, Do As You're Told"
Re: VPNs on iOS are a scam
#205I was developing VPN client for one of the popular VPN provider in the past for iOS and the solution was quite simple - enable on-demand VPN for 0.0.0.0/0 In this case, iOS will always wait until connection to VPN is established before sending any packets out. Without on-demand, VPN may leak. If I remember correctly, leaks occurred mostly after waking from sleep but before the tunnel had chance to be set up. Or in si…
Re: VPNs on iOS are a scam
#206Networking is dynamic it takes many sequential steps to configure. There is no ZAP, it is done. I don't know of an OS that locks out "user programs" until configuration is complete. Yeah, since networking is dynamic that could never work -- "user programs" would be locked out forever!
At the start of the First Test there are packets going to non-tunnel locations at the same time the VPN is being set up, not a surprise. Packet ordering / routing at this time granularity is also not surprising.
Need to take a moment to review the "drop everything" when a VPN is up standpoint. OS Networking stacks don't really understand what a VPN is, it is just an endpoint to route packets. A TCP connection has internal state that is bound to the addresses that were used when it was set up - which is tied to the state of the routing table. A new point-to-point endpoint, like a VPN would invalidate that state. Most (many?) TCP/IP stacks keep a cache of the initial route on the socket. As long as that is still valid (or updated), that is where the packets go. Killing TCP connections for every (temporary) network flap would make a lot more people MAD.
The "DNS" to NextDNS with DoH connection is interesting. This 100% isn't coming from iOS itself. It doesn't support it. So it must be coming from an App. But what app and how? There is a NextDNS app which up front claims "Encrypt all DNS queries on all networks with the official NextDNS app for iOS". The author does appear to have configured the router to use NextDNS, perhaps they also have that App installed as well and it is also hijacking networking to do DNS? A dunno.
The "flood stuff" is interesting, but I think it might just be an attempt to perform STUN to make sure UPD traffic can be transported - to Apple endpoints. I think "second test" is the same thing happening again.
So what is left is the traffic being sent to apple endpoints. Now I wonder how the VPNs the author is using are implemented. The Big Sur VPN brouhaha was because apps were trying to implement a VPN using NEFilterDataProvider instead of a "tun" interface and routing. I wonder if this is just the same issue but on iOS.
Not related, but I do wonder what these VPN services offer in terms of "Firewall" protection or if when you use them ALL ports are forwarded to your device. This would make all of their endpoints a "great target" for continuous scanning for getting inside a network if the VPN user had something misconfigured, like say an experimental Apache, Nginx, PHP, Rails, Django, MySQL project. Doh. Methinks I should spend some currency and experiment. Sadly black-hats are probably already doing this.
Re: VPNs on iOS are a scam
#207Earlier quoted context omitted.
> This. And the idea that these so called ‘VPN’ services somehow improve your security and privacy on the internet is laughable. Actually, they do: Neither your ISP nor the government (assuming the VPN provider is in a "hostile" jurisdiction) can intercept, analyze or modify your Internet traffic when you are using a VPN to mask your Internet access. There have been multiple instances of this in the past [1][2] and o…
> Actually, they do: Neither your ISP nor the government (assuming the VPN provider is in a "hostile" jurisdiction) can intercept, analyze or modify your Internet traffic No, you're just delegating those capabilities to some completely unregulated random actors instead. > which means any sort of shady bullshit would be a virtual death sentence This assumes that their shady bullshit is discovered by someone. I would b…
It's a question of trust in the end. Telco providers not just in the US but across the Western world have shown time and time again that they cannot be trusted: traffic manipulation, DNS hijacking, selling data to the highest bidder [1], engaging in open corruption to prevent competition, predatory sales tactics, fee scams, peering extortion [2], misappropriating government funds [3] - name the act and you'll find a dominant ISP having done or still doing that practice.
VPN providers generally don't have that baggage attached.
> This assumes that their shady bullshit is discovered by someone. I would bet good money that the vast majority of it isn't.
I agree, but at least the incentives are aligned completely different than with ISPs. The large ISPs can do whatever they want, even breaking the law, because their consumers have no other choice - rural ISPs will get competition from Starlink soon enough, but people in condos? They're stuck with whatever the landlord offers, and the landlord won't care even if there is competition as long as the monopoly ISP pays higher kickbacks.
[1] https://www.ftc.gov/news-events/news/press-releases/2021/10/...
[2] https://www.heise.de/hintergrund/Missing-Link-Regulierer-vs-...
[3] https://eu.jsonline.com/in-depth/news/2021/07/14/weve-spent-...
Re: VPNs on iOS are a scam
#208It's also worth pointing out that tethered/hotspot data shared to the iPhone with a VPN enabled at the iPhone level will not travel through the VPN, but will rather leak your phone's IP: https://apple.stackexchange.com/questions/266871/is-there-a-...
That seems like expected behavior, or at least one worth testing with an IP checker or something on the tethered device. I would be pretty surprised if I connected to a VPN on my mobile device, then tethered to it, and my traffic went over the VPN tunnel. I would just establish a VPN tunnel on the tethered device if I wanted that.
Re: VPNs on iOS are a scam
#209I think Apple is transparent about Always on VPN (blocking traffic except over the tunnel) requiring provisioning using MDM tools. Apple Configurator is free and allows anyone to set this up. Any other VPN is just best effort. https://support.apple.com/guide/deployment/vpn-overview-depa...
Seems targeted at Enterprise customers, not your average consumer. Kind of a big deal that likely 90%+ of iOS VPN app users assume they're private when they're not. False advertising IMO, and Apple is getting their 30%.
Also, just checked Mullvad, which seems to open an IPSec server on your local device and then install a vpn config on your ios device. From the local IPSec server a connection is made to mullvad via wireguard. On-demand is also enabled by default.
But yea, VPN were initially targeted at enterprises anyway. So I don’t mind that i actually have to install vpn profiles by hand.
Re: VPNs on iOS are a scam
#210This should trend to the top of HN. Apple bills themselves as a privacy-centric company. I hope they clean this up asap.
It is clear that Apple’s privacy efforts are only aimed at privacy for you from organisations that aren’t Apple. Apple doesn’t really care about preserving your privacy from Apple (and by extension the FBI). They maintain backdoors in iMessage specifically to preserve the ability of Apple/FBI to read your messages: https://www.reuters.com/article/us-apple-fbi-icloud-exclusiv... The fact that Apple OSes leak your true…