Live data from Hacker News

Apple's iCloud+ “VPN”

metzdowd.com

211–220 of 413 posts

Re: Apple's iCloud+ “VPN”

#211

I was curious how they would actually implement this, if it's actually onion routing that's pretty cool. I wonder what advantage this gives over using NextDNS?

NextDNS is encrypted DNS. DNS is like using your neighbor across the street for all your directions, except you have to shout.

"YO, WHERE'S THE GROCERY STORE AGAIN? ALSO AFTER THAT I'M VISITING THE STRIP CLUB, AGAIN."

NextDNS turns that shout into a signal/telegram message, to a different neighbor. There's still a neighbor involved, but at least the neighborhood doesn't get to hear anymore.

If they include DNS in the onion routing scheme, it turns into a game of telephone, where the neighbor doesn't know you anymore.

Your traffic, and directions become more private.

Re: Apple's iCloud+ “VPN”

#212

> It's not clear if the API will be public for other browsers or applications to use. Apple has already confirmed that other app traffic will go through iCloud Private Relay “no matter what networking API you're using”, with some exemptions: > Not all networking done by your app occurs over the public internet, so there are several categories of traffic that are not affected by Private Relay. > Any connections your a…

So will this mean if I’m using Cloudflare 1.1.1.1 that I won’t get the iCloud private relay since they implement DoH as a VPN in iOS?

Re: Apple's iCloud+ “VPN”

#213
post #72

Earlier quoted context omitted.

No. NextDNS and Pi-Hole serve DNS requests and are mainly used for ad blocking and content restrictions on your network. They don't tunnel or redirect your actual internet traffic the way a VPN does.

Shameless self-plug: NextDNS does not, but ControlD does do that - https://controld.com

Your service seems to support the same features as your provider -- are you 1:1 reselling or do you add stuff?

Re: Apple's iCloud+ “VPN”

#214
post #113

I hope it'll not bring captcha hell, as Google does for using VPNs. Twitter is simply blocking my VPN provider. eBay sends scary email every time I login.

This will come down to reputation. VPN providers which don't do a good job managing abuse from their networks get blocked a lot more readily than better run networks, and in this case they'd be able to make pretty strong assurances that they can link activity to a single user.

Re: Apple's iCloud+ “VPN”

#215
post #209

Earlier quoted context omitted.

Surely some "unique" identifier is required for each TCP session between Apple and the exit node so that Apple knows where to send the data it gets back, even if it's just the port on which Apple connect to the exit node as with standard TCP session management.

How would that help you identify all of a particular users interactions (rather than one)? Why would you expect them to log it?

If Apple logged (incoming IP from user, outgoing port to exit node) pairs for each session, and the exit node logged all requests, this should be sufficient to associate all requests with a given user IP, right? Or am I misunderstanding you?

I wouldn’t expect them to log it, personally, I think that can only lead to headaches down the line. My reason for responding is just that I disagree that there is no way for another party to associate all requests even if Apple & exit node both fully cooperate and keep logs.

Re: Apple's iCloud+ “VPN”

#216

Earlier quoted context omitted.

Yes, backups, and Apple should get on that. However, your photos in Google Photos, your location data, your uploads in Google Drive (equivalent to iCloud Drive OP is talking about), not end to end encrypted and no option for it. I think market share is another sign. Does anyone use actual Android Backup, or do they use the unencrypted “backups” in G Photos and elsewhere? For that reason should the FBI care? Maybe I’m…

Let's be really frank about it - no large company is going to offer end-to-end encryption of photos because of what kind of photos might end up on their infrastructure if they do. And honestly I don't blame them at all . I'd just like to see Apple be more transparent with this one particular issue because it undermines so much of what they're advertising to the consumer. A transparency label for iCloud backup showing…

Are you really arguing that because child pornography exists, no large company should offer ETE photos?

Despite there been reasonable solutions like bloom filters and client sided hash detection, so that known child abuse material can be detected, without it needing to compromise the privacy of 99.99999% of users?

And that photos present some of the most sensitive materials on your device:

- geo-IP location showing basically everywhere you have taken a photo in, ever since the dawn of time

- people's consensual sex tapes

- photos of passwords, account recovery codes, private keys, seed words

Re: Apple's iCloud+ “VPN”

#217

Earlier quoted context omitted.

I think that's painting with a pretty broad brush. What's wrong with Mullvad, for example?

Who runs Mullvad? I find it funny that people here mistrust companies like Facebook and Google, but then turn around and hand off their entire network activity to a faceless, anonymous VPN company.

I think a lot of that distinction turns on how well your network data is linked to your identity. In the case of Mullvad, you can pay them anonymously by putting cash in an envelope and just mailing it to them,[1] which lowers the trust factor involved.

[1] https://mullvad.net/en/pricing/

Re: Apple's iCloud+ “VPN”

#218
post #110

Interesting. I thought I recalled talking about this on HN previously: https://news.ycombinator.com/item?id=10355868 _-__--- on Oct 8, 2015 | parent | favorite | on: Verizon revives "zombie cookie" device tracking on... Tor as an OS-level feature may not spark the best reaction. It's been given a bad name ("deep web," silk road, etc) in mass media and many people don't understand it enough to think of it as anything…

An even more impressive prediction in 2015, a time when Apple was not positioned as some type of savior of user privacy.

I actually wrote a deep dive on Apple’s pivot to privacy. https://saturation.substack.com/p/apple-facebook-and-the-glo...

Re: Apple's iCloud+ “VPN”

#219

Earlier quoted context omitted.

Which vpn do you use?

Private Internet Access. I used to use NordVPN but found it to be much slower, less stable, worse macOS integration, not as good on the privacy front.

Do you have any thoughts on PIA vs Mullvad?

Re: Apple's iCloud+ “VPN”

#220

Props to Apple for the design of this service. It doesn't hit all the privacy targets that long-time personal VPN users might be looking for, and it doesn't get into the game of trying to circumvent region locked content*, but otherwise it's likely to be a solid privacy improvement for almost all users in a careful and deliberate way. I use a VPN for other reasons (downloading Ubuntu ISOs mostly) but I'll probably tu…

Why do you use a VPN to download free and publicly available iso images? (Ubuntu). Just curious. Do you download directly from a mirror or use BitTorrent for this? (If the latter I think I kind of understand the rationale for the VPN)

My ISP throttles bittorrent traffic.
Post reply on HN