Live data from Hacker News

Apple's iCloud+ “VPN”

metzdowd.com

221–230 of 413 posts

Re: Apple's iCloud+ “VPN”

#221

Interesting. I thought I recalled talking about this on HN previously: https://news.ycombinator.com/item?id=10355868 _-__--- on Oct 8, 2015 | parent | favorite | on: Verizon revives "zombie cookie" device tracking on... Tor as an OS-level feature may not spark the best reaction. It's been given a bad name ("deep web," silk road, etc) in mass media and many people don't understand it enough to think of it as anything…

No offense or anything but what’s the point of making this comment outside of showing that you were right? Good prediction.

Re: Apple's iCloud+ “VPN”

#222

Earlier quoted context omitted.

Private Internet Access. I used to use NordVPN but found it to be much slower, less stable, worse macOS integration, not as good on the privacy front.

Do you have any thoughts on PIA vs Mullvad?

PIA is owned in a weird structure I don't understand in a jurisdiction where any legal agreements with my home country are, most likely, non-existant or untested. They also seem to have enormous amounts on money to spend on marketing or paying off torrent review sites.

Everybody recommends them, but all of these things make me uneasy.

Re: Apple's iCloud+ “VPN”

#223
post #113

I hope it'll not bring captcha hell, as Google does for using VPNs. Twitter is simply blocking my VPN provider. eBay sends scary email every time I login.

Because Apple is so large and well respected, issues will be blamed on whoever is putting up the captcha, not Apple.

Re: Apple's iCloud+ “VPN”

#224

Interesting. I thought I recalled talking about this on HN previously: https://news.ycombinator.com/item?id=10355868 _-__--- on Oct 8, 2015 | parent | favorite | on: Verizon revives "zombie cookie" device tracking on... Tor as an OS-level feature may not spark the best reaction. It's been given a bad name ("deep web," silk road, etc) in mass media and many people don't understand it enough to think of it as anything…

No offense or anything but what’s the point of making this comment outside of showing that you were right? Good prediction.

(Fair question. I just found it amusing. I'm annoyed it got voted to the top. For substantive discussion, people should look down page)

Re: Apple's iCloud+ “VPN”

#228
post #212

> It's not clear if the API will be public for other browsers or applications to use. Apple has already confirmed that other app traffic will go through iCloud Private Relay “no matter what networking API you're using”, with some exemptions: > Not all networking done by your app occurs over the public internet, so there are several categories of traffic that are not affected by Private Relay. > Any connections your a…

So will this mean if I’m using Cloudflare 1.1.1.1 that I won’t get the iCloud private relay since they implement DoH as a VPN in iOS?

Not super familiar with 1.1.1.1, but I use NextDNS and it's no longer implemented as a VPN – they use the native iOS encrypted DNS feature. I wonder how iCloud Private Relay works with that.

Re: Apple's iCloud+ “VPN”

#229
post #47

My guess is one of the major reasons for having the exit nodes in the same geo location as entry nodes is to have continuous operations in China. Without this constraint, they would have allowed chinese consumers to access the free web, which would ban them instantaneously. I don't think Apple cares as much about video content providers, though.

Apple also isn't in the business of people bypass region restrictions. This seems focused on privacy.

Re: Apple's iCloud+ “VPN”

#230

Earlier quoted context omitted.

Not necessarily. I thought it was mainly about encrypting traffic in untrusted networks. Cloudflare already does it like this in their VPN service.

Correct. I guess it wasn't really obvious from the linked mail. The introduction video at https://developer.apple.com/videos/play/wwdc2021/10096/ is a lot clearer.

Not sure why you said correct, as it's both. A big part of private relay -- I would say the most significant part -- is to allow people to talk to websites without giving up their personal IP (and from that pretty tight geolocation, and with fingerprinting a correlation with loads of other data they collect). Apple makes a big deal about it being about maintaining privacy, not just against snooping of traffic -- which is unlikely -- but against fingerprinting and targeting from the services and sites you connect to.

And to answer the original guy, no Apple does not add any headers or details to tell the destination what your IP address is. They just see that they're talking to an exit node somewhere approximal of your general region.

Post reply on HN