Live data from Hacker News

Apple's iCloud+ “VPN”

metzdowd.com

271–280 of 413 posts

Re: Apple's iCloud+ “VPN”

#271

Correct me if I’m wrong, but as I understand it a two-hop onion network is still trivially breakable with (two) warrants, especially since both Apple and Cloudflare/etc., are US companies. Which would make it a VPN in the duck-type sense.

It depends, whether they do no logs. There are many VPN providers in the US which don’t have logs, so that if they are subpoenaed, they have nothing to give. The beauty of Apple’s double hop is that if one partner was hacked, secretly wiretapped, or had lied about not keeping logs, your connection would still be private. But, that assumes that nobody on this network is keeping logs. If they are, then it could be theo…

> It depends, whether they do no logs

Courts can compel them to keep logs.

Re: Apple's iCloud+ “VPN”

#272

Earlier quoted context omitted.

>I was under the impression that what isn’t forbidden by law was legal by default. Even beyond that, personal privacy from the government is enshrined in the 4th amendment. Just because there was some executive actions and illegal laws made does not mean the 4th amendment suddenly disappears. No person or entity has the right to dragnet all communications.

> personal privacy from the government is enshrined in the 4th amendment Yeaaaaah, let's just pretend Snowden and Manning never happened.

[deleted]

Re: Apple's iCloud+ “VPN”

#273

Earlier quoted context omitted.

Timestamp, source and destination ip addresses, username. In the case of the exit node, url.

We don’t know that Apple keeps logs. These are things they could theoretically keep, but we don’t know if they store them or not.

If they don’t clearly state ‘no logs’ then its unlikely they are not logging. My bet is they’re logging everything, because they have no advantage in not logging.

Re: Apple's iCloud+ “VPN”

#274
post #56

Does this compare to NextDNS[1]. I moved from Pi Hole[2] to NextDNS and I'm happy with it. 1. https://nextdns.io 2. https://pi-hole.net

Just curious, are you on the free tier? Just wondering if 300k queries per month is sufficient for the average person. I have no reference to base that number on.

I'm on the free tier and haven't hit the cap.

I've also found that I still get creepily-targeted advertising, which is presumably based on IP. For example, I watched a youtube video in Firefox Focus on my iPhone. Later that day, I saw a youtube recommendation for a very similar video (on a topic that I do not ever engage with, except for the single video earlier that days) on my laptop, in Safari.

I use NextDNS on both devices. It's nice, but it's not a silver bullet.

Re: Apple's iCloud+ “VPN”

#275
post #216

Earlier quoted context omitted.

Let's be really frank about it - no large company is going to offer end-to-end encryption of photos because of what kind of photos might end up on their infrastructure if they do. And honestly I don't blame them at all . I'd just like to see Apple be more transparent with this one particular issue because it undermines so much of what they're advertising to the consumer. A transparency label for iCloud backup showing…

Are you really arguing that because child pornography exists, no large company should offer ETE photos? Despite there been reasonable solutions like bloom filters and client sided hash detection, so that known child abuse material can be detected, without it needing to compromise the privacy of 99.99999% of users? And that photos present some of the most sensitive materials on your device: - geo-IP location showing b…

I’m arguing that because it exists no company of Apple’s size is going to risk unknowingly hosting it, and I wouldn’t either if I were in their shoes.

I agree with you in terms of photos being some of the most private information we have, but the E2E argument doesn’t ever get won by the tech community without a guarantee of blocking/catching/preventing CP and being able to make that evidence available for prosecution.

To the arguments above: Any processing server side implies no real E2E. Any processing client side is by definition under the control of the client and subject to forgery/hacking/spoofing/tampering.

Re: Apple's iCloud+ “VPN”

#276
post #254

Earlier quoted context omitted.

Your prediction of it being called Apple Undercover is significantly more 80’s though. And I like it. So much so that I would accept Apple using something other than Helvetica this one time for a Miami Vice typeface and a Michael Knight and Kitt intro at WWDC. I cannot stress enough that Hasselhoff needs to stay in character the entire time or the whole concept doesn’t work.

Hasselhoff drifts on to stage in KITT, jumps out, and tackles Tim Cook. They then get up, shake, laugh, and take turns explaining how iCloud+ VPN makes it look like everything you do online comes from Apple.

He may sing in German as the musical guest they sometimes have at the end of the keynotes, but that’s as much flexibility as I’m willing to allow.

Re: Apple's iCloud+ “VPN”

#277
post #212

> It's not clear if the API will be public for other browsers or applications to use. Apple has already confirmed that other app traffic will go through iCloud Private Relay “no matter what networking API you're using”, with some exemptions: > Not all networking done by your app occurs over the public internet, so there are several categories of traffic that are not affected by Private Relay. > Any connections your a…

So will this mean if I’m using Cloudflare 1.1.1.1 that I won’t get the iCloud private relay since they implement DoH as a VPN in iOS?

DNSCloak still works with Private Cloud.

Re: Apple's iCloud+ “VPN”

#278
post #110

Earlier quoted context omitted.

An even more impressive prediction in 2015, a time when Apple was not positioned as some type of savior of user privacy.

It's really not about privacy though, the insight needed (not that I'm saying it was easy to make this particular prediction) is that Apple is all about the Walled Garden. It can't be Tor because Apple doesn't own Tor, and so that's not inside the Walled Garden, whereas "Apple Undercover" even if it were functionally no better or worse than Tor, is magically blessed by the Apple branding. And Apple have been all abou…

Tor has reputation problems. Lots of services block tor exit nodes because of all the abuse that comes from them.

By making it a feature for paying subscribers only, Apple probably hopes that their solution won't be interesting for criminals. (Apple will likely cooperate with law enforcement)

Re: Apple's iCloud+ “VPN”

#279

Earlier quoted context omitted.

>I was under the impression that what isn’t forbidden by law was legal by default. Even beyond that, personal privacy from the government is enshrined in the 4th amendment. Just because there was some executive actions and illegal laws made does not mean the 4th amendment suddenly disappears. No person or entity has the right to dragnet all communications.

> personal privacy from the government is enshrined in the 4th amendment Yeaaaaah, let's just pretend Snowden and Manning never happened.

I'm doing the opposite. Saying that the fed is actively engaging in illegal search and seizure is not ignoring the whistleblowers that brought the scope of the issue to light, it's acknowledging the issue.

Re: Apple's iCloud+ “VPN”

#280
sounds awesome! tor as a system service with a professionally managed network. beyond making ad tracking harder, i wonder what sorts of new application spaces this may open up. i can already think of one! (and no, it's not some shady illegitimate/illegal bs)
Post reply on HN