Live data from Hacker News

Apple's iCloud+ “VPN”

metzdowd.com

291–300 of 413 posts

Re: Apple's iCloud+ “VPN”

#291
post #254

Earlier quoted context omitted.

Hasselhoff drifts on to stage in KITT, jumps out, and tackles Tim Cook. They then get up, shake, laugh, and take turns explaining how iCloud+ VPN makes it look like everything you do online comes from Apple.

He may sing in German as the musical guest they sometimes have at the end of the keynotes, but that’s as much flexibility as I’m willing to allow.

The Hoff MUST sing ‘Jump in my car’ for this to really land.

https://youtu.be/dm7jEA3frY4

Re: Apple's iCloud+ “VPN”

#293
post #250

Earlier quoted context omitted.

Because Google is definitely the most trustworthy company when it comes to data governance and respecting user privacy. No chance they'd use it to put you into a FLoC-type thing, benefiting their own advertising business while shutting out competitors. Google, the engineering company, always plays second fiddle to Google, the advertising company.

I trust Google and Apple 100x more (low estimate) than I do Comcast/Verizon, AT&T, etc.

I agree on the Apple, but not on Google. AT&T, Comcast, Verizon, Deutschetelekom, British Telecom, NTT, etc. Have spent the last 15 to 20 years being absolutely deskilled by people leaving for better jobs in the hyperscalers. If you’re worried about any telecom carrier looking at your traffic then all you need to do is make sure that encrypted client hello and DNS over HTTPS are used by the devices that you have. The products that they use to do deep packet inspection are all falling apart at this point and since they have no internal technologist they are busy asking vendors to fix it for them, and the vendors can’t fix it either.

Worrying about the carriers was really hot for a while especially post Snowden, but it’s really not a genuine threat.

Re: Apple's iCloud+ “VPN”

#294
post #173
post #7

I think this is great, if only as a way to kill the bullshit consumer VPN business, which sells snake oil.

> I think this is great, if only as a way to kill the bullshit consumer VPN business, which sells snake oil. Having a US megacorporation kill a whole market segment and pull it into their monopolized walled garden sure seems like an improvement. After all, they pinky promise they will not ever abuse that! /s

By this logic our computer operating systems would not improve, ever. Web browsers, built-in networking, music players, image editors, mail programs, even Solitare - all things that at one time were separate market segments.

Re: Apple's iCloud+ “VPN”

#295

Interesting. I thought I recalled talking about this on HN previously: https://news.ycombinator.com/item?id=10355868 _-__--- on Oct 8, 2015 | parent | favorite | on: Verizon revives "zombie cookie" device tracking on... Tor as an OS-level feature may not spark the best reaction. It's been given a bad name ("deep web," silk road, etc) in mass media and many people don't understand it enough to think of it as anything…

I love the moments when you can point back to an old post and say, "called that!"

(No snark, I really do love it.)

Enjoy the moment, future seer.

Re: Apple's iCloud+ “VPN”

#296
post #212

Earlier quoted context omitted.

So will this mean if I’m using Cloudflare 1.1.1.1 that I won’t get the iCloud private relay since they implement DoH as a VPN in iOS?

Not super familiar with 1.1.1.1, but I use NextDNS and it's no longer implemented as a VPN – they use the native iOS encrypted DNS feature. I wonder how iCloud Private Relay works with that.

I have the beta and it currently doesn’t appear to work.

Re: Apple's iCloud+ “VPN”

#297
post #87

> An big tradeoff for some is that the exit node is always chosen to be in the same geo location as the entry node. You can view this as a sop to the various on-line video providers How could it be a "sop" to video services, isn't it exactly what they want, no more no less?

What video services really want is for each user to be identifiable by IP address. This doesn't quite give them that, but it does region-lock them.

Why do they want that though? They can still remember you, right, since you’re logged in?

Re: Apple's iCloud+ “VPN”

#298

Earlier quoted context omitted.

That wouldn’t change that clicking the lock icon in your browser would show the same certificate on every website, and that this certificate was universally valid. Pretty obvious…

> show the same certificate on every website Not really, because, you can use on-demand certificate issuance. Hell, if you really want to, you can even name your certificates the same as existing certificates and the only way to detect the forgery would be to compare the actual public keys (and who does THAT). I feel like I'm writing an evil roadmap here, but, you can even do multiple root certs with different names…

If and when browsers start requiring pre-certificate transparency logging, anything like this should no longer be possible to pull off, since none of the fake certificates would be able to contain a stapled pre-certificate "signoff" from a trusted CT log.

Re: Apple's iCloud+ “VPN”

#299
post #105
post #92

Earlier quoted context omitted.

I wish I could pay for bbc iPlayer service outside old blighty. But they don't allow it.

smartdnsproxy.com - 2 weeks, no credit card needed. Works perfectly and you don't need to use a VPN, just one of their DNS servers.

I took a look at this, it seems the way it works is when you do a DNS lookup it does a lookup itself and rewrites the IPs before returning to you. It stores a mapping of client IP and rewritten IP to real IP and when it gets a request on the rewritten IP it looks up the original and proxies the request. Pretty cool, but I wouldn't trust it with anything unencrypted. It offers no privacy benefits.

Re: Apple's iCloud+ “VPN”

#300
post #222

Earlier quoted context omitted.

Do you have any thoughts on PIA vs Mullvad?

PIA is owned in a weird structure I don't understand in a jurisdiction where any legal agreements with my home country are, most likely, non-existant or untested. They also seem to have enormous amounts on money to spend on marketing or paying off torrent review sites. Everybody recommends them, but all of these things make me uneasy.

After the recent freenode drama, best to avoid them.
Post reply on HN