Live data from Hacker News

Apple's iCloud+ “VPN”

metzdowd.com

31–40 of 413 posts

Re: Apple's iCloud+ “VPN”

#31
post #19

Earlier quoted context omitted.

Why do you use a VPN to download free and publicly available iso images? (Ubuntu). Just curious. Do you download directly from a mirror or use BitTorrent for this? (If the latter I think I kind of understand the rationale for the VPN)

linux iso is code for pirated content

And here I was, still thinking Linux was "an illegal hacker operation system, invented by a Soviet computer hacker named Linyos Torovoltos, before the Russians lost the Cold War".

Re: Apple's iCloud+ “VPN”

#32
post #22
post #6

Earlier quoted context omitted.

> This breaks DNS resolution for company-internal domains. Is this not the case for any VPN or proxying service? In fact, it could even be a security flaw if your internal domains were accessible on external VPN style endpoints?

> Is this not the case for any VPN or proxying service? No, it's not. > In fact, it could even be a security flaw if your internal domains were accessible on external VPN style endpoints? It would be, but then this is not something that happens on a network configured in the way you describe.

I use NordVPN. It specifically has an opt-in setting to use locally discovered DNS in favor of their in-network DNS. This is crucial since out-of-network DNS can leak activity.

I’m not sure what kind of network you believe I described, but would be useful to have a clearer explanation from you.

Re: Apple's iCloud+ “VPN”

#33

Does this compare to NextDNS[1]. I moved from Pi Hole[2] to NextDNS and I'm happy with it. 1. https://nextdns.io 2. https://pi-hole.net

No. NextDNS and Pi-Hole serve DNS requests and are mainly used for ad blocking and content restrictions on your network. They don't tunnel or redirect your actual internet traffic the way a VPN does.

Re: Apple's iCloud+ “VPN”

#34

Does this compare to NextDNS[1]. I moved from Pi Hole[2] to NextDNS and I'm happy with it. 1. https://nextdns.io 2. https://pi-hole.net

Oh, that's interesting. What convinced you to switch? Not having to host it yourself or some specific features?

Re: Apple's iCloud+ “VPN”

#36
post #22
post #6

Earlier quoted context omitted.

> This breaks DNS resolution for company-internal domains. Is this not the case for any VPN or proxying service? In fact, it could even be a security flaw if your internal domains were accessible on external VPN style endpoints?

> Is this not the case for any VPN or proxying service? No, it's not. > In fact, it could even be a security flaw if your internal domains were accessible on external VPN style endpoints? It would be, but then this is not something that happens on a network configured in the way you describe.

"No, it's not"

The root's observation is that it doesn't use the machine configured DNS. The overwhelming majority of VPNs also don't use the machine configured DNS. Maybe not "any", but if you're using a VPN you're generally going to want your DNS going over it as well.

But it is worth noting if you're on a corporate network, or if you use a DNS solution like NextDNS -- when you turn on PR those no longer play a part, at least to Safari traffic.

Re: Apple's iCloud+ “VPN”

#37
post #23
post #15

Earlier quoted context omitted.

> but UK residents do typically pay for the content whereas those outside the UK are unable to. In essence, what you're saying boils down to "it's already paid for, but nobody else can have it anyway". It's unreasonable and there is no need to make excuses for this behaviour.

It's generally down to the terms for content that networks (BBC in this case) buy licenses to. The IP owners don't want the networks to allow the whole world access to that content for the price that the network is willing to pay to show it to their region.

But also, and mostly, in reverse. The BBC is the producer and license owner of a ton of programming, and rather than offer that to the world for a subscription fee, they choose to offer it to select partners (previously mainly PBS, now Netflix and Amazon) for a licensing fee, or sometimes in a coproduction arrangement.

This is big money, up-front, with no need to build out a global delivery system or deal with millions of customers.

Re: Apple's iCloud+ “VPN”

#38
Correct me if I’m wrong, but as I understand it a two-hop onion network is still trivially breakable with (two) warrants, especially since both Apple and Cloudflare/etc., are US companies. Which would make it a VPN in the duck-type sense.

Re: Apple's iCloud+ “VPN”

#40
post #24

Props to Apple for the design of this service. It doesn't hit all the privacy targets that long-time personal VPN users might be looking for, and it doesn't get into the game of trying to circumvent region locked content*, but otherwise it's likely to be a solid privacy improvement for almost all users in a careful and deliberate way. I use a VPN for other reasons (downloading Ubuntu ISOs mostly) but I'll probably tu…

> I use a VPN for other reasons (downloading Ubuntu ISOs mostly). This made me smile. Good one. For context, copyright trolls recently tried to extort torrent users for downloading and sharing Ubuntu ISOs.

If you want to give context, a link to the story would be nice:

https://arstechnica.com/gadgets/2021/05/fake-dmca-takedown-n...

Importantly, OpSec (the company doing this torrent-dmca-for-hire stuff) says the DMCA itself was spoofed

> OpSec Security’s DCMA notice sending program was spoofed on Wednesday, May 26, 2021, by unknown parties across multiple streaming platforms.

Post reply on HN