Live data from Hacker News

Apple's iCloud+ “VPN”

metzdowd.com

301–310 of 413 posts

Re: Apple's iCloud+ “VPN”

#301

Does anybody know, how iCloud+ VPN would compare with Cloudflare WARP in terms of better privacy protection.

Don’t forget that neither is a pure VPN, though that’s not always a bad thing — Private Relay is better than a VPN because onion routing means “no one party”[1] can correlate your connections and identity.

However WARP, being more like a VPN, requires you to trust Cloudflare to not log DNS lookups / the servers you connect to and associate that with your origin IP.

Why do I hesitate to call WARP a real VPN? It reveals your actual IP address to websites you visit via X-Forwarded-For. [2]

Also I think the fact that iCloud Private Relay will be built-in makes it more private than WARP — more users’ traffic will come out of each node.

[1]: Obviously this is imperfect because the Apple (which knows your IP) and third-party (which knows the network traffic) nodes will likely be in the same jurisdiction as each other, subject to the same laws, as mentioned by other commenters.

[2]: https://twitter.com/eastdakota/status/1176987146177196032

edit: typo, line break, clarified Private Relay concept

Re: Apple's iCloud+ “VPN”

#302
post #156

Earlier quoted context omitted.

Apple is in crossfire: (a) There is pressure from many governments to give backdoor for surveillance. Or just comply with subpoenas that are against human rights. (b) Complying with local laws generates PR damage. It makes privacy and ethics as a brand strategy look disingenuous. The solution is, of course, to generate truly secure system where Apple can't make backdoors. Those services may not be available in some c…

This is something Apple is increasingly working on. For example, in Fall 2020 they actually revised their CPU designs (including older CPUs) with a new Secure Enclave design that uses mailboxes to more securely store the number authentication attempts inside the secure enclave. The goal of this is to make it so that even if the FBI had an incident similar to 2016, Apple would not be able to fulfill their request to m…

That only works if you don't give control of the servers over to a third party and also use encryption on the servers. Which Apple has not been able to do across the board.

Re: Apple's iCloud+ “VPN”

#304
post #295

Interesting. I thought I recalled talking about this on HN previously: https://news.ycombinator.com/item?id=10355868 _-__--- on Oct 8, 2015 | parent | favorite | on: Verizon revives "zombie cookie" device tracking on... Tor as an OS-level feature may not spark the best reaction. It's been given a bad name ("deep web," silk road, etc) in mass media and many people don't understand it enough to think of it as anything…

I love the moments when you can point back to an old post and say, "called that!" (No snark, I really do love it.) Enjoy the moment, future seer.

I mean, he also said it was phenomenally unlikely…. Maybe 1/2 a point.

Re: Apple's iCloud+ “VPN”

#305
post #213
post #72

Earlier quoted context omitted.

Shameless self-plug: NextDNS does not, but ControlD does do that - https://controld.com

Your service seems to support the same features as your provider -- are you 1:1 reselling or do you add stuff?

Not sure what you mean by that. The features are not the same, see https://kb.controld.com/compare

Re: Apple's iCloud+ “VPN”

#306

Earlier quoted context omitted.

Private Internet Access. I used to use NordVPN but found it to be much slower, less stable, worse macOS integration, not as good on the privacy front.

Do you have any thoughts on PIA vs Mullvad?

FWIW, Mozilla VPN is based off Mullvad, which I've enjoyed for a year to download Linux ISOs and I've never had an issue with. Also they have one of the most anonymous of setups (accept cash, crypto, no username or passwords or personal details required, you're just given a random account number you can add credit to)

NordVPN is oversubscribed crap.

PIA was founded by Andrew Lee, the big brain behind the current Freenode drama, with help of the infamous Mark Karpeles of Mt. Gox fame. I'd rather use something else.

Re: Apple's iCloud+ “VPN”

#307

Earlier quoted context omitted.

totally agree. I had no end of shit trying to watch BBC News channel from abroad. I'm a UK national, I own a house in the UK, I pay UK taxes, I pay your stupid TV licence fee, you're broadcasting live over 3 separate CDNs, just let me watch the fucking news. I eventually subscribed to an illegal IPTV service for that one sodding channel. I don't even need the other 17,000 channels. the BBC drove me to it

Completely off-topic: great choice of name. That number is burned into my mind, and will be forever

cheers ;)

Re: Apple's iCloud+ “VPN”

#308
post #255

From Apple's statement[0]: > The first assigns the user an anonymous IP address that maps to their region but not their actual location. The second decrypts the web address they want to visit and forwards them to their destination. This separation of information protects the user’s privacy because no single entity can identify both who a user is and which sites they visit. Apple is not saying nobody can deanonymize y…

That makes me wonder whether an analysis could be done over a long period of time to determine where in the region the user isn't, and thereby narrow down where the user is.

Re: Apple's iCloud+ “VPN”

#309
post #15

Props to Apple for the design of this service. It doesn't hit all the privacy targets that long-time personal VPN users might be looking for, and it doesn't get into the game of trying to circumvent region locked content*, but otherwise it's likely to be a solid privacy improvement for almost all users in a careful and deliberate way. I use a VPN for other reasons (downloading Ubuntu ISOs mostly) but I'll probably tu…

> but UK residents do typically pay for the content whereas those outside the UK are unable to. In essence, what you're saying boils down to "it's already paid for, but nobody else can have it anyway". It's unreasonable and there is no need to make excuses for this behaviour.

Licensing issues aside, it would cost _additional_ money to actually serve all that content to a global audience (shipping bytes over the internet isn't free).

Re: Apple's iCloud+ “VPN”

#310

Earlier quoted context omitted.

> Otherwise how come that would even be legal to run? Why wouldn’t it be? I was under the impression that what isn’t forbidden by law was legal by default. AFAIK, running a VPN platform isn’t illegal. > If someone commits a crime and government cannot find evidence, because Apple gives shielding, then isn't that making them hypothetically an accomplice? I hate this argument. It’s lazy and can be used to accuse anybod…

>I was under the impression that what isn’t forbidden by law was legal by default. Even beyond that, personal privacy from the government is enshrined in the 4th amendment. Just because there was some executive actions and illegal laws made does not mean the 4th amendment suddenly disappears. No person or entity has the right to dragnet all communications.

> No person or entity has the right to dragnet all communications.

Indeed. And the fact that this is not recognised as a fundamental human right is a serious limitation of the charter and universal declaration. And yet, it comes up regularly.

Post reply on HN