Live data from Hacker News

Apple's iCloud+ “VPN”

metzdowd.com

331–340 of 413 posts

Re: Apple's iCloud+ “VPN”

#331
post #255

From Apple's statement[0]: > The first assigns the user an anonymous IP address that maps to their region but not their actual location. The second decrypts the web address they want to visit and forwards them to their destination. This separation of information protects the user’s privacy because no single entity can identify both who a user is and which sites they visit. Apple is not saying nobody can deanonymize y…

That makes me wonder whether an analysis could be done over a long period of time to determine where in the region the user isn't, and thereby narrow down where the user is.

I'm curious what the details around the anonymous IP address assignment are. Protecting copyright holders seems to be the point of the IP assignment to not break content restrictions.

Are they able to assign a set for an entire country? If so, that doesn't narrow it down all that much. However, major league sports blackouts wouldn't work, so is it by city?

Re: Apple's iCloud+ “VPN”

#332

Earlier quoted context omitted.

Apple has claimed this shtick several times (as well as many other VPN companies), but it actually requires a pretty intricate software setup to pull off. The best VPN services won't even have hard drives to store logs in: that way, even individuals with a court-issued warrant can't get your info. I'd imagine there's sufficient pressure on Apple from PRISM and other governments to keep some level of rudimentary logs.

> The best VPN services won't even have hard drives to store logs in: that way, even individuals with a court-issued warrant can't get your info Courts can compel them to log this information, so all claims about not keeping logs are just theater. The second they're ordered to by a court in the US, they will.

IANAL! The legal theory is that US courts can stop you from taking actions, but cannot compel you to take actions.

So they can stop you from deleting existing logs, but they cannot require you to collect logs you aren't already collecting.

I have no idea how well this idea has been tested in court, but that's the theory on which providers who don't even have hard drives are relying.

Re: Apple's iCloud+ “VPN”

#333

> All in all, a very Apple approach: They deny themselves any knowledge of a customer's DNS queries and Web traffic, so if served with a subpoena they have very little to respond with. Maybe I am missing something but I view this is a rather genius move. They have plausible deniability + actually introduce some protection for their users. Not sure how to read the original post though. Is it praising Apple? Is it mock…

Apple has claimed this shtick several times (as well as many other VPN companies), but it actually requires a pretty intricate software setup to pull off. The best VPN services won't even have hard drives to store logs in: that way, even individuals with a court-issued warrant can't get your info. I'd imagine there's sufficient pressure on Apple from PRISM and other governments to keep some level of rudimentary logs.

(And if Apple has logs of which IP address accessed a resource from which egress provider at a specific time, that is often enough to do what most governments are looking for... such is the limitation of two hops, and why Tor has three. I truly hope Apple has designed their system to avoid logging anything about their ingress packet flows.)

Re: Apple's iCloud+ “VPN”

#334
post #309
post #15

Earlier quoted context omitted.

> but UK residents do typically pay for the content whereas those outside the UK are unable to. In essence, what you're saying boils down to "it's already paid for, but nobody else can have it anyway". It's unreasonable and there is no need to make excuses for this behaviour.

Licensing issues aside, it would cost _additional_ money to actually serve all that content to a global audience (shipping bytes over the internet isn't free).

yet they deliver over 3 CDNs, yes THREE, for a maximum viewership of one country

Re: Apple's iCloud+ “VPN”

#335
post #267

Earlier quoted context omitted.

Your prediction of it being called Apple Undercover is significantly more 80’s though. And I like it. So much so that I would accept Apple using something other than Helvetica this one time for a Miami Vice typeface and a Michael Knight and Kitt intro at WWDC. I cannot stress enough that Hasselhoff needs to stay in character the entire time or the whole concept doesn’t work.

> I would accept Apple using something other than Helvetica At this point, Helvetica itself would give a retro feeling if used by Apple. They’ve been all in on San Francisco for several years.

Nobody goes there anymore. It's too crowded.

https://imgur.com/gallery/2eBXYnT

Re: Apple's iCloud+ “VPN”

#336

Earlier quoted context omitted.

What video services really want is for each user to be identifiable by IP address. This doesn't quite give them that, but it does region-lock them.

Why do they want that though? They can still remember you, right, since you’re logged in?

Not all media sites require one to be logged in.

However, there are many reasons why a video service might want each user to be individually identifiable by IP.

- Many media items are contractually region-locked

- The same user from too many simultaneous IPs might mean shared credentials, a perceived loss of revenue

- The same user from geographically disparate IPs might also mean shared credentials, even if not simultaneous.

I'm sure there are more.

Re: Apple's iCloud+ “VPN”

#337

Earlier quoted context omitted.

Why do you use a VPN to download free and publicly available iso images? (Ubuntu). Just curious. Do you download directly from a mirror or use BitTorrent for this? (If the latter I think I kind of understand the rationale for the VPN)

Until a few months ago, I had never really used BitTorrent to do anything - save for about 20 minutes back in HS almost 20 years ago (!) (I think I was running uTorrent on Windows, it was weird and I really didn't know how to use it.) However, in order to "acquire" [this][1], torrenting was realistically the only sensible option I had. A direct download from the Internet Archive would have taken roughly 7 hours @ 100…

13GB would take less than 20 minutes at 100Mbps. Regardless, I’m not sure why you only consider near instant downloads “sensible”. I often spent several days downloading things when I was younger.

Re: Apple's iCloud+ “VPN”

#338
post #7

I think this is great, if only as a way to kill the bullshit consumer VPN business, which sells snake oil.

what is bullshit about it

Internet reselling doesn’t have nearly as much privacy as internet resellers suggest

If you are only hiding from your local network and ISP its fine

If you want to do that and change your location to a website it’s fine

If you are hiding from any government for a civil or criminal charge it is not fine

If you are hiding from any government intelligence so nobody knows anything it is not fine

It doesnt matter what “no logging” claims the internet reseller has, this is not verifiable and can also change at any moment

Re: Apple's iCloud+ “VPN”

#339

Earlier quoted context omitted.

Private Internet Access. I used to use NordVPN but found it to be much slower, less stable, worse macOS integration, not as good on the privacy front.

Do you have any thoughts on PIA vs Mullvad?

PIA is owned by the person who owns Freenode, afaik. I would certainly look into that before trusting them.

Re: Apple's iCloud+ “VPN”

#340

Earlier quoted context omitted.

I think that's painting with a pretty broad brush. What's wrong with Mullvad, for example?

Who runs Mullvad? I find it funny that people here mistrust companies like Facebook and Google, but then turn around and hand off their entire network activity to a faceless, anonymous VPN company.

Have you tried answering that question? Mullvad isn't faceless and anonymous.
Post reply on HN