Live data from Hacker News

Apple's iCloud+ “VPN”

metzdowd.com

341–350 of 413 posts

Re: Apple's iCloud+ “VPN”

#341

Here is a simple question: Why is there only one "Tor". Why haven't there been more onion routing projects. (Maybe there have been and I am just not aware.) Perhaps the same reason(s) we never saw widespread adoption of remote proxies, despite their usefulness in many situations. Although in some respects onion routing seems quite an improvement over "simple" proxies.

The more nodes you have participating the more secure an onion system tends to be. Since the Tor network can carry most kinds of traffic, the motivation to avoid a fork is strong.

> The more nodes you have participating the more secure an onion system tends to be.

Tor isn't very large as it is, and (I would guess) it's the largest. If another onion routing network didn't grow the audience, you would have two even smaller networks.

> the Tor network can carry most kinds of traffic

Isn't Tor limited to routing TCP? That would rule out QUIC, for example.

Re: Apple's iCloud+ “VPN”

#342
post #3

My experience with this so far was... mixed. - This breaks DNS resolution for company-internal domains. - This routes all my traffic through CloudFlare or another CDN I might or might not trust (yes, the IP is hidden, but not the data) - it significantly slows down my internet access on my location. - it tends to turn itself on again without my intervention especially the last point is very problematic for me

> the IP is hidden, but not the data

Isn't the great majority of your traffic HTTPS?

Re: Apple's iCloud+ “VPN”

#343

Correct me if I’m wrong, but as I understand it a two-hop onion network is still trivially breakable with (two) warrants, especially since both Apple and Cloudflare/etc., are US companies. Which would make it a VPN in the duck-type sense.

It depends, whether they do no logs. There are many VPN providers in the US which don’t have logs, so that if they are subpoenaed, they have nothing to give. The beauty of Apple’s double hop is that if one partner was hacked, secretly wiretapped, or had lied about not keeping logs, your connection would still be private. But, that assumes that nobody on this network is keeping logs. If they are, then it could be theo…

> There are many VPN providers in the US which don’t have logs

Many claim they don't have logs, and my understanding is that it has been sometimes revealed that they do have logs. Also, how do you run a server without logs? Many think those claims are BS.

Re: Apple's iCloud+ “VPN”

#344
post #312
post #24

Earlier quoted context omitted.

> I use a VPN for other reasons (downloading Ubuntu ISOs mostly). This made me smile. Good one. For context, copyright trolls recently tried to extort torrent users for downloading and sharing Ubuntu ISOs.

The sad thing is that actual Linux ISOs are so over-mirrored that using BitTorrent generally has no benefit and may be slower.

High availability (through mirrors) is still a good thing. My experience is that torrent files are sometimes a lot faster, sometimes less so. Just as mirrors.

Re: Apple's iCloud+ “VPN”

#345

Earlier quoted context omitted.

> The best VPN services won't even have hard drives to store logs in: that way, even individuals with a court-issued warrant can't get your info Courts can compel them to log this information, so all claims about not keeping logs are just theater. The second they're ordered to by a court in the US, they will.

IANAL! The legal theory is that US courts can stop you from taking actions, but cannot compel you to take actions. So they can stop you from deleting existing logs, but they cannot require you to collect logs you aren't already collecting. I have no idea how well this idea has been tested in court, but that's the theory on which providers who don't even have hard drives are relying.

IANAL as well, but your first line is definitely not true. A writ of mandamus is one of many such ways a court can compel behavior, though typically a tool of last resort.

Courts order individuals, businesses and officials to take actions as a matter of course: to stand trial, to comply with subpoenas, to adhere to a contract, to make restitution, and so on.

I am not deeply familiar with lawful intercept law and case law around national security letters (what little there is), but I would not gamble anything of value on the principle that courts cannot compel someone to take actions.

Re: Apple's iCloud+ “VPN”

#346
post #305
post #213

Earlier quoted context omitted.

Your service seems to support the same features as your provider -- are you 1:1 reselling or do you add stuff?

Not sure what you mean by that. The features are not the same, see https://kb.controld.com/compare

It says on your page you use Windscribe, they have this page

https://windscribe.com/features/robert

Sorry, purely a curiosity I didn't mean to come across as calling you out

Re: Apple's iCloud+ “VPN”

#347

Here is a simple question: Why is there only one "Tor". Why haven't there been more onion routing projects. (Maybe there have been and I am just not aware.) Perhaps the same reason(s) we never saw widespread adoption of remote proxies, despite their usefulness in many situations. Although in some respects onion routing seems quite an improvement over "simple" proxies.

You need lots of nodes to make it secure, performance is low even by VPN standards, and it’s dangerous to run a node. Unless you have some likely way to change one of those it’s going to be really hard to get volunteers – and payment is worse because most customers will expect better service.

Re: Apple's iCloud+ “VPN”

#349
So I seem to be completely missing... what is this actually for? What's the value proposition for the average consumer?

It doesn't replace a VPN into your company's or university's network (for accessing private resources).

It's not for accessing streaming TV in different regions.

HTTPS is already secure.

In theory it seems like it could be used for illegal torrent downloading, but given that Apple is in the media business, something tells me they'll do their best to block torrenting.

And for things like videoconferencing, it will almost certainly degrade performance to a degree (latency, bandwidth, or both).

The only thing left seems to be your ISP and/or coffee shop WiFi being able to track what IP addresses you communicate with. Instead, they don't, but Apple does. Is that really a benefit, or a benefit any average consumer cares about?

Re: Apple's iCloud+ “VPN”

#350

Earlier quoted context omitted.

Until a few months ago, I had never really used BitTorrent to do anything - save for about 20 minutes back in HS almost 20 years ago (!) (I think I was running uTorrent on Windows, it was weird and I really didn't know how to use it.) However, in order to "acquire" [this][1], torrenting was realistically the only sensible option I had. A direct download from the Internet Archive would have taken roughly 7 hours @ 100…

13GB would take less than 20 minutes at 100Mbps. Regardless, I’m not sure why you only consider near instant downloads “sensible”. I often spent several days downloading things when I was younger.

Not so fast.

Yes, 100Mbps is ~12.5 MB/s, however when I initially tried the .mp4 link I found actual speeds to be much less, (hence the hours long wait I mentioned) so there's definitely throttling going on somewhere.

Also, don't count your chickens before they hatch. I remember downloading Flight Simulator 2002 mods over a 56K modem in my youth - anything over 10MB was a stretch - and I didn't actually have a broadband connection until I went off to college in 2005.

Post reply on HN