Live data from Hacker News

Apple's iCloud+ “VPN”

metzdowd.com

371–380 of 413 posts

Re: Apple's iCloud+ “VPN”

#371

I've been trying to point this out to people but YouTube personalities have a louder voice than anyone else so you end up with bad information. Props to Apple for offering an (albeit low entropy) onion router on their own infrastructure. I can't imagine this is going to win them any friends in government circles but it's definitely a step in the right direction. I'd also really like to see Apple come clean about the…

> I can't imagine this is going to win them any friends in government circles but it's definitely a step in the right direction. Apple already has all the friends they need in the "government circles". They're fully enrolled in PRISM and are well-known to kowtow to the demands of corrupt leadership (see: Russian iPhones, Chinese iCloud hosting)

You can't not comply with the government of a country unless you are a country. And the citizens of Russia and China would not appreciate that, because they actually like their governments, and don't care what you think.

Re: Apple's iCloud+ “VPN”

#372

Earlier quoted context omitted.

Any large company can offer E2E encryption, as long as they don't have extenuating interests that could make them liable for the way I use their services. Unless Apple is harvesting my data on the regular, they should have no problem with me being the sole keyholder for my iCloud account.

I think Apple would need to ship a different OS in China. Cloud services offered there must store data in the country and be operated by Chinese companies. (Apple is complying with this) But Chinese companies HAVE TO assist the authorities in obtaining systematic access to private sector data. (This is not possible with E2E for backups and photos)

Apple (and every large company in the world) already ship different features to different regions.

Re: Apple's iCloud+ “VPN”

#373
post #216

Earlier quoted context omitted.

Are you really arguing that because child pornography exists, no large company should offer ETE photos? Despite there been reasonable solutions like bloom filters and client sided hash detection, so that known child abuse material can be detected, without it needing to compromise the privacy of 99.99999% of users? And that photos present some of the most sensitive materials on your device: - geo-IP location showing b…

I’m arguing that because it exists no company of Apple’s size is going to risk unknowingly hosting it, and I wouldn’t either if I were in their shoes. I agree with you in terms of photos being some of the most private information we have, but the E2E argument doesn’t ever get won by the tech community without a guarantee of blocking/catching/preventing CP and being able to make that evidence available for prosecution…

Absolutely every large company hosts an incredible amount of child pornography and abuse material.

Facebook is the largest platform for child trafficking, and Google is the world's largest resource for finding out how to commit criminal acts.

Crime always exist. We shouldn't build a techno-totalitarian surveillance state just because crime exists.

"It is better that ten guilty persons escape than that one innocent suffer".

Chinese Communists employed similar but opposite reasoning during the uprisings in Jiangxi, China in the 1930s: "Better to kill a hundred innocent people than let one truly guilty person go free".

Re: Apple's iCloud+ “VPN”

#374
post #346
post #305

Earlier quoted context omitted.

Not sure what you mean by that. The features are not the same, see https://kb.controld.com/compare

It says on your page you use Windscribe, they have this page https://windscribe.com/features/robert Sorry, purely a curiosity I didn't mean to come across as calling you out

ControlD uses transparent proxies in combination with DNS to do things you can't do with a VPN. Like this: https://twitter.com/ControlDNS/status/1358267260465463297

It's also made by the same team as Windscribe.

Re: Apple's iCloud+ “VPN”

#375

Earlier quoted context omitted.

Completely off-topic: great choice of name. That number is burned into my mind, and will be forever

To continue the off-topicness... That number almost always works for store 'loyalty program' discounts too. 867-5309

especially at Jenny's Diner

Re: Apple's iCloud+ “VPN”

#377
post #61

Earlier quoted context omitted.

Of course it was a false flag issue, it never made sense from the beginning.

In a world where white noise[1], birdsong[2] and someone playing Beethoven on the piano[3] get copyright strikes/takedown notices - I don't think someone getting a copyright notice for downloading Ubuntu is that far fetched. [1] https://www.bbc.com/news/technology-42580523 [2] https://news.ycombinator.com/item?id=3637124 [3] https://news.ycombinator.com/item?id=27004577

There's actually an album called Ubuntu. Quite possible some duncehead set up a bot to download all torrents with Ubuntu in the name and scrape the IPs.

https://en.wikipedia.org/wiki/Ubuntu_%28album%29

Re: Apple's iCloud+ “VPN”

#378

Earlier quoted context omitted.

Would you clear the misunderstanding then?

iCloud Backup works differently to all other iCloud services. How it all works is documented: https://support.apple.com/guide/security/welcome/web

Nowhere in the linked site that I’ve been able to find does it explain clearly that iCloud backup undermines on-device encryption.

The point is that the deep compromises made inside iCloud Backup are hidden from the user and (at best) buried deep in technical documentation. So deep in fact that I can’t find any mention of it on that site at all.

Re: Apple's iCloud+ “VPN”

#379

Earlier quoted context omitted.

if you disable from quick menu, it turns back on. if you disable from settings, it doesn’t

And when you do so it does flash a message along the lines of “Disconnecting nearby wifi until tomorrow”. Which makes it pretty clear it’s not a wifi kill switch but just a “my current connection is shit, let me use cellular” button.

yeah, but even so, it’s one of these occasions where an os symbol has been altered to change behaviour without the user’s consent or control

it’s not quite as egregious, but it reminds me of how a lot of desktop apps now just minimise to tray rather than actually ending the process when you click the close button. discord is probably the worst offender for that, since it’s not (that I’m aware) a customisable behaviour

Re: Apple's iCloud+ “VPN”

#380

Earlier quoted context omitted.

Yes, backups, and Apple should get on that. However, your photos in Google Photos, your location data, your uploads in Google Drive (equivalent to iCloud Drive OP is talking about), not end to end encrypted and no option for it. I think market share is another sign. Does anyone use actual Android Backup, or do they use the unencrypted “backups” in G Photos and elsewhere? For that reason should the FBI care? Maybe I’m…

Let's be really frank about it - no large company is going to offer end-to-end encryption of photos because of what kind of photos might end up on their infrastructure if they do. And honestly I don't blame them at all . I'd just like to see Apple be more transparent with this one particular issue because it undermines so much of what they're advertising to the consumer. A transparency label for iCloud backup showing…

I don't understand this line of reasoning. Why should photo libraries not be end-to-end encrypted?

Are you suggesting that Apple or the government should be able to search your personal photo library stored in the cloud at any time because maybe you might have child porn in there?

I understand that companies need to scan groups and social features that are used for trafficking underage porn. But do we really need to snoop into the private libraries of innocent people just because they might have illegal material?

Having access to millions of peoples photos is such a huge privacy risk that I can't think giving it up is worth while to make it slightly easier to catch a handful of criminals.

Post reply on HN