Live data from Hacker News

Apple's iCloud+ “VPN”

metzdowd.com

391–400 of 413 posts

Re: Apple's iCloud+ “VPN”

#391
post #311

Earlier quoted context omitted.

By this logic our computer operating systems would not improve, ever. Web browsers, built-in networking, music players, image editors, mail programs, even Solitare - all things that at one time were separate market segments.

All of those products have been improved by COMPETITION. The most critical, most important and ONLY thing that makes modern capitalism work for non-rich human beings. Every single field you mention was thriving when there were multiple players fighting over your money and have started to become exploitative and abusive as soon as one player killed the others and started rent-seeking. Competition is crucial for market…

Consumer VPN isn’t a market where competition is driving better products. All of the products are the same technically - it’s a trivial service to standup. Sort of like a home security company… there are good ones, but most are garbage peddling FUD, especially fear.

The differentiation is purely marketing. Some VPN providers are basically grey market means to bypass TV blackouts. Others claim to be privacy focused, but are in fact the opposite. A few are actually privacy focused.

IMO, having megacorp(s) roll up the junk use cases actually drives meaningful competition by putting the lousy players out of business or driving consolidation in a crowded market.

Re: Apple's iCloud+ “VPN”

#392

Earlier quoted context omitted.

IANAL! The legal theory is that US courts can stop you from taking actions, but cannot compel you to take actions. So they can stop you from deleting existing logs, but they cannot require you to collect logs you aren't already collecting. I have no idea how well this idea has been tested in court, but that's the theory on which providers who don't even have hard drives are relying.

IANAL as well, but your first line is definitely not true. A writ of mandamus is one of many such ways a court can compel behavior, though typically a tool of last resort. Courts order individuals, businesses and officials to take actions as a matter of course: to stand trial, to comply with subpoenas, to adhere to a contract, to make restitution, and so on. I am not deeply familiar with lawful intercept law and case…

Let's assume that your are right, which I think is true. While courts cannot compel companies to do some things, they can certainly compel them to do things that are a normal part of business, like producing paperwork, or in this case, logging activity.

With an NSL, they could approach a company and require them to start collecting logs and also to not communicate about the new requirement, at which point a privacy-focused company's only choice would be to either comply or stop offering the VPN service entirely without saying why.

Without an NSL, the company would be free to communicate about why it was no longer offering the VPN service, or to announce that they were going to be logging from that point on, giving people an option to stop using the service if that's a problem for them.

But not having a hard drive in place currently, that prevents the courts from getting information about any activity before the court order or NSL is issued, as far as I can tell, which I guess is what those companies are counting on.

Not an easy business to be in, in any case.

Re: Apple's iCloud+ “VPN”

#393

Earlier quoted context omitted.

Not all media sites require one to be logged in. However, there are many reasons why a video service might want each user to be individually identifiable by IP. - Many media items are contractually region-locked - The same user from too many simultaneous IPs might mean shared credentials, a perceived loss of revenue - The same user from geographically disparate IPs might also mean shared credentials, even if not simu…

We were talking about video streaming services though, they usually require a log in, and in any case they’ll have a cookie so they know who you are. Region locking is fine right, that’s exactly what Cloud+ provides, same thing with your third point. As to the second one, I don’t know how big the simulated regions are but i suppose it will look like different houses at least. I’m sure netflix will think of something…

> We were talking about video streaming services though

Were we? I read "on-line video providers," which could as easily be the BBC or YouTube as Netflix. It seems like your most recent comment is the first one to mention streaming.

Re: Apple's iCloud+ “VPN”

#394

Earlier quoted context omitted.

The point is that the Constitution is largely meaningless, feel-good fluffery that has no actual bearing on which of our so-called rights are actually available to us. It's an aspirational document in a largely lawless land, more a historical oddity than the supreme anything. If you wait for legislators and law enforcement to fix personal privacy, you've already lost... the US law enforcement culture is actively host…

>The point is that the Constitution is largely meaningless, feel-good fluffery that has no actual bearing on which of our so-called rights are actually available to us. IANAL but this sounds fundamentally wrong in every way I interpret it. The Constitution is a set of laws that cannot be contradicted by any other law, executive action, or judicial action, with the exception of an amendment.

It can and often has been simply ignored.

Re: Apple's iCloud+ “VPN”

#395

Earlier quoted context omitted.

We were talking about video streaming services though, they usually require a log in, and in any case they’ll have a cookie so they know who you are. Region locking is fine right, that’s exactly what Cloud+ provides, same thing with your third point. As to the second one, I don’t know how big the simulated regions are but i suppose it will look like different houses at least. I’m sure netflix will think of something…

> We were talking about video streaming services though Were we? I read "on-line video providers," which could as easily be the BBC or YouTube as Netflix. It seems like your most recent comment is the first one to mention streaming.

Those are all video streaming sites.

Re: Apple's iCloud+ “VPN”

#396

Earlier quoted context omitted.

Who runs Mullvad? I find it funny that people here mistrust companies like Facebook and Google, but then turn around and hand off their entire network activity to a faceless, anonymous VPN company.

I think a lot of that distinction turns on how well your network data is linked to your identity. In the case of Mullvad, you can pay them anonymously by putting cash in an envelope and just mailing it to them,[1] which lowers the trust factor involved. [1] https://mullvad.net/en/pricing/

They still have your real IP address, which is what you were trying to hide in the first place

Re: Apple's iCloud+ “VPN”

#397
post #370
post #257

Earlier quoted context omitted.

In the bloom filter example, what device calculates the hash inputs for the bloom filters? If it's the server, then the server needs a copy of the image to check. So is it the client? If so, how can you prevent a malicious client from forging their hashes to be those of known-safe images? Not saying it's not possible to build an E2E image storage service that also has the protections society tends to demand. Just say…

Apple has direct-from-bootloader control over all of their hardware, unless you boot Linux on a Mac (in which case you don't get iCloud). So a 'malicious client' doesn't need to be part of the threat model here. And also, if you really stretch your argument, that's like saying we need to outlaw Linux and open source software because malicious actors can modify the code. The whole idea that society demands content pro…

Thanks for the "how" - I guess if you fully control the client and server, there's some extra checks you could implement client-side based on the cryptographic root of trust.

FWIW, I wasn't really trying to make a prescriptive statement about how the world ought to be, I was more trying to describe what (I think) the perspective of these corporations has been on the matter.

In the past, I've been an encryption advocate with the knowledge that we (tech) must sacrifice some ability to appease politicians in implementing it. What you're describing sounds like an innovative way to preserve privacy and provide security for at-risk people, which is a perspective I haven't heard before.

Re: Apple's iCloud+ “VPN”

#398

Earlier quoted context omitted.

IANAL! The legal theory is that US courts can stop you from taking actions, but cannot compel you to take actions. So they can stop you from deleting existing logs, but they cannot require you to collect logs you aren't already collecting. I have no idea how well this idea has been tested in court, but that's the theory on which providers who don't even have hard drives are relying.

IANAL as well, but your first line is definitely not true. A writ of mandamus is one of many such ways a court can compel behavior, though typically a tool of last resort. Courts order individuals, businesses and officials to take actions as a matter of course: to stand trial, to comply with subpoenas, to adhere to a contract, to make restitution, and so on. I am not deeply familiar with lawful intercept law and case…

If the court did compel a VPN company to log compromising information, I'd imagine most companies would tell you. After all, you're just trying to be transparent to your consumers.

Re: Apple's iCloud+ “VPN”

#399

Earlier quoted context omitted.

Any large company can offer E2E encryption, as long as they don't have extenuating interests that could make them liable for the way I use their services. Unless Apple is harvesting my data on the regular, they should have no problem with me being the sole keyholder for my iCloud account.

I think Apple would need to ship a different OS in China. Cloud services offered there must store data in the country and be operated by Chinese companies. (Apple is complying with this) But Chinese companies HAVE TO assist the authorities in obtaining systematic access to private sector data. (This is not possible with E2E for backups and photos)

Apple already does this. All Chinese iCloud data is stored in a mainland datacenter, completely owned and operated by their government. Similar setups exist in Russia and France, where Apple kowtows to local governments at any cost to turn a buck in their hometown.

Re: Apple's iCloud+ “VPN”

#400
post #31
post #19

Earlier quoted context omitted.

linux iso is code for pirated content

And here I was, still thinking Linux was "an illegal hacker operation system, invented by a Soviet computer hacker named Linyos Torovoltos, before the Russians lost the Cold War" .

I think you've confused it with Lunix.
Post reply on HN