Live data from Hacker News

Apple's iCloud+ “VPN”

metzdowd.com

51–60 of 413 posts

Re: Apple's iCloud+ “VPN”

#51
Does this mean that all DDoS mitigation techniques need to exist before the exit node of this traffic? Which in turn mean, that everyone needs to outsource their DDoS mitigation to Apple.

Also the corollary would be, that anyone who is able to bypass the protection mechanisms Apple has in place to control DDoS, can use it to DDoS a service like Google, Microsoft and get the entire service banned for all iCloud+ users. Right?

Re: Apple's iCloud+ “VPN”

#52
post #7

I think this is great, if only as a way to kill the bullshit consumer VPN business, which sells snake oil.

what is bullshit about it

Have you noticed all the ads say “Hackers can spy on your connection when you log into your bank at Starbucks.”

That’s complete FUD. HTTPS completely avoids this issue (especially with a bank). Very few websites use HTTP now.

While VPNs do have their valid use (preventing your ISP from spying, changing geolocation, and private networks for eg, work), most of the marketing is spreading misinformation.

Re: Apple's iCloud+ “VPN”

#53
post #47

My guess is one of the major reasons for having the exit nodes in the same geo location as entry nodes is to have continuous operations in China. Without this constraint, they would have allowed chinese consumers to access the free web, which would ban them instantaneously. I don't think Apple cares as much about video content providers, though.

I don’t think this service is being offered in China, period.

Re: Apple's iCloud+ “VPN”

#55
post #15

Props to Apple for the design of this service. It doesn't hit all the privacy targets that long-time personal VPN users might be looking for, and it doesn't get into the game of trying to circumvent region locked content*, but otherwise it's likely to be a solid privacy improvement for almost all users in a careful and deliberate way. I use a VPN for other reasons (downloading Ubuntu ISOs mostly) but I'll probably tu…

> but UK residents do typically pay for the content whereas those outside the UK are unable to. In essence, what you're saying boils down to "it's already paid for, but nobody else can have it anyway". It's unreasonable and there is no need to make excuses for this behaviour.

Yes you're right, I was giving a reason more than an excuse. I don't think they should be doing it.

Re: Apple's iCloud+ “VPN”

#56

Does this compare to NextDNS[1]. I moved from Pi Hole[2] to NextDNS and I'm happy with it. 1. https://nextdns.io 2. https://pi-hole.net

Just curious, are you on the free tier? Just wondering if 300k queries per month is sufficient for the average person. I have no reference to base that number on.

Re: Apple's iCloud+ “VPN”

#57
post #51

Does this mean that all DDoS mitigation techniques need to exist before the exit node of this traffic? Which in turn mean, that everyone needs to outsource their DDoS mitigation to Apple. Also the corollary would be, that anyone who is able to bypass the protection mechanisms Apple has in place to control DDoS, can use it to DDoS a service like Google, Microsoft and get the entire service banned for all iCloud+ users…

Apple has sort of addressed this with only having it work with Safari and other apps that implement the API, rather than system-wide as something you can connect to. It’s probably going to take a lot of reverse engineering before hackers figure out the API and how to get third party devices to connect and authenticate, if at all. If you can’t get third party devices to connect, you are missing the first D in DDOS.

Re: Apple's iCloud+ “VPN”

#58
post #23

Earlier quoted context omitted.

It's generally down to the terms for content that networks (BBC in this case) buy licenses to. The IP owners don't want the networks to allow the whole world access to that content for the price that the network is willing to pay to show it to their region.

But also, and mostly, in reverse. The BBC is the producer and license owner of a ton of programming, and rather than offer that to the world for a subscription fee, they choose to offer it to select partners (previously mainly PBS, now Netflix and Amazon) for a licensing fee, or sometimes in a coproduction arrangement. This is big money, up-front, with no need to build out a global delivery system or deal with millio…

GP wanted to watch BBC News in particular. I don’t think there’s any licensing issue with that, surely?

Re: Apple's iCloud+ “VPN”

#59
post #52

Earlier quoted context omitted.

what is bullshit about it

Have you noticed all the ads say “Hackers can spy on your connection when you log into your bank at Starbucks.” That’s complete FUD. HTTPS completely avoids this issue ( especially with a bank). Very few websites use HTTP now. While VPNs do have their valid use (preventing your ISP from spying, changing geolocation, and private networks for eg, work), most of the marketing is spreading misinformation.

I've never understood how a VPN doesn't get too carried away to pull a MITM with some central cert

Re: Apple's iCloud+ “VPN”

#60
post #47

My guess is one of the major reasons for having the exit nodes in the same geo location as entry nodes is to have continuous operations in China. Without this constraint, they would have allowed chinese consumers to access the free web, which would ban them instantaneously. I don't think Apple cares as much about video content providers, though.

It wouldn't have been too hard to just implement this feature for chinese customers if that was the only driver.

But I agree that making the exit node in the same country probably goes beyond video content providers, it avoids all sorts of potential legal, diplomatic and practical issues.

Post reply on HN