Live data from Hacker News

iOS allows DNS request to escape the VPN tunnel

twitter.com

51–60 of 78 posts

Re: iOS allows DNS request to escape the VPN tunnel

#51

Earlier quoted context omitted.

I'm not following. Your link appears to be specific to corporate environments. The title of the document is: "VPN overview for Apple device deployment." It further states "Secure access to private corporate networks is available in iOS ..." An individual iPhone user who is not using a company issued device would not be beholden to MDM restrictions or profiles. Nor would access to "private corporate networks" be neces…

You can create and install mobileconfig profiles on any iPhone, even unmanaged.

Yes and if it's an unmanaged device it is by definition not being managed by an MDM. The title of the link makes it clear that the context is "device deployment." Further the section un the linked article states"Always On VPN"

">Always On VPN activation requires device supervision."

Supervision denotes a managed device"

"Supervision generally denotes that the device is owned by the organization, which provides additional control over its configuration and restrictions."[1]

No regular non-corporate iOS device user is ever likely to be downloading manually distributed mobile profiles.

[1] https://support.apple.com/guide/deployment/about-device-supe...

Re: iOS allows DNS request to escape the VPN tunnel

#52

Earlier quoted context omitted.

Spoofing GPS is trivial. Getting caught or not is a toss of the coin

Cheating the location on my phone is gravy. Broadcasting an RF signal to spoof GPS (and especially across a campus), that my friend, is not trivial or cheap.

Trying to set up an alternate 3d volume of GPS space sounds very difficult.

But broadcasting a loud signal that tells everyone in range that they are at the same exact point doesn't seem too hard to me. Couldn't that even be as simple as replaying a single-antenna recording taken somewhere else?

Re: iOS allows DNS request to escape the VPN tunnel

#53

Earlier quoted context omitted.

https://mullvad.net/en/blog/2022/10/10/android-leaks-connect... and I'll bet good money Android does the same thing if it can't get internet access over WiFi

I'm not defending Google in anyway, I'm sure they do, and I'd be the first to deride them too. But HN generally has a lot more forgiveness for apple, for some reason.

Apple does a lot of marketing around protecting user privacy better than the competition. In this case, iOS leaks more data than Android.

Re: iOS allows DNS request to escape the VPN tunnel

#54

Earlier quoted context omitted.

You can create and install mobileconfig profiles on any iPhone, even unmanaged.

Yes and if it's an unmanaged device it is by definition not being managed by an MDM. The title of the link makes it clear that the context is "device deployment." Further the section un the linked article states"Always On VPN" ">Always On VPN activation requires device supervision." Supervision denotes a managed device" "Supervision generally denotes that the device is owned by the organization, which provides additi…

I once was invited to install a profile as a beta testing user. I guess this process is now streamlined through the TestFlight app though.

Re: iOS allows DNS request to escape the VPN tunnel

#56
post #9

Always-on VPN that tunnels everything requires MDM commissioning. It's documented by Apple. See the section "Always On VPN": https://support.apple.com/guide/deployment/vpn-overview-depa... Is it dubious that Apple doesn't let VPN apps do this as well? Maybe. But this is known and documented.

Should it be expected that individual users should be familiar with corporate deployment documentation just to know that their VPN app they bought actually leaks?

Re: iOS allows DNS request to escape the VPN tunnel

#57
Related ProtonVpn article:

"We’ve raised this issue with Apple multiple times. Unfortunately, its fixes have been problematic. Apple has stated that their traffic being VPN-exempt is “expected”, and that “Always On VPN is only available on supervised devices enrolled in a mobile device management (MDM) solution”. We call on Apple to make a fully secure online experience accessible to everyone, not just those who enroll in a proprietary remote device management framework designed for enterprises."

https://protonvpn.com/blog/apple-ios-vulnerability-disclosur...

Re: iOS allows DNS request to escape the VPN tunnel

#60

Earlier quoted context omitted.

SSHing to another machine isn’t a solution, you’re just using a different machine. The way to solve it and still continue to use iOS is to implement your VPN at the network layer. e.g. use one of those wifi routers with a VPN client built in.

They circumvent this by forcing certain traffic to circumvent your hardened WiFi by using the mobile network radios.

iOS Airplane Mode
Post reply on HN