Live data from Hacker News

Apple's iCloud+ “VPN”

metzdowd.com

81–90 of 413 posts

Re: Apple's iCloud+ “VPN”

#81
post #56

Does this compare to NextDNS[1]. I moved from Pi Hole[2] to NextDNS and I'm happy with it. 1. https://nextdns.io 2. https://pi-hole.net

Just curious, are you on the free tier? Just wondering if 300k queries per month is sufficient for the average person. I have no reference to base that number on.

I'm on the paid tier. I pay the yearly subscription. Our family of four (2 kids) easily hit 1+ Million queries a month.

Re: Apple's iCloud+ “VPN”

#82

I've been trying to point this out to people but YouTube personalities have a louder voice than anyone else so you end up with bad information. Props to Apple for offering an (albeit low entropy) onion router on their own infrastructure. I can't imagine this is going to win them any friends in government circles but it's definitely a step in the right direction. I'd also really like to see Apple come clean about the…

> I can't imagine this is going to win them any friends in government circles but it's definitely a step in the right direction. Quite the opposite. Governments probably already have taps to decrypted traffic. Otherwise how come that would even be legal to run? If someone commits a crime and government cannot find evidence, because Apple gives shielding, then isn't that making them hypothetically an accomplice?

By the same logic, I’m the taxpayer who paid to help build the highway that the drug kingpin used to get away during a high speed chase. I’m an accomplice now.

I’m the scientist who purified the water that the criminal used to get enough strength to run away. I’m an accomplice now.

Re: Apple's iCloud+ “VPN”

#83
post #65

Correct me if I’m wrong, but as I understand it a two-hop onion network is still trivially breakable with (two) warrants, especially since both Apple and Cloudflare/etc., are US companies. Which would make it a VPN in the duck-type sense.

That’s the beauty of this. Party 2 only knows Apple’s IP. Apple doesn’t know what site you’re visiting. So how do you assemble “all traffic to this site” even by subpoenaing both parties?

To party 1: "Give us a netflow log of all of this user's traffic." To party 2: "Give us a list of all outbound connections matching this netflow list of inbound proxying requests."

It would work the other way around as well (going from visited sites to a given Apple id). If you can monitor all nodes in an onion routing network, you can deanonymize everybody.

Re: Apple's iCloud+ “VPN”

#84
post #3

My experience with this so far was... mixed. - This breaks DNS resolution for company-internal domains. - This routes all my traffic through CloudFlare or another CDN I might or might not trust (yes, the IP is hidden, but not the data) - it significantly slows down my internet access on my location. - it tends to turn itself on again without my intervention especially the last point is very problematic for me

To use it you're clearly using early beta software. Clearly it isn't going to "turn itself on again". I turned it on and actually forgot I did. Performance is decent here. I mean of course it's going to be worse than native, but that's the compromise. As to trusting Cloudflare -- what do you mean? You understand your connection is still TLS end-to-end encrypted (presuming that's what we're talking about), right? I me…

> Clearly it isn't going to "turn itself on again"

Why is it so clear? An iPhone hotspot turns itself off as soon as a device disconnects, with no option to leave it on, presumably for security or battery reasons.

Re: Apple's iCloud+ “VPN”

#85

Props to Apple for the design of this service. It doesn't hit all the privacy targets that long-time personal VPN users might be looking for, and it doesn't get into the game of trying to circumvent region locked content*, but otherwise it's likely to be a solid privacy improvement for almost all users in a careful and deliberate way. I use a VPN for other reasons (downloading Ubuntu ISOs mostly) but I'll probably tu…

> trying to circumvent region locked content

Semi-related to this, but they do offer an option to pick between preserving your approximate location and using a broader location.

The example they took in one of the sessions was, if you live in San José, with the first option, you'll get an exit node near San José so you can still get local "content". With the second one, you could get an exit node in Los Angeles.

In practice in Europe, it looks a bit different. I do live in the north west of France, and with the first option I regularly get an exit node in the southwest of France (from Fastly), about 700km away (which is pretty fine by me).

With the second one however, I get exit nodes in Germany and the Netherlands (pretty much exclusively Cloudflare), which can become an issue with region locked content. I had the issue with Prime Video last week not offering me a Tennis match for which they only bought rights for in France.

Obviously it's still early and they might tighten a bit the locations outside of the US, but overall it's definitely quick and well thought out.

Last thing, all your traffic from Safari (and presumably some other Apple services ? Still unclear) whether http or https will be routed through it. Only http traffic from 3rd party apps (Firefox, curl etc) is routed through the relays, which I think is a pretty sensible default.

Re: Apple's iCloud+ “VPN”

#86
post #10

I don’t really mind paying few bucks for privacy. But I think Apple in the process is gonna kill a lot VPN providers. While I don’t care right now I hope it doesn’t make Apple a monopoly.

It won’t harm VPN providers, I don’t think, for a few reasons. - VPNs are actually less private than iCloud+ double hop design, but could be much faster due to only having a single hop. - Unlike a VPN, you can’t choose the location of the server you exit at, and the exit server cannot be in a different nation. If you are in the US, iCloud+‘s relays are in the US. No circumventing georestrictions here. - Apple does no…

Additionally, this only works for port 80 traffic from apps. Other traffic is not run through this, so a VPN would still be useful in those scenarios.

Re: Apple's iCloud+ “VPN”

#87
> An big tradeoff for some is that the exit node is always chosen to be in the same geo location as the entry node. You can view this as a sop to the various on-line video providers

How could it be a "sop" to video services, isn't it exactly what they want, no more no less?

Re: Apple's iCloud+ “VPN”

#88
post #61

Earlier quoted context omitted.

If you want to give context, a link to the story would be nice: https://arstechnica.com/gadgets/2021/05/fake-dmca-takedown-n... Importantly, OpSec (the company doing this torrent-dmca-for-hire stuff) says the DMCA itself was spoofed > OpSec Security’s DCMA notice sending program was spoofed on Wednesday, May 26, 2021, by unknown parties across multiple streaming platforms.

Of course it was a false flag issue, it never made sense from the beginning.

In a world where white noise[1], birdsong[2] and someone playing Beethoven on the piano[3] get copyright strikes/takedown notices - I don't think someone getting a copyright notice for downloading Ubuntu is that far fetched.

[1] https://www.bbc.com/news/technology-42580523

[2] https://news.ycombinator.com/item?id=3637124

[3] https://news.ycombinator.com/item?id=27004577

Re: Apple's iCloud+ “VPN”

#89

Earlier quoted context omitted.

I've never understood how a VPN doesn't get too carried away to pull a MITM with some central cert

Because if you used a central cert, every device would have to whitelist that cert, and just clocking the lock icon in your browser would reveal it.

Many consumer VPNs install a client, and it would be trivial to ship a new trusted certificate with it.

Re: Apple's iCloud+ “VPN”

#90
Interesting. I thought I recalled talking about this on HN previously:

https://news.ycombinator.com/item?id=10355868

    _-__--- on Oct 8, 2015 | parent | favorite | on: Verizon revives "zombie cookie" device tracking on...

    Tor as an OS-level feature may not spark the best reaction. It's been given a bad name ("deep web," silk road, etc) in mass media and many people don't understand it enough to think of it as anything other than bad.
    I think that it'd be cool to have, but I don't think that Apple would ever implement it.

        jameshart on Oct 8, 2015 [–]

        Agree, it's phenomenally unlikely, but then again there is a part of me which could actually imagine Apple doing something like it. They wouldn't use Tor, of course, they'd build a proprietary equivalent, and then come out on a black stage to 'introduce Apple Undercover, a revolutionary enhancement to personal network privacy and security'.
Post reply on HN