Live data from Hacker News

Apple's iCloud+ “VPN”

metzdowd.com

1–10 of 413 posts

Re: Apple's iCloud+ “VPN”

#2
https://developer.apple.com/videos/play/wwdc2021/10096/

A pretty decent overview of the scope of the product.

As mentioned in the video, the service also is involved if your app does HTTP over port 80, offering at least some marginal level of improvement. Otherwise it leaves your app traffic as is.

As to Mail, the linked comment mentions that but I don't remember it being a part of the solution (nor does it seem feasible that it could be). Apple offers privacy improvements in mail, but not via the private relay.

Re: Apple's iCloud+ “VPN”

#3
My experience with this so far was... mixed.

- This breaks DNS resolution for company-internal domains.

- This routes all my traffic through CloudFlare or another CDN I might or might not trust (yes, the IP is hidden, but not the data)

- it significantly slows down my internet access on my location.

- it tends to turn itself on again without my intervention

especially the last point is very problematic for me

Re: Apple's iCloud+ “VPN”

#4
post #3

My experience with this so far was... mixed. - This breaks DNS resolution for company-internal domains. - This routes all my traffic through CloudFlare or another CDN I might or might not trust (yes, the IP is hidden, but not the data) - it significantly slows down my internet access on my location. - it tends to turn itself on again without my intervention especially the last point is very problematic for me

To use it you're clearly using early beta software. Clearly it isn't going to "turn itself on again".

I turned it on and actually forgot I did. Performance is decent here. I mean of course it's going to be worse than native, but that's the compromise.

As to trusting Cloudflare -- what do you mean? You understand your connection is still TLS end-to-end encrypted (presuming that's what we're talking about), right? I mean...presuming the site your talking to isn't using Cloudflare SSL. In no way does this reduce that security. If you're talking about HTTP, well everyone in between can already see that.

Re: Apple's iCloud+ “VPN”

#5
post #3

My experience with this so far was... mixed. - This breaks DNS resolution for company-internal domains. - This routes all my traffic through CloudFlare or another CDN I might or might not trust (yes, the IP is hidden, but not the data) - it significantly slows down my internet access on my location. - it tends to turn itself on again without my intervention especially the last point is very problematic for me

It directs to an Apple server, then CloudFlare, so considering it’s basically a double VPN speed decreases have been reasonable.

The fact they can see unencrypted HTTP data is a downside with all VPNs. At least you have the double hop going in your favor.

As for turning on by itself, it’s annoying, but it is the very first developer-only preview so I’m not complaining yet.

Re: Apple's iCloud+ “VPN”

#6
post #3

My experience with this so far was... mixed. - This breaks DNS resolution for company-internal domains. - This routes all my traffic through CloudFlare or another CDN I might or might not trust (yes, the IP is hidden, but not the data) - it significantly slows down my internet access on my location. - it tends to turn itself on again without my intervention especially the last point is very problematic for me

> This breaks DNS resolution for company-internal domains.

Is this not the case for any VPN or proxying service? In fact, it could even be a security flaw if your internal domains were accessible on external VPN style endpoints?

Re: Apple's iCloud+ “VPN”

#8
post #6
post #3

My experience with this so far was... mixed. - This breaks DNS resolution for company-internal domains. - This routes all my traffic through CloudFlare or another CDN I might or might not trust (yes, the IP is hidden, but not the data) - it significantly slows down my internet access on my location. - it tends to turn itself on again without my intervention especially the last point is very problematic for me

> This breaks DNS resolution for company-internal domains. Is this not the case for any VPN or proxying service? In fact, it could even be a security flaw if your internal domains were accessible on external VPN style endpoints?

Also it’s developer preview 1. People like the OP who gripe about bugs on such an unfinished product are the reason why Apple doesn’t make those first builds available to anyone but their registered developers for the first month.

Re: Apple's iCloud+ “VPN”

#9
Props to Apple for the design of this service. It doesn't hit all the privacy targets that long-time personal VPN users might be looking for, and it doesn't get into the game of trying to circumvent region locked content*, but otherwise it's likely to be a solid privacy improvement for almost all users in a careful and deliberate way.

I use a VPN for other reasons (downloading Ubuntu ISOs mostly) but I'll probably turn this on and leave it running on all my devices because of how transparent it appears to be. I trust Apple's onion-routing design more than I trust my VPN provider not to log things.

* I'm actually glad they don't try to get around region locks. I consume a lot of BBC content and live in the UK. I'm constantly struggling with my VPNs (with UK endpoints) being blocked because others outside the UK could be using them. It would be nice if the BBC didn't block like this, but UK residents do typically pay for the content whereas those outside the UK are unable to.

Re: Apple's iCloud+ “VPN”

#10
I don’t really mind paying few bucks for privacy. But I think Apple in the process is gonna kill a lot VPN providers. While I don’t care right now I hope it doesn’t make Apple a monopoly.
Post reply on HN