24 ms·
Apple's iCloud+ “VPN”
- defaultname 5y agohttps://developer.apple.com/videos/play/wwdc2021/10096/ https://developer.apple.com/videos/play/wwdc2021/10096/ A pretty decent overview of the scope of the product. As mentioned in the video, the service also is involved if your app does HTTP over port 80, offering at least some marginal level of improvement. Otherwise it leaves your app traffic as is. As to Mail, the linked comment mentions that but I don't remember it being a part of the solution (nor does it seem feasible that it could be). Apple offers privacy improvements in mail, but not via the private relay.
- Jyaif 5y agoTo be exact, the video says that it includes all insecure HTTP traffic, so if you use HTTPS for now you are saved.
- floatingatoll 5y agohttps://developer.apple.com/wwdc21/10085 https://developer.apple.com/wwdc21/10085 Privacy Relay is also discussed in the privacy pillars video for a few minutes, starting at 24m30s.
- pilif 5y agoMy experience with this so far was... mixed. - This breaks DNS resolution for company-internal domains. - This routes all my traffic through CloudFlare or another CDN I might or might not trust (yes, the IP is hidden, but not the data) - it significantly slows down my internet access on my location. - it tends to turn itself on again without my intervention especially the last point is very problematic for me
- defaultname 5y agoTo use it you're clearly using early beta software. Clearly it isn't going to "turn itself on again". I turned it on and actually forgot I did. Performance is decent here. I mean of course it's going to be worse than native, but that's the compromise. As to trusting Cloudflare -- what do you mean? You understand your connection is still TLS end-to-end encrypted (presuming that's what we're talking about), right? I mean...presuming the site your talking to isn't using Cloudflare SSL. In no way does this reduce that security. If you're talking about HTTP, well everyone in between can already see that.
- marmaduke 5y ago> Clearly it isn't going to "turn itself on again" Why is it so clear? An iPhone hotspot turns itself off as soon as a device disconnects, with no option to leave it on, presumably for security or battery reasons.
- kerng 5y ago[Clearly not turn itself on.] Funny story, I was shocked and quite annoyed that an iPhone automatically turns on Wifi and stuff every day by itself - even if you turn it off... Still dont know how to actually turn it off
- permo-w 5y agoif you disable from quick menu, it turns back on. if you disable from settings, it doesn’t
- nucleardog 5y agoAnd when you do so it does flash a message along the lines of “Disconnecting nearby wifi until tomorrow”. Which makes it pretty clear it’s not a wifi kill switch but just a “my current connection is shit, let me use cellular” button.
- permo-w 5y agoyeah, but even so, it’s one of these occasions where an os symbol has been altered to change behaviour without the user’s consent or control it’s not quite as egregious, but it reminds me of how a lot of desktop apps now just minimise to tray rather than actually ending the process when you click the close button. discord is probably the worst offender for that, since it’s not (that I’m aware) a customisable behaviour
- ryankrage77 5y agoDiscords behaviour is customisable (at least on Windows). Settings > app settings - Window settings > close button - minimize to tray. Turning this off causes Discord to quit completely when clicking the red X in the top right.
- gjsman-1000 5y agoIt directs to an Apple server, then CloudFlare, so considering it’s basically a double VPN speed decreases have been reasonable. The fact they can see unencrypted HTTP data is a downside with all VPNs. At least you have the double hop going in your favor. As for turning on by itself, it’s annoying, but it is the very first developer-only preview so I’m not complaining yet.
- yunohn 5y ago> This breaks DNS resolution for company-internal domains. Is this not the case for any VPN or proxying service? In fact, it could even be a security flaw if your internal domains were accessible on external VPN style endpoints?
- gjsman-1000 5y agoAlso it’s developer preview 1. People like the OP who gripe about bugs on such an unfinished product are the reason why Apple doesn’t make those first builds available to anyone but their registered developers for the first month.
- pilif 5y agoI have of course reported the issues using the feedback app, but judging by previous experiences with other apple betas, I wouldn’t hold my hopes up of any of this getting fixed. There’s value in talking about issues early as it allows admins of corporate networks to make adjustments to their infrastructure (like introducing split dns rather than just have *.internal.example.com resolve to internal addresses) to be prepared for the eventual launch of this feature in September
- krageon 5y ago> Is this not the case for any VPN or proxying service? No, it's not. > In fact, it could even be a security flaw if your internal domains were accessible on external VPN style endpoints? It would be, but then this is not something that happens on a network configured in the way you describe.
- yunohn 5y agoI use NordVPN. It specifically has an opt-in setting to use locally discovered DNS in favor of their in-network DNS. This is crucial since out-of-network DNS can leak activity. I’m not sure what kind of network you believe I described, but would be useful to have a clearer explanation from you.
- defaultname 5y ago
- williamtwild 5y ago"yes, the IP is hidden, but not the data" Using TLS it certainly should be.
- stock_toaster 5y agoDoes it work like an https proxy (with CONNECT) or a socks proxy? Because if it is instead actually unwrapping the connection somehow (eg. mitm) then they would be able to see the content, and that seems like a huge no-go -- both for the users, AND for apple as I would think it would open them up to liability. note: they certainly would be able to see unencrypted http traffic regardless though.
- EveYoung 5y agoDoes Apple preserve the client source IP in the request (similar to Cloudflare's VPN) or will the server only see the IP of the exit node?
- dividuum 5y agoThe whole point of the service is to hide the client source IP.
- EveYoung 5y agoNot necessarily. I thought it was mainly about encrypting traffic in untrusted networks. Cloudflare already does it like this in their VPN service.
- dividuum 5y agoCorrect. I guess it wasn't really obvious from the linked mail. The introduction video at https://developer.apple.com/videos/play/wwdc2021/10096/ https://developer.apple.com/videos/play/wwdc2021/10096/ is a lot clearer.
- defaultname 5y agoNot sure why you said correct, as it's both. A big part of private relay -- I would say the most significant part -- is to allow people to talk to websites without giving up their personal IP (and from that pretty tight geolocation, and with fingerprinting a correlation with loads of other data they collect). Apple makes a big deal about it being about maintaining privacy, not just against snooping of traffic -- which is unlikely -- but against fingerprinting and targeting from the services and sites you connect to. And to answer the original guy, no Apple does not add any headers or details to tell the destination what your IP address is. They just see that they're talking to an exit node somewhere approximal of your general region.
- alam2000 5y ago
- xiphias2 5y ago> This breaks DNS resolution for company-internal domains. Why would it? The WWDC developer video clearly states that it’s only for public domains.
- ec109685 5y agoI believe the DNS requests are routed through their ingress proxy, so there's no chance to hit an internal split horizon DNS server.
- wolverine876 5y ago> the IP is hidden, but not the data Isn't the great majority of your traffic HTTPS?
- ezfe 5y ago> it tends to turn itself on again without my intervention This is listed as a known issue in the release notes
- Spooky23 5y agoI think this is great, if only as a way to kill the bullshit consumer VPN business, which sells snake oil.
- VWWHFSfQ 5y agowhat is bullshit about it
- KMnO4 5y agoHave you noticed all the ads say “Hackers can spy on your connection when you log into your bank at Starbucks.” That’s complete FUD. HTTPS completely avoids this issue (especially with a bank). Very few websites use HTTP now. While VPNs do have their valid use (preventing your ISP from spying, changing geolocation, and private networks for eg, work), most of the marketing is spreading misinformation.
- anonymouse008 5y agoI've never understood how a VPN doesn't get too carried away to pull a MITM with some central cert
- gjsman-1000 5y agoBecause if you used a central cert, every device would have to whitelist that cert, and just clocking the lock icon in your browser would reveal it.
- jen20 5y agoMany consumer VPNs install a client, and it would be trivial to ship a new trusted certificate with it.
- acdha 5y agoThis is true, but note that, for example, on iOS an application can't do that without prompting. Now, most people would probably hit “Approve” if one of their security products said it was necessary.
- danpalmer 5y agoProps to Apple for the design of this service. It doesn't hit all the privacy targets that long-time personal VPN users might be looking for, and it doesn't get into the game of trying to circumvent region locked content*, but otherwise it's likely to be a solid privacy improvement for almost all users in a careful and deliberate way. I use a VPN for other reasons (downloading Ubuntu ISOs mostly) but I'll probably turn this on and leave it running on all my devices because of how transparent it appears to be. I trust Apple's onion-routing design more than I trust my VPN provider not to log things. * I'm actually glad they don't try to get around region locks. I consume a lot of BBC content and live in the UK. I'm constantly struggling with my VPNs (with UK endpoints) being blocked because others outside the UK could be using them. It would be nice if the BBC didn't block like this, but UK residents do typically pay for the content whereas those outside the UK are unable to.
- loloquwowndueo 5y agoWhy do you use a VPN to download free and publicly available iso images? (Ubuntu). Just curious. Do you download directly from a mirror or use BitTorrent for this? (If the latter I think I kind of understand the rationale for the VPN)
- syntaxstic 5y agoProbably because of this - https://arstechnica.com/gadgets/2021/05/fake-dmca-takedown-notice-targeted-ubuntu-downloaders-yesterday/ https://arstechnica.com/gadgets/2021/05/fake-dmca-takedown-n...
- xuki 5y agolinux iso is code for pirated content
- Jiocus 5y agoAnd here I was, still thinking Linux was "an illegal hacker operation system, invented by a Soviet computer hacker named Linyos Torovoltos, before the Russians lost the Cold War".
- maxpert 5y agoI don’t really mind paying few bucks for privacy. But I think Apple in the process is gonna kill a lot VPN providers. While I don’t care right now I hope it doesn’t make Apple a monopoly.
- gjsman-1000 5y agoIt won’t harm VPN providers, I don’t think, for a few reasons. - VPNs are actually less private than iCloud+ double hop design, but could be much faster due to only having a single hop. - Unlike a VPN, you can’t choose the location of the server you exit at, and the exit server cannot be in a different nation. If you are in the US, iCloud+‘s relays are in the US. No circumventing georestrictions here. - Apple does not market their service as a VPN and never said it is one. For most customers, they don’t know this is a VPN substitute because it doesn’t call itself one. So if you have “VPN” in your mind, this isn’t something you think of as an option.
- CubsFan1060 5y agoAdditionally, this only works for port 80 traffic from apps. Other traffic is not run through this, so a VPN would still be useful in those scenarios.
- mariojv 5y agoTo clarify: port 80 and 443 (TLS connections), right? Or is TLS traffic only routed through the private relay in Safari, not other apps?
- gjsman-1000 5y agoAll traffic in Safari goes through relay. However, in 3rd party apps, all traffic over 80 goes through relay and traffic over 443 is exempt. There is going to be an API though for if you want your 3rd party app’s 443 to go over the relay if you desire.
- 5y ago
- Operyl 5y agoSo far the two different third parties I’ve seen are Cloudflare and Akamai. Has worked relatively well here, besides the fact that some bug has made it so it turns back on randomly, which isn’t a big deal.
- Brajeshwar 5y agoDoes this compare to NextDNS[1]. I moved from Pi Hole[2] to NextDNS and I'm happy with it. 1. https://nextdns.io https://nextdns.io 2. https://pi-hole.net https://pi-hole.net
- marceldegraaf 5y agoNo. NextDNS and Pi-Hole serve DNS requests and are mainly used for ad blocking and content restrictions on your network. They don't tunnel or redirect your actual internet traffic the way a VPN does.
- lucasverra 5y agoThis is the correct observation. - A nextDNS user having that same question answered by official team
- yegor 5y agoShameless self-plug: NextDNS does not, but ControlD does do that - https://controld.com https://controld.com
- corobo 5y agoYour service seems to support the same features as your provider -- are you 1:1 reselling or do you add stuff?
- yegor 5y agoNot sure what you mean by that. The features are not the same, see https://kb.controld.com/compare https://kb.controld.com/compare
- corobo 5y agoIt says on your page you use Windscribe, they have this page https://windscribe.com/features/robert https://windscribe.com/features/robert Sorry, purely a curiosity I didn't mean to come across as calling you out
- neximo64 5y agoIt just re routes traffic to your nearest Fastly pop and mixes traffic up with everyone else nearby.
- judge2020 5y agoIt specifically goes through an Apple proxy first and fastly (or other partners like Akamai and Cloudflare) don't see the incoming IP address.
- bitcurious 5y agoCorrect me if I’m wrong, but as I understand it a two-hop onion network is still trivially breakable with (two) warrants, especially since both Apple and Cloudflare/etc., are US companies. Which would make it a VPN in the duck-type sense.
- gjsman-1000 5y agoIt depends, whether they do no logs. There are many VPN providers in the US which don’t have logs, so that if they are subpoenaed, they have nothing to give. The beauty of Apple’s double hop is that if one partner was hacked, secretly wiretapped, or had lied about not keeping logs, your connection would still be private. But, that assumes that nobody on this network is keeping logs. If they are, then it could be theoretically possible to piece them together. However considering Apple’s marketing with privacy, it would be interesting to see whether they keep logs on each endpoint or not.
- nojito 5y agoWhat would the logs contain? I believe everything is encrypted on device before being sent to Apple.
- TedDoesntTalk 5y agoTimestamp, source and destination ip addresses, username. In the case of the exit node, url.
- gjsman-1000 5y agoWe don’t know that Apple keeps logs. These are things they could theoretically keep, but we don’t know if they store them or not.
- LegitShady 5y agoIf they don’t clearly state ‘no logs’ then its unlikely they are not logging. My bet is they’re logging everything, because they have no advantage in not logging.
- gjsman-1000 5y agoSo far, partners of Apple I’ve seen the service forwarding to are CloudFlare, Akamai, and Fastly. There may be more but those are the ones I’ve seen and heard.
- ehsankia 5y agoWait a second, didn't the Fastly breakage happen the day after WWDC? What are the chances that the one client was Apple and their config was for this service :)
- headmelted 5y agoI've been trying to point this out to people but YouTube personalities have a louder voice than anyone else so you end up with bad information. Props to Apple for offering an (albeit low entropy) onion router on their own infrastructure. I can't imagine this is going to win them any friends in government circles but it's definitely a step in the right direction. I'd also really like to see Apple come clean about the iCloud backup encryption debacle. A lot of people are trusting it to be something it's not and it should really be clarified on-device what it is and is not before opting in.
- ______- 5y ago> I'd also really like to see Apple come clean about the iCloud backup encryption debacle Are you referring to this article?: https://www.reuters.com/article/us-apple-fbi-icloud-exclusive/exclusive-apple-dropped-plan-for-encrypting-backups-after-fbi-complained-sources-idUSKBN1ZK1CT https://www.reuters.com/article/us-apple-fbi-icloud-exclusiv... It's why I only use my Apple ID for grabbing apps from the app store. I have disabled all the `cloud storage` features of iCloud. iCloud is a privacy nightmare.
- gjsman-1000 5y agoBy that logic though, Google Drive, OneDrive, AmazonS3, they are all privacy nightmares. And you might agree, but Apple is hardly alone. And like the article says, they didn’t want to poke the bear anymore. Of course the FBI has congressional friends. It is possible that Apple saw the risk of it backfiring and making things worse as too great.
- modeless 5y agoGoogle does end-to-end encryption of Android backups. And Apple knows how to do it too, but they intentionally restricted their implementation to only cover backups of Keychain passwords and a few other things, apparently because they don't have the courage to stand up to the FBI, according to Reuters. Strange considering their public stance against the FBI in the San Bernardino case and on privacy issues in general. Especially since iCloud backup totally defeats the highly touted end-to-end encryption in iMessage.
- bhaavan 5y agoMy guess is one of the major reasons for having the exit nodes in the same geo location as entry nodes is to have continuous operations in China. Without this constraint, they would have allowed chinese consumers to access the free web, which would ban them instantaneously. I don't think Apple cares as much about video content providers, though.
- gjsman-1000 5y agoThat’s not the reason. In China, Myanmar, Egypt, and several other countries this service will not be available at all. Those customers will just have regular old iCloud. A more likely reason is that video streaming services with georestrictions like Netflix, Amazon, or BBC would have lost their minds.
- whynotminot 5y agoI don’t think this service is being offered in China, period.
- simias 5y agoIt wouldn't have been too hard to just implement this feature for chinese customers if that was the only driver. But I agree that making the exit node in the same country probably goes beyond video content providers, it avoids all sorts of potential legal, diplomatic and practical issues.
- lxgr 5y ago> I don't think Apple cares as much about video content providers, though. Not being able to watch Netflix, Amazon Video etc. in Safari seems like something Apple would in fact care about.
- krferriter 5y agoNot if it gets them banned in those countries.
- Mindwipe 5y agoHBO is blocking Private Relay regardless.
- bhaavan 5y agoDoes this mean that all DDoS mitigation techniques need to exist before the exit node of this traffic? Which in turn mean, that everyone needs to outsource their DDoS mitigation to Apple. Also the corollary would be, that anyone who is able to bypass the protection mechanisms Apple has in place to control DDoS, can use it to DDoS a service like Google, Microsoft and get the entire service banned for all iCloud+ users. Right?
- gjsman-1000 5y agoApple has sort of addressed this with only having it work with Safari and other apps that implement the API, rather than system-wide as something you can connect to. It’s probably going to take a lot of reverse engineering before hackers figure out the API and how to get third party devices to connect and authenticate, if at all. If you can’t get third party devices to connect, you are missing the first D in DDOS.
- mariojv 5y agoThere is also almost certainly an authentication mechanism in place, even if you were to reverse engineer the API. You'd need a bunch of paid iCloud accounts to have a DDoS be at all feasible with this service. Additionally, Cloudflare themselves, one of Apple's third party partners, offer DDoS protection services. Because they see all the exit traffic, they'd be able to detect the DDoS and block it.
- Ensorceled 5y agoThat's why this concern seemed weird to me; the exit nodes ARE the DDoS protection services. I can't see Cloudflare putting themselves in the position of needed to protect their clients from themselves ...
- gjsman-1000 5y agoOtherwise, by the poster’s logic, why hasn’t CloudFlare been a DDoS vector?
- njacobs5074 5y agoDoes anyone have pointers to info/articles about the countries that are on the "no VPN" capability list? Some of them make sense to me, i.e. China which has a long history of censoring their citizens. But in particular, I'm trying to find out why South Africa is on that list seeing as I live there. Edit: In [1], Apple is quoted as saying, "We respect national laws wherever we operate" but did not elaborate further. [1] https://mybroadband.co.za/news/internet/400893-apple-will-not-launch-feature-to-hide-online-identity-in-south-africa-or-china.html https://mybroadband.co.za/news/internet/400893-apple-will-no...
- gjsman-1000 5y agoAnother reason could also be that the servers operate in the same nation that you are from. If Apple or no suitable partner has servers in South Africa, that could also be a reason. And, of course it could be politics. The South African government, I wouldn’t know, but it could be possible that they wouldn’t let tech companies from the US build servers in their nation.
- jammmety 5y agoApple said it also will not offer "private relay" in Belarus, Colombia, Egypt, Kazakhstan, Saudi Arabia, South Africa, Turkmenistan, Uganda and the Philippines. https://www.reuters.com/world/china/apples-new-private-relay-feature-will-not-be-available-china-2021-06-07/ https://www.reuters.com/world/china/apples-new-private-relay...
- tyingq 5y agoI'm curious how they are securing the feature that keeps you in the same region. Since that feature encourages content providers to not block, it would be a desirable target to work around.
- permo-w 5y agoyeah I was thinking about how difficult it might be to spoof your location prior to the Apple Router, and have it come out the other side nicely laundered
- Grustaf 5y ago> An big tradeoff for some is that the exit node is always chosen to be in the same geo location as the entry node. You can view this as a sop to the various on-line video providers How could it be a "sop" to video services, isn't it exactly what they want, no more no less?
- pwinnski 5y agoWhat video services really want is for each user to be identifiable by IP address. This doesn't quite give them that, but it does region-lock them.
- Grustaf 5y agoWhy do they want that though? They can still remember you, right, since you’re logged in?
- pwinnski 5y agoNot all media sites require one to be logged in. However, there are many reasons why a video service might want each user to be individually identifiable by IP. - Many media items are contractually region-locked - The same user from too many simultaneous IPs might mean shared credentials, a perceived loss of revenue - The same user from geographically disparate IPs might also mean shared credentials, even if not simultaneous. I'm sure there are more.
- Grustaf 5y agoWe were talking about video streaming services though, they usually require a log in, and in any case they’ll have a cookie so they know who you are. Region locking is fine right, that’s exactly what Cloud+ provides, same thing with your third point. As to the second one, I don’t know how big the simulated regions are but i suppose it will look like different houses at least. I’m sure netflix will think of something though.
- 5y ago
- jameshart 5y agoInteresting. I thought I recalled talking about this on HN previously: https://news.ycombinator.com/item?id=10355868 https://news.ycombinator.com/item?id=10355868 _-__--- on Oct 8, 2015 | parent | favorite | on: Verizon revives "zombie cookie" device tracking on... Tor as an OS-level feature may not spark the best reaction. It's been given a bad name ("deep web," silk road, etc) in mass media and many people don't understand it enough to think of it as anything other than bad. I think that it'd be cool to have, but I don't think that Apple would ever implement it. jameshart on Oct 8, 2015 [–] Agree, it's phenomenally unlikely, but then again there is a part of me which could actually imagine Apple doing something like it. They wouldn't use Tor, of course, they'd build a proprietary equivalent, and then come out on a black stage to 'introduce Apple Undercover, a revolutionary enhancement to personal network privacy and security'.
- matt-attack 5y agoWow props for quite a prediction. You definitely deserve some recognition for that one.
- toxik 5y agoAn even more impressive prediction in 2015, a time when Apple was not positioned as some type of savior of user privacy.
- jameshart 5y agoI’m not so sure. If you read back up that thread, the thought that triggered it was from qzervaas: Apple's already shown they don't like this behaviour with their randomised MAC addresses in iOS 8+. And elsewhere in the thread people called out the fact apple had already introduced support for ad blocking. So Apple’s privacy-positive posture was already in the air. I think there is a sense in which privacy was already a differentiator for Apple in iOS (as contrasted with Google’s motives in android in particular of course) - so this did feel like a not completely implausible way they could go to double down on that differentiator.
- 5y ago
- whiteboardr 5y agoActually surprised how this only shows up on HN now. Expected this to take the top spot right after the keynote.
- basisword 5y agoI'm currently running the beta and this doesn't work on my router (provided by one of the largest ISP's in the UK). When I go to settings it displays a message that the router is unsupported by private relay. Hopefully it's something they can fix before launch but if not I wonder how many other routers are unsupported?
- nuker 5y agoI hope it'll not bring captcha hell, as Google does for using VPNs. Twitter is simply blocking my VPN provider. eBay sends scary email every time I login.
- NorwegianDude 5y agoYou can disable the captcha by paying the site a 30 % cut of the purchase price of the Apple device and the subscription./s
- acdha 5y agoThis will come down to reputation. VPN providers which don't do a good job managing abuse from their networks get blocked a lot more readily than better run networks, and in this case they'd be able to make pretty strong assurances that they can link activity to a single user.
- xnx 5y agoBecause Apple is so large and well respected, issues will be blamed on whoever is putting up the captcha, not Apple.
- res0nat0r 5y agoIs this like Cloudflare Warp then? https://1.1.1.1/ https://1.1.1.1/
- alpb 5y agothe beta seems to be using Warp actually.
- thih9 5y agoWhat's are the differences between a VPN and an onion router approach? Could anyone explain or link to an article?
- thehappypm 5y agoA VPN is a middleman that accepts your traffic and forwards it, hiding who you are to servers. An onion router is like a VPN but instead of 1 middleman, the middleman is a whole random network of middlemen, and those middlemen also hand off to other middlemen.
- mikemyoung1 5y agoThis is a great summary, thanks
- permo-w 5y agoWhat I don’t get is why people don’t regard Onion Routers as a form of VPN. It’s still uses a virtual private network, just more of them. a network of networks. Surely TOR is a type of VPN? Maybe there’s some details I’m missing. I’m no expert
- detaro 5y agoReally mostly convention. Yes you could label it that way, but people consider it to be enough of it's own thing to not do so. (+ there is some value in not conflating the two because they do have different threat models etc and users should treat them differently too)
- pdimitar 5y ago> All in all, a very Apple approach: They deny themselves any knowledge of a customer's DNS queries and Web traffic, so if served with a subpoena they have very little to respond with. Maybe I am missing something but I view this is a rather genius move. They have plausible deniability + actually introduce some protection for their users. Not sure how to read the original post though. Is it praising Apple? Is it mocking them? We don't have to be polar of course, I am just wondering.
- yreg 5y ago>In one move, Apple has taken onion routing from a specialized tool for hackers to something that will be in daily use on billions of devices. Sounds like praise to me.
- smoldesu 5y agoApple has claimed this shtick several times (as well as many other VPN companies), but it actually requires a pretty intricate software setup to pull off. The best VPN services won't even have hard drives to store logs in: that way, even individuals with a court-issued warrant can't get your info. I'd imagine there's sufficient pressure on Apple from PRISM and other governments to keep some level of rudimentary logs.
- heavyset_go 5y ago> The best VPN services won't even have hard drives to store logs in: that way, even individuals with a court-issued warrant can't get your info Courts can compel them to log this information, so all claims about not keeping logs are just theater. The second they're ordered to by a court in the US, they will.
- pwinnski 5y agoIANAL! The legal theory is that US courts can stop you from taking actions, but cannot compel you to take actions. So they can stop you from deleting existing logs, but they cannot require you to collect logs you aren't already collecting. I have no idea how well this idea has been tested in court, but that's the theory on which providers who don't even have hard drives are relying.
- ROARosen 5y ago> or you can view it as a concession to reality: If Apple didn't do this, the video providers would block their exit nodes, as they do with any VPN provider that gets large enough for them to notice. I seriously doubt any reasonable video streaming service would cut off such a huge chunk of their user base just because they are using an iPhone.
- grantcox 5y agoI expect they would just show a message "to view our content, download our app - Safari is not supported"
- spideymans 5y agoBut when you download the app: “please use safari to pay for subscriptions” :)
- soheil 5y agoI think the title should be: Apple's iCloud+ "TOR-esque"
- permo-w 5y agoApple Routing
- amq 5y agoPotentially, this provides troves of data to the exit node operators (CloudFlare, Fastly, Akamai, ...). Yes, it's the same with all VPNs and ISPs, but I think users should be made aware that now instead of your ISP analyzing the data, an even bigger and more capable corporation is. And if Apple is controlling the entire onion chain (I would be surprised if they weren't), they have even more data available, mainly with a corresponding IP of yours. In the net sum, you are hiding the transmitted data from your ISP and the IP from the sites you visit, but you are handing over all this information to a centralized place - Apple and exit node providers. Potentially, they can use the information to connect the dots more easily and fully than any ISP or site ever could.
- aeontech 5y agoThis is not quite correct though - entry side and exit side are specifically and intentionally not operated by same entities. So Apple knows who you are but doesn’t know what you’re looking for or where you’re going - your traffic is passed straight through to the exit layer. Exit layer operator knows what you’re looking for and where you are going but doesn’t know who you are or where you’re coming from.
- amq 5y agoThe exit node operator can extract useful information even without knowing your IP, especially until Encrypted Client Hello (ECH) is ubiquitous.
- soheil 5y agoThis could also mean now major companies security teams have even more incentive to track onion routing users and to check their pattern of traffic to ensure they are legitimate Apple users and not some tor user instead of just blanket-blocking every tor user. This could make tor less secure in the long term if more open source/closed source projects (NSA notwithstanding) are started and dedicated to analyzing and delayering tor traffic.
- beermonster 5y agoThis is interesting. I think overall I approve as it benefits people by default. It does mean you now have to trust Apple since that's the first hop. However you're already doing this when you spin up your AWS Lightsail Wireguard instance, say. AWS can see ingress and egress traffic and so you just need AWS to not be part of your threat model. Same here. Though I dont see this as too much of a problem since it applies to devices and services where you've already made this explicit choice. The app limitation thing is a shame and hopefully there will be an API at a later date. The exit node choice based on exit-locality kinda makes me think Apple either: - Want to restrict this service being (ab)used for geolocked content (Netflix etc) - Want to speed up the service by providing the closest exit node (Performance) Of course given all the FBI cases, you also have to consider other possibilties for the creation of this service.
- joshstrange 5y agoCraig Federighi, on the most recent episode of The Talk Show with John Gruber [0] about 47 minutes into the episode, talked about this and I think both your assumptions are correct. For the first one I'm sure they didn't want to deal with the complexity of picking an exit location nor did they want to be a party to getting around geo-locking and so this gave them the best of both worlds, no UI and no issue with geo-blocking. For the second point I think that is also the reason as well as it's often helpful if a website knows your general location (For relevant recommendations, CDN routing, etc) but we'd prefer if the website didn't know exactly where we are coming from (IP-wise) which can be used for tracking/ads. [0] https://daringfireball.net/thetalkshow/2021/06/11/ep-316 https://daringfireball.net/thetalkshow/2021/06/11/ep-316
- nuker 5y ago> your AWS Lightsail Wireguard instance This will still be your fixed IP, not adding much to your privacy.
- freakynit 5y agoApple in a few months to VPN's: give us 30% share if you want to serve as exit node to Apple iCloud+ VPN. Two part strategy as always: 1. Get yourself in-between of an already functioning system, by force if needed 2. Abuse your market position to gain millions of users, make it super easy to use this as default, and make existing players compete for their 70% share of what they already were earning. - Enjoy new billions on top of existing trillions
- permo-w 5y agoThis goes against my general distrust of giant corporations, but I trust Apple a lot more than I do the extremely shady VPN companies infesting the internet
- modernerd 5y ago> It's not clear if the API will be public for other browsers or applications to use. Apple has already confirmed that other app traffic will go through iCloud Private Relay “no matter what networking API you're using”, with some exemptions: > Not all networking done by your app occurs over the public internet, so there are several categories of traffic that are not affected by Private Relay. > Any connections your app makes over the local network or to private domain names will be unaffected. > Similarly, if your app provides a network extension to add VPN or app-proxying capabilities, your extension won't use Private Relay and neither will app traffic that uses your extension. > Traffic that uses a proxy is also exempt. From https://developer.apple.com/videos/play/wwdc2021/10096/ https://developer.apple.com/videos/play/wwdc2021/10096/.
- ls612 5y agoSo will this mean if I’m using Cloudflare 1.1.1.1 that I won’t get the iCloud private relay since they implement DoH as a VPN in iOS?
- firloop 5y agoNot super familiar with 1.1.1.1, but I use NextDNS and it's no longer implemented as a VPN – they use the native iOS encrypted DNS feature. I wonder how iCloud Private Relay works with that.
- richbradshaw 5y agoI have the beta and it currently doesn’t appear to work.
- jedisct1 5y agoDNSCloak still works with Private Cloud.
- fossuser 5y agoI was curious how they would actually implement this, if it's actually onion routing that's pretty cool. I wonder what advantage this gives over using NextDNS?
- peddling-brink 5y agoNextDNS is encrypted DNS. DNS is like using your neighbor across the street for all your directions, except you have to shout. "YO, WHERE'S THE GROCERY STORE AGAIN? ALSO AFTER THAT I'M VISITING THE STRIP CLUB, AGAIN." NextDNS turns that shout into a signal/telegram message, to a different neighbor. There's still a neighbor involved, but at least the neighborhood doesn't get to hear anymore. If they include DNS in the onion routing scheme, it turns into a game of telephone, where the neighbor doesn't know you anymore. Your traffic, and directions become more private.
- ComodoHacker 5y ago>why don't VPN providers implement a onion router ProtonVPN does.
- vmception 5y agoApple should release a token for the routing nodes to stake and get slashed for poor quality connectivity
- xnx 5y agoThis is great. I hope this spurs Google to make their VPN (https://one.google.com/about/vpn https://one.google.com/about/vpn) more widely available. A few audiences they could expand it to: any ChromeOS device, any Pixel phone, any Android phone, any mobile Chrome user, any Chrome user.
- crossroadsguy 5y agoThey’ll release that as a Chrome app.
- irae 5y agoA lot of people think of VPN as escaping Google mega-giga-tracking schemes. So growing their own would be doomed to fail.
- unknown_error 5y agoBecause Google is definitely the most trustworthy company when it comes to data governance and respecting user privacy. No chance they'd use it to put you into a FLoC-type thing, benefiting their own advertising business while shutting out competitors. Google, the engineering company, always plays second fiddle to Google, the advertising company.
- smoldesu 5y agoTo be fair, Apple's software has always played second fiddle to their hardware. I trust Apple with a VPN about as much as I do Google.
- unknown_error 5y agoThey don't have an inherent conflict of interest the way Google does (advertising vs privacy in the same company). The App Store makes them plenty of money, and if anything, enhancing user "privacy" by limiting access of other adtech vendors only strengthens their walled garden and increases revenue. Even something like Fortnite or the Epic store... as long as they can dictate their entire stack from hardware to software (very much unlike Google + OEMs + third-party stores), they'll have a huge advantage over Google in terms of being able to limit your personal info being used by third parties, while still retaining it for their own use.
- shp0ngle 5y agoI’m literally using VPNs just to get around geo-blocking. Still, this is interesting.
- vngzs 5y agoFrom Apple's statement[0]: > The first assigns the user an anonymous IP address that maps to their region but not their actual location. The second decrypts the web address they want to visit and forwards them to their destination. This separation of information protects the user’s privacy because no single entity can identify both who a user is and which sites they visit. Apple is not saying nobody can deanonymize you - they are being very careful to only state that no single entity can deanonymize you. Hence you should still assume this is not a good protection against any entity with subpoena power, or the ability to compel the cooperation of Apple and their 3rd-party egress relay providers. [0]: https://9to5mac.com/2021/06/07/apple-icloud-private-relay-feature-china/ https://9to5mac.com/2021/06/07/apple-icloud-private-relay-fe...
- allochthon 5y agoThat makes me wonder whether an analysis could be done over a long period of time to determine where in the region the user isn't, and thereby narrow down where the user is.
- bjtitus 5y agoI'm curious what the details around the anonymous IP address assignment are. Protecting copyright holders seems to be the point of the IP assignment to not break content restrictions. Are they able to assign a set for an entire country? If so, that doesn't narrow it down all that much. However, major league sports blackouts wouldn't work, so is it by city?
- ezfe 5y agoPresumably they're not actually blocking the current location - just not using it to inform their selection.
- Siira 5y agoThey might just use randomization, which is only statistically not where the user is. It’s the intuitive approach, and easy.
- GoofballJones 5y agoI liked this little article as it reminds me of when the Web was still young and mainly just text with no formatting or graphics yet. Takes me right back to 1991!
- steveharman 5y ago"...why don't VPN providers implement a onion router.." Pretty sure Nord already does. Probably others.
- kibleopard 5y ago> The routing uses two hops; Apple provides the first, and "independent third parties" (not yet specified) provide the second. This isn’t true though, they have specified who the independent third parties will be: CloudFlare Warp, Fastly, and Akamai. See here: https://www.barrons.com/articles/fastly-stock-outage-think-apple-51623269551 https://www.barrons.com/articles/fastly-stock-outage-think-a...
- a-dub 5y agosounds awesome! tor as a system service with a professionally managed network. beyond making ad tracking harder, i wonder what sorts of new application spaces this may open up. i can already think of one! (and no, it's not some shady illegitimate/illegal bs)
- gordon_freeman 5y agoDoes anybody know, how iCloud+ VPN would compare with Cloudflare WARP in terms of better privacy protection.
- dustyharddrive 5y agoDon’t forget that neither is a pure VPN, though that’s not always a bad thing — Private Relay is better than a VPN because onion routing means “no one party”[1] can correlate your connections and identity. However WARP, being more like a VPN, requires you to trust Cloudflare to not log DNS lookups / the servers you connect to and associate that with your origin IP. Why do I hesitate to call WARP a real VPN? It reveals your actual IP address to websites you visit via X-Forwarded-For. [2] Also I think the fact that iCloud Private Relay will be built-in makes it more private than WARP — more users’ traffic will come out of each node. [1]: Obviously this is imperfect because the Apple (which knows your IP) and third-party (which knows the network traffic) nodes will likely be in the same jurisdiction as each other, subject to the same laws, as mentioned by other commenters. [2]: https://twitter.com/eastdakota/status/1176987146177196032 https://twitter.com/eastdakota/status/1176987146177196032 edit: typo, line break, clarified Private Relay concept
- SavantIdiot 5y agoWhere are the Apple VPN exit points? I wish there was a non-dubious VPN service with an exit in a non GDPR country, or at least one with internet privacy. I rolled a strongswan VPN through AWS EC2 but all the egress points are in countries that can be exposed.
- theonlybutlet 5y agoI'm curious how does the second hop work? are the third parties contracted by Apple to provide the service? What's in it for them?
- pram 5y agoI presume the answer is “money”
- theonlybutlet 5y agoYes but how?
- pram 5y agoBy paying them for the services utilized. You think Cloudflare and Akamai are doing it for free? Really?
- theonlybutlet 5y agoNo, I do not. You didn't read my original comment, I asked if apple selecting them and are they paying them.
- o8r3oFTZPE 5y agoHere is a simple question: Why is there only one "Tor". Why haven't there been more onion routing projects. (Maybe there have been and I am just not aware.) Perhaps the same reason(s) we never saw widespread adoption of remote proxies, despite their usefulness in many situations. Although in some respects onion routing seems quite an improvement over "simple" proxies.
- gabmiral 5y agoIf I recall correctly, I2P uses some sort of onion routing.
- marshray 5y agoThe more nodes you have participating the more secure an onion system tends to be. Since the Tor network can carry most kinds of traffic, the motivation to avoid a fork is strong.
- wolverine876 5y ago> The more nodes you have participating the more secure an onion system tends to be. Tor isn't very large as it is, and (I would guess) it's the largest. If another onion routing network didn't grow the audience, you would have two even smaller networks. > the Tor network can carry most kinds of traffic Isn't Tor limited to routing TCP? That would rule out QUIC, for example.
- o8r3oFTZPE 5y agoMaybe could chain the networks together. An exit node on one onion routing network might automatically send traffic to another onion routing network.
- acdha 5y agoYou need lots of nodes to make it secure, performance is low even by VPN standards, and it’s dangerous to run a node. Unless you have some likely way to change one of those it’s going to be really hard to get volunteers – and payment is worse because most customers will expect better service.
- dcow 5y agoIsn’t iCloud+ “VPN” (Private Relay) just white-labled Cloudflare Warp? Is “onion router” a new development or is Jerry overzealously inferring there’s more than meets the eye here?
- deleted 5y ago[deleted]
- LonesomeGeorge 5y agoDoes it mean iOS devices in China can go across GFW with Apple's VPN?
- weikju 5y ago1) the egress would still be in China 2) regardless of #1, iCloud Relay will not be available in China (as well as other countries)
- grouphugs 5y agono
- crazygringo 5y agoSo I seem to be completely missing... what is this actually for? What's the value proposition for the average consumer? It doesn't replace a VPN into your company's or university's network (for accessing private resources). It's not for accessing streaming TV in different regions. HTTPS is already secure. In theory it seems like it could be used for illegal torrent downloading, but given that Apple is in the media business, something tells me they'll do their best to block torrenting. And for things like videoconferencing, it will almost certainly degrade performance to a degree (latency, bandwidth, or both). The only thing left seems to be your ISP and/or coffee shop WiFi being able to track what IP addresses you communicate with. Instead, they don't, but Apple does. Is that really a benefit, or a benefit any average consumer cares about?
- ezfe 5y agoIt provides VPN-style protection against your ISP and does also protect you against IP address tracking. This means you and people in your household have one fewer data point that links you.
- busymom0 5y agoNot being able to circumvent region locked content makes it only 50% useful for me unfortunately. I often end up using Epic browser which has a built in proxy from other countries to watch region locked content. I would recommend it for non-confidential stuff.