10 ms·
VPNs on iOS are a scam
- cosmin800 4y agoModern oses/devices are so complex and out of specs nowdays that my only solution is to use a vpned gateway, router, access point.
- deleted 4y ago[deleted]
- mmastrac 4y agoTitle should be: "VPNs on iOS are a scam", but a less sensationalist title might be: "VPNs on iOS leak traffic".
- deleted 4y ago[deleted]
- MikePlacid 4y agoTrue. I’ve used VPN on iOS to play a second account on some online game. Worked like a charm, so it was definitely NOT a scam. If I wanted to hide my activity / identity from more serious people - I would never use iOS in the first place. But it’s good to know that there are leaks, anyway. PS. And I guess all VPNs use the same base VPN functionality provided by iOS, so “is” looks a bit more appropriate than “scam”.
- rndgermandude 4y agoIt's not even the VPNs that leak, it's the Apple VPN implementation that does.
- ghostInTheSSH 4y agoSerious q, do other implementations exist that I can use on an iOS device?
- bitsoda 4y ago"Apple's VPN Implementation Leaks Traffic"
- Mo3 4y agoThe article is really good and informative, but that title man.. I almost didn't click and read it because of it
- martin1975 4y agoThis should trend to the top of HN. Apple bills themselves as a privacy-centric company. I hope they clean this up asap.
- dfox 4y agoiOS devices create lot of weird traffic on local network. And the only meanigful-ish other packet trace seems like APNS subscription update and some kind of iCloud traffic, there is probably zero reason why would you want that to go through “VPN” tunnel.
- deleted 4y ago[deleted]
- autoexec 4y agoThere are times when it might be useful to separate out different types of traffic to separate interfaces. I kind of wish there was an easy way to set rules like "Anything I do over these applications should go through the VPN, some of the random traffic my OS constantly spews in the background should be sent through the unsecured connection, but anything going out to these networks should just be blackholed" but I haven't come across one.
- sneak 4y agoIt is clear that Apple’s privacy efforts are only aimed at privacy for you from organisations that aren’t Apple. Apple doesn’t really care about preserving your privacy from Apple (and by extension the FBI). They maintain backdoors in iMessage specifically to preserve the ability of Apple/FBI to read your messages: https://www.reuters.com/article/us-apple-fbi-icloud-exclusive/exclusive-apple-dropped-plan-for-encrypting-backups-after-fbi-complained-sources-idUSKBN1ZK1CT https://www.reuters.com/article/us-apple-fbi-icloud-exclusiv... The fact that Apple OSes leak your true IP (and thus city-level location) to Apple around your VPN is not an issue to Apple; it may even be intentionally preserved this way to aid investigations.
- ignoramous 4y ago
- kogir 4y agoI think Apple is transparent about Always on VPN (blocking traffic except over the tunnel) requiring provisioning using MDM tools. Apple Configurator is free and allows anyone to set this up. Any other VPN is just best effort. https://support.apple.com/guide/deployment/vpn-overview-depae3d361d0/web https://support.apple.com/guide/deployment/vpn-overview-depa...
- cmeacham98 4y agoThat Apple documents that 'normal' VPNs are broken on iOS doesn't change the fact that they're broken.
- mike_d 4y agoVPNs were always meant to carry internal traffic to a private network, not the public internet (hence the name Virtual Private Network). The fact that a VPN server can send you a route for 0.0.0.0/0 always was and always will be a happy accident.
- Aaargh20318 4y ago> VPNs were always meant to carry internal traffic to a private network, not the public internet This. And the idea that these so called ‘VPN’ services somehow improve your security and privacy on the internet is laughable. All they do is let you get onto the public, untrusted, internet through a different on-ramp. There is no point to them. The internet is just as untrustworthy through a VPN service as it is through any other internet connection.
- w14 4y ago> There is no point to them. What about this? "Under the provisions of the Investigatory Powers (IP) Act, it is now possible for the Law Enforcement Agency (LEA) community to lawfully obtain Internet Connection Records (ICR) in support of their investigations. Following the completion of some initial trial activities, work is now underway to provision a national ICR service." https://www.digitalmarketplace.service.gov.uk/digital-outcomes-and-specialists/opportunities/17267 https://www.digitalmarketplace.service.gov.uk/digital-outcom...
- fzfaa 4y agoI remember recently using Cloudflare Warp and using one of those webpages that tell you your IP address and it showed my real IP address. It was a bit weird.
- vbezhenar 4y agoWarp is not designed to hide your address. If website is behind cloudflare, it'll know your IP address. If website is not behind cloudflare, your address will not be available.
- asldjajlfkj 4y agoThere was some communication (forum,discord) that this would change in the future. Apparently the plan was or is to hide the IP from pages on Cloudflare as well. But no idea if that’s implemented yet.
- ceejayoz 4y agoThat doesn’t sound right. https://blog.cloudflare.com/warp-for-desktop/ https://blog.cloudflare.com/warp-for-desktop/ > WARP was built on the philosophy that even people who don’t know what “VPN” stands for should be able to still easily get the protection a VPN offers.
- tedunangst 4y agoCrazy that cloudflare's marketing wouldn't be entirely forthcoming.
- Shank 4y ago> From a technical perspective, WARP is a VPN. But it is designed for a very different audience than a traditional VPN. WARP is not designed to allow you to access geo-restricted content when you’re traveling. It will not hide your IP address from the websites you visit. If you’re looking for that kind of high-security protection then a traditional VPN or a service like Tor are likely better choices for you. See: https://blog.cloudflare.com/announcing-warp-plus/ https://blog.cloudflare.com/announcing-warp-plus/
- jgtrosh 4y agoIs Android better in this regard?
- ignoramous 4y agoNot really, no. Ref: https://github.com/celzero/rethink-app/issues/224 https://github.com/celzero/rethink-app/issues/224
- jaimex2 4y agoYeah, though apps can whitelist themselves to exclude from VPN routing.
- hsbauauvhabzb 4y agoI don’t care for VPNs but I do want an adblocker. What are my options aside from using a public pihole dns or a vpn to a private dns server?
- haunter 4y agoFirefox Focus then in Settings > Safari enable it as a content blocker
- LeoPanthera 4y agoAd blocking is entirely possible. Safari supports ad blocking natively. OS-level blocking can be achieved via a DNS filter which can be run on-device. I use AdGuard Pro to do both: https://adguard.com/en/adguard-ios-pro/overview.html https://adguard.com/en/adguard-ios-pro/overview.html But other choices are available too.
- ecliptik 4y agoTailscale + Pihole works well, https://tailscale.com/kb/1114/pi-hole/ https://tailscale.com/kb/1114/pi-hole/
- giobox 4y agoI use this setup to get mobile adblock while on Verizon (iOS sadly has never let you override the default DNS server for cellular, just wifi). It works more or less perfectly, albeit with a noticeable hit to device battery life... so much so my wife who otherwise loves PiHole on the home network refuses to use it on her iPhone. Using iOS's built in support for browser adblockers is largely as effective and doesn't come with the battery life hit.
- BonoboIO 4y agoYou can use your custom dns over https server You can use AdGuard or select your own filterlists. Nextdns.io I use the free tier.
- 4y ago
- hkpack 4y agoI was developing VPN client for one of the popular VPN provider in the past for iOS and the solution was quite simple - enable on-demand VPN for 0.0.0.0/0 In this case, iOS will always wait until connection to VPN is established before sending any packets out. Without on-demand, VPN may leak. If I remember correctly, leaks occurred mostly after waking from sleep but before the tunnel had chance to be set up. Or in similar situations. Anyway, on-demand option solved all of them.
- tinus_hn 4y agoWould be nice if someone who actually knows what he’s doing looked into this. This guy might be on to something or he might be creating a whole lot of drama about nothing.
- rootusrootus 4y agoFor sure. I appreciate when someone admits they don't know something, because that is honest. But OTOH, there was a fair amount of "I don't know why this does what it does" in this blog post. I'd like to see this same topic worked up by someone with more knowledge.
- sneak 4y agoHe's on to something. For months I carried iOS devices only without sim cards and used an external VPN router with LTE.
- TazeTSchnitzel 4y agoAirplane Mode used to be a true “all wireless disabled” mode, but Apple have relaxed it a bit over time, possibly because it's so frequently used and there are so many services provided by WiFi and Bluetooth now that aren't related to the Internet (e.g. connecting to AirPods or an Apple Watch). They also relaxed what turning off WiFi and Bluetooth in the Control Center (separately from Airplane Mode) do, so that things like AirDrop still work. But I think the options in the Settings app are still meant to truly turn off wireless, rather than just mostly? Also: if Settings says you're connected to a WiFi network, but you don't see a WiFi icon at the top of the screen, I think that means there's no working Internet connection.
- derobert 4y agoI think airplane mode is intended to comply with the rules for using the device on an airplane. That used to be no radios whatsoever (and device turned off during takeoff and landing). The rules on aircraft changed, so the feature was updated.
- autoexec 4y agoI suspect they wanted the feature changed because it gives them better data when tracking you and other nearby devices and that once the rules for airlines changed they figured they could get away with giving users a false sense of security, which is why the feature is still called "airplane mode" which the public understands to mean everything is disconnected even though that's no longer the case.
- icehawk 4y agoThis how routing behavior has been on Mac OS for about 15 years now. Mac OS route selection always takes into account the source address of the IP packet in addition to the routes in the routing table. If a socket binds to a particular address, the Mac OS kernel will choose routes associated with the interface that address is on and ignore the others.
- genewitch 4y agothankfully Windows does not do this. if i set interface metrics manually, and a lower metric interface becomes connected, all external traffic will immediately go through the new interface. Likewise, if i switch between wifi and cellular on an android device, all existing connections stop and must be refreshed. to wit, on both windows and android, youtube videos will continue to play, but things like HN or reddit will stop loading until whichever connection takes precedence comes fully up. I would argue that's the only "sane" way to do it, but then again i'm no network engineer. I just rely on my devices to work this way so i don't saturate the wrong links or get poor upload speeds when i need them.
- ignoramous 4y ago> Likewise, if i switch between wifi and cellular on an android device... On an Android (like on iOS), both WiFi and Cellular interfaces can be active at once. Apps (with appropriate permission) are free to bind to either. > ...all existing connections stop and must be refreshed. On network changes (in particular address changes), TCP connectivity may break. SCTP / QUIC / UDP (and UDP-based protocols like WireGuard and MoSH) should continue to work just fine.
- dfox 4y agoI think that the value of this article is perfectly summarized by the sentence “Not sure what SYN is.”
- genewitch 4y agoare you saying that a packet leaving iOS and hitting the router's logs, without going through the "VPN" does not leak either your IP to the destination or your destination to your ISP?
- nucleardog 4y agoI think he’s saying that any sort of network analysis done by someone that doesn’t understand basics of TCP is kinda suspect and may be more prone to errors in the analysis methodology or interpretation of results. I tend to agree. My only takeaway after seeing that was “if I ever need a 100% leak free tunnel on iOS, validate it”. I certainly won’t be taking any of this at face value without replicating it.
- genewitch 4y agothe local router shouldn't see any other connections inbound or outbound from the device other than the "VPN" ip you are connected to. I submit that it doesn't take an expert to come to that conclusion. Other comments in this thread explain that the iOS/MacOS kernel keep old established routing tables intact under some circumstances, and that's (one) issue. Another appears to be the unreliability or inconsistency of "airplane mode" and invalid assumptions about that.
- nucleardog 4y ago> I submit that it doesn't take an expert to come to that conclusion. Probably not, but if, in the middle of trying to diagnose my car, someone pointed to the muffler and said "I'm not sure what this thing's for." I probably would look for a second opinion on their diagnosis especially if it was "there is a major manufacturing defect in this model of automobile". It doesn't matter if the problem looked like it was staring us in the face. Obviously I can't spot any major flaws with what the writer put together after a single read or I'd be pointing them out. I'm not calling it wrong. I'm just saying I'd want more verification from someone that has a better understanding of networking concepts to make it less likely that basic mistakes impacted the outcome. If the write-up has given you enough confidence, all the power to you.
- glerk 4y agoDevice-level VPNs are very useful for bypassing geographic restrictions, but I wouldn’t rely on them for hiding traffic from ISPs, unless you are in control of 100% of what your device does.
- permo-w 4y agohow good is wireguard at controlling this?
- ignoramous 4y agoWireGuard can be used as a VPN (L3 transport) but it cannot address the shortcomings of an OS' implementation of the VPN APIs.
- lizardactivist 4y agoThe iPhone was never made to be truly secure, so this is to be expected I suppose.
- lilsoso 4y agoIt's also worth pointing out that tethered/hotspot data shared to the iPhone with a VPN enabled at the iPhone level will not travel through the VPN, but will rather leak your phone's IP: https://apple.stackexchange.com/questions/266871/is-there-a-way-to-force-tethered-data-to-go-through-an-ios-vpn-instead-of-passi https://apple.stackexchange.com/questions/266871/is-there-a-...
- icelancer 4y agoThat seems like expected behavior, or at least one worth testing with an IP checker or something on the tethered device. I would be pretty surprised if I connected to a VPN on my mobile device, then tethered to it, and my traffic went over the VPN tunnel. I would just establish a VPN tunnel on the tethered device if I wanted that.
- triyambakam 4y agoI think the average user would not expect that!
- throwaway98797 4y agoaverage user here i would not expect it to work like that i’d think my traffic is protected, why protect it twice
- weberer 4y agoThe problem is for tethered devices that don't support VPN software, like video game consoles.
- woojoo666 4y agothis happens with android too. Which sucks. Although it is possible with root, which shows the benefit of having full control over your device
- j16sdiz 4y agoJust like iOS, you can do the same with managed device.
- deleted 4y ago[deleted]
- userbinator 4y agoIf only you could easily print out the routing table and/or modify it so you could direct the traffic exactly where you want it (i.e. stuff it all through the VPN tunnel)... ...and that's when you realise that trying to configure a device to which you do not actually have full control of is a futile endeavour. As such, in agreement with many of the others here, I don't consider this much of a bug nor a "scam". It's merely an effect of what VPNs are (an additional network interface) and how routing works, combined with a device whose manufacturer deliberately does not want to put users in full control of the routing table.
- psd1 4y agoI'd approach this from the router. If you give the device a static DHCP lease, then you can block it from 0.0.0.0 and allow it to your VPN provider's IP blocks. You might want to give the device its own WiFi network if you don't trust it to honour DHCP
- jrvarela56 4y agoThe author put together "A Defensive Computing Checklist" Site: https://defensivecomputingchecklist.com/ https://defensivecomputingchecklist.com/ Discussion: https://news.ycombinator.com/item?id=32490866 https://news.ycombinator.com/item?id=32490866
- 1vuio0pswjnm7 4y ago"Data is leaving my iPad and not traveling through the VPN tunnel." It is is interesting how the iPad purchaser refers to "my iPad". He owns the computer. But how much control does he have over it. He runs an OS controlled by a HW manufacturer turned trillion dollar tracking and data collection company. (Apple computers are extremely chatty on any network and phone home 24/7. Apple is fervent about its need to collect and store data from purchasers.^1) As such, he cannot find the problem in the iOS source code, remove the phone home "features", re-compile and reinstall it. The best he can do is complain to the internet. I have owned various Apple computers over the years, including an iPad. However I never used any Apple computer with an Apple OS for internet use.^1 I only connect them to the LAN. I just think there are better OS, namely ones I can edit, to use for internet-facing computers. For internet usage, I like OS where I can control the routing table. Since I started keeping these computers running "consumer OS" off the internet in the 2000s, the internet has become a vector for pervasive surveillance. I treat computers running Windows the same way. No direct internet access. In the 1990s/2000s I can recall the "experts" advising against leaving computers connected to the internet when not in use. Today, "tech" companies try to compel people to leave their computers connected 24/7. Not to mention "experts" who believe this is justified because "automatic updates". Granting 24h remote access to unknown people to install software on computers that do not belong to them. Some people call this a "botnet". I do not care for broken software that continually needs fixing. But as the author alludes to when he quotes Steve Gibson, iOS is never broken, it just has not been fixed yet. 1. Today's Apple computers require some connection in the beginning to "sign-up", "register", download "approved" software, etc. 2. Apple computers owned by employers excluded. Also excluded are older Apple computers on which I ran NetBSD.
- autoexec 4y ago> In the 1990s/2000s I can recall the "experts" advising against leaving computers connected to the internet when not in use. Today, "tech" companies try to compel people to leave their computers connected 24/7. There is a lot of wisdom we've thrown away from those days. Software phoning home was viewed as malicious and there were lists of applications that did it to shame companies and warn others to stay away. Pretty much every OS and major application today would rightly have been considered Spyware. If we'd kept "Never use your real name/info on the internet" the world would be a better place. The rule allowed for E-commerce so we'd still have amazon, but facebook and all its problems wouldn't exist. Pop-ups were considered evil, and we fought to stamp them out but today the same annoyance is commonplace and accepted, they just show up as modal windows and cookie banner notices.
- dcow 4y agomac/iOS still needs to do subnet local stuff like renew the DHCP lease and discover other link-local devices using mDNS/Bonjour. The system also periodically makes sure interfaces are “up” so it can seamlessly route traffic between cell and wifi. I would not assume that the presence of traffic where DST != VPN tunnel endpoint means that application traffic is leaking over the VPN. I only skimmed the article so someone correct me if there was a case of that observed. The “bug” where existing connections aren't terminated when you bring a VPN up sounds annoying but I can also see why the system wouldn't force terminate existing connections. The connection to the router’s public IP sounds like a hairpin. I also wouldn't be surprised if user-space VPN is outside of the scope of the APNS connection that the system maintains through sleep states.
- crazygringo 4y agoCan someone clarify this better than the author? Trying to read through the whole thing, I can't tell if if this is claiming: a) When a VPN is activated, pre-existing connections will continue communicating outside the VPN, but all new connections happen via the VPN b) Apple services like the app store and/or certain other apps leak outside the VPN because of a) more than you would expect c) Apple services like the app store and/or certain other apps leak outside the VPN for other reasons totally unrelated to a) The author's tl;dr just says "data leaks" but I really just can't follow what that actually means. It seems like a) is not entirely unexpected or necessarily a problem -- you probably turn on a VPN before initiating activities/apps you want routed through the VPN, so not usually problematic? But b) means it might be more serious than that, while c) would be even scarier?
- sneak 4y agoApple iOS and macOS maintain OS-level connections to Apple (using hardware serial number linked certificates) for notifications. This means the Apple APNS client IP logs relate directly to your tracking serials and both your VPN and non-VPN ids, linking them. They also contain your non-VPN IP history, which is your travel history, as client IP is city level geolocation. https://m.youtube.com/watch?v=tL8_caB35Pg https://m.youtube.com/watch?v=tL8_caB35Pg
- krnlpnc 4y agoTechnically imperfect and “a scam” are very different things
- dcow 4y agoI wonder if the author tried using an On Demand VPN rule for the default route. That's always what I've done when setting this stuff up. Correct me if I'm wrong, but you don't need a device management profile to enable an on-demand VPN for all traffic. Then, reboot your phone and all application traffic, or traffic that isn't something system (APNS) or management/link-local (dhcp, mdns, etc.) will use the tunnel.
- sneak 4y agoAPNS client cert is linked to your hardware serial, so by linking all your non-VPN client IPs together by serial, Apple gets your travel history due to city-level client IP geolocation. Enough points (APNS is always connected, so whenever your phone is on) and this uniquely identifies you (even if the serial number wasn’t bought with your own credit card). Then they have to give it to DHS/ICE/FBI/CIA without a warrant on demand, thanks to FAA702. They, of course, already have all of the cell tower association records, as well as all of the Secure Flight program data from the TSA. It’s not a difficult query to figure out which serial numbers are which IMEIs are which humans.
- dcow 4y agoNo I agree on the it's not good that APNS is an exception. I suspect that it's something technical like in order to receive push data in low power states, since the kernel isn't awake, userspace VPN is not involved. In an ideal world you'd be able to choose whether you wanted to spend a little extra battery to bump into a higher power state so that this information didn't leak.
- koprulusector 4y agoNot to be pedantic, but UDP is connectionless. Also, regarding the UDP datagrams seen after the IKE exchange, maybe relayed to NAT-T? https://en.wikipedia.org/wiki/NAT_traversal#IPsec https://en.wikipedia.org/wiki/NAT_traversal#IPsec
- alanfranz 4y agoI think the analysis has some good points, but the author is lacking a bit of networking skills, so I’m not sure how trustworthy this can be. Two yellow flags: * vpn gateway address can be different from public vpn exit address. What is the surprising part? * I don’t know what pings your “uncloaked” public ip address, but still, when using a vpn, you’re using your own ip address to connect to the gateway. So, there’s no real leak - it would be a leak if some packets went _through the vpn_ to 99.99.99.99, because an observer could spot the strange ip and determine it’s the uncloaked source address. Anyway: who can tell what an iphone or ipad can do? You probably have an associated apple account, et cetera. If you trust such a device for total anonymity, you’re doing it wrong from the start. Pick a Linux laptop for that.
- FabHK 4y agoI'm on a VPN... and can't read that article.
- timbit42 4y agoI'm on a VPN and can read this article, but there are more and more websites lately that appear to be blocking VPNs.
- DavideNL 4y ago...and then there is the Apple Watch which doesn't support VPN's as far as i know. So, when apps can communicate from iPhone->Watch, even with a perfectly functioning VPN on the iPhone your public IP can leak via the Watch (if the app is also installed on the Watch.)
- VogonPoetry 4y agoNeed to give the article author a lot of slack! If you are here, please read some more about networking :-). Networking is dynamic it takes many sequential steps to configure. There is no ZAP, it is done. I don't know of an OS that locks out "user programs" until configuration is complete. Yeah, since networking is dynamic that could never work -- "user programs" would be locked out forever! At the start of the First Test there are packets going to non-tunnel locations at the same time the VPN is being set up, not a surprise. Packet ordering / routing at this time granularity is also not surprising. Need to take a moment to review the "drop everything" when a VPN is up standpoint. OS Networking stacks don't really understand what a VPN is, it is just an endpoint to route packets. A TCP connection has internal state that is bound to the addresses that were used when it was set up - which is tied to the state of the routing table. A new point-to-point endpoint, like a VPN would invalidate that state. Most (many?) TCP/IP stacks keep a cache of the initial route on the socket. As long as that is still valid (or updated), that is where the packets go. Killing TCP connections for every (temporary) network flap would make a lot more people MAD. The "DNS" to NextDNS with DoH connection is interesting. This 100% isn't coming from iOS itself. It doesn't support it. So it must be coming from an App. But what app and how? There is a NextDNS app which up front claims "Encrypt all DNS queries on all networks with the official NextDNS app for iOS". The author does appear to have configured the router to use NextDNS, perhaps they also have that App installed as well and it is also hijacking networking to do DNS? A dunno. The "flood stuff" is interesting, but I think it might just be an attempt to perform STUN to make sure UPD traffic can be transported - to Apple endpoints. I think "second test" is the same thing happening again. So what is left is the traffic being sent to apple endpoints. Now I wonder how the VPNs the author is using are implemented. The Big Sur VPN brouhaha was because apps were trying to implement a VPN using NEFilterDataProvider instead of a "tun" interface and routing. I wonder if this is just the same issue but on iOS. Not related, but I do wonder what these VPN services offer in terms of "Firewall" protection or if when you use them ALL ports are forwarded to your device. This would make all of their endpoints a "great target" for continuous scanning for getting inside a network if the VPN user had something misconfigured, like say an experimental Apache, Nginx, PHP, Rails, Django, MySQL project. Doh. Methinks I should spend some currency and experiment. Sadly black-hats are probably already doing this.
- deleted 4y ago[deleted]
- _v8ex 4y ago[dead]
- otabdeveloper4 4y agoThere's lots of reasons to use a VPN besides 'privacy'. The vast majority of people use them for IP spoofing.
- timbit42 4y agoIP spoofing is privacy of their real IP.
- otabdeveloper4 4y agoBy "IP spoofing" I mean getting around range IP bans. It's not for privacy reasons.
- cherryblossom00 4y agoI use VPNs to access region-restricted content (mostly to pretend I’m in the USA) and not for the privacy aspects, so VPNs aren’t really a ‘scam’.
- lupire 4y agoThe real lesson is here: > I am not a fan of making a VPN connection on your only router, but suggest having a second router dedicated to VPN connections. When you need a VPN, connect to the second router (Wi-Fi or Ethernet), when you don't need a VPN, connect to your main router. Aka, don't use a device with two network sockets if it is critically important to avoid using one of them.
- d_theorist 4y agoVPNs in general are a scam. To be clear, I mean the big VPNs that advertise themselves as helping with privacy are actually a scam. There are obviously some situations and use-cases where using a VPN makes sense (e.g. geo-shifting), but as a general solution for privacy on the internet they make no sense.
- beeboop 4y agoUntil browsers become more fingerprint resistant, there is zero privacy online. Firefox is making good strides but even with all settings turned to the max (including the about:config settings for fingerprint resisting) it is still able to be fingerprinted by the tools online used to check for this.
- proneb1rd 4y agoMost of what you see is probably Apple bypassing all VPNs to talk to their own servers. There are more serious problems though, with any app being able to bypass VPN simply by prohibiting Wi-Fi interface and iOS gladly letting all traffic via LTE, unfiltered. That's been described in https://blog.disconnect.me/ios-vpn-leak-advisory/ https://blog.disconnect.me/ios-vpn-leak-advisory/. It's well known and pretty sad that these issues go unaddressed for years. VPN developers have little power to change that given that VPN apps run in a walled garden of Apple in a sandboxed environment. Hence the the best effort at this point with a hope that this can addressed in the coming updates. It would be great if more of these pop up on Apple forums and Apple Feedback with people demanding improvements on transparency and privacy from the company. So far reading your blog post looks like a recollection of what's been going on. I really wanna throw an analogy of a bear waking up from hibernation. This is not sensational and just reiterates what's been said before you, yet the title throws a shadow at VPNs just to sound like it.
- iuJqi_XkvKsJ2Q 4y agoDoes the property "includeAllNetworks" [1] provided by Apple's VPN API not work, or do all VPNs currently rely on the default value (false)? [1] https://developer.apple.com/documentation/networkextension/nevpnprotocol/3131931-includeallnetworks https://developer.apple.com/documentation/networkextension/n...
- cutehax 4y agoAgreed with most comments here, the implementation is leaky as heck. It’s a ‘best efforts’ VPN service at best and you can tell this especially when in a mall and there’s a walled garden in place. I use iVPN and regularly have to disable wireguard to pass the walled garden to then also regenerate a certificate. Enabling VPN through the iVPN app is hit and miss, likely because Apple have decided to do their own thing and implement ‘Private relay’ instead. Yeh… Apple, Five Eyes, Privacy is all pretty much an illusion when you have this many devices in this many pockets. Whatever it is, vpn’s or end to end encryption, it’s all really only as secure as the touch screen controller telemetry logs.