13 ms·
I think Apple is transparent about Always on VPN (blocking traffic except over the tunnel) requiring provisioning using MDM tools. Apple Configurator is free an
by kogir 4y ago
I think Apple is transparent about Always on VPN (blocking traffic except over the tunnel) requiring provisioning using MDM tools. Apple Configurator is free and allows anyone to set this up.
Any other VPN is just best effort.
https://support.apple.com/guide/deployment/vpn-overview-depae3d361d0/web https://support.apple.com/guide/deployment/vpn-overview-depa...
- cmeacham98 4y agoThat Apple documents that 'normal' VPNs are broken on iOS doesn't change the fact that they're broken.
- mike_d 4y agoVPNs were always meant to carry internal traffic to a private network, not the public internet (hence the name Virtual Private Network). The fact that a VPN server can send you a route for 0.0.0.0/0 always was and always will be a happy accident.
- Aaargh20318 4y ago> VPNs were always meant to carry internal traffic to a private network, not the public internet This. And the idea that these so called ‘VPN’ services somehow improve your security and privacy on the internet is laughable. All they do is let you get onto the public, untrusted, internet through a different on-ramp. There is no point to them. The internet is just as untrustworthy through a VPN service as it is through any other internet connection.
- w14 4y ago> There is no point to them. What about this? "Under the provisions of the Investigatory Powers (IP) Act, it is now possible for the Law Enforcement Agency (LEA) community to lawfully obtain Internet Connection Records (ICR) in support of their investigations. Following the completion of some initial trial activities, work is now underway to provision a national ICR service." https://www.digitalmarketplace.service.gov.uk/digital-outcomes-and-specialists/opportunities/17267 https://www.digitalmarketplace.service.gov.uk/digital-outcom...
- jolux 4y agoAnd what makes you trust that the VPN provider wouldn’t share these records if asked?
- crest 4y agoPick one in a suitable jurisdiction with a track record of sending such records and requests for them to the bit bucket?
- autoexec 4y agoIn the end you have to trust someone or you might as well just stay offline forever. In the US, very few people have much choice in their ISP. If you are lucky you might have more than two options. Many ISPs are known to be untrustworthy. They outright state they will mine your internet history and sell it. If I have the choice between an ISP who I know will sell my browsing history and a VPN which might, but claims not to? Well, I know which one I'm going to pick.
- thayne 4y agoThey also state they can and will shut down your service for copyright infringement.
- autoexec 4y agoIf ISPs don't shut down people's accounts they'll get sued for billions in fines. There are still open court cases against multiple ISPs for not cutting enough people off from the internet. So far, courts have agreed with the RIAA/MPA who paid good money for the laws we have.
- thayne 4y agoYes, the media industry is certainly more to blame here. Although, the current ISP oligopoly means that there are less companies to sue or otherwise bully. And it doesn't help that some major ISPs are owned by companies that also produce copyrighted content they want to protect.
- autoexec 4y ago> All they do is let you get onto the public, untrusted, internet through a different on-ramp. There is no point to them. Not true, at all. There are several good reasons to use VPNs to get a different on-ramp to the otherwise untrusted internet. - Avoid ISP tracking: Your ISP should see only traffic to and from the VPN. - Access content intended for those in other regions: Many sites and services only show certain content to people who enter the internet from specific places. - Limit the amount of activity linked by trackers: Visiting certain sites only from different IPs/browsers will help keep logs of that traffic isolated from the logs of your other browsing. - Allows you to connect to sites and services that cannot connect back to you once you've disconnected: A lot of people, even those with dynamic IPs, keep their address for months or years at a time. VPNs provide a great way to cycle through IPs. VPNs don't solve every problem, but they're a powerful tool to keep in your tookbox. There are many many very valuable uses for VPNs some that offer privacy/security benefits and some that are just plain useful. It's wild to hear anyone say that "There is no point to them."
- Shared404 4y agoThank you for saving me the typing. No it's not gonna make you an invisible unhackable ghost, but at least I don't have to worry about my ISP screwing me over.
- dTal 4y agoWhy are you worried about your ISP tracking you but not the VPN company? In effect you've simply added another ISP on top.
- a1369209993 4y agoMost people can switch VPN companies more easily than they can switch ISPs.
- Shared404 4y agoThis is the case for me. I _know_ that my ISP is untrustworthy, I've read the ToS.It's also bundled with my apartment and I can't switch. What I can switch however is what VPS company I use, or what commercial VPN I connect to. Plus, the harm from being banned by a VPN is a lot lower than an ISP, as low as the chances of either are.
- wyager 4y ago> And the idea that these so called ‘VPN’ services somehow improve your security and privacy on the internet is laughable I trust Mullvad more than I trust Optimum.
- Aaargh20318 4y agoBut the point is you shouldn't trust either of them.
- chakalakasp 4y agoThing is, if you ping experts in the privacy field (like Mike Bazzell, the former FBI OSINT guy who billionaires and celebs hire to keep their personal info off the internet), they will all say the VPNs are a very important tool to create a layer of privacy between you and the site you are visiting and also a good tool to prevent said sites from easily profiling you. No, they are not a panacea -- much like the security universe, the privacy universe requires lots of other active and passive behavioral and technological changes to properly lock things down to whatever standard you require for your threat model. But they are very much an important tool. For a small subset of people it's literally a tool that protects their life. So yeah, it's a kinda a big deal if it leaks. (Which is why most privacy experts, were you to tell them you were sufficiently paranoid, would have you fire up a pfSense and link it permanently to a VPN service and then run a separate brand of VPN software on whatever device, so that you have two layers going through two companies.)
- mike_d 4y ago> who billionaires and celebs hire to keep their personal info off the internet I also do this type of work on the side. When it matters a device level VPN is never the correct option, because every OS leaks to some extent. They get a device where the cellular components have been disabled and it can only connect to a fixed wifi AP carried by one of their EP guys that tunnels the traffic back to a datacenter.
- mschuster91 4y ago> This. And the idea that these so called ‘VPN’ services somehow improve your security and privacy on the internet is laughable. Actually, they do: Neither your ISP nor the government (assuming the VPN provider is in a "hostile" jurisdiction) can intercept, analyze or modify your Internet traffic when you are using a VPN to mask your Internet access. There have been multiple instances of this in the past [1][2] and ongoing (e.g. DNS [3]), and ISP "middleboxes" have been historically the biggest impediment in rolling out new features. Ubiquitous HTTPS has shut down a lot of that shit, but until DNS-over-HTTPS becomes actual mainstream DNS (and SSL SNI!) will still leak a lot of information to entities that have a direct financial interest in collecting, packaging and selling this data to advertisers - there is a reason why ISPs oppose any legislation that turns them into "dumb pipes" after all. Security-wise, at least if you are using any kind of untrusted network (e.g. university campus, public hotspots) a decent VPN software that uses the OS-provided firewall to completely drop any incoming and outgoing packets except for the VPN tunnel connection is also a massive benefit. The downside of course is that you are now forced to trust the VPN provider instead of the ISP - but at least the VPN provider market is healthy and extremely competitive, which means any sort of shady bullshit would be a virtual death sentence, unlike the ISP market where you are in many cases stuck with one or two options. Not to forget, VPNs also provide privacy on the "other end": as many providers don't cycle through IP addresses sometimes for months, advertising providers can track your movement across the Internet simply by collecting your origin IP. A good VPN provider regularly changes the origin IP visible to sites you access. [1] https://www.privateinternetaccess.com/blog/comcast-still-uses-mitm-javascript-injection-serve-unwanted-ads-messages/ https://www.privateinternetaccess.com/blog/comcast-still-use... [2] https://labs.ripe.net/author/babak_farrokhi/is-your-isp-hijacking-your-dns-traffic/ https://labs.ripe.net/author/babak_farrokhi/is-your-isp-hija... [3] https://www.csoonline.com/article/2953718/t-mobile-caught-in-crossfire-of-injected-ad-war-between-shady-ad-networks-and-google.html https://www.csoonline.com/article/2953718/t-mobile-caught-in...
- neilalexander 4y ago> Actually, they do: Neither your ISP nor the government (assuming the VPN provider is in a "hostile" jurisdiction) can intercept, analyze or modify your Internet traffic No, you're just delegating those capabilities to some completely unregulated random actors instead. > which means any sort of shady bullshit would be a virtual death sentence This assumes that their shady bullshit is discovered by someone. I would bet good money that the vast majority of it isn't. They could be sampling traffic and selling it to other companies without modifying it and users would never be any the wiser. Honestly, I wish we could get past this broken narrative that VPNs are a panacea.
- eru 4y ago> There is no point to them. There might be no point to their security and privacy, but they are still good for getting foreign-country Netflix.
- enlyth 4y agoIn the UK if you download a TV show or other copyrighted material without a VPN, you can get a letter from your ISP as a warning together with a list of the content you've downloaded, and they may terminate your service if you continue. A VPN solves this, and does protect your privacy, so your comment is just needless hyperbole.
- Angostura 4y agoYou're paying to insert a potential man-in-the-middle attack. That's got to be worth something.
- raxxorraxor 4y agoThat would be true if we didn't have regional content blocking, location tracking and general surveillance by supposedly democratic states. I recommend VPN services in regions where legislation of your home country might difficulties getting data.
- _8j50 4y ago[flagged]
- anyfoo 4y ago> You are wrong on this, the private part indicates the privacy it provides not the destination. I remember using VPNs long before, to my knowledge, people were using them in the way you describe, and I was always under the impression that the "P" in VPN meant "connecting private networks" together over the Internet. This document from 2001 agrees with me: https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-2000-server/bb742566(v=technet.10) https://docs.microsoft.com/en-us/previous-versions/windows/i... "From the user’s perspective, the VPN connection is a point-to-point connection between the user’s computer and a corporate server. The nature of the intermediate internetwork is irrelevant to the user because it appears as if the data is being sent over a dedicated private link."
- autoexec 4y agoVPNs were used primarily by companies to allow secure access to their network from the outside. It doesn't surprise me that documents aimed at businesses running Windows servers would describe them in the context of that use case. It doesn't mean that was the entire point, or purpose. It's just one thing they were commonly used for.
- deleted 4y ago[deleted]
- anyfoo 4y ago> VPNs were used primarily by companies to allow secure access to their network from the outside. Yeah, that was the entire argument.
- autoexec 4y agoAt the same time that I was working at an ISP on a product that would let employees from various companies connect via dial up and VPN into their corporate networks (whose gateways were also on our network) several of my co-workers were using a VPN of their own to connect to their home networks, but not to access the resources on those home networks (although some did that too). They wanted to use the internet from their machines at home in order to hide their internet activity from our IT department. This is basically the same thing people do with VPNs now, only instead of hiding their internet activity from IT, they hide it from their ISP. VPNs were always used for things other than connecting someone to a corporate network, it's just that most of the general internet population at that time (and I'm guessing you're old enough to remember this) were not aware of the technology and not tech savvy enough to set it up. This is true even for the employees of the companies we had as customers. We had to build entire software products that did nothing but hand hold people through setting up a dial up networking connection. It's not surprising that corporations were the majority users of VPN technology until the rest of the public (who don't have IT staff) caught up, at which point it became increasingly more common for people to use it to hide their internet traffic.
- genewitch 4y agoi will have agree with your definition, but the issue here isn't with the nomenclature, it's with the bill of goods being sold as a service. what people expect, and what is being sold, is an encrypted tunnel that all traffic goes through, to an endpoint. That this is called "VPN" is irrelevant. I have a GL-iNet Mango that i have setup to provide "always on wireguard" to a computer in a datacenter i control the public IP for. I haven't tested, but i expect all data sent to and from any devices connected to that Device's SSID to be tunneled via wireguard to the computer in the DC, and therefore, to all outside observers the DC is where my device is. Obviously the ISP can see the session, but since they have no say over the DC endpoint, they have no way of knowing what the traffic is or where it's going. It could just be me doing SSH or video streaming or backups to and from the datacenter, or i could be watching netflix or youtube. In that circumstance, an iOS device shouldn't be able to leak my local network's ostensible "public IP", since the actual transport layer is outside of the iOS device's control. With all of this being said, i don't think there's any way to guarantee that leaks are impossible without literally air-gapping your devices and forcing all traffic through something that cannot communicate with anything but the remote endpoint - that is, if the wireguard connection fails, all pings fail, all TCP/UDP/etc traffic times out, and so on. In this manner, probably all things sold as "secure VPN" or as a service that does that are scams. This is the issue that TFA is complaining about. in a situation where it's life and death - i would find an open wifi access point and connect a wireless bridge device (e.g. tp link TL-WR802N), with an STP ethernet cable to something similar to the gl-iNET mango, with 100% forced wireguard connectivity. I'd only consider this viable after doing tshark or tcpdump on the server i control log access to, to verify that my (local) MAC address and/or stuff like webrtc or whatever are blocked/dropped. sorry for the length, but i didn't want to make multiple comments all over the threads.
- cmeacham98 4y agoI'm not sure what your point is here? To be clear, is what you're saying that it is ok for VPNs to be broken (or at least less bad) because their most popular usage isn't what they were originally intended for? If that wasn't your point, what was?
- userbinator 4y agoI don't like how the word "proxy" got replaced with "VPN" either, but I think it was to create a distinction between the per-connection, often single-protocol nature of proxies (HTTP/HTTPS/SOCKS) and something that acts like a whole (virtual) network interface.
- nirvdrum 4y agoMaybe that wasn't the original intent, but it's a designed and supported configuration. Many places don't want a fleet of Windows laptops to become network bridges to their intranet. The default configuration for most VPN setups is to route all traffic. If you want to selectively route traffic, you have to specifically set up a split tunnel. While you could only route client traffic to an intranet endpoint and prevent access to any external services, that wouldn't be very practical in most deployments so a proxy is added on top. This type of deployment is common and has been used for decades.
- remram 4y agoWe should start calling them vISP or something.
- zajio1am 4y ago'VPN' is just a nickname for secure tunnels. These can be used for many different purposes.
- autoexec 4y agoThat's the Apple Way though isn't it? Apple says "Do it exactly how we tell you" and you shouldn't expect anything to work if you deviate from the One True Path that Apple has laid out for you. "Think Different, Do As You're Told"
- neilalexander 4y agoOh, come on. This is an utterly lazy argument and it adds absolutely nothing useful to the discussion.
- rodgerd 4y agoIs Apple responsible for the false advertising of other companies?
- deleted 4y ago[deleted]
- xoa 4y agoI hope Wireguard makes it into iOS/macOS at some point. Still early days relative to other protocols of course but it's so much simpler and more reliable (even beyond the security benefits). I use it extensively on both platforms for access to my own networks and services nowadays.
- KindOne 4y agoIt already exists in the App Store. I've been using it since April 28th of this year. ios/ipad: https://apps.apple.com/us/app/wireguard/id1441195209 https://apps.apple.com/us/app/wireguard/id1441195209 macos: https://apps.apple.com/us/app/wireguard/id1451685025 https://apps.apple.com/us/app/wireguard/id1451685025
- isatty 4y agoWireGuard is already available on both platforms - or do you mean kernel space WireGuard without an additional app? Fwiw the existing app integrates seamlessly into the apple ecosystem.
- mdeeks 4y agoI think the OP means so that it can be used without an app and so it can be used with Apple's "Always On VPN" setup. Right now I believe "Always On VPN" only works with the OS supported VPNs: IKEv2, L2TP, SSL VPN, and Cisco IPSEC https://support.apple.com/guide/deployment/vpn-overview-depae3d361d0/1/web/1.0 https://support.apple.com/guide/deployment/vpn-overview-depa...
- happyopossum 4y agoNope, there are a ton of 3rd party SSL/other VPN clients that use the same frameworks that can be set to always on - the app just has to be written that way. Consumer VPNs typically aren't.
- mdeeks 4y agoMy mistake! The docs I linked weren't clear about it.
- rapind 4y agoSeems targeted at Enterprise customers, not your average consumer. Kind of a big deal that likely 90%+ of iOS VPN app users assume they're private when they're not. False advertising IMO, and Apple is getting their 30%.
- mccorrinall 4y agoI use perfect privacy and they provide IPSec configs for iOS. Their guide even makes note to enable on-demand to prevent leaks. Also, just checked Mullvad, which seems to open an IPSec server on your local device and then install a vpn config on your ios device. From the local IPSec server a connection is made to mullvad via wireguard. On-demand is also enabled by default. But yea, VPN were initially targeted at enterprises anyway. So I don’t mind that i actually have to install vpn profiles by hand.
- nyolfen 4y agowhat is the point of wrapping wireguard with ipsec? bet-hedging?
- deleted 4y ago[deleted]
- mccorrinall 4y agoiOS has no native wireguard support
- Youden 4y agoThe issue in the article isn't that the VPN is sometimes inactive, it's that when the VPN is active, some traffic escapes the VPN. As far as I can see the linked page doesn't say that your VPN will leak unless you're using Always On. Plus, that page documents the VPN features built in to iOS itself, not VPNs provided by apps.
- jart 4y agoThe ProtonMail article said it only applies to pre-existing connections, because iOS doesn't force them to close when an app enables its VPN. I'd be reluctant to call that a leak, unless it contradicts Apple's documented behaviors, which as far as I can tell make no mention of a systemwide VPN except for corporate "always on" ones. Besides, is there any reason why you can't just toggle airplane after enabling a consumer VPN to kill off the old connections? Then it should probably be fine.
- mkingston 4y agoThat's a clever thought. Do you know whether connections could be established outside the tunnel after you disable airplane mode but before the tunnel is re-established?
- jart 4y agoIf that were possible then ProtonMail would have certainly said so, since that'd garner serious attention. In any case, the functionality as a whole isn't documented, so even if it works, Apple could theoretically take it away just like that. That of course doesn't mean we shouldn't rely on it, since if the only other option is a corpnet we're left with little other choice. I have the same problem with Apple because I depend on static binaries. Under the Apple regime, they too have an uncertain future and only continue to exist at Apple's pleasure. It's discomforting but not the end of the world.
- ratata 4y agoAccording to the author, IOS makes new connections outside of the tunnel after the VPN was enable. There is no effective workaround.
- deleted 4y ago[deleted]
- sneak 4y agoLockdown mode on iOS for high security will prohibit the use of provisioning profiles.
- astrange 4y agoConfiguration profiles, not provisioning profiles. That just means you install them before locking it down. Also, the supervision requirement for always on VPN is a stronger limitation than lockdown mode; you have to erase the phone to supervise it.
- sneak 4y agoAhh thanks for the clarification, I didn't know there was a difference. Configuration profiles are however how you force DoH or disable certain privacy leaks from phoning home to Apple. There are no UI settings for some of the important ones.
- deleted 4y ago[deleted]
- sneak 4y agoThat's not what transparent means.
- raxxorraxor 4y agoThat is pretty user hostile it seems.