10 ms·
iOS allows DNS request to escape the VPN tunnel
- drcongo 4y agoAlso Google / Android, but that doesn't get the clicks.
- nb_key 4y ago> We confirm that iOS 16 does communicate with Apple services outside an active VPN tunnel. Worse, it leaks DNS requests. #Apple services that escape the VPN connection include Health, Maps, Wallet.We used @ProtonVPN and #Wireshark
- khana 4y ago
- RetpolineDrama 4y agoWallet at least has a semi-plausible non-evil answer: Users who kick their VPN on to another country and try to use apple pay at checkout will unexpectedly get declined (because the purchase would appear to be coming from another country perhaps?). Apple could fix that with proper UI though.
- jaywalk 4y agoI don't see any reason why Apple Pay would use IP geolocation like that when it's running on a device that has GPS.
- tablespoon 4y ago> I don't see any reason why Apple Pay would use IP geolocation like that when it's running on a device that has GPS. One reason is that GPS doesn't work well (or at all) indoors, through cell-tower geolocation should work well enough for that case.
- thelopa 4y agoA compromised device can send a false location or the user may have disabled location. Geolocation has relatively predictable failures.
- bierjunge 4y agoGPS can be easily spoofed. Back in the university days, we (me + a few friends) used to get some radios and antennas to create a signal stronger than the one coming from satellites. It was always fun when the semester started and all freshmen were using Google Maps to navigate through the campus, but the map always showed their location in North Korea. Good ol' times.
- lapcat 4y agoDupe: https://news.ycombinator.com/item?id=33173163 https://news.ycombinator.com/item?id=33173163
- disabled 4y agoLast that I heard, Raspberry Pi with VPN installed along with PiHole that you SSH/VNC (via iOS app) in to is your best option.
- kube-system 4y agoSSHing to another machine isn’t a solution, you’re just using a different machine. The way to solve it and still continue to use iOS is to implement your VPN at the network layer. e.g. use one of those wifi routers with a VPN client built in.
- tablespoon 4y ago> The way to solve it and still continue to use iOS is to implement your VPN at the network layer. e.g. use one of those wifi routers with a VPN client built in. That's a little impractical for a phone. You'd have to lug around some kind of VPN-enabled mobile hotspot, plus batteries to power it.
- kube-system 4y agoYou’re right, it ain’t convenient… but mobile hotspots already have batteries.
- addingnumbers 4y agoThey circumvent this by forcing certain traffic to circumvent your hardened WiFi by using the mobile network radios.
- kube-system 4y agoThat is a possibility but the last I checked it was not the case.
- egberts1 4y agoiOS Airplane Mode
- 4y ago
- dljsjr 4y agoAlways-on VPN that tunnels everything requires MDM commissioning. It's documented by Apple. See the section "Always On VPN": https://support.apple.com/guide/deployment/vpn-overview-depae3d361d0/web https://support.apple.com/guide/deployment/vpn-overview-depa... Is it dubious that Apple doesn't let VPN apps do this as well? Maybe. But this is known and documented.
- giobox 4y agoSo many times law enforcement take advantage of this too, to fingerprint devices. The number of people caught because someone leaks packets outside the VPN for a few seconds because they forgot to configure VPN to disable outbound data if VPN drops... I've long wondered if making always on VPN require MDM provisioning on iPhones was a sop to police/criminal investigation forces, especially after Apple's public fights with the FBI over matters like the locked San Bernadino phone etc. I bet very few crims installing VPNs are aware of that apple support doc. If this was working as it arguably should and could be done easily without MDM provisioning, it would remove a genuinely useful avenue for law enforcement and add more fuel to the the FBI's dislike for Apple's security features.
- roamerz 4y agoYou used FBI and the term law enforcement in the same sentence. Sad to say the respect I once had for what the FBI likes and dislikes has been greatly diminished by the political bias that seems to influence it’s actions. I look forward to the day when they are strictly law enforcement and without political agenda. We as a country need them.
- bogomipz 4y agoI'm not following. Your link appears to be specific to corporate environments. The title of the document is: "VPN overview for Apple device deployment." It further states "Secure access to private corporate networks is available in iOS ..." An individual iPhone user who is not using a company issued device would not be beholden to MDM restrictions or profiles. Nor would access to "private corporate networks" be necessarily relevant.
- emptyparadise 4y agoiOS devices are leaky as hell. I once tried blackholing all requests besides those to a VPN service on a router level, and even then my iPhone would just fall back to mobile data for notifications and other Apple services.
- account-5 4y agoI can't even imagine the uproar that would be a thread about Google doing this!
- joshstrange 4y agohttps://mullvad.net/en/blog/2022/10/10/android-leaks-connectivity-check-traffic/ https://mullvad.net/en/blog/2022/10/10/android-leaks-connect... and I'll bet good money Android does the same thing if it can't get internet access over WiFi
- account-5 4y agoI'm not defending Google in anyway, I'm sure they do, and I'd be the first to deride them too. But HN generally has a lot more forgiveness for apple, for some reason.
- Zak 4y agoApple does a lot of marketing around protecting user privacy better than the competition. In this case, iOS leaks more data than Android.
- joshstrange 4y agoCompletely different situation. The iPhone falls back to mobile data if it can't get to the internet over WiFi.
- neilalexander 4y agoIt’s also optional (called “Wi-Fi Assist”).
- netfortius 4y agoAdd Android to this: https://mullvad.net/en/blog/2022/10/10/android-leaks-connectivity-check-traffic/ https://mullvad.net/en/blog/2022/10/10/android-leaks-connect...
- jacooper 4y agoAndroid only leaks connection checks. While on IOS any system app doesn't use the VPN or DNS requests. VPNs are useless on iOS, and its made to be this way, again the "privacy OS" isn't privacy focused at all. https://www.michaelhorowitz.com/VPNs.on.iOS.are.scam.php https://www.michaelhorowitz.com/VPNs.on.iOS.are.scam.php
- CharlesW 4y agoFrom TFA: "Apple also said that the Always On VPN feature of MDM offers a fix. Mobile Device Management is over my head. […] According to Apple, MDM lets the corporate IT techies force all data leaving an iOS device to go to the company. But, MDM is is not available to consumers." There appear to be several easy-to-use MDM solutions that cater to small businesses that would also work fine for families. Apple even has one, Apple Business Essentials.
- sschueller 4y agoThat is like saying you can only lock your door if your neighbor has a key as well.
- WallyFunk 4y agoFor those looking for a workaround, you can get a VPN router in my case, a GL.iNet Mango[0] router. The great thing: even if the VPN connection drops, it doesn't leak your real/naked IP, and also /all/ traffic on an iOS device has to pass through the VPN. No special exceptions for Apple traffic. The only caveat is you have to carry this when traveling, which means if you're traveling light, carrying this around could be burdensome. If you are at home most of the time though, such a router is invaluable. [0] https://www.amazon.co.uk/GL-iNet-GL-MT300N-V2-Converter-Pre-installed-Performance/dp/B073TSK26W https://www.amazon.co.uk/GL-iNet-GL-MT300N-V2-Converter-Pre-...
- DavideNL 4y agoRelated ProtonVpn article: "We’ve raised this issue with Apple multiple times. Unfortunately, its fixes have been problematic. Apple has stated that their traffic being VPN-exempt is “expected”, and that “Always On VPN is only available on supervised devices enrolled in a mobile device management (MDM) solution”. We call on Apple to make a fully secure online experience accessible to everyone, not just those who enroll in a proprietary remote device management framework designed for enterprises." https://protonvpn.com/blog/apple-ios-vulnerability-disclosure/ https://protonvpn.com/blog/apple-ios-vulnerability-disclosur...
- mensetmanusman 4y agoThis type of feature is useful for places like China that need to imprison people that speak out against the ccp. Our tech overlords are not immune to pressures if we teach them how it is abused.
- egberts1 4y agoThat is why a detached but portable WiFi/5G router is for … to block these Apple shenanigans … While your phone is in Airplane mode and regular (but your router’s) WiFi only network
- londons_explore 4y agoAnd remember... This is WiFi. But over the LTE connection, which is far harder to sniff without very expensive equipment, it could be doing almost anything. And you can't even check what it's doing.
- flixing 4y agocan you not sniff it with services like nextdns?
- londons_explore 4y agoI assume that anything evil going on wouldn't use the configured DNs servers... Just like things also bypass the configured VPN...