Cloudflare 1.1.1.1 iOS app
itunes.apple.com
itunes.apple.com
I believe keeping VPN connected drains the battery because some of the device's chips cannot "sleep"
A VPN-based app also disconnects when going from Wi-FI to cellular.
Worse, when going from cellular to WiFi (ie: going back home) with a VPN on, the iPhone just keeps using the mobile network until the VPN is disconnected
These apps usually try to auto-connect to VPN but when your connection is spotty, it becomes a very annoying, you have to kill the app, disconnect the vpn manually etc
As user you're left manually putting the VPN on/off constantly if you're on the move
It's definitively not a "set and forget thing". I wish Apple could give a way for ad-blockers and this kind of apps to function normally without using a VPN as a crutch
The reason the “VPN” icon appears is because VPN profiles are how you override iOS network settings on unmanaged devices: which can include just DNS. Any time a profile is ‘active’, the icon appears.
You could generate your own unsigned profile to do the same, if you were so inclined.
- it automatically switches networks, both to and from WiFi
- it does not disconnect when switching
- the 1.1.1.1 app does not make anything more spotty or unreliable; it’s just DNS. Openvpn yes, but this app clearly not.
As for the battery issue: could very well be true, I have no idea how to test it.
The difference between this app and an actual VPN are clear from using it.
All that said, I don't need to VPN while at home to home network and prefer a little more granularity instead wifi or cell only. I believe this could be where battery drain would come from, at least in my case as the client constantly retries at home though it will never resolve the proper host internally cause I am lazy admin.
Not entirely true, in my experience it really fucks with your ability to connect to public hotspots (ex. airports, airplanes, trains, coffee shops) which took me a while to realize
It's not cloudflare you should blame here, but those providers
[0] https://itunes.apple.com/us/app/dnscloak-dnscrypt-doh-client...
I prefer DNS over HTTPS as some networks intercept DNS traffic, fail to parse the TLS-wrapped DNS payloads, and fail. DoH exists because DoTLS is prone to more interference.
As well as the configuration file for the script that comes with dnscrypt-proxy: https://github.com/jedisct1/dnscrypt-proxy/blob/master/utils...
a) your ISP can competently run a secure DNS service correctly (latency is not the whole story of 'performance')
b) it's acting entirely in your interests and not attempting to hijack your DNS service to insert ads etc.
Personally, I've had ISPs where neither of these things have been true.
Verizon owns Oath, Att owns App Nexus, Comcast has a whole suite of adtech companies & owns gigantic publishers. Time Warner literally started out in the sell side of advertising.
I've considered just creating a VPN back to my gigabit connection at home (running R715 in a homelab rack) but not super keen about the data making a round trip back home first, especially when travelling.
13:20:52 up 10:57, 1 user, load average: 0.00, 0.03, 0.00
I just restarted it 11 hours ago, but the load is never high for the two containers. Currently free -m is reporting 114/927 usedHaving the 1.1.1.1 on my phone is great except when I'm at home and want it disabled.
I don't trust them one tiny bit.
I fully understand disagreeing with Cloudflare’s decision to turn a blind eye towards what their customers are doing. I just don’t understand why this behavior means you “don’t trust them”. What do you think Cloudflare is going to do?
What they did was, one time and one time only, kicked someone off their platform for publicly advertising that Cloudflare supported their awful site. This was a unilateral decision made by the Cloudflare CEO because he was mad that they were saying that, and it's a decision that he admitted was wrong and said would not happen again.
So this wasn't about "censoring legal speech" but rather for the specific act of trying to publicly associate Cloudflare with white supremacy ideology, and it's something they've committed to not doing again.
Its the two-faced nature of it I object to.
Its private company - those can choose who they make bussiness with.
Also lets not forget they are nothing like carrier. Carrier laws exist because there is no possible alternative. This is just CDN we are talking about. You can quite easily replace it, even yourself.
From wikipedia: "Freedom of speech is a principle that supports the freedom of an individual or a community to articulate their opinions and ideas without fear of retaliation, censorship, or legal sanction."
A platform either supports free speech or it doesn't. Most of them do not. That's fine as long as we (and they) understand the difference between freedom and censorship. Freedom is awesome but comes at a cost, censorship is good too but comes at a cost...
And let's be clear, I'm not taking the stance that they shouldn't refuse service to hate speech websites, I'm saying that IMO they morally and ethically should strive not to provide service to obvious scams and malware websites either.
I really don't think that the "common carrier" angle holds any water. An ISP requires infrastructure and as a user you don't even have a lot of choice about which one you use. Even if you do have a choice it's not like you can change your ISP easily and quickly. That's why "common carrier" and net neutrality make some sense in that context.
Cloudflare is much closer to a web host than an ISP. You can still very much host websites that will be accessible by everybody without Cloudflare's help. If OVH hosted spammers and botnets and refused to do anything about it under the guise of "free speech" would we consider that a good thing? Is it really all that noble?
Would the problem here be more clear if Cloudflare did nothing when people use them to provide hosting services for child porn sites? Why do you think it's OK for Cloudflare to decide when to ignore the law and when to do something about obviously illegal content?
And we free persons are at liberty to disagree with their lime. Personally, their delineation seems self-serving and marginally scummy. (The service and this app are appreciated and used.)
But hey - if you want to pretend that a site which pretends to be Bank of America is somehow in some grey area, then by all means be a phishing apologist.
Also, while I certainly believe that some phishing site pretending to be Bank of America should be illegal, I’m not actually sure what law that would violate. Is it actually illegal or do you just believe that it it should be? And I’m not looking for “it violates copyright/trademark” as an answer, that’s a civil issue.
There is a reason why platforms like Cloudflare, Google and ISPs are against proactively moderating their own services; from a business standpoint it's an expensive and futile task (because it's dead easy for malicious actors to set up new sites and re-abuse the aforementioned services) and from a social perspective it's not Cloudflares job as a CDN to dictate what is and isn't socially acceptable.
Now just because Cloudflare have taken the decision not to police the internet that doesn't mean they cannot be trusted with your privacy. Those two points you're trying to equate are actually unrelated.
I am not saying you are wrong, but the decision is which provider do I trust the least? I personally do not trust Verizon Wireless at all and they know my real name, mobile phone number, address, and credit card number. Cloudflare does not have these validated data points about me, so maybe they are using my data in a nefarious way, but they don't have the other PII to go along with it. Perhaps they have a method to match my data requests to publicly purchased PII, but their matching is not already validated by me, so there is a chance for error fuzzing.
Most web hosts are going to be more strict than CloudFlare is, but you'll notice that most scummy sites use scummy hosts.
This app enables your DNS requests to be encrypted. Your requests are still seen by Cloudflare, of course.
Reason I ask... I have a one-tap shortcut to turn off WIFI and Bluetooth for leaving home. Would be awesome to turn off WIFI / Bluetooth / turn on Cloudfare with a single tap as I head out the door.
I don't need the battery drain from VPN usage while sitting at home, and already have my DNS routed away from my ISP.
Edit: After playing around a bit, with the CloudFlare app alongside Net Analyzer, DNS on cellular appears to modified from my cell provider to what I think is the CloudFlare VPN profile on the device with IP addresses 192.0.2.2, 192.0.2.3, 192.0.2.4.
Is Cloudflare also servicing internet requests or are requests still being serviced by the cellular providers after DNS is resolved?
I imagine this is a trivially simple way of snooping on an unsuspecting target. Let’s say you don’t trust your spouse. You install this app – showing them the security benefits as advertised by the application, letting them do their own research if necessary – then a day later come back and scroll through their DNS logs looking for cheatonmypartner.com.
- You need to be able to unlock their device without their knowledge to view the DNS logs.
- Therefore you know their PIN or have your fingerprint loaded (as I do on my partner's phone and vice versa).
- Therefore you can just install [any other tracking malware] and hide the icon in a folder somewhere. And now you don't have a VPN icon in the toolbar.
But does [any other tracking malware] actually exist for iOS?
Much easier would be to install a router with OpenWRT, set a DNS server (that your DHCP points to) and look at the logs. Or even running Wireshark in your own network should do the trick.
As long the DNS requests are not encrypt, you should got the information you want.
DNSCloak supports Cloudflare (among many other options), and has since day one. It will also let you choose how to steer DNS traffic, what domains to block and when, has a built-in cache to reduce latency, and more.
Short of installing & packet sniffing myself, or breaking apart the package; neither of which I have time to do.
(edit: to be clear, I’d love more options, including one that allows me to use Google’s DoH DNS, but I won’t blindly instal an app that intercepts my traffic, even if ‘just’ DNS)
1. You won't be able to configure real VPN, iOS allows only one VPN profile. Get a real VPN for native IKEv2 client you have.
2. It gives CF golden mine of your browsing history. It already has your traffic to many sites in plaintext, emails and passwords included
3. You trust the third-party app without the source code, probaly with access all your traffic
Cloudflare do both
I trust my UK ISPs ( Goscomb, AA.net ) to whom I pay a monthly fee for service more than I do some US-based company who wants to provide me a critical service for 'free'. And yet which at other times prevents me reaching websites with a 'One more step...' blocker page.
Having netflix.com is a lot more revealing than having an AWS block.
> “Cloudflare will never sell your data or use it to target ads. Period.".
https://www.producthunt.com/posts/the-1-1-1-1-app#comment-69...
>According to Apple, Future Mind's AdBlock app violates section 4.2 of the App Store Review Guidelines, which dictates that apps must be useful, unique, and "app-like."
‾\_(ツ)_/‾
Some Ad Blockers are implemented as VPNs. This is unfortunate, and they should use the Safari Content Blockers interface instead. Content Blockers cannot intercept or sell your content, since the code is sandboxed and doesn't get network access. NeverAds seems to work well for me.
"Best of all: No upsells, no in-app purchases, and free for life. Website owners pay us to make your Internet faster so you don’t have to."
That sounds totally against net neutrality to me. Unless website owners are not getting preferential speed up.
That’s part of why this app is in CF’s interests.
This SO post seemed to give a lot of details if you need it
https://stackoverflow.com/questions/9555403/capturing-mobile...
Good luck!
I could be wrong, though, since the NetworkExtension would have to be written in Swift, so I don't see why they wouldn't just write the rest in Swift and/or ObjC... would be happy to be wrong actually.
you can run your own easily
just connect to roots
/s