VPNs on iOS are a scam
michaelhorowitz.com
michaelhorowitz.com
In this case, iOS will always wait until connection to VPN is established before sending any packets out.
Without on-demand, VPN may leak.
If I remember correctly, leaks occurred mostly after waking from sleep but before the tunnel had chance to be set up. Or in similar situations. Anyway, on-demand option solved all of them.
Any other VPN is just best effort.
https://support.apple.com/guide/deployment/vpn-overview-depa...
The fact that a VPN server can send you a route for 0.0.0.0/0 always was and always will be a happy accident.
This. And the idea that these so called ‘VPN’ services somehow improve your security and privacy on the internet is laughable. All they do is let you get onto the public, untrusted, internet through a different on-ramp. There is no point to them. The internet is just as untrustworthy through a VPN service as it is through any other internet connection.
What about this?
"Under the provisions of the Investigatory Powers (IP) Act, it is now possible for the Law Enforcement Agency (LEA) community to lawfully obtain Internet Connection Records (ICR) in support of their investigations. Following the completion of some initial trial activities, work is now underway to provision a national ICR service."
https://www.digitalmarketplace.service.gov.uk/digital-outcom...
The other concept I’ve heard put out is to add layers - your traffic hits Vultr, then Hetzner, then etc etc. Conceivably if you cross enough jurisdictions you can make it very difficult for a legal adversary to attack your traffic.
Would I bet on this for activities I needed to remain exceptionally private? No - but if I needed relatively consistently low latency traffic and a decent baseline of privacy it might just work.
Not true, at all. There are several good reasons to use VPNs to get a different on-ramp to the otherwise untrusted internet.
- Avoid ISP tracking: Your ISP should see only traffic to and from the VPN.
- Access content intended for those in other regions: Many sites and services only show certain content to people who enter the internet from specific places.
- Limit the amount of activity linked by trackers: Visiting certain sites only from different IPs/browsers will help keep logs of that traffic isolated from the logs of your other browsing.
- Allows you to connect to sites and services that cannot connect back to you once you've disconnected: A lot of people, even those with dynamic IPs, keep their address for months or years at a time. VPNs provide a great way to cycle through IPs.
VPNs don't solve every problem, but they're a powerful tool to keep in your tookbox.There are many many very valuable uses for VPNs some that offer privacy/security benefits and some that are just plain useful. It's wild to hear anyone say that "There is no point to them."
No it's not gonna make you an invisible unhackable ghost, but at least I don't have to worry about my ISP screwing me over.
What I can switch however is what VPS company I use, or what commercial VPN I connect to.
Plus, the harm from being banned by a VPN is a lot lower than an ISP, as low as the chances of either are.
And your "VPN in YouTube ads" surely does that
Yeah, that's the point. People have infinitely more choices for VPN providers than for ISPs. The VPN provider could be in another country. You can even run your own VPN on hosted infra.
True. But we know very few people do that
This comes with its own risks and you lose some advantages of a commercial service, such as being "lost among the crowd" of other VPN users.
Again though, if the US Government is a potential adversary, there's still risk here. Intelligence services could have a 0-day on your linux distro, or an operative within the hosting company. If they get access, they can turn your hosted VM against you.
Though a point has to be made about using a hosted VM for VPN purposes, you have some level of control about which specific software, configuration and encryption schemes etc. you want to use for your stack. Only downside is that currently there isn't sufficient hypervisor protection from the host kernel afaik.
However I do agree with you that either way, the risk threshold is too high if you are concerned about high level state actors. Neither commercial VPNs nor hosting providers can solve the "anonymity" problem for you.
And you are sure your connection to a VPN service won't get you flagged ?
Sure, you'll probably end up facilitating a few petabytes of copyright infringing torrent traffic every day, but you'll also have a direct connection to countless people who think they're totally anonymous.
This is the best part really. No three letter agency is going to spoil their honeypot in order to bust some kid for downloading movies and video games. They've got bigger fish to fry. The more successful they are at keeping their users safe from the copyright goons the more popular and "trustworthy" their little honeypot will seem. Your downloads will still probably earn you another black mark in your dossier, one more thing they could use against you if you ever became a problem for them, but still, free movies, music, and games! Might as well make oppression work for you.
Huge benefit in my opinion.
Can you eli5 that please?
It is possible to encrypt SNI, but most sites do not support that as the setup is non-trivial and error-prone.
So HTTPS doesn't really stop tracking, it only prevents people from snooping on what data you are sending to and receiving from the website
But then in practice for ESNI to be effective one needs for the site to use CDN or similar solutions to ensure that there are a lot of sites for the given IP.
I trust Mullvad more than I trust Optimum.
So yeah, it's a kinda a big deal if it leaks. (Which is why most privacy experts, were you to tell them you were sufficiently paranoid, would have you fire up a pfSense and link it permanently to a VPN service and then run a separate brand of VPN software on whatever device, so that you have two layers going through two companies.)
I also do this type of work on the side. When it matters a device level VPN is never the correct option, because every OS leaks to some extent. They get a device where the cellular components have been disabled and it can only connect to a fixed wifi AP carried by one of their EP guys that tunnels the traffic back to a datacenter.
Actually, they do: Neither your ISP nor the government (assuming the VPN provider is in a "hostile" jurisdiction) can intercept, analyze or modify your Internet traffic when you are using a VPN to mask your Internet access. There have been multiple instances of this in the past [1][2] and ongoing (e.g. DNS [3]), and ISP "middleboxes" have been historically the biggest impediment in rolling out new features.
Ubiquitous HTTPS has shut down a lot of that shit, but until DNS-over-HTTPS becomes actual mainstream DNS (and SSL SNI!) will still leak a lot of information to entities that have a direct financial interest in collecting, packaging and selling this data to advertisers - there is a reason why ISPs oppose any legislation that turns them into "dumb pipes" after all.
Security-wise, at least if you are using any kind of untrusted network (e.g. university campus, public hotspots) a decent VPN software that uses the OS-provided firewall to completely drop any incoming and outgoing packets except for the VPN tunnel connection is also a massive benefit.
The downside of course is that you are now forced to trust the VPN provider instead of the ISP - but at least the VPN provider market is healthy and extremely competitive, which means any sort of shady bullshit would be a virtual death sentence, unlike the ISP market where you are in many cases stuck with one or two options.
Not to forget, VPNs also provide privacy on the "other end": as many providers don't cycle through IP addresses sometimes for months, advertising providers can track your movement across the Internet simply by collecting your origin IP. A good VPN provider regularly changes the origin IP visible to sites you access.
[1] https://www.privateinternetaccess.com/blog/comcast-still-use...
[2] https://labs.ripe.net/author/babak_farrokhi/is-your-isp-hija...
[3] https://www.csoonline.com/article/2953718/t-mobile-caught-in...
No, you're just delegating those capabilities to some completely unregulated random actors instead.
> which means any sort of shady bullshit would be a virtual death sentence
This assumes that their shady bullshit is discovered by someone. I would bet good money that the vast majority of it isn't. They could be sampling traffic and selling it to other companies without modifying it and users would never be any the wiser.
Honestly, I wish we could get past this broken narrative that VPNs are a panacea.
It's a question of trust in the end. Telco providers not just in the US but across the Western world have shown time and time again that they cannot be trusted: traffic manipulation, DNS hijacking, selling data to the highest bidder [1], engaging in open corruption to prevent competition, predatory sales tactics, fee scams, peering extortion [2], misappropriating government funds [3] - name the act and you'll find a dominant ISP having done or still doing that practice.
VPN providers generally don't have that baggage attached.
> This assumes that their shady bullshit is discovered by someone. I would bet good money that the vast majority of it isn't.
I agree, but at least the incentives are aligned completely different than with ISPs. The large ISPs can do whatever they want, even breaking the law, because their consumers have no other choice - rural ISPs will get competition from Starlink soon enough, but people in condos? They're stuck with whatever the landlord offers, and the landlord won't care even if there is competition as long as the monopoly ISP pays higher kickbacks.
[1] https://www.ftc.gov/news-events/news/press-releases/2021/10/...
[2] https://www.heise.de/hintergrund/Missing-Link-Regulierer-vs-...
[3] https://eu.jsonline.com/in-depth/news/2021/07/14/weve-spent-...
This is true, although there's still a very large risk element here. The average person is not likely to be able to safely determine which VPN providers are trustworthy or not. They also aren't likely to understand their limitations, i.e. they don't grant you perfect anonymity, they don't grant you perfect immunity, they may or may not capture the traffic that you intended or thought.
In that case, is it really a good thing for VPN internet provider usage to be on the rise? All we're seemingly doing is handing people more guns to potentially shoot themselves in the foot with.
ISPs, for all of their transgressions, tend to be registered and regulated companies and that makes it much easier to at least find someone to target with legal action if needs be. The bar might be low but there are some standards to which they have to adhere to. Many VPN providers are nameless and faceless "organisations" with little-to-no regulation or responsibility. It's difficult to know if they take your privacy seriously, whether they are taking adequate precautions not to log, to not leak data or to adequately secure their systems.
Hell, it's entirely possible that your VPN provider is actually just an FBI honeypot on the lookout for people who are only actually using a VPN service because they have something to hide. How would you tell if they were?
I just don't really buy the argument that having different incentives means they are any less likely to be nefarious or negligent.
This is exactly the problem with VPNs, they give you a false sense of security. When your traffic goes over the public internet, you should assume everyone and their grandmother can track it. So the traffic cannot be intercepted at your ISP, that only leaves a billion other places where it can be intercepted.
> The downside of course is that you are now forced to trust the VPN provider instead of the ISP
No. The point is neither should be trusted.
There might be no point to their security and privacy, but they are still good for getting foreign-country Netflix.
A VPN solves this, and does protect your privacy, so your comment is just needless hyperbole.
I recommend VPN services in regions where legislation of your home country might difficulties getting data.
what people expect, and what is being sold, is an encrypted tunnel that all traffic goes through, to an endpoint. That this is called "VPN" is irrelevant.
I have a GL-iNet Mango that i have setup to provide "always on wireguard" to a computer in a datacenter i control the public IP for. I haven't tested, but i expect all data sent to and from any devices connected to that Device's SSID to be tunneled via wireguard to the computer in the DC, and therefore, to all outside observers the DC is where my device is. Obviously the ISP can see the session, but since they have no say over the DC endpoint, they have no way of knowing what the traffic is or where it's going. It could just be me doing SSH or video streaming or backups to and from the datacenter, or i could be watching netflix or youtube.
In that circumstance, an iOS device shouldn't be able to leak my local network's ostensible "public IP", since the actual transport layer is outside of the iOS device's control.
With all of this being said, i don't think there's any way to guarantee that leaks are impossible without literally air-gapping your devices and forcing all traffic through something that cannot communicate with anything but the remote endpoint - that is, if the wireguard connection fails, all pings fail, all TCP/UDP/etc traffic times out, and so on. In this manner, probably all things sold as "secure VPN" or as a service that does that are scams. This is the issue that TFA is complaining about.
in a situation where it's life and death - i would find an open wifi access point and connect a wireless bridge device (e.g. tp link TL-WR802N), with an STP ethernet cable to something similar to the gl-iNET mango, with 100% forced wireguard connectivity. I'd only consider this viable after doing tshark or tcpdump on the server i control log access to, to verify that my (local) MAC address and/or stuff like webrtc or whatever are blocked/dropped.
sorry for the length, but i didn't want to make multiple comments all over the threads.
To be clear, is what you're saying that it is ok for VPNs to be broken (or at least less bad) because their most popular usage isn't what they were originally intended for?
If that wasn't your point, what was?
While you could only route client traffic to an intranet endpoint and prevent access to any external services, that wouldn't be very practical in most deployments so a proxy is added on top. This type of deployment is common and has been used for decades.
ios/ipad: https://apps.apple.com/us/app/wireguard/id1441195209
Fwiw the existing app integrates seamlessly into the apple ecosystem.
Consumer VPNs typically aren't.
Considering the added benefits of taking your other desktop Linux security configuration to mobile, A Linux mobile could be a viable choice for those who need reliable transparent security.
Kind of a big deal that likely 90%+ of iOS VPN app users assume they're private when they're not. False advertising IMO, and Apple is getting their 30%.
Also, just checked Mullvad, which seems to open an IPSec server on your local device and then install a vpn config on your ios device. From the local IPSec server a connection is made to mullvad via wireguard. On-demand is also enabled by default.
But yea, VPN were initially targeted at enterprises anyway. So I don’t mind that i actually have to install vpn profiles by hand.
As far as I can see the linked page doesn't say that your VPN will leak unless you're using Always On.
Plus, that page documents the VPN features built in to iOS itself, not VPNs provided by apps.
That's discussed in the article.
Also, the supervision requirement for always on VPN is a stronger limitation than lockdown mode; you have to erase the phone to supervise it.
Configuration profiles are however how you force DoH or disable certain privacy leaks from phoning home to Apple. There are no UI settings for some of the important ones.
But it’s good to know that there are leaks, anyway.
PS. And I guess all VPNs use the same base VPN functionality provided by iOS, so “is” looks a bit more appropriate than “scam”.
...and that's when you realise that trying to configure a device to which you do not actually have full control of is a futile endeavour.
As such, in agreement with many of the others here, I don't consider this much of a bug nor a "scam". It's merely an effect of what VPNs are (an additional network interface) and how routing works, combined with a device whose manufacturer deliberately does not want to put users in full control of the routing table.
If you give the device a static DHCP lease, then you can block it from 0.0.0.0 and allow it to your VPN provider's IP blocks.
You might want to give the device its own WiFi network if you don't trust it to honour DHCP
Apple doesn’t really care about preserving your privacy from Apple (and by extension the FBI).
They maintain backdoors in iMessage specifically to preserve the ability of Apple/FBI to read your messages:
https://www.reuters.com/article/us-apple-fbi-icloud-exclusiv...
The fact that Apple OSes leak your true IP (and thus city-level location) to Apple around your VPN is not an issue to Apple; it may even be intentionally preserved this way to aid investigations.
I tend to agree. My only takeaway after seeing that was “if I ever need a 100% leak free tunnel on iOS, validate it”. I certainly won’t be taking any of this at face value without replicating it.
Probably not, but if, in the middle of trying to diagnose my car, someone pointed to the muffler and said "I'm not sure what this thing's for." I probably would look for a second opinion on their diagnosis especially if it was "there is a major manufacturing defect in this model of automobile". It doesn't matter if the problem looked like it was staring us in the face.
Obviously I can't spot any major flaws with what the writer put together after a single read or I'd be pointing them out. I'm not calling it wrong. I'm just saying I'd want more verification from someone that has a better understanding of networking concepts to make it less likely that basic mistakes impacted the outcome.
If the write-up has given you enough confidence, all the power to you.
i would not expect it to work like that
i’d think my traffic is protected, why protect it twice
Also: if Settings says you're connected to a WiFi network, but you don't see a WiFi icon at the top of the screen, I think that means there's no working Internet connection.
The rules on aircraft changed, so the feature was updated.
Yup.
Enough points (APNS is always connected, so whenever your phone is on) and this uniquely identifies you (even if the serial number wasn’t bought with your own credit card).
Then they have to give it to DHS/ICE/FBI/CIA without a warrant on demand, thanks to FAA702.
They, of course, already have all of the cell tower association records, as well as all of the Secure Flight program data from the TSA. It’s not a difficult query to figure out which serial numbers are which IMEIs are which humans.
https://adguard.com/en/adguard-ios-pro/overview.html
But other choices are available too.
Using iOS's built in support for browser adblockers is largely as effective and doesn't come with the battery life hit.
I use the free tier.
There are more serious problems though, with any app being able to bypass VPN simply by prohibiting Wi-Fi interface and iOS gladly letting all traffic via LTE, unfiltered. That's been described in https://blog.disconnect.me/ios-vpn-leak-advisory/.
It's well known and pretty sad that these issues go unaddressed for years. VPN developers have little power to change that given that VPN apps run in a walled garden of Apple in a sandboxed environment. Hence the the best effort at this point with a hope that this can addressed in the coming updates.
It would be great if more of these pop up on Apple forums and Apple Feedback with people demanding improvements on transparency and privacy from the company.
So far reading your blog post looks like a recollection of what's been going on.
I really wanna throw an analogy of a bear waking up from hibernation. This is not sensational and just reiterates what's been said before you, yet the title throws a shadow at VPNs just to sound like it.
[1] https://developer.apple.com/documentation/networkextension/n...
Yeh… Apple, Five Eyes, Privacy is all pretty much an illusion when you have this many devices in this many pockets. Whatever it is, vpn’s or end to end encryption, it’s all really only as secure as the touch screen controller telemetry logs.
To be clear, I mean the big VPNs that advertise themselves as helping with privacy are actually a scam.
There are obviously some situations and use-cases where using a VPN makes sense (e.g. geo-shifting), but as a general solution for privacy on the internet they make no sense.
Also, regarding the UDP datagrams seen after the IKE exchange, maybe relayed to NAT-T?
It is is interesting how the iPad purchaser refers to "my iPad". He owns the computer. But how much control does he have over it. He runs an OS controlled by a HW manufacturer turned trillion dollar tracking and data collection company. (Apple computers are extremely chatty on any network and phone home 24/7. Apple is fervent about its need to collect and store data from purchasers.^1) As such, he cannot find the problem in the iOS source code, remove the phone home "features", re-compile and reinstall it. The best he can do is complain to the internet.
I have owned various Apple computers over the years, including an iPad. However I never used any Apple computer with an Apple OS for internet use.^1 I only connect them to the LAN. I just think there are better OS, namely ones I can edit, to use for internet-facing computers. For internet usage, I like OS where I can control the routing table. Since I started keeping these computers running "consumer OS" off the internet in the 2000s, the internet has become a vector for pervasive surveillance. I treat computers running Windows the same way. No direct internet access.
In the 1990s/2000s I can recall the "experts" advising against leaving computers connected to the internet when not in use. Today, "tech" companies try to compel people to leave their computers connected 24/7. Not to mention "experts" who believe this is justified because "automatic updates". Granting 24h remote access to unknown people to install software on computers that do not belong to them. Some people call this a "botnet". I do not care for broken software that continually needs fixing. But as the author alludes to when he quotes Steve Gibson, iOS is never broken, it just has not been fixed yet.
1. Today's Apple computers require some connection in the beginning to "sign-up", "register", download "approved" software, etc.
2. Apple computers owned by employers excluded. Also excluded are older Apple computers on which I ran NetBSD.
There is a lot of wisdom we've thrown away from those days. Software phoning home was viewed as malicious and there were lists of applications that did it to shame companies and warn others to stay away. Pretty much every OS and major application today would rightly have been considered Spyware.
If we'd kept "Never use your real name/info on the internet" the world would be a better place. The rule allowed for E-commerce so we'd still have amazon, but facebook and all its problems wouldn't exist.
Pop-ups were considered evil, and we fought to stamp them out but today the same annoyance is commonplace and accepted, they just show up as modal windows and cookie banner notices.
This comment is a gish-gallop RMS-y soapboxing which is largely irrelevant-to-the-article points: that iPads (possibly all iOS devices) only pass some of their traffic over a VPN connection.
This stuff is up to whoever has root on your device, be it Apple or eg. bad guy exploiting 0day in captive portal, but certainly not you.
I believe that is not the case. It is strongly suggested during the sign-up process, and some functionality depends on it, but it is not required, as far as I know.
Trying to read through the whole thing, I can't tell if if this is claiming:
a) When a VPN is activated, pre-existing connections will continue communicating outside the VPN, but all new connections happen via the VPN
b) Apple services like the app store and/or certain other apps leak outside the VPN because of a) more than you would expect
c) Apple services like the app store and/or certain other apps leak outside the VPN for other reasons totally unrelated to a)
The author's tl;dr just says "data leaks" but I really just can't follow what that actually means.
It seems like a) is not entirely unexpected or necessarily a problem -- you probably turn on a VPN before initiating activities/apps you want routed through the VPN, so not usually problematic? But b) means it might be more serious than that, while c) would be even scarier?
This means the Apple APNS client IP logs relate directly to your tracking serials and both your VPN and non-VPN ids, linking them.
They also contain your non-VPN IP history, which is your travel history, as client IP is city level geolocation.
> I am not a fan of making a VPN connection on your only router, but suggest having a second router dedicated to VPN connections. When you need a VPN, connect to the second router (Wi-Fi or Ethernet), when you don't need a VPN, connect to your main router.
Aka, don't use a device with two network sockets if it is critically important to avoid using one of them.
So, when apps can communicate from iPhone->Watch, even with a perfectly functioning VPN on the iPhone your public IP can leak via the Watch (if the app is also installed on the Watch.)
The vast majority of people use them for IP spoofing.
Site: https://defensivecomputingchecklist.com/
Discussion: https://news.ycombinator.com/item?id=32490866
Networking is dynamic it takes many sequential steps to configure. There is no ZAP, it is done. I don't know of an OS that locks out "user programs" until configuration is complete. Yeah, since networking is dynamic that could never work -- "user programs" would be locked out forever!
At the start of the First Test there are packets going to non-tunnel locations at the same time the VPN is being set up, not a surprise. Packet ordering / routing at this time granularity is also not surprising.
Need to take a moment to review the "drop everything" when a VPN is up standpoint. OS Networking stacks don't really understand what a VPN is, it is just an endpoint to route packets. A TCP connection has internal state that is bound to the addresses that were used when it was set up - which is tied to the state of the routing table. A new point-to-point endpoint, like a VPN would invalidate that state. Most (many?) TCP/IP stacks keep a cache of the initial route on the socket. As long as that is still valid (or updated), that is where the packets go. Killing TCP connections for every (temporary) network flap would make a lot more people MAD.
The "DNS" to NextDNS with DoH connection is interesting. This 100% isn't coming from iOS itself. It doesn't support it. So it must be coming from an App. But what app and how? There is a NextDNS app which up front claims "Encrypt all DNS queries on all networks with the official NextDNS app for iOS". The author does appear to have configured the router to use NextDNS, perhaps they also have that App installed as well and it is also hijacking networking to do DNS? A dunno.
The "flood stuff" is interesting, but I think it might just be an attempt to perform STUN to make sure UPD traffic can be transported - to Apple endpoints. I think "second test" is the same thing happening again.
So what is left is the traffic being sent to apple endpoints. Now I wonder how the VPNs the author is using are implemented. The Big Sur VPN brouhaha was because apps were trying to implement a VPN using NEFilterDataProvider instead of a "tun" interface and routing. I wonder if this is just the same issue but on iOS.
Not related, but I do wonder what these VPN services offer in terms of "Firewall" protection or if when you use them ALL ports are forwarded to your device. This would make all of their endpoints a "great target" for continuous scanning for getting inside a network if the VPN user had something misconfigured, like say an experimental Apache, Nginx, PHP, Rails, Django, MySQL project. Doh. Methinks I should spend some currency and experiment. Sadly black-hats are probably already doing this.
* vpn gateway address can be different from public vpn exit address. What is the surprising part?
* I don’t know what pings your “uncloaked” public ip address, but still, when using a vpn, you’re using your own ip address to connect to the gateway. So, there’s no real leak - it would be a leak if some packets went _through the vpn_ to 99.99.99.99, because an observer could spot the strange ip and determine it’s the uncloaked source address.
Anyway: who can tell what an iphone or ipad can do? You probably have an associated apple account, et cetera. If you trust such a device for total anonymity, you’re doing it wrong from the start. Pick a Linux laptop for that.
I think it greatly depends on your threat level and who you're hiding from.
Mac OS route selection always takes into account the source address of the IP packet in addition to the routes in the routing table.
If a socket binds to a particular address, the Mac OS kernel will choose routes associated with the interface that address is on and ignore the others.
I would argue that's the only "sane" way to do it, but then again i'm no network engineer. I just rely on my devices to work this way so i don't saturate the wrong links or get poor upload speeds when i need them.
On an Android (like on iOS), both WiFi and Cellular interfaces can be active at once. Apps (with appropriate permission) are free to bind to either.
> ...all existing connections stop and must be refreshed.
On network changes (in particular address changes), TCP connectivity may break. SCTP / QUIC / UDP (and UDP-based protocols like WireGuard and MoSH) should continue to work just fine.
https://blog.cloudflare.com/warp-for-desktop/
> WARP was built on the philosophy that even people who don’t know what “VPN” stands for should be able to still easily get the protection a VPN offers.
Is the page not clear about that?