iOS VPNs have leaked traffic for years, researcher claims
arstechnica.com
arstechnica.com
The author of WireGuard lamented that certain network pathway must be preserved for existing Apple infrastructure before WireGuard app can be approved and made available by Apple App Store.
So, there is no easy way to catalogue what kind of cellular data traffic unless we magically ran a network capture (WireSHARK) at cell tower level or root our iOS phone.
I do do know for iOS phones that cellular data traffic is drastically different than LAN-based WiFi traffic.
A side loaded app would still be beholden to the OS networking stack.
Multiply “you” by all possible “yous”, multiplied by downsides of “just install an app” not vetted, for those “yous”. What’s the net effect on total privacy or safety of all yous out there?
If “you” are here on HN, odds are you are a vanishingly small part of the venn diagram of yous that should inform an iPhone PdM’s thinking on this issue.
EXCEPT, of course, for the NPS (net promotor score) / influencer aspect of you. Because we’re still in an era where the IT person in a circle causes others to make choices. HN users still have a disproportionate voice in tech trend setting.
But, as that person, you also have a responsibility to advise in well considered ways that help the person being advised, not yourself. As engineers, our entire purpose is to pay a blood/sweat/tears price to make technology accessible and useful to non-engineers.
You know what to do. They don’t. This device is for them.
Why not replicate that (IMO) success?
Because if I understand GP correctly, they are talking about the ability for devs and white hats to install software which enables debugging and logging so it becomes much easier to find stuff like this?
We have two models. People who like one can choose that. People who don’t can choose this. Sometimes solutions have multiple equilibria.
Of course there is. Facebook and Oracle would immediately have some mandatory spyware you’d need to install. Curtailing developers’ freedom is a favourable choice for many consumers. Apple reflects that market pressure. (Android, its inverse.)
https://developer.apple.com/documentation/network/recording_...
It said so in the article you commented on:
iOS doesn’t let you record a packet trace directly.FWIW, this capability IS available to individuals using the free Apple Configurator application. The only catch is you'll need a machine running the latest MacOS to run the latest Apple Configurator.
How does this interact with public wifi captive portals, which often are a barrier to get online in the first place? A pretty common need would be to click through the public portal, sometimes dealing with email verification links or Facebook logins for those portals that require identifying oneself, and then to want 100% of traffic after the Internet connection is open to go through the VPN.
In other words, road warriors with security concerns need a solution that is NOT always-on but is comprehensive when on. Apparently iOS doesn't support this as per the article, and the always-on MDM suggestion isn't that either.
"VPNs on iOS are a scam" - https://news.ycombinator.com/item?id=32488308
https://john.kozubik.com/pub/NetworkSlug/tip.html
"A Network Slug, or "Slug", is a transparent layer 2 firewall running on a device with only two interfaces ..."
"So, while the device participates on the physical layer of the (probably ethernet) network, it does not have an IP address and cannot answer IP (or even ICMP) requests ..."
In my case, if I needed a VPN, I would use the excellent 'sshuttle' on, for instance, port 40 and then set the slug to allow only TCP port 40 and nothing else.
No misconfiguration possible. No footguns.
What distinguishes a "slug" is that it is not on the TCP/IP network - you cannot connect to it - and it acts as a "dumb" chokepoint that cannot be misconfigured or attacked or co-opted by other actors or software.[1]
Further, it is a physical, wired device with exactly two ports so you can conceptually witness - with your eyes - how your traffic is locked to whatever VPN you may be using.
[1] Yes, of course it can but when we think of a layer 2 bridge with no TCP/IP connectivity being attacked by a remote actor ... we're bordering on science fiction. For what it's worth, the FreeBSD filesystem I use on my slugs is mounted read-only. Defense in depth.
https://john.kozubik.com/pub/NetworkSlug/
... and this is the body underneath:
https://john.kozubik.com/pub/NetworkSlug/body.html
... and that is where you can see some details of what a "slug" looks like and how they may be set up, etc.
There's no such configurable firewall on iOS or Android so you just have to trust that the system VPN interface is watertight.
https://news.ycombinator.com/item?id=24838816
https://news.ycombinator.com/item?id=25109724
(this was reverted after backlash)
There is some pseudo netdev being used for tunneling into Apple Network infrastructure and they are blockable.
In addition to unimpeded Apple network pathway, DNS resolver is being resolved by Apple DNS recursive DNS server during your tunneling setup, arguably resolving even just the IP address(es) as well as DNS names of VPN server.
More on this sad saga of Apple iOS and VPN, et. al.:
https://www.michaelhorowitz.com/VPNs.on.iOS.are.scam.php#whe...
Edit: of course, an external router would only leverage the WiFi part of iOS. We could use just the WiFi part of iOS and totally ignore the mysterious cellular traffic.
Why not?
Since the slug is invisible, and has no IP address, and runs no daemons, etc., the only misconfiguration possible would be the initial one.
Once the slug is in place, there is no more "accidentally didn't use the VPN..."
No surprise with IOS, and I am rather sure the same can be said for Android. Cell Phones are closed systems, so the manufacturers can get around anything and probably do a good job of hiding this too.
If you want to hide yourself, never use any Cell Phone.
https://www.michaelhorowitz.com/VPNs.on.iOS.are.scam.php
This includes WiFi as well.