Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    iPhone: Privacy Warning

    Scheduled Pinned Locked Moved DHCP and DNS
    20 Posts 6 Posters 4.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • johnpozJ
      johnpoz LAYER 8 Global Moderator @AndyRH
      last edited by johnpoz

      @andyrh said in iPhone: Privacy Warning:

      IMHO on my trusted network is not the time or place.

      Exactly!! Here is my shit ipad thinking it can use apple doh servers

      doh.jpg

      I resolve to a BS IP that I block and log..

      dohdns.jpg

      Not shown is also my stupid iphone trying the same nonsense..

      An intelligent man is sometimes forced to be drunk to spend time with his fools
      If you get confused: Listen to the Music Play
      Please don't Chat/PM me for help, unless mod related
      SG-4860 24.11 | Lab VMs 2.8, 24.11

      1 Reply Last reply Reply Quote 0
      • E
        ericafterdark @AndyRH
        last edited by

        Well, I deleted the network ('forgot' as Apple calls it) and reconnected. Result: no more warning. For now I guess.

        Maybe activating SSL/TLS Service on the DNS Resolver did fix something after all.

        johnpozJ 1 Reply Last reply Reply Quote 0
        • johnpozJ
          johnpoz LAYER 8 Global Moderator @ericafterdark
          last edited by johnpoz

          @eirikrcoquere said in iPhone: Privacy Warning:

          Maybe activating SSL/TLS Service on the DNS Resolver did fix something after all.

          I don't think so - the gui would setup dot and not doh. And to point your iphone to your own server running doh or dot you would need to create a profile you load, etc.

          I do believe that unbound can do doh, but I do not think setting it up is exposed in the gui.. That is for running a local dot server.. And I also believe that unbound has to be compiled with the ability
          "--with-libnghttp2" Which I do not believe the version on pfsense has?

          But unless you setup the profile you loaded on your phone, I don't see how it would point to your local unbound running on pfsense be it dot or doh. There is I am sure apps you could install that point your iphone to some service doing dot or doh. like cloudflare, googledns, etc. But I do not believe without loading your profile you could point to some local dot or doh server you were running. Unless there is some app I am unaware of that makes it easier then loading the profile you create.

          Keep in mind there also difference between forwarding your unbound to a dot server, and running dot locally, or doh.. Forwarding to a dot server would not prevent your phone from showing you that privacy warning. Now it might have gone away when you forgot the network, but most likely the warning will come back if you are blocking it from talking to the apple doh server.

          For reference
          DOT = dns over tls which by default uses 853, but can use other ports
          DoH = dns over https which by default uses the standard 443 port, but also can use other ports as well.

          Neither of which really provide any privacy in the big picture because your isp can still see where you go via IP, and even when you go to https until such time that encrypted sni is actually a real thing they can see the sni your going to in the tls handshake, etc.. So while they might not easy get your dns queries they sure know the fqdn your going to for your https traffic, and anything in the clear, etc. So your not really actually hiding anything from your isp in the big picture.

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 24.11 | Lab VMs 2.8, 24.11

          E 1 Reply Last reply Reply Quote 0
          • bingo600B
            bingo600
            last edited by

            I still have to "Block DoH" in pfSense.
            Does anyone have a "neat" url to a "decent Recipe" ?

            I do have this on my piHole though , and my phone vlan uses the piHole for resolving.
            ca9b9a7e-6d8b-4e19-bcc0-6df011e0915f-image.png

            /Bingo

            If you find my answer useful - Please give the post a šŸ‘ - "thumbs up"

            pfSense+ 23.05.1 (ZFS)

            QOTOM-Q355G4 Quad Lan.
            CPUĀ  : Core i5 5250U, Ram : 8GB Kingston DDR3LV 1600
            LANĀ  : 4 x Intel 211, DiskĀ  : 240G SAMSUNG MZ7L3240HCHQ SSD

            1 Reply Last reply Reply Quote 0
            • E
              ericafterdark @johnpoz
              last edited by

              @johnpoz said in iPhone: Privacy Warning:

              @eirikrcoquere said in iPhone: Privacy Warning:

              Maybe activating SSL/TLS Service on the DNS Resolver did fix something after all.

              I don't think so - the gui would setup dot and not doh. And to point your iphone to your own server running doh or dot you would need to create a profile you load, etc.

              I do believe that unbound can do doh, but I do not think setting it up is exposed in the gui.. That is for running a local dot server.. And I also believe that unbound has to be compiled with the ability
              "--with-libnghttp2" Which I do not believe the version on pfsense has?

              But unless you setup the profile you loaded on your phone, I don't see how it would point to your local unbound running on pfsense be it dot or doh. There is I am sure apps you could install that point your iphone to some service doing dot or doh. like cloudflare, googledns, etc. But I do not believe without loading your profile you could point to some local dot or doh server you were running. Unless there is some app I am unaware of that makes it easier then loading the profile you create.

              Keep in mind there also difference between forwarding your unbound to a dot server, and running dot locally, or doh.. Forwarding to a dot server would not prevent your phone from showing you that privacy warning. Now it might have gone away when you forgot the network, but most likely the warning will come back if you are blocking it from talking to the apple doh server.

              For reference
              DOT = dns over tls which by default uses 853, but can use other ports
              DoH = dns over https which by default uses the standard 443 port, but also can use other ports as well.

              Neither of which really provide any privacy in the big picture because your isp can still see where you go via IP, and even when you go to https until such time that encrypted sni is actually a real thing they can see the sni your going to in the tls handshake, etc.. So while they might not easy get your dns queries they sure know the fqdn your going to for your https traffic, and anything in the clear, etc. So your not really actually hiding anything from your isp in the big picture.

              Ah, that is true. I am not working with profiles on my devices so I can safely disable that functionality again.

              Still I think it is weird that Apple is displaying that warning. I have a default straight forward setup. It's not like I am filtering anything on the pfSense. It's plain old DNS Resolver at work with default settings.

              johnpozJ 1 Reply Last reply Reply Quote 0
              • johnpozJ
                johnpoz LAYER 8 Global Moderator @ericafterdark
                last edited by

                @eirikrcoquere said in iPhone: Privacy Warning:

                It's plain old DNS Resolver at work with default settings.

                Well does that fqdn resolve? There is AAAA for it.. So maybe just having issue with your IPv6..

                An intelligent man is sometimes forced to be drunk to spend time with his fools
                If you get confused: Listen to the Music Play
                Please don't Chat/PM me for help, unless mod related
                SG-4860 24.11 | Lab VMs 2.8, 24.11

                E 1 Reply Last reply Reply Quote 0
                • E
                  ericafterdark @johnpoz
                  last edited by

                  @johnpoz said in iPhone: Privacy Warning:

                  @eirikrcoquere said in iPhone: Privacy Warning:

                  It's plain old DNS Resolver at work with default settings.

                  Well does that fqdn resolve? There is AAAA for it.. So maybe just having issue with your IPv6..

                  The pfSense pushes two DNS IPs to the clients. An IPv4 and IPv6 address. The IPv4 one is private LAN, the IPv6 is a public address. I think because that's the way my IPv6 is configured. My ISP hands out a /48 and I assign /64s. Track Interface functionality on the LAN interface.

                  johnpozJ 1 Reply Last reply Reply Quote 0
                  • johnpozJ
                    johnpoz LAYER 8 Global Moderator @ericafterdark
                    last edited by johnpoz

                    @eirikrcoquere said in iPhone: Privacy Warning:

                    Track Interface functionality on the LAN interface.

                    Just a theory mind you - but you ipv6 was working.. So no warning it could talk to its doh server. Then your IPv6 range changed. And now can not talk to doh server on IPv6 = warning..

                    It comes down to this - apple device can not talk to its doh servers, whatever the reason = most likely get a warning that your dns is not private.. Who cares is my point.. No shit I don't want my dns set to your servers in the freaking first place ;) hehehe

                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                    If you get confused: Listen to the Music Play
                    Please don't Chat/PM me for help, unless mod related
                    SG-4860 24.11 | Lab VMs 2.8, 24.11

                    E 1 Reply Last reply Reply Quote 0
                    • E
                      ericafterdark @johnpoz
                      last edited by

                      @johnpoz said in iPhone: Privacy Warning:

                      @eirikrcoquere said in iPhone: Privacy Warning:

                      Track Interface functionality on the LAN interface.

                      Just a theory mind you - but you ipv6 was working.. So no warning it could talk to its doh server. Then your IPv6 range changed. And now can not talk to doh server on IPv6 = warning..

                      That does make sense….! I’ll check and verify next time it happens and report back.

                      1 Reply Last reply Reply Quote 0
                      • N
                        NeddieTone
                        last edited by

                        This post is deleted!
                        N 1 Reply Last reply Reply Quote 0
                        • DefenderLLCD
                          DefenderLLC
                          last edited by DefenderLLC

                          This setting has to do with disabling the "Private Wi-Fi Address" setting for each Wi-Fi network your iOS, iPadOS, and watchOS devices have joined. The purpose of this feature is to mask your device's real MAC address with a randomized MAC address. This warning is just indicating that this security feature has been turned off on the selected Wi-Fi network.

                          If you re-enable this setting (the default is enabled) on the given Wi-Fi network, then that warning will go away; however, that may cause issues if you secure your wireless network with MAC address filtering or use DHCP reservations.

                          I personally disable this setting on my devices while on my own Wi-Fi networks.

                          johnpozJ 1 Reply Last reply Reply Quote 0
                          • johnpozJ
                            johnpoz LAYER 8 Global Moderator @DefenderLLC
                            last edited by johnpoz

                            @cloudified while that might be part of it.. There is a warning if you turn off private addresses, there is also another warning that can pop up about insecure dns.

                            Which is what the user asked about

                            This network is blocking encrypted DNS traffic.

                            I thought for that encrypted dns warning at least so far, maybe something changed with the latest 16.1 ios update you had to have some app trying to use encrypted dns to get that warning. The ios itself doesn't try and use that native.

                            I just looked and I for sure block doh and dot, so highly unlikely any of that is getting outbound. But all I get is the privacy warning about private wifi address is turned off.

                            An intelligent man is sometimes forced to be drunk to spend time with his fools
                            If you get confused: Listen to the Music Play
                            Please don't Chat/PM me for help, unless mod related
                            SG-4860 24.11 | Lab VMs 2.8, 24.11

                            DefenderLLCD 1 Reply Last reply Reply Quote 0
                            • DefenderLLCD
                              DefenderLLC @johnpoz
                              last edited by DefenderLLC

                              @johnpoz said in iPhone: Privacy Warning:

                              @cloudified while that might be part of it.. There is a warning if you turn off private addresses, there is also another warning that can pop up about insecure dns.

                              Which is what the user asked about

                              This network is blocking encrypted DNS traffic.

                              I thought for that encrypted dns warning at least so far, maybe something changed with the latest 16.1 ios update you had to have some app trying to use encrypted dns to get that warning. The ios itself doesn't try and use that native.

                              I just looked and I for sure block doh and dot, so highly unlikely any of that is getting outbound. But all I get is the privacy warning about private wifi address is turned off.

                              There have been no changes in any of the iOS 16 or 16.1 developer beta notes about checking for DNS encryption that I can recall.

                              johnpozJ 1 Reply Last reply Reply Quote 0
                              • johnpozJ
                                johnpoz LAYER 8 Global Moderator @DefenderLLC
                                last edited by johnpoz

                                @cloudified here is the warning the OP was talking about.

                                https://developer.apple.com/forums/thread/661116

                                encrypted.jpg

                                If you google you will find lots of people complaining/asking about it - how to make it go away, etc.

                                An intelligent man is sometimes forced to be drunk to spend time with his fools
                                If you get confused: Listen to the Music Play
                                Please don't Chat/PM me for help, unless mod related
                                SG-4860 24.11 | Lab VMs 2.8, 24.11

                                DefenderLLCD 1 Reply Last reply Reply Quote 0
                                • DefenderLLCD
                                  DefenderLLC @johnpoz
                                  last edited by

                                  @johnpoz said in iPhone: Privacy Warning:

                                  @cloudified here is the warning the OP was talking about.

                                  https://developer.apple.com/forums/thread/661116

                                  I just read the release notes, so I didn't see this forum post until now, so thanks for sharing it.

                                  1 Reply Last reply Reply Quote 0
                                  • N
                                    NeddieTone @NeddieTone
                                    last edited by

                                    This post is deleted!
                                    1 Reply Last reply Reply Quote 0
                                    • First post
                                      Last post
                                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.