Apple's newly announced “private relay” will not be available in China
reuters.com
reuters.com
The "private relay" feature first sends web traffic to a server maintained by Apple, where it is stripped of a piece of information called an IP address. From there, Apple sends the traffic to a second server maintained by a third-party operator who assigns the user a temporary IP address and sends the traffic onward to its destination website.
The use of an outside party in the second hop of the relay system is intentional, Apple said, to prevent even Apple from knowing both the user's identity and what website the user is visiting.
Very interesting. But what stops Apple from looking at the packet from the user device and seeing the destination address?
According to the article, The "private relay" feature first sends web traffic to a server maintained by Apple ...
Where is it aggregated with other people's traffic? Doesn't Apple have access to sender and destination addresses at that point?
https://www.fastcompany.com/90643627/apple-privacy-wwdc-priv...
>This is where iCloud Private Relay comes in—and puts VPNs to shame. iCloud Private Relay uses a dual-hop architecture. When you navigate to a website through Safari, iCloud Private Relay takes your IP address, which it needs to connect you to the website you want to go to, and the URL of that site. But it encrypts the URL so not even Apple can see what website you are visiting. Your IP and encrypted destination URL then travels to an intermediary relay station run by a third-party trusted partner. Apple would not name these trusted partners, but says the company is working with some of the largest content providers out there. Before getting to this relay station, however, your IP address is anonymized and randomized, so the relay partner can’t identify you or your device. Then at the relay station, the destination URL is unencrypted, so the third-party provider can send you on to the website you want to go to.
>Because of this dual-hop architecture, neither Apple nor the relay station knows both who you are and where you are going. Apple knows who you are (because you are using iCloud Private Relay), but it doesn’t know where you’re browsing. Its third-party partner knows where you are browsing–but not who you are.
If Apple chooses to invest resources in it, I expect Apple's Private Relay servers are much more secure than Tor servers. I hope Apple allows non-Apple users to utilize Private Relay.