Wait, so my data will be routed to US servers, as an EU resident, where the data protection laws are not as strong as where I live? This is a really bad idea, as US is known to tap any data they can get on their soil.
Wait, so my data will be routed to US servers, as an EU resident, where the data protection laws are not as strong as where I live? This is a really bad idea, as US is known to tap any data they can get on their soil.
Personal data should be protected by TLS (edit: and/or application-level encryption) so packet routing is irrelevant to privacy and data protection.
I am very worried that the demand for protection of personal data (which is good) is mutating into an expectation of fully regional Internets that do not peer with each other (which IMO is bad).
When any server in USA soil can be changed into a backdoor, accompanied with a gag order on disclosure, I certainly do not want all my egress traffic routed into any computer in USA.
And while I may not have direct control over where my data is actually routed, but there absolutely are legal restrictions on where companies may route them.
But from a threat model I would dare to say, if you control the platform (OS, Cloud Service) you can easy bypass encryption or deploy your own keys as well.
In the end it is still a trust question.
I guess it's sort of a good thing that Apple is getting into the business of giving away snake oil to combat people selling it. The big iOS privacy changes that would help are DNS over HTTPS (maybe it already does this and requiring permissions for non-HTTPS network access. Maybe they could limit relay routing to non-HTTPS browser traffic?
At least in the Developer Beta 2
There are clearly some bugs. Occasionally I, in Canada, get routed through the US. This guy got routed through the US. Neither case should happen by Apple's description. Apple is quite intentionally trying to avoid their relays getting around geo-restrictions (likely to avoid them getting blacklisted).
It's supposed to, but that is definitely not currently the case.
If that will be fixed during the beta period is unclear.
1. Settings -> Apple ID -> Private Relay
2. Settings -> Network -> Use iCloud Private Relay
Is private relay still in Beta? That might explain it if the serve side component only got deployed in one or two of Apple's US datacentres.
I think you meant to say, the US is known to tap ALL data we can get our grubby little paws on. We don't care if it's on our soil or not.
AIUI, it's arguably harder if it's on our soil, as then we might be spying on US citizens which requires a touch more paperwork.
NOTE: I'm not condoning this behaviour, just stating my understanding of it.