That’s what’s different with iCloud relay - Apple’s weight to force changes upstream.
Either Etsy changes their policy now during the beta (my guess is they will), or they change it in a panic in November when iPhones can no longer access the site to buy anything.
(No-one is going to switch off private relay to convenience a single website).
If you're a seller and a decent chunk of your income comes from Etsy you definitely would. They already do that with avoiding VPNs to not get suspended.
That prevents buyers from buying also.
Etsy will adapt, quickly.
At least, it would if their Etsy accounts weren't getting locked until they can contact support.
That said, the Etsy app won't be subject to Private Relay, so if the functionality is there then a lot of users won't have to worry about it as much.
Why? As far as I know it will apply to apps as well.
> In iOS 15 and macOS 12, Private Relay will apply to all web browsing in Safari, all DNS name resolution queries, and a small subset of traffic from apps.
> Specifically, this will include all insecure HTTP traffic, such as TCP port 80.
This implies that app traffic won't apply to HTTPS traffic, which supports my assertion, but then later in the video:
> Not all networking done by your app occurs over the public internet, so there are several categories of traffic that are not affected by Private Relay.
> Any connections your app makes over the local network or to private domain names will be unaffected.
> Similarly, if your app provides a network extension to add VPN or app-proxying capabilities, your extension won't use Private Relay and neither will app traffic that uses your extension.
> Traffic that uses a proxy is also exempt.
So this says that HTTPS traffic will be included, which disproves my assertion, and seems more likely to be true.
99.9% of etsy userbase would not.
99% of computer users do not inhabit the same galaxy as you do when it comes to understanding and managing technical details.
At the same time, 99% of computer users have no idea why we can’t just ‘slap x button there and make it do x’ and that is just as infuriating.
I'm sorry to tell you this, but sooo many people in the US alone are not technically literate enough to know how to debug an issue like this.
Private Relay guarantees that users can't use the system to pretend to be from a different region, so you can continue to enforce region-based access restrictions. Details about the proxy IP addresses will be available as an article associated with this session.
Though I haven't been able to find the aforementioned article.
[1]: https://developer.apple.com/videos/play/wwdc2021/10096/
https://developer.apple.com/support/prepare-your-network-for...
And their IPs, as mentioned in that article:
https://mask-api.icloud.com/egress-ip-ranges.csv
Seems to be mostly Fastly IP addresses right now, but I'm sure that'll change over time.
Could an attacker use a VPN? Sure—and there are also plenty of evildoers in the US. But it's an extra barrier.
What I really don't want, however, is for my password manager (or any other service) to make these decisions for me. I will probably travel some day, and when I do, I don't want to be locked out of my account due to "unusual traffic" (yes, it is unusual for me to travel, that doesn't mean it won't happen).
I’m not an expert on Risk Based authentication, but your Etsy example sounds exactly like RBA. They use IP address as a factor in determining the risk associated with allowing the login, and suspend accounts with random IPs to prevent the “attacker” from wreaking havoc.
RBA: https://en.wikipedia.org/wiki/Risk-based_authentication
I just scoped my IMO to our Identity and Access Management World.
Let’s say ~30% of Etsy.com views are through Safari (iOS + macOS; ignoring that Chrome on iOS is a viewframe around WebKit anyway). Of those, 25% have iCloud+.
Let’s say they did this and 50% of people did visit the site through Chrome.
That’s ~4% less revenue for them. I don’t know what Etsy makes per year, but ~4% of whatever that is will be on the order of millions of dollars. So, this is a no-brainer.
Let's say that ~100% of Etsy.com views are through Safari. Of those, 100% have iCloud+.
Let's say they did this and 0% of people visit the site through chrome.
That's 100% less revenue for them. Pretty amazing that this one feature could completely kill Etsy's revenue stream.
(For what it's worth, I agree with you that Etsy is not going to tell Safari users to pound sand, but your arbitrary numbers don't make an actual point unless they're based in facts and figures.)
In other words, your comment reads as “if everyone stops visiting Etsy, then they will make $0”, which…yeah. Makes sense to me.
They plug the numbers into the formula and see "If we block IE11 users from being able to use the site, we lose 1% of our traffic, which equates to X dollars. Is that a substantial amount? If so, we support IE11, if not, IE11 support goes out the door."
So yeah, you can plug in the numbers you did and try to negate his argument, but that doesn't make his argument wrong. Just means you understand the argument but fail to accept it.
2. The point of the math was to show that it's a big deal for basically any reasonable values. It doesn't depend on the exact numbers.