T-Mobile begins blocking iPhone users from enabling iCloud Private Relay in US
9to5mac.com
9to5mac.com
Verizon, AT&T and T-Mobile say they’re not blocking Apple’s iCloud Private Relay - https://news.ycombinator.com/item?id=29901056
If Apple really wanted to force the issue, they could tell T-Mobile no more iPhone contracts unless you do it. Apple can survive and thrive on fewer networks - the iPhone was AT&T exclusive for a long time at the beginning.
If that happened, there would be no way for T-Mobile to get a supply of iPhones. People would need to buy iPhones from Apple and then replace the SIM cards themselves. It would make T-Mobile bend pretty quickly unless they managed to get Verizon and AT&T to join them on the issue.
But then Apple has a second card to play, and that's the court of public opinion. If Apple wanted to make a public ad lambasting the carriers for undermining people's privacy, the damage would also force them to bend.
Finally, of course, there's the fact that carriers need Apple just as much as Apple needs carriers. However, between the carriers and Apple, who has $200 billion in the bank to do things themselves if they wanted?
Edit: Heck, T-Mobile has a market value of $130 billion. AT&T has a market cap of $188B, and Verizon $223 billion. If Verizon and AT&T joined T-Mobile in protest, Apple could theoretically attempt (or at least threaten) a hostile takeover of any of them. That would cause a lot of discussion among the carriers and send a strong message very quickly.
That ad would be candy to the Apple PR team trying to push the “Apple is secure and respects your privacy” campaign. I bet we’ll see Apple use the court of public opinion here, and win with it.
Again though, rupturing this conversation is mutually assured destruction. The reason why Apple won't call T-Mobile's bluff is because it's better for them to look like a symbiotic company than an adversarial one, and T-Mobile can get away with this because data protection in the US is a moot-point anyways. It's about as unremarkable as news gets.
Hell, Apple was even nice enough to give T-Mobile a special error message when you try to use Private Relay:
> "Your cellular plan doesn’t support iCloud Private Relay. With Private Relay turned off, this network can monitor your internet activity, and your IP address is not hidden from known trackers or websites."
I wouldn't call it security theater if I couldn't see the curtains on the left and right.
Your suggested response doesn't change my mind at all, it seems quite desperate and pathetic. And I want to see a stronger moral stance on trade with China.
Apple trys to manipulate public opinion constantly.
OTOH, one way to become the most valuable company in history is to not go pulling stunts like that. Nothing the street loves more than predictability.
Edit: Another, "smarter" tactic that Apple might use is by sending messages to the Board of Directors. If Apple can get the Board of Directors on their side (or at least convince them that management is fighting a war they can't win)... another way to freak out execs at the carriers.
I also think it's silly to equate a company's power to the amount of money they have (at least in the first world) but your hypothetical does raise an interesting question: who's deeper in bed with the State, Big Telecom or FAANG? All of them answer to the government, even T-Mobile; but who's got the most favor? Understanding the heinous stuff the American government got away with when they had telecom under their thumb doesn't set a very optimistic baseline of expectations. It might even lead certain people to believe (surprise surprise) that Apple's dedication to privacy doesn't really mean much when there's money on the line. Arguing about how "Apple is better because they have more capital resources" has about as much pragmatic value as a child's crayon drawing.
Unless Apple has one-upped Room 641A, I think you're describing a power fantasy.
Apple would literally capture the entire value chain of the iDevice ecosystem with such a stunt, not to mention have yet another steady stream of income.
I think that was a very different time though. Smartphones were just becoming popular. A lot of other upcoming smartphones also had carrier exclusives at that time (Verizon with the Droid line). I don't know if that would be acceptable in today's world.
A joint move like that by the carriers would be subject to a lot of antitrust scrutiny, where as apple can move on it's own with a lot less scrutiny.
Or the other cellular networks could start running ads touting that they let iPhone users use all of the iPhone features.
"Does your cell phone company hold you back? With Cincinnati Bell, you can do things with your iPhone that T-Mobile won't let you."
Apple could even help pay for the ads. It's not like companies with aligned interests don't do ad cost-sharing all the time anyway.
Edit: Wikipedia says Cincinnati Bell sold its mobile network to Verizon in 2014:
Now whether Apple shareholders want Apple operating a mobile network is a completely different question.
Changing sims is VERY easy, but a sim that doesn't match an approved phone is also easy to block?
The article asserts that an error in the settings menu appears: "Your cellular plan doesn’t support iCloud Private Relay. With Private Relay turned off, this network can monitor your internet activity, and your IP address is not hidden from known trackers or websites."
This doesn't appear to just be a situation where T-Mobile started blocking it at the network level; it appears to be one where Apple submitted.
While there's a lot of theories in this comment about how Apple will respond; I don't see that happening (in a public way, of course). Apple's leadership in 2022 doesn't have the same convictions their leadership has had in the past. They're capable of being a positive force for change, in fair weather; but when the weather gets rough, or when forces assert power over their expression of values, they fold.
Alternate phrasing which betrays different expectations: "We could not connect to the iCloud Private Relay servers. This may indicate an issue with your network provider, blah blah blah."
No VPNs is mostly standard-operating-procedure in, say, China. That being said: I'd assume that feature, let alone the settings page to configure it, is hidden in versions of the software distributed in countries like that. This error message is likely for countries where the service is available; just not on your carrier.
But putting that aside and even considering their stance of submission to the CCP; they betray every spoken value their American executives verbalize. That is standard operating procedure for 2022 Apple, and most other gigacorporations. That is the lens that every statement Tim makes, every word spoken at their keynotes, needs to be viewed through; that they're willing to invest their infinite money in whatever projects they believe aligns with their values, but they're wholly unwilling to stand up for those values when those projects are battle-tested in even such an absolutely inconsequential way as this.
Of course, they can prove me wrong by standing up to T-Mobile and using them as an example. I mean my god, you couldn't ask for a better example to make, T-Mobile/Sprint is a fourth-rate bargain bin cellular carrier, we're not talking about a nation state; this is a toddler mad at his parents because they won't let him eat candy for dinner. If they can't even resolve that, what hope do any of their values have?
TMobile has numerous pay-for-play access contracts in place for companies like netflix and hulu. in return they get a QoS tier and guaranteed minimums for their subscribers.
conversely, as others have mentioned and the article itself, private relay is absolutely haram. it damages tmobiles ability to deliver edge content from their contractually obligated players like netflix (without a region netflix quality might suffer) and it completely sidesteps all of TMobiles lucrative user plans that include access to streaming media as a feature relative to the users data cap.
increasingly private "anything" on a cellphone is becoming a hostile proposition for carriers as their revenue is largely based on predatory surveillance capitalism. without metrics and metadata, theyre no different than the water company.
Please correct me if I'm wrong. If that's the case, I believe most/all iPhone users watch Netflix/content sites via an app, so that traffic would not be routed via Private Relay.
This may affect Mac Safari traffic, though. I am curious if they have any exceptions on the backend for edge content providers.
If I were any of the carriers, I wouldn't worry about this in the slightest.
Apple attempting to gain ownership of a mobile carrier in order to impose it's will on the market would be met with incredibly harsh regulatory scrutiny.
Beyond that, there's a strategic reason Apple hasn't launched their own mobile offering. The minute Apple owns a particular mobile carrier, they would be pretty well cut off from the other mobile carriers, or they would have to negotiate deals that would probably be argued to be collusive trade practices.
The real solution is that the United States needs real data security and privacy laws that prevent network operators from reselling your usage history, location tracking, and other personal details. It's a national security issue at this point.
Also, as a carrier, I’m not worried about Google’s MVNO for one simple reason: Google hates humans.
For all that the carriers are bad to their customers, they at least have a footprint in meatspace. Google’s DNA finds physical footprint and real human interaction anathema.
I would gladly take Google in a customer foot race any day.
There's a difference between temporary sales presence contracted out and a permanent retail presence, though, you're right.
In other words, if they keep this behavior up, Google will begin to compete as well as advocate (fight for the regulation, laws, etc) for other, smaller, new ISPs to enter the market. Or fight harder on the net-neutrality front. Or potentially worst of all for the incumbent/monopolistic ISPs, fight to make them dumb-pipes.
Then again, maybe it's just another google product/service destined from conception for the graveyard...
It seems safe to assume that Apple doesn't like user APN traffic being tracked any more than the rest of their traffic, and so I would imagine this is essentially the roadmap for all Apple Services provided to their users over the next few years.
It's also possible the Beta is just to see what happens when they make the traffic visible and possible to block, and having seen the carriers tending towards "block anything that inhibits tracking", they might simply target Private Relay 2.0 as "HTTP3 over 443/udp to http3.apple.com" and have that be an N-way reflector point for all customer-provided Apple services, including Private Relay and the rest as different channels over that multipath HTTP3 layer. They chose to implement Private Relay in a way that could be detected, and are measuring how neutrality-hating carriers respond. Assuming it's their final answer is not a bet I'd take.
It isn't a forceful use of power by Apple and it clearly informs just the simple truth that the users carrier is hostile and maybe they want to switch.
Does your carrier implement this? If not, will you switch carriers? It’s unclear what degree of importance you assign to your expectation, as it could be anything from “for the tasks I care about” to “in every possibly way without exception”. (For me: It’s not important eniugh to switch carriers on its own, though it’s certainly a factor if I have greater reasons.)
By the way, your parent comment hypothesizing about http/3 and Apple services likely being routed via Private Relay was also very insightful. The http/3 part seems quite speculative, but I could easily see the Apple services being routed over Private Relay as part of any standard "dogfooding" roadmap.
It’s absolutely speculative to consider http3 a viable replacement for ”a VPN”, as many consider Private Relay to be^, but that’s not due to any technical limitation. We could benchmark Squid-over-http3 versus Wireguard VPN in various latency and packet loss scenarios today (if implemented), and get productive and interesting results. We could do the same with varnish / nginx versus openvpn / pptpd. Whether or not it supports CONNECT is worth noting, but is no obstacle for “let’s assume that everything is HTTP”, as appears widely applicable to both Apple’s services to their customers, and a significant majority of consumer VPN traffic, today.
Have those benchmarks been performed yet? Are we all doing it wrong by using wireguard et al. to Mullvad et al. for 99% HTTP traffic and we just don’t realize it yet? I look forward someday to finding out the answer :)
ps. iOS carrier APIs and functionality are NDA’d so I don’t have any other information or useful examples to offer, as my experience with carriers as their customer is very limited. Perhaps others will know; apologies.
^ I haven’t seen an FP yet titled “If it can’t carry SSH traffic, it’s not a VPN”, but certainly there’ll be one someday. I can’t predict when, though, anymore than I can guess when someone else will realize to seriously ask, supported by benchmarks and encapsulation overhead charts, “Should tcp be deprecated in favor of http?”. (I have no opinion on what the correct answers are at this time.)
https://tmo.report/2022/01/t-mobile-blocking-icloud-private-...
> However, many of the users we’ve heard from, and tested ourselves, do not have any such content filtering enabled. We’ve followed up with T-Mobile for additional clarification, but have not yet heard back.
> Visiting secured web sites (https) because encryption prevents Web Guard from seeing the content of those websites
I guess T-Mobile should start downgrading HTTPS to HTTP /s
https://www.theverge.com/22878885/verizon-att-t-mobile-apple...
Yeah, that's not Apple's style. Besides, they don't want all of the legacy crap that comes with owning a cell phone carrier.
I suspect the issue is making its way up the corporate ladder through various directors and Vice Presidents.
And I'm sure Apple's got a business plan for running their own MVNO they could dust off if things get out of hand. But let's hope it doesn't come to that.
But this would be rewarding existing ownership with a buy-out.
No, because then people will ask why they also don't use the leverage to enable this feature in China/Russia/...
It doesn’t have the ability to give a middle finger to both those governments and still be able to sell devices to Russians and Chinese people to use Private Relay on.
This blocking is a net neutrality issue. Hope it doesn't hold, at least in Europe.
> People would need to buy iPhones from Apple and then replace the SIM cards themselves.
The horror! We've been doing this the entire time here in Russia. Carriers have always had exactly zero say on what phones can and can't do.
I mean, why isn't this already a thing? This isn't difficult at all. I don't buy my phone from my carrier. When I get a new phone, I simply take the old sim out and put it in the new one. The last time I had to do more was when the phones changed from a standard SIM to a mini SIM - the old one wouldn't physically fit. That was some years ago, though.
I'd think the bigger issue might be with the US phone networks: Do they still force you to use your phone with the carrier even though this isn't necessary at all? And if so, why haven't folks protested since it is obviously a way to trap people into one carrier.
Also, since folks in non-US countries can just buy a phone and put a sim card in, Apple won't have any issues adjusting whatsoever.
Another issue is probably the "incentives" provided through the network providers and their partners, especially when an iPhone is traded in. Often times it results in significant "savings" for the consumer. (I imagine Apple could implement something similar, if not superior if they wanted)
Finally it's physical presence. Apple has done a fantastic job of creating a physical place to serve your needs, and of course you can always buy online, but there are those that prefer or require going to a place to take care of their phone needs.
I also shudder to imagine what the Apple stores would look like if they had to deal with and resolve the kinds of network issues (not to mention some of the characters that need the help) I've seen the superabundance of network provider mall/strip-mall stores deal with.
Hopefully all of these are just remnants of a time we'd all like to put behind us.
There is no need to buy a phone from the mobile network in the US. People have been able to pop a SIM into a phone and call the mobile network and have them add the IMEI for many years.
They have poor security practices like storing passwords in plaintext [2], and they had a large data breach (probably about 100M customers affected) last year. [3]
A̶n̶d̶ ̶n̶o̶w̶,̶ ̶i̶t̶ ̶s̶e̶e̶m̶s̶ ̶t̶h̶e̶y̶ ̶a̶r̶e̶ ̶t̶h̶r̶o̶w̶i̶n̶g̶ ̶i̶n̶ ̶s̶o̶m̶e̶ ̶p̶r̶o̶t̶o̶c̶o̶l̶ ̶b̶l̶o̶c̶k̶i̶n̶g̶ ̶t̶o̶o̶.̶
PS: This isn't protocol blocking at the packet/port level, so I may have used "protocol blocking" a bit inappropriately. Apparently Apple allows the carriers to prevent people from enabling iCloud Private Relay, and T-Mobile is doing that. Apple is probably doing so due to the pressure by the carriers. In August, four carriers (Vodafone, Telefonica, Orange and T-Mobile ) signed a letter urging the European Commission to stop Apple from providing Private Relay. (According to a report by The Telegraph: https://archive.fo/BRUS4#selection-915.74-925.194) This, of course, still quite preposterous.
[1]: https://news.ycombinator.com/item?id=29744347
[2]: https://news.ycombinator.com/item?id=16776347
[3]: https://news.ycombinator.com/item?id=28192423 (The first comment by @jonathanmayer has a list of other recent T-Mobile security incidents)
That might be true, but at least AT&T doesn't block private VPNs, nor has plans to do so.
"A."
"But B!"
>> "But still, A." <<
If so, maybe you shouldn't be saying you/att have no plans to. And if not, maybe you shouldn't be saying they have no plans to
I'm part of AT&T Cybersecurity.
But if you want proof of what AT&T isn’t going to do, it’s going to take a while to compile.
I love to travel, and nothing beats being able to land in (pretty much) any country in the world, turn on your phone and have working service just like that. No SIM cards, no different numbers, no local pre-paid cards, and no crazy international fees.
As someone who enjoys work/travel for weeks to months at a time, every other major carrier is not feasible for this (think 10$/day, which becomes unreasonable when you're out of the country for 3+ weeks).
Unless somebody else could recommend another option it seems I'm stuck with T-Mobile for now.
I'd do Cincinnati Bell in a heartbeat, if I could.
Also, Google Fi kinda sucks. They used to be the cheapest, but nowadays you can get better prices from other services. For example, Google charges $10/gb/mo, whereas Mint Mobile (another T-mobile MVNO) charges 4gb for $15/mo, or $30 for unlimited.
Google Fi is only cheaper if you use less than 1.5gb of data per month, and the service quality is probably the same.
...and that's not even mentioning all the privacy concerns attached to Google.
It's exciting to watch how many years in a row they can stay at $10/GB, and not in a good way.
Fi caps out at $60/mo (so 6gb), after which you get unlimited data for "free". However, you only get 15gb of high priority.
I think Fi is trying to take advantage of the Google brand to sell MVNO service at a crazy markup.
My car has an "unlimited" plan with AT&T, and holy crap, it's worthless. If I actually need to do something, like, now, usually I have to turn off my phone's wifi if the car's on.
And this isn't me modifying my behavior. If I had a habit of watching YouTube or Netflix from all over the place, I'd get a different phone plan. I'm not like penny pinching here. It's just that my current phone plan works, I like how easy it is to administer, and switching providers in a huge PITA for a family of 4, so something else better be damn good.
Fi does not feed usage information or otherwise into the ad machine. See the privacy notice on https://fi.google.com/about/tos/
Band 12 fulfills the same role in some areas, and is supported on most phones, but T-Mobile doesn't have a nationwide license for it.
Sure, people can't call me on my usual number, but I see that as an additional benefit. I'm on vacation.
With Wifi calling + texting, you can even use your US number internationally since it will work off the eSim data.
Plus, it's primarily the T-Mobile network anyways with the addition of the US Cellular network and the old Sprint network.
https://tmo.report/2022/01/t-mobile-blocking-icloud-private-...
tl;dr - disable T-Mo Content Filtering on your account and PR will work just fine
PS: The 9to5mac article has an update which indicates that the blocking is _not_ exclusive to users who have "filtering and blocking features enabled".
AT&T essentially bankrolled OANN, Trump's propaganda network. Verizon has done tons of shady stuff in the past as well.
Plus my bill for TMO has been constant (like the same) for years straight - no overages or surprise bills. Not going back to ATT/VZ for a long time if ever.
I also can't complain that I get 8 lines of unlimited everything for $150.
What? I was using T-Mobile in 2018 in the US.
Because there is no reason to get internet from any of the big boys if you're in downtown Chicago. All you need is fiber to the big brick building next to McCormick Place, and there is fiber under every El track, in the old freight tunnels, along the Metra tracks, and just plain old every street.
This is probably the best of the dozen choices you have. When I lived downtown, I got gigabit internet for $15 a month.
You've got to be kidding me if you think you want Comcast.
https://news.ycombinator.com/item?id=29875805
Phone carriers do not want to be a dumb pipe - and having Private Relay go through their networks breaks:
- HTTP header enrichment (which they use for self-care/customer sites/services),
- zero rating (which they set up deals for with social networks, music streaming services, etc., often applying specific QoS tags) and
- all sorts of value added services (many using deep packet inspection and DNS analytics) that they offer instead of raw, unfettered connectivity.
I don't think many people are aware of exactly how much data telcos are sitting on, anonymized or not.
And, of course, it also plays havoc with legal interception because there is no easy way to do MITM.
(edit: readability)
Zero-rating is really bad for Apple. And by making themselves the virtual network layer, they have the ability to roll out their own last mile networks later.
If anything makes it moot, it's not other technology; it's social engineering attacks.
First, they dont get the right people, because good people dont go to telco. Second, they have super fragmented stacks, especially in markets that have consolidated over the years. Third, they simply dont have figures out ANY business model for that data (except some We SeLl LoCaTiOn DaTa To GoVeRnMenTs that is illegal in most Western countries anyway by now).
So... all this "TELCO SOOO BAD BECAUSE ALL MY DATA THEY EAT" talking is laughable to me after seeing the truth. I am surprised what people here in HN think of the capabilities of telcos.
Edit: as I saw some comments below on "three letter agencies". Fun fact, ALL the 8 telcos that I have experienced hat guys from the local "three letter agencies" working there to detect crime stuff.
Plenty of telcos want to force competitors out of the market with zero rating and triple play subscriptions, but I don't think any of them have made any moves against net neutrality this bad. A few years ago I've seen carriers doing HTTP introspection to force images through their compression proxies (usually budget ISPs who want to stop people from actually using up their data plan so they can make a profit) but that seems to have stopped completely now.
As for legal interception, this doesn't make any difference. When law enforcement finds that the suspects are communicating over Apple's network, they'll just knock on Apple's door with a warrant and demand a wire tap from their network. That's how legal interception of "privacy protection" VPN providers works, and Apple isn't even trying to ship traffic outside national borders, just to the closest data center.
From that article:
> Via The Telegraph, operators including Vodafone, Telefonica and T-Mobile signed an open letter voicing their opposition to the rollout of the feature.
Those are each large telcos with operations in a multitude of countries.
The Telegraph only seems to provide any sources that are about the UK. I can't find any sources outside of the Telegraph for Telefonica, for example, mostly because Google only lists articles copy/pasting the Telegraph.
Apple allows network providers to turn this feature off, but any DPI and analysis the ISPs do would be highly illegal in the EU, so I don't see the advantage that disabling private relays would get them.
Honestly, Apple should provide an override for this block. It seems to be based on DNS, so a custom DNS server should be enough to bypass the block entirely it seems?
I read it as referring to those telcos' international HQ's. The Telegraph article reports that the letter to the European Commission was signed by Vodafone, Telefónica, Orange and T-Mobile.
First, Telefónica isn't active in the UK under that name, only as part of Virgin Media O2 (their joint venture with Liberty Global) [1]. T-Mobile (Deutsche Telekom) and Orange (France Télécom) haven't even been active in the UK at all since 2016 (when BT acquired their joint venture EE) [2].
Therefore, if the Telegraph were reporting on the UK only, the list of telcos that signed the letter doesn't make sense in the first place.
Second, if the letter were indeed authored by UK telcos, why would they have sent it to the European Commission? That's an EU institution, and the UK isn't part of the EU anymore.
(Not asking for sarcastic not-in-good-faith explanations of BS reasons that you are imagining.
Asking for anyone who understands more about a cell carrier's needs than I do, to explain what «the feature cuts off networks and servers from accessing vital network data and metadata and could impact “operator’s ability to efficiently manage telecommunication networks.» actually means, to someone who is not a telecom engineer but does understand engineering.
And/or other motives, but based on understanding more of their business than I do, not just wild guesses!)
When everything is encrypted and goes over the ISP just to the VPN endpoints, they can't do anything. In the end, they will have to arrange peering not with content providers but with VPN providers, who works for Apple.
PS. There is a lot of tension in current setup, even without Apple stepping up. In the old fashion market, the last mile is the king. Big grocery chains have direct access to users, so they are the strong side in the relation with producers. They can position brand X over Y, if they have better margin. They also create their own brand Z rip-off and sell that directly. Just look what Amazon does in that space. When it comes to ISP, they have direct users and have very little to say. They are basically dump pipes, just like the power line.
T-Mobile was very vocal in the past in that space. They often wanted the MANGAs (heh) of the world to pay them a share from their ads. I remember T-Mobile threatening, that they might replace some ads with their own ads. Since they provide the users with phones, they can install their own certs on devices. Chrome has SSL pinning not only, to save users from hackers, but to save their own business model being attacked by ISPs.
(Of course, it was likely never about the traffic exchange itself, but rather the ability to route, shape, and track traffic dynamically on a host-by-host basis, as others have speculated.)
> "However, starting April 26, 2021, T‑Mobile will begin using some data we have about you, including information we learn from your web and device usage data (like the apps installed on your device) and interactions with our products and services, for our own and 3rd party advertising, unless you tell us not to."
T-Mobile sells browser history data to advertisers, and Private Relay blocks that revenue stream. They are on the offensive to protect their new-found profit center, and most likely are doing this now to show Apple that this is not a feature that they want to see be turned on by default.
It's the beginning of the same saber rattling that Facebook did when Apple announced it would simply ask customers if they wanted to allow apps to track them
Though Speedtest on your cell might show your connection speed as 100 megabits/sec down, cell networks special-case video by identifying it as video and rate-limiting it to something like 1 megabit/sec. This is considered "efficient network management". For T-Mobile, this based on the plan (https://www.t-mobile.com/cell-phone-plans), they sell either "SD streaming" or "4k UHD streaming". "SD streaming" is a fancy way to express that they rate-limit identified video streams to 1 megabit/sec.
They identify video streams by watching the IP your phone is connecting to and/or the hostname mentioned in the TLS SNI header and checking if it is Youtube, Netflix, etc. Sending video content over a VPN removes their ability to understand what the content is.
For example, if you run out of data for a month, many carriers will continue giving you access to the internet APN, but then block access to "external" websites. This is so you can easily open your browser and "top up" on data to continue using your device.
Or the usage of HTTP (not HTTPS) was relatively common back when I was in the space (7-10 years ago). There wasn't a need to use HTTP because the carrier was in full control of the pipe between the device and the server. Adding in a VPN that somehow tries to intercept that traffic (that was supposed to exist entirely within the telecom) is not going to work.
1. Browsing history. We know that Verizon is tracking it for their gain: https://www.wired.com/story/verizon-user-privacy-settings/. It seems reasonable that T-Mobile and others don't want that door to close on them.
2. Video streaming management. Carriers typically restrict video streaming on some/all of their plans to certain resolutions. For example, I think most American carriers limit video streaming to around 480/720p at 1.5Mbps or less unless you have bought a premium plan. VPNs often get around this and I know that my carrier can't detect Netflix access through iCloud Private Relay. Right now, iCloud Private Relay doesn't proxy app traffic, but it could in the future.
3. It looks like mobile carriers are looking to get into "edge cloud" stuff. Verizon has been pushing this and they recently emphasized this in their 5G Ultra presentation. If traffic is going through iCloud Private Relay, buying expensive "edge cloud" services from Verizon is a waste of money since the traffic would be leaving the network to go through Private Relay.
3a. Netflix ships "Open Connect Appliances" that ISPs can hook into their network to serve Netflix content. If your traffic is going through a proxy, you start accessing the content on a server farther away. This mostly doesn't apply given that Private Relay only does Safari traffic, but one could see Private Relay expanding to apps in the future.
4. I think there is a certain knowledge of what is using data that can be helpful to carriers. For example, I worked for a university and they wanted to set different QoS for things like peer-to-peer file sharing vs. web browsing. The university didn't want to punish P2P tech or anything like that. They just wanted to make sure that P2P usage didn't overwhelm other users and uses of the network. Likewise, it could help the university spot patterns like viruses/bots that might be using a lot of network traffic.
4a. I think this can also play into how companies position their offerings. For example, T-Mobile has introduced features like "Music Freedom" and "Binge On" that allowed unlimited audio streaming and video streaming before unlimited plans were a thing. They surely did analysis of network usage of those features before introducing them. You can look at how much video streaming users are doing and then model how much data would be used if you limited it to 480p (including accounting for an uptick in usage due to it being unlimited). However, if you don't know how data is being used, you lose the ability to spot patterns that might be opportunities.
4b. It makes sense to want to offer different QoS for different services. If someone is using FaceTime, you want that to be a good experience. You don't want to prioritize a speed test over someone's FaceTime call. You don't want to prioritize downloading from YouTube over a FaceTime call. That YouTube video can be buffered and if you know that you've transferred 15 megabits worth of 1.5Mbps video, you kinda know that the user doesn't need the next 1.5 megabits of video for 10 seconds.
4c. I know that a lot of people want their connection to be an unbiased dumb-pipe, but I think that people only want that because they tend to see crappy stuff from companies looking for money. Seeing it from a university that only wanted to give people the best possible network experience feels a bit different. QoS can be a positive thing and a dumb-pipe isn't always great.
I'm a bit surprised that T-Mobile would go this route at this time. iCloud Private Relay doesn't proxy app traffic at this time and I haven't seen that they have a similar browsing-history program like Verizon's. Still, there are reasons to want to be able to understand your traffic both for business reasons and for a better customer experience. Again, I'm surprised because it seems like the reasons today are slimmer. I think the Netflix OCA use case is a good one since it reduces network usage in a way that simply helps the parties involved, but wouldn't really be possible if the traffic first went via another external server.
I'd emphasize that nothing here is to say that T-Mobile is doing the right thing. It's just to bring up areas where a company might want to know more about its network access patterns. Some of that can be used for good like the Netflix OCA system or giving higher QoS guarantees to FaceTime. Some of it can be used for bad like knowing using browsing history for advertising.
Right now a hypothetical metro area might have a 20G circuit to Carrier A, a 20G circuit to Carrier B, and 20G of private peering to {Netflix, Google, etc}. With private relay they need to rip all that out and replace it with a 60G pipe to Apple.
[0] https://www.techrepublic.com/article/the-real-reason-behind-...
[1] https://mashable.com/article/how-to-stop-tmobile-att-verizon...
I turned off WiFi, turned on iCloud Private Relay, and browsed to a site at work while watching the Apache logs for the hit.
Site showed up, and the Apache logs showed the hit came from 172.224.242.xx, which is in the block 172.224.0.0/12 which is assigned to Akami.
I turned iCloud Private Relay off, hit refresh, and the hit came from 172.58.46.xx, which is in the block 172.32.0.0/11 which is assigned to T-Mobile.
I then turned WiFi on and iCloud Private Relay on, hit refresh, and it came from the same IP that it had with it on when WiFi was off.
I then turned iCloud Private Relay off, hit refresh, and it came from an IP in the block 73.0.0.0/8 which belongs to Comcast, which is my wired home ISP.
Looks like there is no blocking going on for my T-Mobile plan.
[1] https://prepaid.t-mobile.com/plan-detail/t-mobile-connect
Customers who chose plans and features with content filtering (e.g. parent controls) do not have access to the iCloud Private Relay to allow these services to work as designed. All other customers have no restrictions.
> However, many of the users we’ve heard from, and tested ourselves, do not have any such content filtering enabled. We’ve followed up with T-Mobile for additional clarification, but have not yet heard back.
https://www.reddit.com/r/tmobile/comments/9ja8y1/i_can_confi...
Like I noted with FaceTime over cellular, it's nothing new.
I wonder if the same could happen to TOR, if VPN end up the same way...
It can't, because some of us don't let third-party corporations control what we're allowed to do with our computer.
Only problem is that you would have to be large enough that the ISPs would care if their scores looked bad.
> The carriers wrote that the feature cuts off networks and servers from accessing “vital network data and metadata and could impact “operator’s ability to efficiently manage telecommunication networks.”
But seriously, it is because it prevents T-Mobile from monetizing you and slowing you down.
It’s completely about monetizing your browsing history.
VPNing everything at scale will impact that monitoring/management. And that will absolutely impact towers, or cause the carriers to throttle users vs apps.
What this prevents is allowing say Youtube to pay TMobile to never throttle their traffic.
The one legitimate argument here is that this prevents traffic shaping based on the destination, which T-Mobile uses to do things like offer unlimited streaming separate from your general data quota.
P ---- CT ---- S
With VPN/whatever:
P ---- CT ---- VE ---- S
P = Phone
CT = Cell Tower
S = Server
VE = VPN endpoint
So given this the cell tower can still determine who is using lots of traffic, they just can snoop on that traffic.
Basically, what everyone wants is for companies like T-Mobile to be a dumb pipe. They invested in spectrum and a network, and they should just lease that network for cost + profit margin. Instead, they want to milk it. They want you to pay more for particular packets. They want the rest of the Internet to pay more for particular packets. They want to inject their own ads into unaffiliated websites. They want to build a marketing profile based on what sites you visit, and send you "offers" based on this. Right now, that is all technically possible, so they'd be defrauding their shareholders if they didn't try. But, we can of course say "no" and route around the damage. Apple is letting their customers say "no", and that means T-Mobile is doomed to irrelevance, and that's a great thing. Infrastructure should be infrastructure.
(Can you imagine what it would be like if other utilities did this kind of shit? Your water would cost less if you were using it to run a Coke-branded soft drink dispenser, but not a Pepsi one. Or, Dell computers could get electricity at a 10% discount, but not Asus ones. It would be unthinkable! But with these big ISPs, it's mandatory.)
I'm guessing the exact legal agreements didn't spell it out like this, but that's how I think of it. Only one company can use this finite resource at once, but just because they bought it doesn't mean there is no limit to what they can do with it.
Can you expand on this? Are you saying that if a business opportunity exists and a company elects not to pursue it that constitutes defrauding shareholders? I would have thought it constituted nothing more than a disagreement over strategy.
Apple notoriously "extorts" developers to be in the app store.
> Basically, what everyone wants is for companies like T-Mobile to be a dumb pipe. They invested in spectrum and a network, and they should just lease that network for cost + profit margin.
I don't think you've considered the alternatives if T-Mobile can no longer monetize traffic:
* Go back to subscribers pay per kb usage
* Eat the costs themselves
* Raise cost of mobile data plans
> Can you imagine what it would be like if other utilities did this kind of shit?
They side step this problem by charging per-use. During peak demand, prices go up. Each customer pays their share. Downside see Texas snowstorm.
They charge $70/month for “unlimited” data which is only 50GB before throttling. I’m pretty sure they can profitably afford to run a network for that much without reselling user data.
This sounds like a clumsy restatement of the urban legend that companies have an obligation to maximize shareholder value. There is in fact no such rule, for the obvious reason that nobody can accurately predict the future and calculate the optimal value.
https://corpgov.law.harvard.edu/2012/06/26/the-shareholder-v...
In this case, a company like Apple could say that they are choosing to forgo short-term profits from selling out their users’ privacy because they feel that the long-term loyalty will be greater, and anyone arguing otherwise would still have to admit that this approach has been phenomenally profitable.
It's not in line with the net neutrality, but it's useful for the direct parties:
a) a video streaming customer wins because they can do video streaming without touching their data allotment.
b) the video streaming server wins because their customers are able to do more streaming
c) t-mobile wins because they've reduced bandwidth requirements
Competitive streaming services that are not included in the program don't win, but t-mobile made it fairly easy to join. Users who want to stream at 4k or whatever don't win, but they can turn off the bandwidth restrictions and use their data allotment if that's what they want to do.
At my last job, I was involved with a lot of zero-rating deals as the application provider; we never paid for it, and I don't recall ever being asked for payment. Some of the carriers even setup plans without our knowledge or consent or assistance; this didn't usually work great long term, because of misidentified traffic, but it indicates the demand was there without us pushing it.
That provides some (or a lot) of value I am guessing.
- Time T0: User requests the DNS record for example.com
- Time T0+10ms: DNS returns "example.com. 193 IN A 10.1.2.3"
- Time T0+20ms: User opens a connection to 10.1.2.3 port 443
Chances are pretty good they're looking at example.com, even if you can't examine a single packet.
I consider those agreements to be violations of Net Neutrality, since they're inherently not treating all data the same.
That said, iCloud private relay only applies to Safari, so T-Mobile blocking it probably doesn’t have much to do with their variable data caps.
See Facebook's internet.org.
For many people, a cheaper plan with slightly lower quality video is a great tradeoff.
I would agree if they do not make that available to all services. At least at the time they did that for music there was a pretty long list of partners so I’d be most interested in knowing whether they charge money or reject applicants.
If so, it's a hassle, but you can specify custom DNS servers (even DoH and DoT) for mobile connections using a .mobileconfig file. https://dns.notjakob.com/ can generate them for you.
Probably a good idea to do this anyway to keep your carrier from spying on your DNS requests.
Complete bunk - Their (TMobile et.al) “value add services” are nowt more than network content provider toll-gates that the proxies bypass. Meanwhile they are also selling every bit of user context data (position, DNS/sites, cookies where unencryptable, phone-id’s etc) that they can scrape individually and in aggregate to any and every advertiser. Context is worth serious money to advertisers.
Sadly, many (American) ISPs are abusing their position to gather and sell personal information from their subscribers. They wasted their "ability to efficiently manage telecommunication networks" the moment they started selling data. They've become adversaries rather than partners because they thought they could have their cake and eat it too. It's sad, really, because with cooperation, everyone would actually be better off with proper network management!
* This could be a Federal Trade Commission problem. T-Mobile, like all major ISPs, has made public representations about upholding net neutrality principles [1]. These voluntary commitments were part of the Trump-era FCC's rationale for repealing net neutrality rules. Breaching the commitments could constitute a deceptive business practice under Section 5 of the Federal Trade Commission Act.
* This could also be a Federal Communications Commission problem. When repealing the Obama-era net neutrality rules, the Trump-era FCC left in place a set of transparency requirements [2]. Making an inaccurate statement about network management practices can be actionable under that remaining component of the FCC's net neutrality rules.
I haven't seen a comment from T-Mobile, so to be clear, that's just based on the report.
[1] https://www.t-mobile.com/responsibility/consumer-info/polici...
[2] https://www.ecfr.gov/current/title-47/chapter-I/subchapter-A...
Who would be responsible for bringing about that action and, if they don't bring about action, what can regular people do about it?
I am also curious if the reports about content filtering being required to deactivate the feature are accurate, and if so, what the default status of that feature is on TMobile's network.
(And I think the complaints about iMessage are its exclusivity - the best solution is an iMessage for Android.)
I don't fault any one company on the messiness of the situation, it's kind of a tragedy of the commons situation. Apple isn't willing to compromise the UX complexity of adding more messaging types with different behavior, Google isn't willing to force carriers and handset manufacturers to make RCS really good, and carriers just don't care about anything other than ARPU and being "value added".
Oh, and WhatsApp interop will never happen even though that would probably actually be good because Facebook.
iMessage would be fine if it wasn't for the shitty vendor lock-out. Everyone I know uses some kind of cross platform chat app, usually either Whatsapp or Telegram. It's sad to see the green bubble shaming that Apple's exclusionary tactics has created be of such influence in US social circles.
[1] https://tmo.report/2022/01/t-mobile-blocking-icloud-private-...
Are there other legal remedies for either the subscriber or from Apple to the ISPs?
This article:
https://www.eff.org/deeplinks/2021/12/where-net-neutrality-t...
talks about how many are hoping that in the near future we will establish some net neutrality regulations, but for now there really isn't anything (at the federal level. Some states have tried).
Disabling this feature is a built-in ability of iOS. It doesn’t depend on ISPs treating the traffic differently.
Also, how can the "land of the free" not have net-neutrality laws?
More technically: NN was implemented via the existing authority of the FCC, rather than any new law. Then the FCC, under new leadership, decided that internet service was outside of that authority, actually, and dropped that enforcement. Under Biden, there has been no change back in the other direction. (And at no point has there been a separate, federal law.)
The paradoxical was a direct reflection of the corruption within the FCC at the hands of the previous administration.
Is free, unlimited HD Netflix steaming worth more than private relay? I’m guessing most people would say yes.
I’d consider switching. Oddly enough though I was able to turn on private relay on T-Mobile USA.
I know at home since I have pihole setup I got an alert that private relay can't work on my home network.
[0]: https://developer.apple.com/support/prepare-your-network-for...
For a moment I was thinking it would only trigger with something specific from the carrier, but I see little reason apple would actually work with them on this. They are not really in the business of making the carriers happy.
Edit: someone else pointed out it is actually a feature that the carriers can do. that... is disappointing.
They explicitly identify school and enterprise networks as legitimate cases where Private Relay needs to be blocked, so that's probably how carriers are doing it as well.
[1]: https://developer.apple.com/support/prepare-your-network-for...
Why are these legitimate? Censorship is wrong even when schools do it.
It's silly (and honestly sad) legislation but these companies were scooping up customers everywhere. If the choice is between "block porn and circumvention" or "no student internet access", choosing the latter could have devastating effects on kids without stable internet access at home. In my opinion, these laws should obviously not reach so far, and anything but a basic DNS block should even be illegal in my opinion, but reality is rarely what I want it to be. In the end, private relays suffer from the same restrictions and DoH and other privacy-enhancing protocols.
I'm not using an ISP that prevents me from accessing perfectly legal Internet services. No matter how they want to brand themselves, today's telcos are ISPs, no more, no less.
When shopping for cell phone providers, our considerations are 1) complete Internet access, 2) coverage, and 3) cost. T-mobile could charge $5 a month for unlimited usage, but if they can't satisfy requirements #1 and #2, then #3 is moot.
They’re not cheap.
Woo oligopoly!
> Private Relay is turned off for your cellular plan.
> Your cellular plan doesn't support iCloud Private Relay.
You genuinely get what you pay for when you spend the extra dollars for the direct carrier relationship with AT&T and Verizon. All of the MVNO's as well as their own prepaid plans will not compare if the towers are busy.
I'd like to be proven wrong, but that looks clear.
Anyone know how Google Fi compares on this criteria? I've been considering switching over for Fi's better security [1], but curious what Fi users think of the service. Since it piggybacks on other networks, does it inherit any of their service restrictions or other problems too?
[1]:https://blog.kraken.com/post/219/security-advisory-mobile-ph...
I saw conflicting reports about whether Google Fi was affected by T-Mobile's reported text message censorship. I don't know where it stands on this iCloud Private Relay issue.
Internet Access - err... it works? I am able to stream Netflix and YT without being locked to 480p.
Coverage - it's basically TMo coverage.
Cost - Fi is a bad deal if you plan to use a lot of data. It's almost 10$/GB (in the worst plan) or around 70$ for an "unlimited" plan, however it can get cheaper with a group (https://fi.google.com/about/plans/) . For me, its a great deal; I'm always close to a WiFi and rarely need mobile data. My bills ended up being around 25$. I'd say Fi's killer "feature" is it's international roaming charges... though I doubt that will be useful anytime soon :')
Though it interests me why mobile networks feel they are able to do this whereas landline ISPs don't tend to in such great numbers. At least, as far as I am aware, Deutsche Telekom aren't adding headers to bare HTTP requests etc.
I'm wondering if it's actually worth caving and having my home traffic tunneled to some provider more reputable.
At the time, the carriers specified much of how the software must work on any phone that they allowed onto their networks, both functionality and UI. Apple wanted the relationship with the carrier to be that Apple was in charge of everything except the low level code for dealing with the cellular network.
Cingular agreed, the iPhone was a huge success, the other carriers then agreed, and that's where we are today.
Now I know to cross T-Mobile off the list.
So Apple has made it very easy for a network admin to disable private relay. All an admin needs to do is blocking name lookups for relay.Apple.com*
*I don’t recall the actual DN used, it’s in Apple’s docs if you are curious.
a) disable this feature (that they likely don't fully understand) or
b) change their cellular service provider
they're going to choose the former even though migrating your phone number is pretty damn easy nowadays.
I was using my own always-on VPN w/ GrapheneOS on T-Mobile's network and was having tons of problems with calls and texts not getting through.
In the end, I want to have a clean network. And that means no private relay for 50% of mobile users and no telcos screwing my DNS, headers, zero rate my traffic whatever.
Seems like I am loose-loose situation to me.
https://developer.apple.com/support/prepare-your-network-for...
There's only one legitimate justification to block it; to better manage their network by caching data locally and not going over the internet. Private relay retains your rough physical location but it obviously connects outside of your ISP's network.
Thing is that's a legit reason to block it, but it isn't a strong one.
Doesn't Apple have a lot that can do there? Wouldn't there be TOS set by Apple that would cover interfering with functionality? I would hope apple would flex some muscle here as this would otherwise set a new dismal precedent where features were only available on a carrier by carrier basis. At one time T-Mobile seemed to try to cultivate a pro-customer perception. I guess those days are long over?
mask.icloud.com
mask-h2.icloud.comIt seems to update once a month [2]
[1] https://developer.apple.com/support/prepare-your-network-for...
[2] https://imgur.com/a/35HIV5M (only showing counts for IPv4, they have huge IPv6 blocks)
Transparency by Apple (and Android, as applicable) to the consumer about what features carriers disable should be mandatory
You don't have to punish carriers. If the market (and consumers) cares about such features, let it decide.
Edit: woodruffs above provided docs
One option that works for me to get custom DNS on iOS cellular connections (I like PiHole ad blocking on my phone) was to setup my own VPN connection to a VPS instance running PiHole for DNS and WireGuard for the VPN. Lets me get custom DNS, pihole adblocking over cellular so long as VPN isn't blocked by your cellular provider etc. Was two trivial Docker containers to get running, costs very little in AWS.
Same trick also lets me access region blocked TV services from my iOS devices over US cellular simply by turning a VPN on - I just stand up the containers on a VPS host based in source country and connect to that.
like Tor exit nodes, or obfs4 bridges
turn it into a war of attrition!
Apple can probably improve the situation by making Private Relay more like a VPN (instead of a fancy web proxy + DNS masker), including reusing the same IPs and domains that iCloud traffic is already going through.
Edit: Apple's docs show two well-known subdomains for Private Relay[1]. Blocking both of those is probably what Verizon's doing.
[1]: https://developer.apple.com/support/prepare-your-network-for...
"Network settings
Some organizations might be required to audit all network traffic by policy. To comply with such a requirement, these networks can block access to Private Relay. Users will be alerted that they need to either disable Private Relay for the network or choose another network. The fastest and most reliable way to do this is to return a negative answer from the network’s DNS resolver, preventing DNS resolution for the mask.icloud.com and mask-h2.icloud.com hostnames necessary for Private Relay traffic."
https://www.apple.com/privacy/docs/iCloud_Private_Relay_Over...
According to this it's only for people with content filters.
Yes, granted, Apple could always extract (and to some extent probably is) your history directly via OS hooks, but the "Private" relay gives them a completely opaque off-device way to centrally track what everyone is visiting, which is just another data point feeding into their rapidly-growing advertisement business.
Paranoid? Maybe, but after the whole on-device scanning fiasco I view Apple in the same category as Google, Facebook and Microsoft when it comes to privacy guarantees.
Err, no it doesn't - that's the whole point of the way it's engineered. All Apple sees is your IP address with none of the request details, and your IP is obscured before being sent to the second relay (Cloudflare, fastly, etc) , who only see the request detail with no origin/requestor information.
[1] https://www.apple.com/privacy/docs/iCloud_Private_Relay_Over...
If your argument is “they probably aren’t doing what they say they’re doing” and so you shouldn’t use their tools, then you better start writing your own operating system from scratch and designing and fabbing your own silicon, because there’s no guarantee any of these companies or open source projects aren’t compromised.
Regardless, the more general concern that parent seems to make is what is to stop Apple in the future from monetizing this data? I think the only thing protecting us as consumers is their policy. And as we all know policies can change very simply with a change to the terms of service.
https://www.apple.com/privacy/docs/iCloud_Private_Relay_Over...
“ODoH sends DNS queries through the first internet relay, so the DNS server cannot identify the user issuing a query. Each query itself is padded and encrypted using Hybrid Public Key Encryption (HPKE) to help ensure that the first internet relay cannot tell the domain name a user is looking up.”
Apple is the “first internet relay” and they seem to explicitly state that they don’t see the DNS queries themselves.
Of course, their PR will spin it up as "privacy focused, totally anonymous, personalized advertisement" and some will just gobble that up as gospel.
I don't trust any of these fuckers any more... :)
1. Privacy is a differentiator for Apple’s business. Google et al can’t compete and win on privacy. Apple can use this to win at recruiting and win at selling their ecosystem.
2. Apple’s hitting revenue/ growth targets. Other r&d investments better align with their ecosystem so there is no business driver today to enter this market.
Having said that I won’t be surprised if Apple misses a few qrtly earning targets and decides to enter the ad market.
All the big carriers have already been sued by FCC for selling location data without permission[1], and even last month Verizon is trying to justify collecting more data on everything you use your phone for[2]. Apple's business model is less gross than ISPs and their partnership with Cloudflare to prevent even themselves from being able to access traffic logs is an extra plus
[1] https://www.nytimes.com/2020/02/27/technology/fcc-location-d... [2] https://www.theverge.com/2021/12/17/22841372/verizon-custom-...
I am really skeptical of this. Not that ISPs are extremely trustworthy, but they're at least bound by some state mandated privacy protections which <Foreign VPN Provider> is not.
The system may not work for everyone (for example, streaming services optimize based on your location, which will break down if the VM lives in some cloud), but I use my phone for music, browsing and email (not video consumption) so it works for me.
alternatively, what would it take to roll your own/DIY private relay?
2 DO droplets, droplet0 runs OpenVPN or something, then private networked to droplet1 which requests are proxied through, and droplet1 recycles IP/region on some scheduled interval?
Pay extra for privacy
Or did they do away with that branding?
Tbh. the article is just not very well written, I also first thought the article implied that T-Mobile US is an EU carrier operating in the US (it isn't, it's an US carrier owned to around 43% by an EU carrier, with which it shares a bunch of thinks, like trademarks).
Reading the article and it's predecessor it seems they are mainly doing it on cheap contracts in the UK??
Which would not be in the EU.
I'm not sure if it's even legal to do so in the EU, tbh. it might be against the net neutrality rules in the EU (though they have loop holes, so not sure).
One of the upcoming ones seems to just ban Kickstarter.
especially the mentioned banners affects US and EU companies alike (or at least did until the US decided to claim rights on EU citizens data through the Cloud act...).
Wrt. to the cookie banner it you mean the one coming from GDPR then the problem is missing enforcement. It must be as easy to opt in as to opt out this means:
- two clicks to opt out one for opt in => illegal
- dark patterns which makes it easier to accidentally opt in => illegal
- spamming people which don't agree to being spied on with "dialog boxes" => illegal (GDPR allows some forms purely functional data storage without consent, for example a non-3rd party cookie to remember that the user is opted out _which is not used for tracking_ is legal without asking for consent, hence there is a technical easy and legal way to not spam people with dialog boxes, hence making it harder for people to opt out by repeating forcing them to redo the action is illegal). Naturally doesn't apply if you clear cookies.
When your product causes your customers to call someone else and complain, don't be surprised if that "someone else" disabled access to your product.
First of all, Private Relay doesn't affect your grocery store's app - 3rd party app traffic doesn't use it. It also can't 'break' your home wifi for your friends. And finally, when it's not working, it's automatically disabled, you are notified, and you continue browsing without it.
But my home network’s DNS is quite … convoluted (intercepted and sent through DOT depending on which vlan you’re on, which somehow broke private relay). From the comments here, I’ve learned how to disable this feature remotely. So that’ll be nice.
I never saw the “it’s broken” notification. So either it came after I last used private relay, or it never broke through my “no notifications” settings.