About iCloud Private Relay
support.apple.com
support.apple.com
Im moving my to-be-paid-for personal google apps accounts over to iCloud for one.
It’s not just a principled approach. Though it just makes sense. Thank god apple has minimal ad income only. Otherwise this wouldn’t happen.
Why? The cover story for App Store is that it's supposed to protect consumers, but then the consumer searches for an app literally by name, and the first hit is a completely different app that paid for an ad. How is that protecting consumers?
Moreover, Apple added App Tracking Transparency, where the cover story is privacy, but coincidentally ATT has at the same time caused people to switch more to Search Ads, because third party ads have become less effective as a result. There's a conflict of interest here.
Meh. I think the paid results are pretty well demarcated, and are, visually, nearly identical to what they looked like at launch in 2016.
Competitors bidding on keywords is definitely lame.
In the UK phone operators have complained about it on the basis that:
> [it allows Apple] to leverage its considerable market power into many areas of the market and thus being able to further entrench its position ... Network providers would no longer be able to use web traffic data over Safari to develop their own digital products and services that complete directly with Apple. For example, a network provider may no longer have access to information about a user's content viewing habits to develop their own content that competes with Apple TV. Similarly, a network provider may no longer be able to share consumer insight with third parties that provide digital advertizing services in competition with Apple Search Ads...
How true that is, who knows, but it's an interesting angle on how it benefits Apple
That complaint by the telcos is what convinced me to turn it on, the entire thing was a big whinge by them about not being able to spy on users anymore (and the hilarious claim that Apple was doing it to move users off Safari)
Do what I do, i encode all emails into giant QR codes on paper that will fade in 72 hours. I then have a staffer chain a briefcase with the email to his or her wrist and fly to the recipient in a private jet. The one time pads are delivered by a separate courier.
Any such scenario would result in the company or their providers controlling a lot of the infrastructure.
That’s why private relay isn’t a bad thing. You’re replacing thousands of individual risks with one. IMO, the protection of Apple’s PR is stronger than any tech.
How is that new though? As the creator of Safari they could store tracking information locally and batch upload it for processing.
It's different in terms of security, but in terms of competition, which is what network providers complained about, there is no difference at all.
To be fair to telcos, (who totally don't deserve it), the original argument they made is that if all phone traffic gets routed to a relay endpoint, and not its real destination, it reduces their ability to network plan and add capacity to the routes that are actually in use.
Hearing this argument means they didn't get what they want and wanted to pull in the antitrust argument, and tipped more of their hands.
In the case of private relay, I believe they are using privacy pass such that a token indicating authorization is anonymous on use. So say, Apple knows who someone is, but Cloudflare and the like who do the actual producing can only tell that Apple authorized proxy access and (for HTTPS) what domains are being accessed.
So Cloudflare in this example may be able to get some statistics of use and share them with Apple, but it will be more about the relative popularities of pornhub.com and cnn.com, and not what percentage or who frequent both.
Take a look at their approach to differential privacy if you are still convinced their data collection is egregious: https://www.apple.com/privacy/docs/Differential_Privacy_Over...
The app tracking dialog on iOS is technically opt-in, but the way it is written reflects that the system and the user have limited control, the "Ask App Not to Track" button implies that Apple acknowledges that their attempts to block tracking are best effort and are not guaranteed to work, because new and clever ways to implement tracking are being created on a regular basis.
For example the gatekeeper revocation check leaks a lot of data about what kind of apps you run. I'm sure some departments of apple really care about privacy but it's a big company and clearly not all of them do.
And whether Apple can only track their own services/apps or other user data/activity. Providing Safari makes it interesting
unless the user consents. So evil.
That’s… kinda the point, no? To prevent scummy people doing scummy things.
Im not supper trusting of any of these big companies. I don’t love regulations but we seem to be headed to some weird monopolistic place.
I also don't buy the whole "well your data might not be shared with X anymore but you're trusting Apple with it". What's the point? Anyone who uses literally any other major operating system is going to deal with the same thing. And the alternative? Android? Unless you want to switch to an indie fork of Android then the telemetry is much worse.
What Private Relay does appear to do is guarantee that no one besides Apple can do scummy things. That's a definite improvement.
So people who sell a service and engage in surveillance to extract money through some other means are upset because another company is selling a service that provides a documented feature that prevents said surveillance.
Why wouldn’t that argument apply to normal VPN? Wouldn’t the mobile carrier be able to provide a spectrum of value-added services if they understood how my employees work? For example, if they were able to see that my accounts payable folks were recording information in SharePoint forms, they could offer a forms solution that was more efficient!
See also getting into Ads after kneecapping the competition.
There is no world where I want my ISP to have access to information about my content viewing habits. Why is this not an opt-in?
Seems like a really silly statement to me.
Long term we've yet to see what the evolution will end up being (Apple could publish a list of their exit nodes for websites to whitelist, causing Mullvad et al to be left out in the cold), but for now I'm cautiously optimistic.
By consolidating all surveillance to Apple?
For two, by hopefully making usage of VPNs more palatable to sites that are currently harassing what they perceive as the small segment of VPN users with blocks and CAPTCHAs.
I admit that #2 is hopeful, and that we might just end up with those sites whitelisting Apple while continuing to hassle everyone else that wants to hide their IP. But I'd prefer to hope for now.
Obviously the real long term answer is the development and adoption of secure protocols instead of centrally-named and centrally-served HTTPS/DNS, but that's orthogonal.
Your comment ends with:
> I appreciate that and it contributes to my overall respect for the company and its approach.
Seems like a straightforward connection: Apple provides the feature → your trust in them increases[1] → you continue to buy from them and recommend them to other people.
[1]: Especially relevant at a time where distrust of big tech companies is rising.
Besides requiring a paid iCloud+ subscription?
That's what iCloud 50GB cost in 2015, and they introduced these new features in 2021.
Likely possible due to falling capex/opex costs for the storage, but still...they added multiple new features and didn't increase the price, even after a fairly substantial amount of inflation over those five to six years.
If Apple wasn't trying to sell iCloud+ then it would have made iCloud Private Relay available to all Apple users without iCloud+.
Apple is not a charity. This is sales 101.
Which would be fine if there marketing wasn't so effective. As it stands, they're an existential risk to the freedom we all currently enjoy in computing. And the environmental impact of pure disposable consumption devices is the kind of thing journalists will be talking about in 30 years - like oil and gas.
And like oil and gas, they're very powerful and have great marketing.
Also, technology has advanced so much in the past 15 years that people are replacing their Apple devices significantly less frequently than they used to.
Not sure about that. We have annual OS updates with force obsolescence via termination of device support and security updates. (Even the "supported" N-2 versions of macOS don't get all the security updates of the latest version.)
And the devices now all have batteries that aren't user-replaceable.
With the 2 year phone carrier contracts, the financial incentive was actually to upgrade your phone every 2 years. Those are mostly gone now, but it's rumored that Apple is working on a new hardware subscription.
Also, as of today, battery replacements for all supported iPhone devices costs less than $70. That’s a very good price and basically includes the labor for free. Nobody is getting ripped off here.
> Even the "supported" N-2 versions of macOS don't get all the security updates of the latest version.
If it’s supported, it’s getting security updates, period. Here is an example of a recent security update for Catalina: https://support.apple.com/kb/DL2089?locale=en_US
I disagree. My 2014 MacBook Pro still works perfectly fine, but it doesn't run Monterey, which I need for work purposes, so I had to buy a new MacBook Pro. I certainly didn't want to drop all that money right now.
> Also, as of today, battery replacements for all supported iPhone devices costs less than $70. That’s a very good price and basically includes the labor for free. Nobody is getting ripped off here.
I've had to replace the battery twice out of warranty on my 2014 MacBook Pro, and it cost more than $70. Moreover, the pandemic has made getting repairs significantly more difficult. Who wants to ship their device off and be without it?
> If it’s supported, it’s getting security updates, period. If you have contrary evidence, I’d like to see it.
I said they don't get all the security updates; I didn't say they get no security updates.
This differential in vulnerability patching is very well known among Mac security researchers. For example: https://www.intego.com/mac-security-blog/apples-poor-patchin... users-security-and-privacy-precarious/
I can sympathize with being frugal. That said, if you're buying a laptop for work, I recommend both financing it and depreciating it on your taxes, if that's an option for you. It's a cost of doing business, and many tax codes treat computers as depreciable assets. In fact, in the U.S., the tax code has a 5-year depreciation schedule for computers - less than the support lifetime.
As for the security updates question, if you have information that Catalina is lacking a critical security update, I'm sure Apple would like to know about it and fix it. They care a lot about this stuff. The article you posted complains about a lack of transparency as to the "why" certain patches aren't backported, but it doesn't declare that there are active security vulnerabilities in those versions, either.
To me it’s obvious how this helps their bottom line: people are very interested in privacy and willing to pay top dollar for it. Every time I turn on an additional privacy service from Apple, I feel their grip tightening on my digital identity as they push themselves even more between me and the direct relationships I have with other websites.
iCloud private relay, email aliases, and “Sign in with Apple” is their final act to completely dominate the relationship between their users and other web applications.
I’m not bitter about it, but I do think it’s helpful and healthier to view Apple in this way and not mistake their efforts as altruistic. They’re simply a company trying to develop a profitable, high retention service… and they’re doing a damn good job at it.
I wish there was a good privacy-embracing cloud platform that I could just pay for directly instead of via buying hardware as Apple does.
iCloud private relay is a great idea but I need it on all my computers and phones. I use Firefox now but their VPN option doesn't hold a candle to what Apple offers with icloud relay. It's really a different thing altogether.
Why? Why not just use a different VPN/Proxy service? A lot of apple features are available elsewhere like Sign-in-with-apple.
Same argument for windows...a lot of iOS users run windows.
Apple has no incentive to actively support android hardware.
Services however makes sense and courting Android is a good strategy.
At the end of the day, they are a very successful business that serves its own bottom line. The privacy angle for the mobile and browser ecosystem, in my eyes, is nothing but market positioning (as more or less anti-Android and anti-Chrome) even if they are engineering novel solutions such as the Private Relay.
If they really cared, they wouldn't be in bed with Google for their search deal, for example: https://www.nytimes.com/2020/10/25/technology/apple-google-s...
Maybe this still indicates the email is valid to a spammer, but it wouldn’t show that you opened it (unlike i.e. Gmail’s image proxy, which only loads upon viewing.)
https://www.litmus.com/blog/apple-mail-privacy-protection-fo...
- Opening Mail, Preferences, and going to the Privacy tab. - Unchecking "protect mail activity" - Checking "hide IP address" - Checking "block all remote content"
Now you have automatic remote content loading disabled, and have private relay enabled. You would need to test this with a "friendly" bit of remote content to be certain, but it seems to work.
When doing this, also ensure you have limit IP tracking enabled on your ethernet or wifi network, as that appears to override this setting (based on the help content which is available in this tab).
This is great in that it gives everyday folks a stupid-simple protection from ISP and mobile service providers.
And yes, of course Apple did it as another reason to sell next tier iCloud service and gain good will of folks, which I think is a much better trade off then ISPs and Sprint/Verizon/etc knowing your full browser history.
I don't get it as VPNs or proxies aren't illegal where I live, how is Apple's private relay not available?
VPS are a digital product while Apple has physical stores or resellers of physical products in these countries. It’s not as easy.
Cloudflare has a good blog post about this: https://blog.cloudflare.com/icloud-private-relay/
Plus, I dont see any benefit of hiding my network traffic here in Germany, tbh.
Theoretically, editing your hosts file might provide the same filters even with Apple's pseudo-TOR enabled if the system respects user preferences. That might be a challenge on iOS, though.
I am using NextDNS on all iOS devices and it works great. Get yourself an account and configure it to your needs. Don't forget to enable the block site instead of 0.0.0.0., then download their CA and trust it.
1. Dramatically reduces the number of entities the government needs to "partner" with (via NSLs and/or TAO) for the firehose of domains visited by Apple users.
2. Apple gets a time series of Safari network traffic for each user
I wonder how many popular domains could be unmasked by an ISP that is supposedly blind to the destination of each packet but can of course still see fine-grained traffic patterns for each user.
(2) Again, by design Apple cannot see what is being requested, so no it doesn't get a time series of safari traffic. If that were a real concern that you had, then recall the Apple could just have Safari report those directly, without having to have any VPN-type insanity.
The text that is important is, it would seem very hard for Apple to say this is if was not true: "This information could be used to determine your identity and build a profile of your location and browsing history over time. iCloud Private Relay is designed to protect your privacy by ensuring that when you browse the web in Safari, no single party—not even Apple—can see both who you are and what sites you're visiting."
my thought was 2 VPS and use Wireguard multihop. VPS 0 connected from my home router, VPS 1 connected to VPS 0 via private networking (ideally in a different geo location). recycle VPS 1 IP/location periodically.
VPN from mobile to home router and get the benefits on the go, with dnsmasq blocking ad hosts in VPS 1 so tracking crap ideally doesn't make it over the wire. thoughts?
…plus I found I would sporadically get connection issues that I resolved by turning it off.
It’s a bummer because I would like to use it, and it being bundled with iCloud is nice.
I haven't used it myself, but it seems reasonable to inform laymen that browsing to a captive portal system will be unprotected. I'm not sure how eggregious the error actually is.
> …plus I found I would sporadically get connection issues that I resolved by turning it off.
Not defending Apple in particular, but connectivity will decrease with every extra hop you make in your connection; you'll notice this when browsing the internet with tor (or, heaven forbid trying to use IRC over tor).
it makes sense that you would have more connectivity issues when using any kind of proxy; and it would get worse with every extra layer of proxy.
I’m not as convinced as you that these problems are inherent to the service, and I’m holding out hope for what Private Relay looks like when it emerges from beta.
> I'm not sure how eggregious the error actually is
Not egregious - annoying. Unusual for Apple. I don’t want to use a service that spits alerts at me as I walk around the city.
What is all this data good for?
When it comes to ads/marketing, it is good enough to make others believe they are driving sales/conversions - whether it actually does is irrelevant as long as everyone believes it does and keeps pouring money into it.
So where as in the olden days, in order to figure out who you were, some actor had to buy logs from the destination sites and from the ISPs, then correlate.
Now they can just buy the information from Apple. How convenient for Apple.
I know Apple says they will only share your information with trusted partners and only with your consent which is implicit when you use private relay. No one ever asks who these partners are though. Probably the same people that used to buy your data from the destination sites and ISPs...
Secondly, Apple makes the OS. If they wanted to spy on you, they could have done so in much easier ways already.
> when you browse the web in Safari, no single party — not even Apple — can see both who you are and what sites you're visiting.
id wager there is an internal team analyzing this data for predictive trends across all their product lines, akin to facebook using onavo data to target and value whatsapp relative to messenger.
it could be used to guide which new streaming series candidate gets more funding/marketing, popular colors for new iPhones, price elasticity across the range, etc.
and of course the surveillance aspect always looms in the background.
[0] - https://www.macrumors.com/2022/05/09/apple-services-push-str...