An investigation into Apple’s new Relay network
blog.apnic.net
blog.apnic.net
I discovered this because pihole blocks private relay by default and I was getting an error in the mail app that it wasn't able to protect my activity: https://apple.stackexchange.com/questions/429899/why-am-i-se...
Have to say I'm a big fan of apple trying to bring more of these features to average users. I had just finished prototyping my own mail server to do exactly what "hide my email" does when apple announced that feature and was very happy to be able to throw that code out in favor of something built into my mail client (although it was actually pretty fun to learn dovecot and postfix).
Protect Mail Activity helps protect your privacy by preventing email senders, including Apple, from learning information about your Mail activity. When you receive an email in the Mail app, rather than downloading remote content when you open an email, Protect Mail Activity downloads remote content in the background by default — regardless of whether you engage with the email. Apple does not learn any information about the content.
In addition, Protect Mail Activity routes all remote content downloaded by Mail through two separate relays operated by different entities. The first knows your IP address but not the remote Mail content you receive. The second knows the remote Mail content you receive but not your IP address, instead providing a generalised identity to the destination. This way, no single entity has the information to identify both you and the remote Mail content you receive. Senders can’t use your IP address as a unique identifier to connect your activity across websites or apps to build a profile about you.
If you choose to disable Protect Mail Activity, the Hide IP Address feature will still mask your IP address using the same two-separate-internet-relays design.
Not seeing the IP is also important for preventing linking: if you have data from other sources (your website, apps, etc.) this can link that activity to an identity for as long as your IP doesn't change. It's not perfect but that's the kind of thing advertisers like because they can see that, say, session A on a desktop computer which generated the email lead to session B on a phone which opened it and consider that all future activity linked to the session IDs from either client is the same person even when your phone moves to another network.
Gmail uses a similar technique to mask metadata, though iirc they do download the images only when the email is first read by the recipient.
If you do open the email, and the spammer maps, say, snotrockets@example.com to a unique AD-SRE21234.JPG filename and that image within the email is displayed, no matter if it goes through Apple's relay or not, wouldn't the spammer then be able to validate your address is both valid and actively opening spam mail at whatever time you opened it?
Image download would happen from a 3rd party and as soon as its received.
So actual usability is quite low. They would spam you anyway, though.
Still a net win.
“Private Relay is not available in Thailand due to local laws and regulations.“
“Privacy is a fundamental human right.” Unless local laws and regulations say otherwise.
> And if you really think authoritarian governments are going to choose iPhones over control, well…
lol, Thailand doesn't even block VPNs. You really think they'd do something as drastic as banning Apple devices over this?
There are many authoritarian countries were banning iPhones would simply be unimaginable, there's no way they'd even think about doing that in places like Russia.
If Apple breaks laws isn't that what Governments should do? For instance in Europe (was it Netherlands ?).Apple has blatantly ignored a ruling on app store and allowed fines to accumulate. The government should have blocked the app store but instead let itself be bullied by Apple
It depends.
I dunno, but the feature is disallowed for a reason. It's more than a VPN because it's so much easier to use than VPNs are typically and I believe it's also enabled by default with iCloud.
Apple certainly could do this.
Expected? No. For a global company without backbone. Wish? Yes.
Findings in the article aside, of course.
If the RIAA gets a court order to reveal who streamed something, shared illegally, etc. would they be able to comply?
Someone who can monitor all the entry points and exit points can probably tie the connection together, but someone in that position can probably also do that for any other vpn service (Nord, proton, etc - though those providers don't have any privacy options).
This whitelist is implemented using the regular macOS/iOS per-app firewall. Not only this is accessible to users, but the whitelist matches based on the Mach-O UUID, which is an arbitrary number put in by the linker...
The restriction on which apps can use iCloud Private Relay is trivially defeatable.
Private Relay hides your IP address and browsing activity in Safari and protects your unencrypted internet traffic so that no one-including Apple-can see both who you are and what sites you're visiting
They made it a few years ago they all apps had to use encryption. Long before private relay came out. I have wondered if this was why.
Vs your isp knowing every site you go to? Or you could get a random VPN service, in which case you have another single company to serve a warrant, only unlike the relay case that vpn knows just as much as your original ISP.
“ As lawful interception takes place in the core network, and the initial 5G NR deployments leveraged the existing 4G EPC network, carriers were able to continue using their existing and compliant lawful interception systems to support their 5G NR deployments. Therefore, Law Enforcement Agencies (LEAs) considered 5G systems as nothing new, just “4G on steroids”. And from a Lawful Interception standpoint, they were right. Those initial systems supported the existing handover specifications such as 3GPP TS 33.106, 33.107 and 33.108 and could only support up to 1Gbps per subscriber bandwidth, since the Evolved Packet Core (EPC) was still 4G and there were capacity limitations on the EPC. Law”
What it does provide is the first private (again, not Tor-level private) VPN that incentivizes sites to allow the traffic. How does it do this?
- traffic is legitimate with a high degree of certainty (it's tied to an iCloud account that can be blocked, and more or less must be run on Apple hardware)
- sites that block private relay are potentially blocking a large audience of Apple users
With more anonymous VPNs there are fewer potential repercussions against malicious traffic, and it's harder to prevent users from abusing the system.
Wait… what? The traffic on this private relay can be traced back to your iCloud account? By Apple? By any website you visit?
What are you talking about?
How does Apple tie your traffic to your iCloud account? They have repeatedly stated that they cannot see what any account is doing.
Apple literally cannot ban you for malicious or fraudulent traffic (assuming you believe them), so what is the difference between this and any other paid VPN service? Those also cost money.
> Authorization is performed by presenting a valid, anonymous token based on RSA blind signatures. These signatures are sent as one-time-use tokens to each proxy when establishing a connection, separating legitimate from illegitimate devices. The proxies can validate the tokens with a public key to validate that the user is legitimate, without actually identifying the user.
> The following fields related to anonymous token issuance are logged as a part of Private Relay’s fraud prevention and anti-abuse measures, but cannot be correlated with connection information: > • iCloud account, software version, and request timestamp
Sounds like both Apple and Cloudflare hops get the token. But Apple stashes a mapping of the token->iCloud account on its end, presumably to deal with fraud requests from Cloudflare. So my understanding then is if Apple gets a fraud/abuse request for someone's token from Cloudflare, it can and will banish your iCloud account from the service.
Edit: on closer reading I think I was wrong... The stated logged data could just be to rate limit the tokens you can request. It doesn't say they log the token itself, and they do say "cannot be correlated with connection information". So it seems you are right!
Do you honestly believe that? One of the most powerful telecommunication hardware companies in America, hilariously somehow NOT being in bed with government agencies? Perhaps Apple can't see your traffic, so by the letter of their statement, what they said is true... but the mystery boxes in locked rooms at Akamai, Fastly, and Cloudflare I'm sure can connect your traffic across the relay hops juuuuuuust fine.
Not to mention the other poster's important point of having the traffic effectively tagged to your iCloud account is stunningly probably very accurate. I knew this thing was bad news the moment I first read about it, now I feel even more strongly it is indeed America's version of the great firewall and social credit score impacted by your net traffic and the websites you visited pumped up on American steroids.
Cloudflare sitting as a proxy in front of tons of other websites otherwise in the wild closes the significant gap left by non-Apple device users.
I believe that that is what they have repeatedly said.
Is your position that Apple is doing some sort of scam on their paying users in order to compromise their privacy to random websites?
I did not bring up any law enforcement organizations, I was responding to the idea that since Apple can ban users, random website operators will trust their relay traffic more. This is a completely unrelated thing.
That being said, there’s still a barrier to entry by having an i-device/i-account. I wonder if there would be a way for them to ban abuse since they have so much control over the ecosystem?
Great
After forbidding privacy by blocking tor and proxy traffic, now CloudFlare is going to red carpet Apple devices only.
I've never had issues with Akamai or the like even on Tor. It's it CloudFlare, they're here to undermine the web neutrality in some way.
Are these companies rebuilding a more private internet?
We need some RFC or standard for what they are doing, not just a registration and relay service run by Apple and CloudFlare.