Apple's “iCloud Private Relay” broke risk based authentication
1–10 of 211 posts
Re: Apple's “iCloud Private Relay” broke risk based authentication
#2Well I'm not sure everyone will be happy to do that. Tying session tokens to source IP addresses is usually not a bad practice and is rarely the only mitigation used.
Re: Apple's “iCloud Private Relay” broke risk based authentication
#3Re: Apple's “iCloud Private Relay” broke risk based authentication
#4Wait, so my data will be routed to US servers, as an EU resident, where the data protection laws are not as strong as where I live? This is a really bad idea, as US is known to tap any data they can get on their soil.
Re: Apple's “iCloud Private Relay” broke risk based authentication
#5Re: Apple's “iCloud Private Relay” broke risk based authentication
#6Did they just reïnvent opinion pieces?
Re: Apple's “iCloud Private Relay” broke risk based authentication
#7> IMO = In My Opinion is a blog format where a author reflects his own opinion Did they just reïnvent opinion pieces?
Re: Apple's “iCloud Private Relay” broke risk based authentication
#8> As of writing this blog I was in Switzerland and the IP used to egress my traffic was in a region located in the US. If this also tends to change a lot and fast you can basically throw away IP addresses as data of your RIBA. Wait, so my data will be routed to US servers, as an EU resident, where the data protection laws are not as strong as where I live? This is a really bad idea, as US is known to tap any data the…
Re: Apple's “iCloud Private Relay” broke risk based authentication
#9"But please stop relying on RIBA for the plain authentication of a user!" Well I'm not sure everyone will be happy to do that. Tying session tokens to source IP addresses is usually not a bad practice and is rarely the only mitigation used.
Using the IP as means is IMO nonsense with todays use of CG-NAT, VPN and so on. It does not rely help securing something.
But these are just my 2 cents ;-)
Disclaimer: I wrote the article
Re: Apple's “iCloud Private Relay” broke risk based authentication
#10> As of writing this blog I was in Switzerland and the IP used to egress my traffic was in a region located in the US. If this also tends to change a lot and fast you can basically throw away IP addresses as data of your RIBA. Wait, so my data will be routed to US servers, as an EU resident, where the data protection laws are not as strong as where I live? This is a really bad idea, as US is known to tap any data the…