Live data from Hacker News

Apple's “iCloud Private Relay” broke risk based authentication

zitadel.ch

21–30 of 211 posts

Re: Apple's “iCloud Private Relay” broke risk based authentication

#21
post #16

Earlier quoted context omitted.

Private relay will egress from the same general region as the client source location. So if you’re in switzerland and hopping through a US exit point that is a bug. This is clearly explained in the wwdc video

You can choose in the OS to use a general location or stick to something in your proximity. At least in the Developer Beta 2

The two options are basically city-level or country but same TZ level. e.g. Toronto, or somewhere in Canada in Eastern time (which I mean would almost certainly be limited to Toronto -- presumably these options make more sense on say the East Coast for the US where there are a number of possible major locations that fit)

There are clearly some bugs. Occasionally I, in Canada, get routed through the US. This guy got routed through the US. Neither case should happen by Apple's description. Apple is quite intentionally trying to avoid their relays getting around geo-restrictions (likely to avoid them getting blacklisted).

Re: Apple's “iCloud Private Relay” broke risk based authentication

#22
post #4

> As of writing this blog I was in Switzerland and the IP used to egress my traffic was in a region located in the US. If this also tends to change a lot and fast you can basically throw away IP addresses as data of your RIBA. Wait, so my data will be routed to US servers, as an EU resident, where the data protection laws are not as strong as where I live? This is a really bad idea, as US is known to tap any data the…

I'm more bemused as why it picked a US server in the first place, as the options panel screenshot suggests it should be presevering the rough location (i.e. pick Belgium or France or somewhere european). Is private relay still in Beta? That might explain it if the serve side component only got deployed in one or two of Apple's US datacentres.

It did change a lot in the last few days. As of now I get some datacenter in Switzerland and Liechtenstein sometimes.

Re: Apple's “iCloud Private Relay” broke risk based authentication

#23
post #4

> As of writing this blog I was in Switzerland and the IP used to egress my traffic was in a region located in the US. If this also tends to change a lot and fast you can basically throw away IP addresses as data of your RIBA. Wait, so my data will be routed to US servers, as an EU resident, where the data protection laws are not as strong as where I live? This is a really bad idea, as US is known to tap any data the…

Private relay will egress from the same general region as the client source location. So if you’re in switzerland and hopping through a US exit point that is a bug. This is clearly explained in the wwdc video

[deleted]

Re: Apple's “iCloud Private Relay” broke risk based authentication

#24
I hadn't known there was a term for this braindead idea that websites should hassle you based on your IP address. Of course there has to be a term, compartmentalization is necessary for getting good people to do bad things.

It's fantastic that Apple is continuing to mitigate commercial surveillance. It's easy to discriminate against us lone individuals who hide our IP addresses, but Apple's market is too big to reject. If they're successful here, I'll have to consider buying a Mac purely for their VPN service.

Perhaps they'll take on CAPTCHAs next.

Re: Apple's “iCloud Private Relay” broke risk based authentication

#25
post #20

When Google Workplace locks users because of this, and I’m fairly sure they will because they’re super aggressive with IPs that change via VPN, they'll bounce incoming mail for that user. Have fun everyone!

Been there done that. Google flagged my account several times already, with nice captchas :-)

They just wanted you to train their AI.

Re: Apple's “iCloud Private Relay” broke risk based authentication

#26
post #4

> As of writing this blog I was in Switzerland and the IP used to egress my traffic was in a region located in the US. If this also tends to change a lot and fast you can basically throw away IP addresses as data of your RIBA. Wait, so my data will be routed to US servers, as an EU resident, where the data protection laws are not as strong as where I live? This is a really bad idea, as US is known to tap any data the…

I'm more bemused as why it picked a US server in the first place, as the options panel screenshot suggests it should be presevering the rough location (i.e. pick Belgium or France or somewhere european). Is private relay still in Beta? That might explain it if the serve side component only got deployed in one or two of Apple's US datacentres.

Yes, it is a macOS Monterey/iOS 15 feature and both are in early (!) Beta. Exit nodes may severly limited at the moment.

Re: Apple's “iCloud Private Relay” broke risk based authentication

#30
post #5

I find authentication the least problematic place where risk based on ip is used. Etsy, for example, will suspend your seller account if it sees too many logins from different IPs or if it's from an IP it has flagged before. It also has terrible seller customer service so it could take weeks to get it un-suspended. Heard of some people using Private Relay getting hit by this during the beta so hopefully Etsy gets rid…

Compared to Google, where you can't contact anybody at all if you're not on a payed account. Yes, it's free, why do you expect service, but they're still making money off me with ads etc., so locking an account down forever because of suspicious activity seems a bit over the top in that case.
Post reply on HN