Live data from Hacker News

Apple's “iCloud Private Relay” broke risk based authentication

zitadel.ch

31–40 of 211 posts

Re: Apple's “iCloud Private Relay” broke risk based authentication

#31
post #28

Author, since you “dearly recommend” a related blog post of yours, please link to that post .

Whops, good catch! There is definitely the link missing. Going to correct that ASAP.

In the meantime: https://zitadel.ch/blog/imo-passkey-in-icloud-keychain/

Re: Apple's “iCloud Private Relay” broke risk based authentication

#33
post #14

Earlier quoted context omitted.

Token binding was a much better way to do this where you'd bind a cookie to a certain client TLS key. Unfortunately only MS implemented support, and that disappeared when they moved to chromium so I'm guessing it's dead.

I think it is still there, even in Edge on Chromium. But still Chrome dropped the hidden support a while ago.

Every source I could find said that it was not carried over to chromium-edge and considering how little use it got (because of poor browser support) I'm not surprised.

Re: Apple's “iCloud Private Relay” broke risk based authentication

#35
post #22

Earlier quoted context omitted.

I'm more bemused as why it picked a US server in the first place, as the options panel screenshot suggests it should be presevering the rough location (i.e. pick Belgium or France or somewhere european). Is private relay still in Beta? That might explain it if the serve side component only got deployed in one or two of Apple's US datacentres.

It did change a lot in the last few days. As of now I get some datacenter in Switzerland and Liechtenstein sometimes.

Which datacenters are they using? Could you provide IPs or ASNs?

Re: Apple's “iCloud Private Relay” broke risk based authentication

#36
post #32

Just occurred to me that Apple’s upcoming iCloud Private Relay will break nearly all GDPR solutions. Am guessing this has been written up already be someone. Any good perspectives?

How? The data stays in EU. Routing to US is clearly a bug (that violates it, yes)

Re: Apple's “iCloud Private Relay” broke risk based authentication

#38
post #22

Earlier quoted context omitted.

It did change a lot in the last few days. As of now I get some datacenter in Switzerland and Liechtenstein sometimes.

Which datacenters are they using? Could you provide IPs or ASNs?

Well as of now the traffic egresses with Cloudflare in Zürich or Bern with the IP 104.28.19.67 :-)

Re: Apple's “iCloud Private Relay” broke risk based authentication

#39
post #14

Earlier quoted context omitted.

I think it is still there, even in Edge on Chromium. But still Chrome dropped the hidden support a while ago.

Every source I could find said that it was not carried over to chromium-edge and considering how little use it got (because of poor browser support) I'm not surprised.

Ok, maybe I remembered wrong. This makes things even worse.

Re: Apple's “iCloud Private Relay” broke risk based authentication

#40
post #4

> As of writing this blog I was in Switzerland and the IP used to egress my traffic was in a region located in the US. If this also tends to change a lot and fast you can basically throw away IP addresses as data of your RIBA. Wait, so my data will be routed to US servers, as an EU resident, where the data protection laws are not as strong as where I live? This is a really bad idea, as US is known to tap any data the…

Private relay will egress from the same general region as the client source location. So if you’re in switzerland and hopping through a US exit point that is a bug. This is clearly explained in the wwdc video

Yeah, and there are solid performance reasons for that too even beyond any legal/privacy ones. Relaying across an ocean could actually be a fairly significant latency hit in many cases. Services that are completely focused on privacy even against some level of state actions (like Tor) may just accept and eat that, but that's not definitely not the threat scenario Apple is targeting and it would diminish its appeal as a fairly transparent service. Even purely in the browser people do engage in a certain amount of real-time activity. I can't see Apple considering adding thousands of miles worth of RTT ideal.
Post reply on HN