Apple's “iCloud Private Relay” broke risk based authentication
61–70 of 211 posts
Re: Apple's “iCloud Private Relay” broke risk based authentication
#62> As of writing this blog I was in Switzerland and the IP used to egress my traffic was in a region located in the US. If this also tends to change a lot and fast you can basically throw away IP addresses as data of your RIBA. Wait, so my data will be routed to US servers, as an EU resident, where the data protection laws are not as strong as where I live? This is a really bad idea, as US is known to tap any data the…
Re: Apple's “iCloud Private Relay” broke risk based authentication
#63I hadn't known there was a term for this braindead idea that websites should hassle you based on your IP address. Of course there has to be a term, compartmentalization is necessary for getting good people to do bad things. It's fantastic that Apple is continuing to mitigate commercial surveillance. It's easy to discriminate against us lone individuals who hide our IP addresses, but Apple's market is too big to rejec…
So if you only ever log in to your financial institution from NY city, they shouldn't be suspicious if they see an attempt to log in from North Macedonia?
Re: Apple's “iCloud Private Relay” broke risk based authentication
#64Please kill opt-out-less 2FA while you’re at it. (Thanks Amazon, been enjoying that change!)
Re: Apple's “iCloud Private Relay” broke risk based authentication
#65Did it actually break risk based authentication though? Sure, legitimate users will be using Apple's Relay, but what's stopping attackers from using it? If the users of the service are choosing to be indistinguishable from attackers, then that's on them. I think of it like reputation in real life. If you come knocking on my door, and I can see and recognize you, I'll open it. If you cover up my peephole or hide yours…
It broke it in the sense that it removed a signal that would allow the service to distinguish legit users from possibly malicious ones. In the case of a legit user that has in the past always authenticated from an IP address or address block geolocated to say, Seattle, the service can look at any authentication attempt from elsewhere as anomalous and raise additional challenges. However, with Relay, that signal is lo…
Re: Apple's “iCloud Private Relay” broke risk based authentication
#66Thank you. Can someone please break security questions next so I don’t have to store four passwords instead of one to login to my accounts? Please kill opt-out-less 2FA while you’re at it. (Thanks Amazon, been enjoying that change!)
Re: Apple's “iCloud Private Relay” broke risk based authentication
#67I find authentication the least problematic place where risk based on ip is used. Etsy, for example, will suspend your seller account if it sees too many logins from different IPs or if it's from an IP it has flagged before. It also has terrible seller customer service so it could take weeks to get it un-suspended. Heard of some people using Private Relay getting hit by this during the beta so hopefully Etsy gets rid…
Compared to Google, where you can't contact anybody at all if you're not on a payed account. Yes, it's free, why do you expect service, but they're still making money off me with ads etc., so locking an account down forever because of suspicious activity seems a bit over the top in that case.
Re: Apple's “iCloud Private Relay” broke risk based authentication
#68I find authentication the least problematic place where risk based on ip is used. Etsy, for example, will suspend your seller account if it sees too many logins from different IPs or if it's from an IP it has flagged before. It also has terrible seller customer service so it could take weeks to get it un-suspended. Heard of some people using Private Relay getting hit by this during the beta so hopefully Etsy gets rid…
That’s what’s different with iCloud relay - Apple’s weight to force changes upstream.
Either Etsy changes their policy now during the beta (my guess is they will), or they change it in a panic in November when iPhones can no longer access the site to buy anything.
(No-one is going to switch off private relay to convenience a single website).
Re: Apple's “iCloud Private Relay” broke risk based authentication
#69Earlier quoted context omitted.
It broke it in the sense that it removed a signal that would allow the service to distinguish legit users from possibly malicious ones. In the case of a legit user that has in the past always authenticated from an IP address or address block geolocated to say, Seattle, the service can look at any authentication attempt from elsewhere as anomalous and raise additional challenges. However, with Relay, that signal is lo…
Thank you, this really well summarises my article.
Re: Apple's “iCloud Private Relay” broke risk based authentication
#70I find authentication the least problematic place where risk based on ip is used. Etsy, for example, will suspend your seller account if it sees too many logins from different IPs or if it's from an IP it has flagged before. It also has terrible seller customer service so it could take weeks to get it un-suspended. Heard of some people using Private Relay getting hit by this during the beta so hopefully Etsy gets rid…