Live data from Hacker News

Apple's “iCloud Private Relay” broke risk based authentication

zitadel.ch

101–110 of 211 posts

Re: Apple's “iCloud Private Relay” broke risk based authentication

#101

I hadn't known there was a term for this braindead idea that websites should hassle you based on your IP address. Of course there has to be a term, compartmentalization is necessary for getting good people to do bad things. It's fantastic that Apple is continuing to mitigate commercial surveillance. It's easy to discriminate against us lone individuals who hide our IP addresses, but Apple's market is too big to rejec…

I was thinking the other day that at the pace at which all the AI stuff is advancing, including hardware accelerators in consumer devices, it won't be long until captchas become useless for their purpose of telling humans and machines apart. It's already at the point where captchas are increasingly frustrating and require way too much attention instead of the simple "enter these characters".

Also, yes, I really wish recaptcha dies a painful death because it often does discriminate me for my IP address and non-acceptance of third-party cookies.

Re: Apple's “iCloud Private Relay” broke risk based authentication

#102

I hadn't known there was a term for this braindead idea that websites should hassle you based on your IP address. Of course there has to be a term, compartmentalization is necessary for getting good people to do bad things. It's fantastic that Apple is continuing to mitigate commercial surveillance. It's easy to discriminate against us lone individuals who hide our IP addresses, but Apple's market is too big to rejec…

> this braindead idea that websites should hassle you based on your IP address So if you only ever log in to your financial institution from NY city, they shouldn't be suspicious if they see an attempt to log in from North Macedonia?

You'd have 2fa for your online banking anyway.

Re: Apple's “iCloud Private Relay” broke risk based authentication

#103
post #76

Earlier quoted context omitted.

How on earth are they proxying through Fastly? I would expect Fastly only sends requests to their customers origins, yet Apple is proxying requests through them to arbitrary websites. I wonder if you could abuse this to bypass ACLs on Fastly customers that block direct origin traffic.

Is it possible that the proxying is done via Cloudflare and Fastly's edge computing platforms? It'd be interesting to see where are the Relay requests coming from (i.e. what is the destination server seeing -- who's connecting to it?) Great point about the ACL.

In Cloudflare's case they already have a consumer-facing product that supports relaying over their network (WARP, with separate IP range versus their reverse proxy service) so Apple is likely using a variant of that.

I was very surprised when I checked and saw Fastly on my iPad as I wasn't aware Fastly had any similar product, in my mind they are (were?) strictly a reverse proxy CDN.

Re: Apple's “iCloud Private Relay” broke risk based authentication

#104
post #90

We're anticipating having to make some changes to our fraud scoring which uses things like location vs. credit card address as signals.

Good. I’m tired of wasting my time with dumb bullshit like vendors thinking my credit card billing address is “suspicious” somehow.

Vendors do that because they’re left holding the bag in chargebacks. Addresses are de facto knowledge based authentication questions in lieu of dynamic credit card codes.

Re: Apple's “iCloud Private Relay” broke risk based authentication

#105

Earlier quoted context omitted.

They will be forced to. That’s what’s different with iCloud relay - Apple’s weight to force changes upstream. Either Etsy changes their policy now during the beta (my guess is they will), or they change it in a panic in November when iPhones can no longer access the site to buy anything. (No-one is going to switch off private relay to convenience a single website).

>(No-one is going to switch off private relay to convenience a single website) If you're a seller and a decent chunk of your income comes from Etsy you definitely would. They already do that with avoiding VPNs to not get suspended.

Etsy does something similar with vpns where they serve a blank page if you try to access it. They don’t even throw up an error message.

That prevents buyers from buying also.

Etsy will adapt, quickly.

Re: Apple's “iCloud Private Relay” broke risk based authentication

#106
post #103

Earlier quoted context omitted.

Is it possible that the proxying is done via Cloudflare and Fastly's edge computing platforms? It'd be interesting to see where are the Relay requests coming from (i.e. what is the destination server seeing -- who's connecting to it?) Great point about the ACL.

In Cloudflare's case they already have a consumer-facing product that supports relaying over their network (WARP, with separate IP range versus their reverse proxy service) so Apple is likely using a variant of that. I was very surprised when I checked and saw Fastly on my iPad as I wasn't aware Fastly had any similar product, in my mind they are (were?) strictly a reverse proxy CDN.

Maybe the sell there leftover ingress bandwidth to apple :-)

Re: Apple's “iCloud Private Relay” broke risk based authentication

#107
post #90

Earlier quoted context omitted.

Good. I’m tired of wasting my time with dumb bullshit like vendors thinking my credit card billing address is “suspicious” somehow.

Vendors do that because they’re left holding the bag in chargebacks. Addresses are de facto knowledge based authentication questions in lieu of dynamic credit card codes.

Hopefully this results in the elimination of credit cards. Vendors should ideally switch to lighting-based settlement or something.

Re: Apple's “iCloud Private Relay” broke risk based authentication

#108
post #8
post #4

> As of writing this blog I was in Switzerland and the IP used to egress my traffic was in a region located in the US. If this also tends to change a lot and fast you can basically throw away IP addresses as data of your RIBA. Wait, so my data will be routed to US servers, as an EU resident, where the data protection laws are not as strong as where I live? This is a really bad idea, as US is known to tap any data the…

Well Switzerland is not completely EU so I’m not sure if it has the same data protection laws.

In terms of privacy, the Swiss law is essentially equivalent to the GDPR.

Re: Apple's “iCloud Private Relay” broke risk based authentication

#110

Earlier quoted context omitted.

I don't believe that's the case. Just listened to Craig Federighi on Jon Gruber's podcast say that the intent is that the relay is regionalized. Your IP will be anonymized, but it will at least correspond to the general location you are in. Possibly this was just a bug in the beta?

It's very buggy so far.

Yep. I've found the setting seems to exist in two places, and it turns itself back on at times (that said, it's a beta):

1. Settings -> Apple ID -> Private Relay

2. Settings -> Network -> Use iCloud Private Relay

Post reply on HN