Live data from Hacker News

Apple's “iCloud Private Relay” broke risk based authentication

zitadel.ch

111–120 of 211 posts

Re: Apple's “iCloud Private Relay” broke risk based authentication

#111

Earlier quoted context omitted.

They will be forced to. That’s what’s different with iCloud relay - Apple’s weight to force changes upstream. Either Etsy changes their policy now during the beta (my guess is they will), or they change it in a panic in November when iPhones can no longer access the site to buy anything. (No-one is going to switch off private relay to convenience a single website).

>(No-one is going to switch off private relay to convenience a single website) If you're a seller and a decent chunk of your income comes from Etsy you definitely would. They already do that with avoiding VPNs to not get suspended.

How many average Etsy users do you think would know that iCloud Private Relay is the cause of their issues?

Re: Apple's “iCloud Private Relay” broke risk based authentication

#112
post #82
post #78

Earlier quoted context omitted.

My guess is that they'll just say Safari isn't supported and push people to Chrome.

Hmm - and alienate anyone on mobile Safari? I doubt it.

And why no one will block the egress IP ranges.

Re: Apple's “iCloud Private Relay” broke risk based authentication

#113
post #78
post #5

I find authentication the least problematic place where risk based on ip is used. Etsy, for example, will suspend your seller account if it sees too many logins from different IPs or if it's from an IP it has flagged before. It also has terrible seller customer service so it could take weeks to get it un-suspended. Heard of some people using Private Relay getting hit by this during the beta so hopefully Etsy gets rid…

My guess is that they'll just say Safari isn't supported and push people to Chrome.

They absolutely will not.

Let’s say ~30% of Etsy.com views are through Safari (iOS + macOS; ignoring that Chrome on iOS is a viewframe around WebKit anyway). Of those, 25% have iCloud+.

Let’s say they did this and 50% of people did visit the site through Chrome.

That’s ~4% less revenue for them. I don’t know what Etsy makes per year, but ~4% of whatever that is will be on the order of millions of dollars. So, this is a no-brainer.

Re: Apple's “iCloud Private Relay” broke risk based authentication

#114
post #71

Earlier quoted context omitted.

The laws specifically mention "at rest". Where your traffic goes while in flight is not regulated. Legally, the US service can't grab and store your data, but that doesn't mean they can't analyze and use your data as it flows through.

It is not clear what the laws say as FISA intrepretations are secret.

You're correct. I'm paraphrasing guidelines from a previous employer's legal department. The Ireland data center was our EU presence, and we needed to know the boundaries of "what happens in Ireland stays in Ireland", so to speak.

Re: Apple's “iCloud Private Relay” broke risk based authentication

#115

Earlier quoted context omitted.

> this braindead idea that websites should hassle you based on your IP address So if you only ever log in to your financial institution from NY city, they shouldn't be suspicious if they see an attempt to log in from North Macedonia?

It was a nice temporary hack in the game of cat and mouse. Now a solution that doesn’t depend on that signal will be required. My bank sends me a card with a grid of coordinates and I have to enter the character at the coordinate when I login, after entering my password, thereby proving something I know and something I have, without also requiring me to have a phone

Yes, that's great. It's also less convenient. Depending on the security threat model, users might tolerate it, or they might not. In the case of lots of money, it's a good practice.

Re: Apple's “iCloud Private Relay” broke risk based authentication

#116

Earlier quoted context omitted.

> this braindead idea that websites should hassle you based on your IP address So if you only ever log in to your financial institution from NY city, they shouldn't be suspicious if they see an attempt to log in from North Macedonia?

You'd have 2fa for your online banking anyway.

And what if your bank only offers SMS for 2fa?

Re: Apple's “iCloud Private Relay” broke risk based authentication

#117
post #88

Earlier quoted context omitted.

IIRC, in one of the WWDC talks, Apple's advice is stop relying on IP address as a signal of the user's location. Either make use of the location APIs on the platform or work out something different.

Trusting location APIs is also silly, as those can be spoofed easily. What Apple is really doing here is subverting the entire concept of geo-blocking services, which is great.

Many APIs can be spoofed. If a system is trusting a third party service for security purposes, that needs to be subject to some close scrutiny. Using location as one signal of many is reasonable, and in some legal regimes, at least for now, required. Using location as the sole signal is foolish, and never was sufficiently reliable for anything but the most casual security check. See for example https://splinternews.com/how-an-internet-mapping-glitch-turn...

Re: Apple's “iCloud Private Relay” broke risk based authentication

#118

Earlier quoted context omitted.

It broke it in the sense that it removed a signal that would allow the service to distinguish legit users from possibly malicious ones. In the case of a legit user that has in the past always authenticated from an IP address or address block geolocated to say, Seattle, the service can look at any authentication attempt from elsewhere as anomalous and raise additional challenges. However, with Relay, that signal is lo…

Why would my visitor be surprised that I'm suspicious though? They're choosing to be suspicious. Another analogy I could make is someone that is blocking their caller ID. Should they be surprised that fewer people will take their call? They're lumping themselves in with spammers. I think Apple -- and anonymizing proxy/VPN services in general -- should be communicating that to their customers.

> Why would my visitor be surprised that I'm suspicious though? They're choosing to be suspicious.

I didn't say that. In the example I gave, you looked through your peephole and couldn't identify the visitor. Perhaps there's a problem with the peephole.

Re: Apple's “iCloud Private Relay” broke risk based authentication

#119
post #100

Earlier quoted context omitted.

Why would my visitor be surprised that I'm suspicious though? They're choosing to be suspicious. Another analogy I could make is someone that is blocking their caller ID. Should they be surprised that fewer people will take their call? They're lumping themselves in with spammers. I think Apple -- and anonymizing proxy/VPN services in general -- should be communicating that to their customers.

> someone that is blocking their caller ID. They do give you valid login and password, why is that not enough?

You've never had your credentials stolen, or lifted in any of the many widely-reported password store breaches? https://haveibeenpwned.com/Passwords

Re: Apple's “iCloud Private Relay” broke risk based authentication

#120
post #99
post #90

Earlier quoted context omitted.

Good. I’m tired of wasting my time with dumb bullshit like vendors thinking my credit card billing address is “suspicious” somehow.

So many companies insist I provide them a "billing address", except I don't have one, it's a uniquely North American thing. Filling that form with gibberish usually does the trick for me.

> it's a uniquely North American thing

It’s a thing in Europe as well.

Post reply on HN