Earlier quoted context omitted.
They will be forced to. That’s what’s different with iCloud relay - Apple’s weight to force changes upstream. Either Etsy changes their policy now during the beta (my guess is they will), or they change it in a panic in November when iPhones can no longer access the site to buy anything. (No-one is going to switch off private relay to convenience a single website).
>(No-one is going to switch off private relay to convenience a single website) If you're a seller and a decent chunk of your income comes from Etsy you definitely would. They already do that with avoiding VPNs to not get suspended.
Apple's “iCloud Private Relay” broke risk based authentication
111–120 of 211 posts
Re: Apple's “iCloud Private Relay” broke risk based authentication
#112Re: Apple's “iCloud Private Relay” broke risk based authentication
#113I find authentication the least problematic place where risk based on ip is used. Etsy, for example, will suspend your seller account if it sees too many logins from different IPs or if it's from an IP it has flagged before. It also has terrible seller customer service so it could take weeks to get it un-suspended. Heard of some people using Private Relay getting hit by this during the beta so hopefully Etsy gets rid…
My guess is that they'll just say Safari isn't supported and push people to Chrome.
Let’s say ~30% of Etsy.com views are through Safari (iOS + macOS; ignoring that Chrome on iOS is a viewframe around WebKit anyway). Of those, 25% have iCloud+.
Let’s say they did this and 50% of people did visit the site through Chrome.
That’s ~4% less revenue for them. I don’t know what Etsy makes per year, but ~4% of whatever that is will be on the order of millions of dollars. So, this is a no-brainer.
Re: Apple's “iCloud Private Relay” broke risk based authentication
#114Earlier quoted context omitted.
The laws specifically mention "at rest". Where your traffic goes while in flight is not regulated. Legally, the US service can't grab and store your data, but that doesn't mean they can't analyze and use your data as it flows through.
It is not clear what the laws say as FISA intrepretations are secret.
Re: Apple's “iCloud Private Relay” broke risk based authentication
#115Earlier quoted context omitted.
> this braindead idea that websites should hassle you based on your IP address So if you only ever log in to your financial institution from NY city, they shouldn't be suspicious if they see an attempt to log in from North Macedonia?
It was a nice temporary hack in the game of cat and mouse. Now a solution that doesn’t depend on that signal will be required. My bank sends me a card with a grid of coordinates and I have to enter the character at the coordinate when I login, after entering my password, thereby proving something I know and something I have, without also requiring me to have a phone
Re: Apple's “iCloud Private Relay” broke risk based authentication
#116Earlier quoted context omitted.
> this braindead idea that websites should hassle you based on your IP address So if you only ever log in to your financial institution from NY city, they shouldn't be suspicious if they see an attempt to log in from North Macedonia?
You'd have 2fa for your online banking anyway.
Re: Apple's “iCloud Private Relay” broke risk based authentication
#117Earlier quoted context omitted.
IIRC, in one of the WWDC talks, Apple's advice is stop relying on IP address as a signal of the user's location. Either make use of the location APIs on the platform or work out something different.
Trusting location APIs is also silly, as those can be spoofed easily. What Apple is really doing here is subverting the entire concept of geo-blocking services, which is great.
Re: Apple's “iCloud Private Relay” broke risk based authentication
#118Earlier quoted context omitted.
It broke it in the sense that it removed a signal that would allow the service to distinguish legit users from possibly malicious ones. In the case of a legit user that has in the past always authenticated from an IP address or address block geolocated to say, Seattle, the service can look at any authentication attempt from elsewhere as anomalous and raise additional challenges. However, with Relay, that signal is lo…
Why would my visitor be surprised that I'm suspicious though? They're choosing to be suspicious. Another analogy I could make is someone that is blocking their caller ID. Should they be surprised that fewer people will take their call? They're lumping themselves in with spammers. I think Apple -- and anonymizing proxy/VPN services in general -- should be communicating that to their customers.
I didn't say that. In the example I gave, you looked through your peephole and couldn't identify the visitor. Perhaps there's a problem with the peephole.
Re: Apple's “iCloud Private Relay” broke risk based authentication
#119Earlier quoted context omitted.
Why would my visitor be surprised that I'm suspicious though? They're choosing to be suspicious. Another analogy I could make is someone that is blocking their caller ID. Should they be surprised that fewer people will take their call? They're lumping themselves in with spammers. I think Apple -- and anonymizing proxy/VPN services in general -- should be communicating that to their customers.
> someone that is blocking their caller ID. They do give you valid login and password, why is that not enough?
Re: Apple's “iCloud Private Relay” broke risk based authentication
#120Earlier quoted context omitted.
Good. I’m tired of wasting my time with dumb bullshit like vendors thinking my credit card billing address is “suspicious” somehow.
So many companies insist I provide them a "billing address", except I don't have one, it's a uniquely North American thing. Filling that form with gibberish usually does the trick for me.
It’s a thing in Europe as well.