Live data from Hacker News

Apple's “iCloud Private Relay” broke risk based authentication

zitadel.ch

121–130 of 211 posts

Re: Apple's “iCloud Private Relay” broke risk based authentication

#121

Earlier quoted context omitted.

You'd have 2fa for your online banking anyway.

And what if your bank only offers SMS for 2fa?

We're talking about how banks should be adapting away from this signal, so perhaps they should support WebAuthn and/or TOTP?

It would honestly be revolutionary for a bank to require hardware authentication and send a security key to every client upon registration.

Re: Apple's “iCloud Private Relay” broke risk based authentication

#122
post #5

I find authentication the least problematic place where risk based on ip is used. Etsy, for example, will suspend your seller account if it sees too many logins from different IPs or if it's from an IP it has flagged before. It also has terrible seller customer service so it could take weeks to get it un-suspended. Heard of some people using Private Relay getting hit by this during the beta so hopefully Etsy gets rid…

They will be forced to. That’s what’s different with iCloud relay - Apple’s weight to force changes upstream. Either Etsy changes their policy now during the beta (my guess is they will), or they change it in a panic in November when iPhones can no longer access the site to buy anything. (No-one is going to switch off private relay to convenience a single website).

Apple’s got their own authentication service now. Maybe Etsy will relax their IP restrictions for customers using that.

Re: Apple's “iCloud Private Relay” broke risk based authentication

#123

I hadn't known there was a term for this braindead idea that websites should hassle you based on your IP address. Of course there has to be a term, compartmentalization is necessary for getting good people to do bad things. It's fantastic that Apple is continuing to mitigate commercial surveillance. It's easy to discriminate against us lone individuals who hide our IP addresses, but Apple's market is too big to rejec…

> this braindead idea that websites should hassle you based on your IP address So if you only ever log in to your financial institution from NY city, they shouldn't be suspicious if they see an attempt to log in from North Macedonia?

People can start wanting to protect their privacy at any time. The situation you describe is more like you traditionally log in "from NYC", and then attempt to log in through a VPN which the snakeoil vendor calls "North Macedonia", and then you get discouraged as if it is a problem with the VPN. If website users could choose to opt in/out of such restrictions I'd see the utility, but that's not what's happening.

Re: Apple's “iCloud Private Relay” broke risk based authentication

#124
post #83

Earlier quoted context omitted.

You have no control where your packets get routed on the Internet, by design of the basic protocols. Personal data should be protected by TLS (edit: and/or application-level encryption) so packet routing is irrelevant to privacy and data protection. I am very worried that the demand for protection of personal data (which is good) is mutating into an expectation of fully regional Internets that do not peer with each o…

Every time I bring up on HN that enforcing national (or regional) law on any extranational company that sends packets to your country will inevitably result in the internet being siloed into legal regions, I get super angry responses. HN seems to love the idea of regulating, taxing, etc. any company that communicates over the internet with people in their country (I’ve even seen packets compared to physical packages…

If you pay attention to the time those comments come out you'll see a specific pattern around european users coffee/lunch/evening times.

Re: Apple's “iCloud Private Relay” broke risk based authentication

#125
post #4

> As of writing this blog I was in Switzerland and the IP used to egress my traffic was in a region located in the US. If this also tends to change a lot and fast you can basically throw away IP addresses as data of your RIBA. Wait, so my data will be routed to US servers, as an EU resident, where the data protection laws are not as strong as where I live? This is a really bad idea, as US is known to tap any data the…

Just because the IP is assigned to the US, does not mean the node was in the US

Re: Apple's “iCloud Private Relay” broke risk based authentication

#127

Earlier quoted context omitted.

Why would my visitor be surprised that I'm suspicious though? They're choosing to be suspicious. Another analogy I could make is someone that is blocking their caller ID. Should they be surprised that fewer people will take their call? They're lumping themselves in with spammers. I think Apple -- and anonymizing proxy/VPN services in general -- should be communicating that to their customers.

Whoah there Nelly! That’s a huge leap from ‘using built in privacy protection features of my phone’ to ‘choosing to be suspicious’. Why should everyone between me and my data have access to an IP address that is tied to my personal data? And when did choosing to not allow that become a shady thing to do? — edited autocorrect of ruins to features

It comes back to reputation. In the real world, we build up a reputation and people can choose to trust us based on it. That also means that they get to know us. I personally like being able to interact with people that I've built up a positive relationship with. Why doesn't that carry over to the virtual world though?

I think everyone's view is tinted by the over-collection of data that some companies are doing. A real-life analogy would be having someone record everything that you do. We've come to accept that to an extent when going into stores, but probably wouldn't hang out with a friend that did that. I don't think the best solution to that is to put a bag over yourself and change your voice so that you're anonymous but still hang out with that friend -- I think it's to tell your friend that you don't want to be recorded. If some service is recording you too invasively, don't do business with them. If you don't know who is recording you, get your government to pass a law like GDPR.

If you want to live in a world without reputation, there will be drawbacks. Attackers will be indistinguishable from regular users, so you have to treat regular users as if they could be attackers; you can't have a tiered approach. The person banned for posting threats (or worse) or otherwise misbehaving on a message platform will be indistinguishable from a new account. The brute force attack will be indistinguishable from the legitimate user. Etc.

To throw out the whole concept of reputation so that you can be perfectly anonymous seems like the wrong solution to the problem.

Re: Apple's “iCloud Private Relay” broke risk based authentication

#128

Earlier quoted context omitted.

Why would my visitor be surprised that I'm suspicious though? They're choosing to be suspicious. Another analogy I could make is someone that is blocking their caller ID. Should they be surprised that fewer people will take their call? They're lumping themselves in with spammers. I think Apple -- and anonymizing proxy/VPN services in general -- should be communicating that to their customers.

> Why would my visitor be surprised that I'm suspicious though? They're choosing to be suspicious. I didn't say that. In the example I gave, you looked through your peephole and couldn't identify the visitor. Perhaps there's a problem with the peephole.

In the Apple Relay case, the person is deliberately making it impossible for me to determine who they are. It isn't a problem with my peephole.

If there is a problem with my peephole, I'm still not trusting the person at the door until I can check it out and fix it.

Re: Apple's “iCloud Private Relay” broke risk based authentication

#129

Did it actually break risk based authentication though? Sure, legitimate users will be using Apple's Relay, but what's stopping attackers from using it? If the users of the service are choosing to be indistinguishable from attackers, then that's on them. I think of it like reputation in real life. If you come knocking on my door, and I can see and recognize you, I'll open it. If you cover up my peephole or hide yours…

> If you cover up my peephole or hide yourself so that I can't recognize you, why would I even let you know I'm home? Even if you tell me who you are, shouldn't I be worried that someone is impersonating you?

Perhaps… but if the culture changes and _everyone_ starts covering the peephole, regardless of their intentions, you'll eventually stop looking because you know it's pointless. That doesn't necessarily mean you'll just open your door willy-nilly, it just means you'll come up with some alternative way of having your visitors prove their unmaliciousness.

Re: Apple's “iCloud Private Relay” broke risk based authentication

#130
post #16

Earlier quoted context omitted.

You can choose in the OS to use a general location or stick to something in your proximity. At least in the Developer Beta 2

The two options are basically city-level or country but same TZ level. e.g. Toronto, or somewhere in Canada in Eastern time (which I mean would almost certainly be limited to Toronto -- presumably these options make more sense on say the East Coast for the US where there are a number of possible major locations that fit) There are clearly some bugs. Occasionally I, in Canada, get routed through the US. This guy got r…

I'd assume apple can be required to relay any customer's traffic's into by the government.
Post reply on HN