Did it actually break risk based authentication though? Sure, legitimate users will be using Apple's Relay, but what's stopping attackers from using it? If the users of the service are choosing to be indistinguishable from attackers, then that's on them. I think of it like reputation in real life. If you come knocking on my door, and I can see and recognize you, I'll open it. If you cover up my peephole or hide yours…
> If you cover up my peephole or hide yourself so that I can't recognize you, why would I even let you know I'm home? Even if you tell me who you are, shouldn't I be worried that someone is impersonating you? Perhaps… but if the culture changes and _everyone_ starts covering the peephole, regardless of their intentions, you'll eventually stop looking because you know it's pointless. That doesn't necessarily mean you'…
Apple's “iCloud Private Relay” broke risk based authentication
131–140 of 211 posts
Re: Apple's “iCloud Private Relay” broke risk based authentication
#132I find authentication the least problematic place where risk based on ip is used. Etsy, for example, will suspend your seller account if it sees too many logins from different IPs or if it's from an IP it has flagged before. It also has terrible seller customer service so it could take weeks to get it un-suspended. Heard of some people using Private Relay getting hit by this during the beta so hopefully Etsy gets rid…
I’m not an expert on Risk Based authentication, but your Etsy example sounds exactly like RBA. They use IP address as a factor in determining the risk associated with allowing the login, and suspend accounts with random IPs to prevent the “attacker” from wreaking havoc.
RBA: https://en.wikipedia.org/wiki/Risk-based_authentication
Re: Apple's “iCloud Private Relay” broke risk based authentication
#133I find authentication the least problematic place where risk based on ip is used. Etsy, for example, will suspend your seller account if it sees too many logins from different IPs or if it's from an IP it has flagged before. It also has terrible seller customer service so it could take weeks to get it un-suspended. Heard of some people using Private Relay getting hit by this during the beta so hopefully Etsy gets rid…
Could an attacker use a VPN? Sure—and there are also plenty of evildoers in the US. But it's an extra barrier.
What I really don't want, however, is for my password manager (or any other service) to make these decisions for me. I will probably travel some day, and when I do, I don't want to be locked out of my account due to "unusual traffic" (yes, it is unusual for me to travel, that doesn't mean it won't happen).
Re: Apple's “iCloud Private Relay” broke risk based authentication
#134Earlier quoted context omitted.
You have no control where your packets get routed on the Internet, by design of the basic protocols. Personal data should be protected by TLS (edit: and/or application-level encryption) so packet routing is irrelevant to privacy and data protection. I am very worried that the demand for protection of personal data (which is good) is mutating into an expectation of fully regional Internets that do not peer with each o…
If personal data from EU citizens is routed through the US in the clear or in a decryptable form, that's probably forbidden under the GDPR. There are exceptions, but this doesn't look like one of these. And while I may not have direct control over where my data is actually routed, but there absolutely are legal restrictions on where companies may route them.
Re: Apple's “iCloud Private Relay” broke risk based authentication
#135I find authentication the least problematic place where risk based on ip is used. Etsy, for example, will suspend your seller account if it sees too many logins from different IPs or if it's from an IP it has flagged before. It also has terrible seller customer service so it could take weeks to get it un-suspended. Heard of some people using Private Relay getting hit by this during the beta so hopefully Etsy gets rid…
They will be forced to. That’s what’s different with iCloud relay - Apple’s weight to force changes upstream. Either Etsy changes their policy now during the beta (my guess is they will), or they change it in a panic in November when iPhones can no longer access the site to buy anything. (No-one is going to switch off private relay to convenience a single website).
Re: Apple's “iCloud Private Relay” broke risk based authentication
#136Earlier quoted context omitted.
Whoah there Nelly! That’s a huge leap from ‘using built in privacy protection features of my phone’ to ‘choosing to be suspicious’. Why should everyone between me and my data have access to an IP address that is tied to my personal data? And when did choosing to not allow that become a shady thing to do? — edited autocorrect of ruins to features
It comes back to reputation. In the real world, we build up a reputation and people can choose to trust us based on it. That also means that they get to know us. I personally like being able to interact with people that I've built up a positive relationship with. Why doesn't that carry over to the virtual world though? I think everyone's view is tinted by the over-collection of data that some companies are doing. A r…
Re: Apple's “iCloud Private Relay” broke risk based authentication
#137Earlier quoted context omitted.
You have no control where your packets get routed on the Internet, by design of the basic protocols. Personal data should be protected by TLS (edit: and/or application-level encryption) so packet routing is irrelevant to privacy and data protection. I am very worried that the demand for protection of personal data (which is good) is mutating into an expectation of fully regional Internets that do not peer with each o…
If personal data from EU citizens is routed through the US in the clear or in a decryptable form, that's probably forbidden under the GDPR. There are exceptions, but this doesn't look like one of these. And while I may not have direct control over where my data is actually routed, but there absolutely are legal restrictions on where companies may route them.
Re: Apple's “iCloud Private Relay” broke risk based authentication
#138Earlier quoted context omitted.
They will be forced to. That’s what’s different with iCloud relay - Apple’s weight to force changes upstream. Either Etsy changes their policy now during the beta (my guess is they will), or they change it in a panic in November when iPhones can no longer access the site to buy anything. (No-one is going to switch off private relay to convenience a single website).
More likely to happen: Apple's IP addresses get allowlisted.
Re: Apple's “iCloud Private Relay” broke risk based authentication
#139Earlier quoted context omitted.
> Why would my visitor be surprised that I'm suspicious though? They're choosing to be suspicious. I didn't say that. In the example I gave, you looked through your peephole and couldn't identify the visitor. Perhaps there's a problem with the peephole.
In the Apple Relay case, the person is deliberately making it impossible for me to determine who they are. It isn't a problem with my peephole. If there is a problem with my peephole, I'm still not trusting the person at the door until I can check it out and fix it.
Re: Apple's “iCloud Private Relay” broke risk based authentication
#140When Google Workplace locks users because of this, and I’m fairly sure they will because they’re super aggressive with IPs that change via VPN, they'll bounce incoming mail for that user. Have fun everyone!
I can think of a few orgs that aggressively block VPN traffic from employees - in some cases the metadata leaked by the end user is a security risk. (Ie you’re doing work stuff in one tab and researching or doing related matters in another)