Live data from Hacker News

Apple's “iCloud Private Relay” broke risk based authentication

zitadel.ch

161–170 of 211 posts

Re: Apple's “iCloud Private Relay” broke risk based authentication

#161
post #97

Good. This will finally make everyone treat all IP addresses equally.

Which is bad if you ever wanted to make a service without user accounts. Also a strange approach by Cloudflare, who sell IP based risk management.

> Also a strange approach by Cloudflare, who sell IP based risk management.

Is it though? To me it seems more like the iCloud Private Relay will make it harder for everyone else maybe but not necessarily much harder for Cloudflare themselves.

Re: Apple's “iCloud Private Relay” broke risk based authentication

#162

Earlier quoted context omitted.

> this braindead idea that websites should hassle you based on your IP address So if you only ever log in to your financial institution from NY city, they shouldn't be suspicious if they see an attempt to log in from North Macedonia?

That's typical if you have a VPN, which many people do.

Presumably if you have a VPN your exit will appear to be the same place, or some small number of places, all the time. So again, a connection and authentication attempt from a different IP would be a signal to be concerned about.

Re: Apple's “iCloud Private Relay” broke risk based authentication

#163

Earlier quoted context omitted.

They absolutely will not. Let’s say ~30% of Etsy.com views are through Safari (iOS + macOS; ignoring that Chrome on iOS is a viewframe around WebKit anyway). Of those, 25% have iCloud+. Let’s say they did this and 50% of people did visit the site through Chrome. That’s ~4% less revenue for them. I don’t know what Etsy makes per year, but ~4% of whatever that is will be on the order of millions of dollars. So, this is…

This is an interesting breakdown, but here's my analysis: Let's say that ~100% of Etsy.com views are through Safari. Of those, 100% have iCloud+. Let's say they did this and 0% of people visit the site through chrome. That's 100% less revenue for them. Pretty amazing that this one feature could completely kill Etsy's revenue stream. (For what it's worth, I agree with you that Etsy is not going to tell Safari users to…

Maybe I’m missing something, but doesn’t your edge case validate my argument?

In other words, your comment reads as “if everyone stops visiting Etsy, then they will make $0”, which…yeah. Makes sense to me.

Re: Apple's “iCloud Private Relay” broke risk based authentication

#164
post #138

Earlier quoted context omitted.

More likely to happen: Apple's IP addresses get allowlisted.

There is no Apple's IP address with Private Relay. Apple is using 3rd part companies as its exit nodes to avoid this "whitelist apple ip addresses" concern.

The "Get ready for iCloud Private Relay" session[1] from this year's WWDC makes it seem like there will be a publicly available list of IP addresses used by Private Relay:

Private Relay guarantees that users can't use the system to pretend to be from a different region, so you can continue to enforce region-based access restrictions. Details about the proxy IP addresses will be available as an article associated with this session.

Though I haven't been able to find the aforementioned article.

[1]: https://developer.apple.com/videos/play/wwdc2021/10096/

Re: Apple's “iCloud Private Relay” broke risk based authentication

#166
post #165

Not quite on topic of this post, but does anyone know how much Private Relay impact iPhone’s battery life? OpenVPN has a noticeable impact.

The battery impact should be entirely negligible. It's not encapsulating your traffic, it's just relaying it to different endpoints. It's not so much a VPN as a 2-tier proxy.

Re: Apple's “iCloud Private Relay” broke risk based authentication

#167
post #4

> As of writing this blog I was in Switzerland and the IP used to egress my traffic was in a region located in the US. If this also tends to change a lot and fast you can basically throw away IP addresses as data of your RIBA. Wait, so my data will be routed to US servers, as an EU resident, where the data protection laws are not as strong as where I live? This is a really bad idea, as US is known to tap any data the…

[deleted]

Re: Apple's “iCloud Private Relay” broke risk based authentication

#168

Earlier quoted context omitted.

How many average Etsy users do you think would know that iCloud Private Relay is the cause of their issues?

They will google it and find a forum result somewhere that says "If you have iCloud, try turning off Private Relay. This solved the problem for me!" followed by a dozen other people saying 'Thanks so much, this fixed it for me too!" At least, it would if their Etsy accounts weren't getting locked until they can contact support. That said, the Etsy app won't be subject to Private Relay, so if the functionality is ther…

> That said, the Etsy app won't be subject to Private Relay

Why? As far as I know it will apply to apps as well.

Re: Apple's “iCloud Private Relay” broke risk based authentication

#169

Earlier quoted context omitted.

How many average Etsy users do you think would know that iCloud Private Relay is the cause of their issues?

They will google it and find a forum result somewhere that says "If you have iCloud, try turning off Private Relay. This solved the problem for me!" followed by a dozen other people saying 'Thanks so much, this fixed it for me too!" At least, it would if their Etsy accounts weren't getting locked until they can contact support. That said, the Etsy app won't be subject to Private Relay, so if the functionality is ther…

You may be putting too much faith in non technical people googling their way to a solution you or I would easily find..

Re: Apple's “iCloud Private Relay” broke risk based authentication

#170
post #4

> As of writing this blog I was in Switzerland and the IP used to egress my traffic was in a region located in the US. If this also tends to change a lot and fast you can basically throw away IP addresses as data of your RIBA. Wait, so my data will be routed to US servers, as an EU resident, where the data protection laws are not as strong as where I live? This is a really bad idea, as US is known to tap any data the…

You have no control where your packets get routed on the Internet, by design of the basic protocols. Personal data should be protected by TLS (edit: and/or application-level encryption) so packet routing is irrelevant to privacy and data protection. I am very worried that the demand for protection of personal data (which is good) is mutating into an expectation of fully regional Internets that do not peer with each o…

[deleted]
Post reply on HN