Live data from Hacker News

Apple's “iCloud Private Relay” broke risk based authentication

zitadel.ch

191–200 of 211 posts

Re: Apple's “iCloud Private Relay” broke risk based authentication

#191

When Google Workplace locks users because of this, and I’m fairly sure they will because they’re super aggressive with IPs that change via VPN, they'll bounce incoming mail for that user. Have fun everyone!

IIRC that is a configuration choice by the company admin. I can think of a few orgs that aggressively block VPN traffic from employees - in some cases the metadata leaked by the end user is a security risk. (Ie you’re doing work stuff in one tab and researching or doing related matters in another)

I was mostly complaining about the way locked accounts bounce mail. I've had accounts locked for "suspicious activity" which is really just logging in from an IP different than the one you normally use. IE: IPs with good reputation, but just not exactly the same IP all the time.

Re: Apple's “iCloud Private Relay” broke risk based authentication

#192
post #100

Earlier quoted context omitted.

> someone that is blocking their caller ID. They do give you valid login and password, why is that not enough?

You've never had your credentials stolen, or lifted in any of the many widely-reported password store breaches? https://haveibeenpwned.com/Passwords

I get your point. No, I have nothing stolen, and I def will not enter my password on HIBP ever :). I think this IP based security checks should be on by default, yes, but with opt-out option. Im using VPN all the time and getting sick of “new device” emails.

Btw, none of Apple services complained yet about my vpn usage.

Re: Apple's “iCloud Private Relay” broke risk based authentication

#193

Earlier quoted context omitted.

Whoah there Nelly! That’s a huge leap from ‘using built in privacy protection features of my phone’ to ‘choosing to be suspicious’. Why should everyone between me and my data have access to an IP address that is tied to my personal data? And when did choosing to not allow that become a shady thing to do? — edited autocorrect of ruins to features

It comes back to reputation. In the real world, we build up a reputation and people can choose to trust us based on it. That also means that they get to know us. I personally like being able to interact with people that I've built up a positive relationship with. Why doesn't that carry over to the virtual world though? I think everyone's view is tinted by the over-collection of data that some companies are doing. A r…

Here’s the problem - my IP address should not signal reputation. They are fungible, and can change on your carrier’s whim. GEO-IP data is spotty at best. And that doesn’t even touch on how IaaS platforms handle IPs.

The only thing that should signal my reputation is my identity, and despite the best efforts of the adtech world, you can’t reliably correlate that to an IP address.

Re: Apple's “iCloud Private Relay” broke risk based authentication

#194

Earlier quoted context omitted.

> Why would my visitor be surprised that I'm suspicious though? They're choosing to be suspicious. I didn't say that. In the example I gave, you looked through your peephole and couldn't identify the visitor. Perhaps there's a problem with the peephole.

In the Apple Relay case, the person is deliberately making it impossible for me to determine who they are. It isn't a problem with my peephole. If there is a problem with my peephole, I'm still not trusting the person at the door until I can check it out and fix it.

If not getting a source IP makes it impossible for you to determine who someone is, you really need to reevaluate your identity systems. IP addresses are not reliable indicators of anything, let alone identity.

Re: Apple's “iCloud Private Relay” broke risk based authentication

#195
post #165

Not quite on topic of this post, but does anyone know how much Private Relay impact iPhone’s battery life? OpenVPN has a noticeable impact.

So far it’s been completely unnoticeable. Browsing performance has mostly been within a few % as well - turns out having your traffic egress at a huge CDNs edge network isn’t a bad thing…

Re: Apple's “iCloud Private Relay” broke risk based authentication

#196

Earlier quoted context omitted.

Doubt it violates anything - the packets may route through a US based relay, but they’re encrypted when they do, and don’t expose any data. The very nature of the internet makes it impossible to guarantee that none of your packets ever route through a specific country (especially one as connected as the US).

> makes it impossible to guarantee that none of your packets ever route through a specific country Technically untrue, since you can add "strict source routing" as an IP packet option that specifies exactly where it will be routed.

Nope, you can’t actually do that on the internet at large. Yes, the RFC exists, but your ISP and their upstream will often ignore or even drop those packets.

Also, SSR doesn’t involve geography - IPs and ASNs can move.

Re: Apple's “iCloud Private Relay” broke risk based authentication

#197

Earlier quoted context omitted.

Doubt it violates anything - the packets may route through a US based relay, but they’re encrypted when they do, and don’t expose any data. The very nature of the internet makes it impossible to guarantee that none of your packets ever route through a specific country (especially one as connected as the US).

I didn’t say it violates it - it does not. I meant that most consent systems that companies add to their site to determine if a user is in EU or not (and hence covered by GDPR) won’t work reliable with Apple users. Most of their geolocation relies on IP addresses.

I was replying to my posts parent who brought up the word violate, not your post.

Re: Apple's “iCloud Private Relay” broke risk based authentication

#198
post #64

Thank you. Can someone please break security questions next so I don’t have to store four passwords instead of one to login to my accounts? Please kill opt-out-less 2FA while you’re at it. (Thanks Amazon, been enjoying that change!)

I’m fine with 2FA, but let’s please kill 2SA (two step authentication) which appears to be, “Let’s take your long high entropy pass-string and ensure its irrelevance with much easier to compromise SMS or email codes”.

Re: Apple's “iCloud Private Relay” broke risk based authentication

#199
post #5

I find authentication the least problematic place where risk based on ip is used. Etsy, for example, will suspend your seller account if it sees too many logins from different IPs or if it's from an IP it has flagged before. It also has terrible seller customer service so it could take weeks to get it un-suspended. Heard of some people using Private Relay getting hit by this during the beta so hopefully Etsy gets rid…

This was happening to me on Instagram as well. Using CloudFlare WARP+ and Instagram would deactivate my account arbitrarily. Figured it out only when I turned it off and the issues went away.

Re: Apple's “iCloud Private Relay” broke risk based authentication

#200

It will be interesting to see if Apple allows hackers to freely abuse the system. If Apple bans end-users for abuse there will be far fewer problems.

This is the big one. But how can Apple ban users for abuse if they themselves cannot know which user is responsible for any particular request? If they can tie individual users to abusive activity then their claims of being a truly private relay service are bogus.
Post reply on HN