When Google Workplace locks users because of this, and I’m fairly sure they will because they’re super aggressive with IPs that change via VPN, they'll bounce incoming mail for that user. Have fun everyone!
IIRC that is a configuration choice by the company admin. I can think of a few orgs that aggressively block VPN traffic from employees - in some cases the metadata leaked by the end user is a security risk. (Ie you’re doing work stuff in one tab and researching or doing related matters in another)
Apple's “iCloud Private Relay” broke risk based authentication
191–200 of 211 posts
Re: Apple's “iCloud Private Relay” broke risk based authentication
#192Earlier quoted context omitted.
> someone that is blocking their caller ID. They do give you valid login and password, why is that not enough?
You've never had your credentials stolen, or lifted in any of the many widely-reported password store breaches? https://haveibeenpwned.com/Passwords
Btw, none of Apple services complained yet about my vpn usage.
Re: Apple's “iCloud Private Relay” broke risk based authentication
#193Earlier quoted context omitted.
Whoah there Nelly! That’s a huge leap from ‘using built in privacy protection features of my phone’ to ‘choosing to be suspicious’. Why should everyone between me and my data have access to an IP address that is tied to my personal data? And when did choosing to not allow that become a shady thing to do? — edited autocorrect of ruins to features
It comes back to reputation. In the real world, we build up a reputation and people can choose to trust us based on it. That also means that they get to know us. I personally like being able to interact with people that I've built up a positive relationship with. Why doesn't that carry over to the virtual world though? I think everyone's view is tinted by the over-collection of data that some companies are doing. A r…
The only thing that should signal my reputation is my identity, and despite the best efforts of the adtech world, you can’t reliably correlate that to an IP address.
Re: Apple's “iCloud Private Relay” broke risk based authentication
#194Earlier quoted context omitted.
> Why would my visitor be surprised that I'm suspicious though? They're choosing to be suspicious. I didn't say that. In the example I gave, you looked through your peephole and couldn't identify the visitor. Perhaps there's a problem with the peephole.
In the Apple Relay case, the person is deliberately making it impossible for me to determine who they are. It isn't a problem with my peephole. If there is a problem with my peephole, I'm still not trusting the person at the door until I can check it out and fix it.
Re: Apple's “iCloud Private Relay” broke risk based authentication
#195Not quite on topic of this post, but does anyone know how much Private Relay impact iPhone’s battery life? OpenVPN has a noticeable impact.
Re: Apple's “iCloud Private Relay” broke risk based authentication
#196Earlier quoted context omitted.
Doubt it violates anything - the packets may route through a US based relay, but they’re encrypted when they do, and don’t expose any data. The very nature of the internet makes it impossible to guarantee that none of your packets ever route through a specific country (especially one as connected as the US).
> makes it impossible to guarantee that none of your packets ever route through a specific country Technically untrue, since you can add "strict source routing" as an IP packet option that specifies exactly where it will be routed.
Also, SSR doesn’t involve geography - IPs and ASNs can move.
Re: Apple's “iCloud Private Relay” broke risk based authentication
#197Earlier quoted context omitted.
Doubt it violates anything - the packets may route through a US based relay, but they’re encrypted when they do, and don’t expose any data. The very nature of the internet makes it impossible to guarantee that none of your packets ever route through a specific country (especially one as connected as the US).
I didn’t say it violates it - it does not. I meant that most consent systems that companies add to their site to determine if a user is in EU or not (and hence covered by GDPR) won’t work reliable with Apple users. Most of their geolocation relies on IP addresses.
Re: Apple's “iCloud Private Relay” broke risk based authentication
#198Thank you. Can someone please break security questions next so I don’t have to store four passwords instead of one to login to my accounts? Please kill opt-out-less 2FA while you’re at it. (Thanks Amazon, been enjoying that change!)
Re: Apple's “iCloud Private Relay” broke risk based authentication
#199I find authentication the least problematic place where risk based on ip is used. Etsy, for example, will suspend your seller account if it sees too many logins from different IPs or if it's from an IP it has flagged before. It also has terrible seller customer service so it could take weeks to get it un-suspended. Heard of some people using Private Relay getting hit by this during the beta so hopefully Etsy gets rid…
Re: Apple's “iCloud Private Relay” broke risk based authentication
#200It will be interesting to see if Apple allows hackers to freely abuse the system. If Apple bans end-users for abuse there will be far fewer problems.