Live data from Hacker News

Apple's “iCloud Private Relay” broke risk based authentication

zitadel.ch

201–210 of 211 posts

Re: Apple's “iCloud Private Relay” broke risk based authentication

#201
post #97

Good. This will finally make everyone treat all IP addresses equally.

Which is bad if you ever wanted to make a service without user accounts. Also a strange approach by Cloudflare, who sell IP based risk management.

As an end user, I hate being discriminated by something I can't really change much. That's all.

And, yes, I do hate Cloudflare and other CDNs with burning passion because the internet is meant to be decentralized. But especially Cloudflare and their "one more step".

Re: Apple's “iCloud Private Relay” broke risk based authentication

#202
post #150

Earlier quoted context omitted.

> It can be made much less accessible because it's not meant to be shared with the remote side. Can be, indeed, but was not in existing implementations, to my knowledge. My point (perhaps I was more clear in my followup comment) was that we shouldn't shed too many tears given the actual implementations did not provide the promised security gains. Were they stepping stones? Maybe. But they didn't (yet) deliver. > A cl…

I feel like your comparison is not fair. IP-based threat detection is still not defending against malware or bad browser extension, and it basically cannot be improved since it relies on something that is not a security mechanism but rather a fundamental part of internet routing. It does not cooperate well with mobile roaming, VPNs, NATs or other routing mechanisms as TFA pointed out. You're comparing a fundamentally…

Yeah, I think I agree with you there. The area for improvement for token binding or something like it is quite promising; not so for using IP signals.

I think token binding itself had some design flaws that made it hard to realize these improvements, but that's not to say that I think IP signals are better (or obviate) cryptographic replacements for bearer tokens—I don't think that. I just think it's an irony of token binding's design that the design suggested an implementation which in practice provided less value than IP binding.

Re: Apple's “iCloud Private Relay” broke risk based authentication

#203
post #83

Earlier quoted context omitted.

You have no control where your packets get routed on the Internet, by design of the basic protocols. Personal data should be protected by TLS (edit: and/or application-level encryption) so packet routing is irrelevant to privacy and data protection. I am very worried that the demand for protection of personal data (which is good) is mutating into an expectation of fully regional Internets that do not peer with each o…

Every time I bring up on HN that enforcing national (or regional) law on any extranational company that sends packets to your country will inevitably result in the internet being siloed into legal regions, I get super angry responses. HN seems to love the idea of regulating, taxing, etc. any company that communicates over the internet with people in their country (I’ve even seen packets compared to physical packages…

No, the solution is not to silo internet into legal regions, the solution is to people in the USA to also lobby for stronger data protection laws.

When any server in USA soil can be changed into a backdoor, accompanied with a gag order on disclosure, I certainly do not want all my egress traffic routed into any computer in USA.

Re: Apple's “iCloud Private Relay” broke risk based authentication

#204
post #88

Earlier quoted context omitted.

Trusting location APIs is also silly, as those can be spoofed easily. What Apple is really doing here is subverting the entire concept of geo-blocking services, which is great.

This does not prevent geo-blocking, because the relay's IP is still in the same region as the user.

Except when it isn’t like in the OP’s article. Also, when datacentres inevitably go down, traffic will be rerouted, potentially to other countries.

Re: Apple's “iCloud Private Relay” broke risk based authentication

#205

Earlier quoted context omitted.

They will be forced to. That’s what’s different with iCloud relay - Apple’s weight to force changes upstream. Either Etsy changes their policy now during the beta (my guess is they will), or they change it in a panic in November when iPhones can no longer access the site to buy anything. (No-one is going to switch off private relay to convenience a single website).

More likely to happen: Apple's IP addresses get allowlisted.

I used to work on anti-hijacking "risk based analysis" at Google. Here's what's even more likely to happen: Apple's IP addresses get marked as VPN/Tor ranges and treated exactly the same way as other such ranges. This may trigger e.g. requirements to use two factor authentication on an account if you wish to log in from such ranges.

Re: Apple's “iCloud Private Relay” broke risk based authentication

#206
post #36

Earlier quoted context omitted.

How? The data stays in EU. Routing to US is clearly a bug (that violates it, yes)

No, I mean detection systems that trigger consent. Most systems look at IP address to determine if you are an EU user, then give you consent options. Now there there is no reliable way to tell

It's not as if IP addresses were ever a reliable way to tell whether a data subject was physically located within the EU. VPNs and proxies have been around forever. Someone could be accessing your site through Tor Browser or I2P while located in the EU—and if so, these are the users who would be most interested in limiting processing of their personal data.

Just assume that no consent is granted. Access to the site or specific services cannot depend on granting consent, which implies that anyone who does grant consent probably failed to understand that it was optional, or did so only to avoid being harassed with further consent requests. The GDPR already makes the "consent" completely one-sided with no possibility of consideration; it might as well have disallowed the requests altogether and saved everyone a great deal of hassle.

Re: Apple's “iCloud Private Relay” broke risk based authentication

#207
Great. RIBA is a really poor method that causes a lot of false positives for expats like myself. I'm really happy that more people will suffer this digital discrimination because it will mean it will go away.

I live in Spain, I'm from the Netherlands and have lived in Ireland as well, leading to tons of "soft block" nightmares.

Re: Apple's “iCloud Private Relay” broke risk based authentication

#208

Earlier quoted context omitted.

You would, sure. 99.9% of etsy userbase would not.

If there’s one lesson I badly want to see all engineers learn is that odds are they haven’t the faintest clue what it’s like to be a typical user. 99% of computer users do not inhabit the same galaxy as you do when it comes to understanding and managing technical details.

I feel you there. I’m a PO so have those kind of arguments regularly!

At the same time, 99% of computer users have no idea why we can’t just ‘slap x button there and make it do x’ and that is just as infuriating.

Re: Apple's “iCloud Private Relay” broke risk based authentication

#209

Earlier quoted context omitted.

If there’s one lesson I badly want to see all engineers learn is that odds are they haven’t the faintest clue what it’s like to be a typical user. 99% of computer users do not inhabit the same galaxy as you do when it comes to understanding and managing technical details.

I feel you there. I’m a PO so have those kind of arguments regularly! At the same time, 99% of computer users have no idea why we can’t just ‘slap x button there and make it do x’ and that is just as infuriating.

So true. And even other engineers too.

Re: Apple's “iCloud Private Relay” broke risk based authentication

#210
post #146

Earlier quoted context omitted.

Isn’t 3d Secure a thing in the US? I have a little app in my phone from my credit card company where I confirm when I am really buying something and it looks more secure than relying on fraud detection.

3D Secure trains customers to type their bank login into popups! It shifts fraud loss liability onto the customer who is even less prepared to deal with it than the merchant. Only a few merchants tried it like Newegg.com. It flopped because the hit to conversion was more than the fraud prevention. It usually fails open (allows transaction to proceed). Merchant side fraud detection is inherently inferior to the bank d…

If that happens then it's definitely an issue, but I've had a couple cards with 3D Secure for about 6-7 years and it's always 2FA using an app ("Did you really buy X at vendor Y?") or, before that, with a keychain hardware token.

I wonder if there's rules depending on which country. When I worked for a small-time credit card "vendor" we could put pretty much anything we wanted in our iFrame.

Post reply on HN