Live data from Hacker News

Apple 'Hide My Email' vulnerability reveals peoples' real email addresses

easyoptouts.com

41–50 of 105 posts

Re: Apple 'Hide My Email' vulnerability reveals peoples' real email addresses

#41
post #22

Earlier quoted context omitted.

> We think enough people rely on Hide My Email for personal safety that it would be irresponsible. I am guessing you haven't tried that excuse on the users your witholding is leaving exposed.

We're hoping that by notifying people that there's a vulnerability, people can stop using Hide My Email if it matters to them. I don't think that disclosing the exploit method will get Apple to fix it faster at this point.

The problem there is users cannot evaluate if it matters to them whilst all information needed to do so is being witheld.

Re: Apple 'Hide My Email' vulnerability reveals peoples' real email addresses

#42

We put up a timeline of the disclosure here: https://easyoptouts.com/guides/apple-hide-my-email-is-leakin...

Thanks for everything y'all do with Easy Opt Outs. I've put a number of family members and acquaintances onto it. I'm glad this service exists at an actually affordable rate

Re: Apple 'Hide My Email' vulnerability reveals peoples' real email addresses

#43

Earlier quoted context omitted.

I think they are hinting at the ad hoc "use hidemyemail" feature within e.g. the mail client. I don't know what I am doing, but from a quick test, the mail header is at least disclosing the internal recipient (mail@host.com) "translation address" (as mail_at_host_com_12345abc_12345abc@icloud.com) and an alias creation date. But the latter seems to be a unix timestamp related to the real address alias creation time an…

> You send an email to the HME address, reply, and then the real mail gets disclosed in the mail source. Does the initial sender matter? Like if it’s the HME address that sends first and receives the reply? I have around 180 of these addresses.

> then the real mail gets disclosed in the mail source.

It's not just in the source, I totally overlooked the fact the real email address is shown as sender. Lol.

> Does the initial sender matter? Like if it’s the HME address that sends first and receives the reply? I have around 180 of these addresses.

Appears so. Here is exactly what I did:

1. Created the HME through mail, sending to other email service address (OMA). (This disclosed the information in my original comment.)

2. Did some reply ping pong. (No additional disclosure.)

3. Send a new email from OMA to above HME.

4. Replied from iOS mail client (UI showing usage of HME alias. Yes, I verified this multiple times not to make a fool of myself.)

5. Received at OMA, the real address is disclosed.

6. On the iOS client side, the mail shows up as sent from the real mail address, too.

Not sure if 1. for HME creation is required, you can likely skip straight to 3. for any HME address.

Funny enough, I observed 6. in the wild before, but was kinda hoping that's an artifact of forwarding a copy of the mail to the thread. I tested this some, but not this particular ping-pong. So yeah... I now gonna check where I evidently leaked my real mail address already...

Re: Apple 'Hide My Email' vulnerability reveals peoples' real email addresses

#44
post #37

Earlier quoted context omitted.

I’m still mildly annoyed every email I send using Mail has my IP embedded in it

Source? I don't think this is true. Doesn't seem to be the case for me. Maybe your email provider attaches your IP address?

It’s in the headers. Send an email to your self from Mail and open the source in the inbox. There is your IP.

Re: Apple 'Hide My Email' vulnerability reveals peoples' real email addresses

#45
post #41

Earlier quoted context omitted.

We're hoping that by notifying people that there's a vulnerability, people can stop using Hide My Email if it matters to them. I don't think that disclosing the exploit method will get Apple to fix it faster at this point.

The problem there is users cannot evaluate if it matters to them whilst all information needed to do so is being witheld.

If having your personal email exposed would be a matter of personal safety or similar, then stop using it. If you're just using it for junk mail or to get a free trial then keep using it.

Re: Apple 'Hide My Email' vulnerability reveals peoples' real email addresses

#48
post #22

Earlier quoted context omitted.

> We think enough people rely on Hide My Email for personal safety that it would be irresponsible. I am guessing you haven't tried that excuse on the users your witholding is leaving exposed.

We're hoping that by notifying people that there's a vulnerability, people can stop using Hide My Email if it matters to them. I don't think that disclosing the exploit method will get Apple to fix it faster at this point.

Its the only reason I even pay the $1 a month icloud plan, so might as well cancel it if its gonna be eternally broken.

Re: Apple 'Hide My Email' vulnerability reveals peoples' real email addresses

#49
I guess the vulnerability should work as follows (I haven't tried it), you send an email with a very large attachment to a "hide my email" address, the server that receives it (private.icloud.com) forwards it to the email server registered in iCloud which, being the very large attachment, sends a response email (from the real address) with the rejected email message. It's the first thing I would try.
Post reply on HN