Live data from Hacker News

Apple 'Hide My Email' vulnerability reveals peoples' real email addresses

easyoptouts.com

51–60 of 105 posts

Re: Apple 'Hide My Email' vulnerability reveals peoples' real email addresses

#51

We put up a timeline of the disclosure here: https://easyoptouts.com/guides/apple-hide-my-email-is-leakin...

Can you comment on this: https://news.ycombinator.com/item?id=48752294 ?

To me it seems, at least in this instance there is not even an exploit needed and the feature apparently is just broken beyond belief.

Re: Apple 'Hide My Email' vulnerability reveals peoples' real email addresses

#52
post #37

Earlier quoted context omitted.

Source? I don't think this is true. Doesn't seem to be the case for me. Maybe your email provider attaches your IP address?

It’s in the headers. Send an email to your self from Mail and open the source in the inbox. There is your IP.

Is this from iOS? I just tested from MacOS, and the only IPs were for the transit and auth servers.

I'm not actually doubting it. saagarjha knows his stuff. I just don't see it, so maybe I'm holding it wrong.

Re: Apple 'Hide My Email' vulnerability reveals peoples' real email addresses

#53
post #50
post #46

[flagged]

Sorry I'm not seeing how your comment is relevant to the orignal post, can you clarify?

The post is about a vulnerability in Apple under CEO Tim Cook, who did horrible things after Steve Jobs died — most importantly, changing the UI/UX.

Re: Apple 'Hide My Email' vulnerability reveals peoples' real email addresses

#54
post #45
post #41

Earlier quoted context omitted.

The problem there is users cannot evaluate if it matters to them whilst all information needed to do so is being witheld.

If having your personal email exposed would be a matter of personal safety or similar, then stop using it. If you're just using it for junk mail or to get a free trial then keep using it.

Yes, but a mitigation suggestion like "keep using it, except don't do X specific sequence" (for example, send to a Yahoo address via the Reply button, or whatever the case may be) could be helpful as well, since it seems that bad actors (and/or good actors spilling the beans) will figure it out sooner than later anyway.

Re: Apple 'Hide My Email' vulnerability reveals peoples' real email addresses

#55
post #8

Is it based on mail undeliverable errors? Or attempts to login using IMAP or SMTP with it? Or is it exposed during the SMTP protocol?

My guess would be it has nothing to do with email itself. Maybe it's some iCloud API that accepts obfuscated emails but returns the original email in the response, or an ID which can be used to retrieve the iCloud email from another API endpoint. Could be as simple as an "add contact/friend" feature in some Apple product (like a mail client, or a file sharing service) that resolves the obfuscated email to the origina…

In the comment section of the 404media article Joseph Cox writes when asked whether it reveals the icloud address the email is forwarded to or the apple id [0]:

> It reveals the email linked to the Apple ID.

So I assume you are right that it has nothing to do with the email itself, but prob some other service that links the obfuscated email to the appleid of the user.

[0] https://www.404media.co/apple-hide-my-email-vulnerability-re...

Re: Apple 'Hide My Email' vulnerability reveals peoples' real email addresses

#56

Earlier quoted context omitted.

It’s in the headers. Send an email to your self from Mail and open the source in the inbox. There is your IP.

Is this from iOS? I just tested from MacOS, and the only IPs were for the transit and auth servers. I'm not actually doubting it. saagarjha knows his stuff. I just don't see it, so maybe I'm holding it wrong.

Same, I remember it being in the headers long ago but don't see it now. macOS Tahoe, Mail.app client, iCloud email sending to itself or to my Gmail, both set up in default ways, IPv6 disabled

Re: Apple 'Hide My Email' vulnerability reveals peoples' real email addresses

#58
post #37

Earlier quoted context omitted.

Source? I don't think this is true. Doesn't seem to be the case for me. Maybe your email provider attaches your IP address?

It’s in the headers. Send an email to your self from Mail and open the source in the inbox. There is your IP.

I also just tried this as well, sending an email from a Migadu-based account to one at both Gmail and MXRoute using Mail.app under macOS 15.7.7. Neither included any private IP address info I could find in either headers or raw source. That would be a good leak to know about and as sibling comment said saagarjha definitely knows their stuff, so any tips to replicate would be appreciated.

Re: Apple 'Hide My Email' vulnerability reveals peoples' real email addresses

#59

Earlier quoted context omitted.

> You send an email to the HME address, reply, and then the real mail gets disclosed in the mail source. Does the initial sender matter? Like if it’s the HME address that sends first and receives the reply? I have around 180 of these addresses.

> then the real mail gets disclosed in the mail source. It's not just in the source, I totally overlooked the fact the real email address is shown as sender. Lol. > Does the initial sender matter? Like if it’s the HME address that sends first and receives the reply? I have around 180 of these addresses. Appears so. Here is exactly what I did: 1. Created the HME through mail, sending to other email service address (OM…

6. is a sign of bad UX but not leakage to the recipient.

Re: Apple 'Hide My Email' vulnerability reveals peoples' real email addresses

#60
post #39

Earlier quoted context omitted.

Fetching any email content is always worse than blocking it, because the typical threshold for spam is "is this inbox monitored". If that is true, then blast it with spam. And fetching anything ever proves that the inbox is monitored.

At least in Gmail, downloading content (e.g. images) is disabled by default for suspicious emails. There is no way for the sender to know if it’s monitored unless this is disabled by explicit user action.

This freaked me out the first time I used Mail. It rendered a PDF about buying bitcoin on PayPal (I don't have PayPal). Looked at the same email in Gmail and Thunderbird, it's just a PDF attachment, no message, and the sender was different. No wonder people are falling for those scams, Mail makes it easy for them.

Now if only I had a better client on my phone (never buying an iPhone again)

Post reply on HN