We put up a timeline of the disclosure here: https://easyoptouts.com/guides/apple-hide-my-email-is-leakin...
To me it seems, at least in this instance there is not even an exploit needed and the feature apparently is just broken beyond belief.
51–60 of 105 posts
We put up a timeline of the disclosure here: https://easyoptouts.com/guides/apple-hide-my-email-is-leakin...
To me it seems, at least in this instance there is not even an exploit needed and the feature apparently is just broken beyond belief.
Earlier quoted context omitted.
Source? I don't think this is true. Doesn't seem to be the case for me. Maybe your email provider attaches your IP address?
It’s in the headers. Send an email to your self from Mail and open the source in the inbox. There is your IP.
I'm not actually doubting it. saagarjha knows his stuff. I just don't see it, so maybe I'm holding it wrong.
Earlier quoted context omitted.
The problem there is users cannot evaluate if it matters to them whilst all information needed to do so is being witheld.
If having your personal email exposed would be a matter of personal safety or similar, then stop using it. If you're just using it for junk mail or to get a free trial then keep using it.
Is it based on mail undeliverable errors? Or attempts to login using IMAP or SMTP with it? Or is it exposed during the SMTP protocol?
My guess would be it has nothing to do with email itself. Maybe it's some iCloud API that accepts obfuscated emails but returns the original email in the response, or an ID which can be used to retrieve the iCloud email from another API endpoint. Could be as simple as an "add contact/friend" feature in some Apple product (like a mail client, or a file sharing service) that resolves the obfuscated email to the origina…
> It reveals the email linked to the Apple ID.
So I assume you are right that it has nothing to do with the email itself, but prob some other service that links the obfuscated email to the appleid of the user.
[0] https://www.404media.co/apple-hide-my-email-vulnerability-re...
Earlier quoted context omitted.
It’s in the headers. Send an email to your self from Mail and open the source in the inbox. There is your IP.
Is this from iOS? I just tested from MacOS, and the only IPs were for the transit and auth servers. I'm not actually doubting it. saagarjha knows his stuff. I just don't see it, so maybe I'm holding it wrong.
Earlier quoted context omitted.
Source? I don't think this is true. Doesn't seem to be the case for me. Maybe your email provider attaches your IP address?
It’s in the headers. Send an email to your self from Mail and open the source in the inbox. There is your IP.
Earlier quoted context omitted.
> You send an email to the HME address, reply, and then the real mail gets disclosed in the mail source. Does the initial sender matter? Like if it’s the HME address that sends first and receives the reply? I have around 180 of these addresses.
> then the real mail gets disclosed in the mail source. It's not just in the source, I totally overlooked the fact the real email address is shown as sender. Lol. > Does the initial sender matter? Like if it’s the HME address that sends first and receives the reply? I have around 180 of these addresses. Appears so. Here is exactly what I did: 1. Created the HME through mail, sending to other email service address (OM…
Earlier quoted context omitted.
Fetching any email content is always worse than blocking it, because the typical threshold for spam is "is this inbox monitored". If that is true, then blast it with spam. And fetching anything ever proves that the inbox is monitored.
At least in Gmail, downloading content (e.g. images) is disabled by default for suspicious emails. There is no way for the sender to know if it’s monitored unless this is disabled by explicit user action.
Now if only I had a better client on my phone (never buying an iPhone again)