17 ms·
Apple's “iCloud Private Relay” broke risk based authentication
- jarym 5y ago"But please stop relying on RIBA for the plain authentication of a user!" Well I'm not sure everyone will be happy to do that. Tying session tokens to source IP addresses is usually not a bad practice and is rarely the only mitigation used.
- ffo 5y agoWell, in the end channel binding would be the best option which really mitigates some threat vectors. For example MITM, secrets extraction out of the browser and so on. But the big issue is that this is not widely supported. Using the IP as means is IMO nonsense with todays use of CG-NAT, VPN and so on. It does not rely help securing something. But these are just my 2 cents ;-) Disclaimer: I wrote the article
- SahAssar 5y agoToken binding was a much better way to do this where you'd bind a cookie to a certain client TLS key. Unfortunately only MS implemented support, and that disappeared when they moved to chromium so I'm guessing it's dead.
- ffo 5y agoI think it is still there, even in Edge on Chromium. But still Chrome dropped the hidden support a while ago.
- md_ 5y agoHmm, I'm not convinced it's better—but it depends a lot on your threat model. For preventing malware from using stolen cookies on a botnet, it's reasonable to argue that it's easier for the malware to steal the TLS client cert (which is no less accessible than the cookie jar itself) than it is for the malware to maintain access to the "good" client IP. As silly as IP-binding of sessions is.
- ffo 5y agoTo use ip binding as means already fails today. I mean CG-NAT and the slow adoption of ipv6 also did help dig that grave and I would argue that with that you can't rely on the IP because it is volatile anyway. From a threat model perspective it is absolutely true that when attacker gains control over the device they could extract the secrets from that said device (they can act as you as well). However token-binding would at least allow for some safeguards against attacks from the application layer (in this case web apps and extensions) in the browser but not against device attacks.
- md_ 5y agoAgreed. And TB arguably could have supported hardware-backed key storage—but no implementations I am aware of did this. My point was only that lamenting the demise of TB as implemented is a bit overdramatic. Lamenting the demise of TB as (perhaps) dreamed about—yeah, I buy that.
- ffo 5y agoTotally agree with your point here. Would love to see a TB implementation depending on hardware keys. But yeah it is gone. If the UX for mTLS (client certs) just was not so terrible it might be a great alternative with even better Security, but that is a dream as well ;-)
- SahAssar 5y agoIt can be made much less accessible because it's not meant to be shared with the remote side. A client cert is also not shared among all users behind a NAT, can be durable across roaming across IPs, and is actually meant to be a security measure unlike IPs.
- kstrauser 5y agoThat’s a great practice as long as zero of your users are on phones — which will generally be the case if you deauthenticate them every time their IP changes and they stop using your site.
- tyingq 5y agoI would guess that the RIBA vendors will adjust as more people start using it.
- csunbird 5y ago> As of writing this blog I was in Switzerland and the IP used to egress my traffic was in a region located in the US. If this also tends to change a lot and fast you can basically throw away IP addresses as data of your RIBA. Wait, so my data will be routed to US servers, as an EU resident, where the data protection laws are not as strong as where I live? This is a really bad idea, as US is known to tap any data they can get on their soil.
- x4e 5y agoWell Switzerland is not completely EU so I’m not sure if it has the same data protection laws.
- ffo 5y agoWe still have separate laws here. But we are moving towards the EU regulations in small steps.
- occamrazor 5y agoIn terms of privacy, the Swiss law is essentially equivalent to the GDPR.
- danceparty 5y agoPrivate relay will egress from the same general region as the client source location. So if you’re in switzerland and hopping through a US exit point that is a bug. This is clearly explained in the wwdc video
- ffo 5y agoYou can choose in the OS to use a general location or stick to something in your proximity. At least in the Developer Beta 2
- defaultname 5y agoThe two options are basically city-level or country but same TZ level. e.g. Toronto, or somewhere in Canada in Eastern time (which I mean would almost certainly be limited to Toronto -- presumably these options make more sense on say the East Coast for the US where there are a number of possible major locations that fit) There are clearly some bugs. Occasionally I, in Canada, get routed through the US. This guy got routed through the US. Neither case should happen by Apple's description. Apple is quite intentionally trying to avoid their relays getting around geo-restrictions (likely to avoid them getting blacklisted).
- marcinzm 5y agoI find authentication the least problematic place where risk based on ip is used. Etsy, for example, will suspend your seller account if it sees too many logins from different IPs or if it's from an IP it has flagged before. It also has terrible seller customer service so it could take weeks to get it un-suspended. Heard of some people using Private Relay getting hit by this during the beta so hopefully Etsy gets rid of that system.
- ffo 5y agoTrue it applies to other services as well. I just scoped my IMO to our Identity and Access Management World.
- fps_doug 5y agoCompared to Google, where you can't contact anybody at all if you're not on a payed account. Yes, it's free, why do you expect service, but they're still making money off me with ads etc., so locking an account down forever because of suspicious activity seems a bit over the top in that case.
- marcinzm 5y agoSometimes Etsy customer service will just say "we no longer have a business relationship and we cannot talk further<disconnect>". So it may be weeks using un-documented email addresses and escalation processes that you only learn about on unofficial subreddits.
- dannyw 5y agoEtsy is a commercial marketplace, it's as free as your local Walmart is free.
- headmelted 5y agoThey will be forced to. That’s what’s different with iCloud relay - Apple’s weight to force changes upstream. Either Etsy changes their policy now during the beta (my guess is they will), or they change it in a panic in November when iPhones can no longer access the site to buy anything. (No-one is going to switch off private relay to convenience a single website).
- tester89 5y ago> IMO = In My Opinion is a blog format where a author reflects his own opinion Did they just reïnvent opinion pieces?
- donmcronald 5y agoWhen Google Workplace locks users because of this, and I’m fairly sure they will because they’re super aggressive with IPs that change via VPN, they'll bounce incoming mail for that user. Have fun everyone!
- ffo 5y agoBeen there done that. Google flagged my account several times already, with nice captchas :-)
- Spooky23 5y agoIIRC that is a configuration choice by the company admin. I can think of a few orgs that aggressively block VPN traffic from employees - in some cases the metadata leaked by the end user is a security risk. (Ie you’re doing work stuff in one tab and researching or doing related matters in another)
- donmcronald 5y agoI was mostly complaining about the way locked accounts bounce mail. I've had accounts locked for "suspicious activity" which is really just logging in from an IP different than the one you normally use. IE: IPs with good reputation, but just not exactly the same IP all the time.
- mindslight 5y agoI hadn't known there was a term for this braindead idea that websites should hassle you based on your IP address. Of course there has to be a term, compartmentalization is necessary for getting good people to do bad things. It's fantastic that Apple is continuing to mitigate commercial surveillance. It's easy to discriminate against us lone individuals who hide our IP addresses, but Apple's market is too big to reject. If they're successful here, I'll have to consider buying a Mac purely for their VPN service. Perhaps they'll take on CAPTCHAs next.
- cratermoon 5y ago> this braindead idea that websites should hassle you based on your IP address So if you only ever log in to your financial institution from NY city, they shouldn't be suspicious if they see an attempt to log in from North Macedonia?
- liketochill 5y agoIt was a nice temporary hack in the game of cat and mouse. Now a solution that doesn’t depend on that signal will be required. My bank sends me a card with a grid of coordinates and I have to enter the character at the coordinate when I login, after entering my password, thereby proving something I know and something I have, without also requiring me to have a phone
- cratermoon 5y agoYes, that's great. It's also less convenient. Depending on the security threat model, users might tolerate it, or they might not. In the case of lots of money, it's a good practice.
- grishka 5y agoYou'd have 2fa for your online banking anyway.
- cratermoon 5y ago
- gkop 5y agoAuthor, since you “dearly recommend” a related blog post of yours, please link to that post.
- dmitshur 5y agoI agree. FWIW, I think it’s https://zitadel.ch/blog/imo-passkey-in-icloud-keychain/ https://zitadel.ch/blog/imo-passkey-in-icloud-keychain/.
- ffo 5y agoWhops, good catch! There is definitely the link missing. Going to correct that ASAP. In the meantime: https://zitadel.ch/blog/imo-passkey-in-icloud-keychain/ https://zitadel.ch/blog/imo-passkey-in-icloud-keychain/
- ffo 5y agoIt is patched now.
- donohoe 5y agoJust occurred to me that Apple’s upcoming iCloud Private Relay will break nearly all GDPR solutions. Am guessing this has been written up already be someone. Any good perspectives?
- klohto 5y agoHow? The data stays in EU. Routing to US is clearly a bug (that violates it, yes)
- djrogers 5y agoDoubt it violates anything - the packets may route through a US based relay, but they’re encrypted when they do, and don’t expose any data. The very nature of the internet makes it impossible to guarantee that none of your packets ever route through a specific country (especially one as connected as the US).
- donohoe 5y agoI didn’t say it violates it - it does not. I meant that most consent systems that companies add to their site to determine if a user is in EU or not (and hence covered by GDPR) won’t work reliable with Apple users. Most of their geolocation relies on IP addresses.
- djrogers 5y agoI was replying to my posts parent who brought up the word violate, not your post.
- netr0ute 5y ago> makes it impossible to guarantee that none of your packets ever route through a specific country Technically untrue, since you can add "strict source routing" as an IP packet option that specifies exactly where it will be routed.
- 5y ago
- james_pm 5y agoWe're anticipating having to make some changes to our fraud scoring which uses things like location vs. credit card address as signals.
- avh02 5y agoas someone who lived abroad but had a US based account i wanted to use to buy things with - "clever" moves like this were the bane of my existence. Combine that with a bank that would freak out if you used the account from abroad it was often a multi-day operation to get a transaction to go through (between support calls to bank and merchant) Though i guess a signal vs hard lock/logic.
- wyager 5y agoGood. I’m tired of wasting my time with dumb bullshit like vendors thinking my credit card billing address is “suspicious” somehow.
- grishka 5y agoSo many companies insist I provide them a "billing address", except I don't have one, it's a uniquely North American thing. Filling that form with gibberish usually does the trick for me.
- cr1895 5y ago> it's a uniquely North American thing It’s a thing in Europe as well.
- supertrope 5y agoVendors do that because they’re left holding the bag in chargebacks. Addresses are de facto knowledge based authentication questions in lieu of dynamic credit card codes.
- wyager 5y agoHopefully this results in the elimination of credit cards. Vendors should ideally switch to lighting-based settlement or something.
- TurningCanadian 5y agoDid it actually break risk based authentication though? Sure, legitimate users will be using Apple's Relay, but what's stopping attackers from using it? If the users of the service are choosing to be indistinguishable from attackers, then that's on them. I think of it like reputation in real life. If you come knocking on my door, and I can see and recognize you, I'll open it. If you cover up my peephole or hide yourself so that I can't recognize you, why would I even let you know I'm home? Even if you tell me who you are, shouldn't I be worried that someone is impersonating you? At the very least I'd expect users from anonymizing IPs to have to jump through some extra hoops like captcha and 2FA.
- cratermoon 5y agoIt broke it in the sense that it removed a signal that would allow the service to distinguish legit users from possibly malicious ones. In the case of a legit user that has in the past always authenticated from an IP address or address block geolocated to say, Seattle, the service can look at any authentication attempt from elsewhere as anomalous and raise additional challenges. However, with Relay, that signal is lost. Legit users and malicious parties become indistinguishable. The service can't tell if traffic from the relay is from a customer or an attacker. What to do? Trust everything? Not good. Treat everything as potentially malicious? Safe, but makes the user experience worse. To use your analogy, if you look through your peephole and can't tell if the person is your best friend or your worst enemy, how do you react? If you assume it's your best friend, you could be in trouble. If you treat the visitor like your worst enemy, you've pissed off your best friend.
- ffo 5y agoThank you, this really well summarises my article.
- cratermoon 5y agoIn my previous work we used the term "progressive authentication" for something similar. If the authentication attempt matched previous patterns, assume it's OK. If one or more of the signals is different but not obviously suspicious, present an additional challenge. This would be the case if the user lived in, for example, Seattle, and the login came from a place like the bay area, which they have previously visited. If it's clearly anomalous, provide all challenges and possible even block the attempt. This would be the case if, for example, an obvious bot script running coming from an address that resolved to an AWS instance in Hong Kong.
- outloudvi 5y agoI thought Private Relay will not change the geo-region of users (e.g., proxy to IPs of the same country) in order to let online streaming companies (e.g,. Netflix) happy. This is different from what said in this post. Is it no longer the case or never the case?
- ffo 5y agoWith the Developer Beta 2 it was more consistent in staying somewhat in the region. But still if you IP is consistently changing it is hard to adapt. Btw. Oftentimes Geo Databases are wrong as well.
- matwood 5y agoIt's buggy, but I've noticed the location has settled down and has me located in my same city now. Initially my IP was showing up all over the US. My guess is they were working on the logic and adding more CDNs. So far I've seen Cloudflare and Fastly.
- r1ch 5y agoHow on earth are they proxying through Fastly? I would expect Fastly only sends requests to their customers origins, yet Apple is proxying requests through them to arbitrary websites. I wonder if you could abuse this to bypass ACLs on Fastly customers that block direct origin traffic.
- gregsadetsky 5y agoIs it possible that the proxying is done via Cloudflare and Fastly's edge computing platforms? It'd be interesting to see where are the Relay requests coming from (i.e. what is the destination server seeing -- who's connecting to it?) Great point about the ACL.
- r1ch 5y agoIn Cloudflare's case they already have a consumer-facing product that supports relaying over their network (WARP, with separate IP range versus their reverse proxy service) so Apple is likely using a variant of that. I was very surprised when I checked and saw Fastly on my iPad as I wasn't aware Fastly had any similar product, in my mind they are (were?) strictly a reverse proxy CDN.
- vmception 5y ago“Welcome back! Hey looks like you are using a new device, how about we just ignore that greeting and use this other separate login process every fucking session”
- rhexs 5y agoThank you. Can someone please break security questions next so I don’t have to store four passwords instead of one to login to my accounts? Please kill opt-out-less 2FA while you’re at it. (Thanks Amazon, been enjoying that change!)
- peteretep 5y agoGood. As someone who moves around a lot esp to countries where I need to use a VPN, this bullshit is the bane of my life
- grishka 5y agoGood. This will finally make everyone treat all IP addresses equally.
- astrange 5y agoWhich is bad if you ever wanted to make a service without user accounts. Also a strange approach by Cloudflare, who sell IP based risk management.
- codetrotter 5y ago> Also a strange approach by Cloudflare, who sell IP based risk management. Is it though? To me it seems more like the iCloud Private Relay will make it harder for everyone else maybe but not necessarily much harder for Cloudflare themselves.
- astrange 5y agoPrivate relay puts you behind 2 proxies (which is almost as good as 7 proxies) so Cloudflare doesn't see your IP either.
- grishka 5y agoAs an end user, I hate being discriminated by something I can't really change much. That's all. And, yes, I do hate Cloudflare and other CDNs with burning passion because the internet is meant to be decentralized. But especially Cloudflare and their "one more step".
- deleted 5y ago[deleted]
- aborsy 5y agoNot quite on topic of this post, but does anyone know how much Private Relay impact iPhone’s battery life? OpenVPN has a noticeable impact.
- amazingman 5y agoThe battery impact should be entirely negligible. It's not encapsulating your traffic, it's just relaying it to different endpoints. It's not so much a VPN as a 2-tier proxy.
- djrogers 5y agoSo far it’s been completely unnoticeable. Browsing performance has mostly been within a few % as well - turns out having your traffic egress at a huge CDNs edge network isn’t a bad thing…
- ReGenGen 5y agoIt will be interesting to see if Apple allows hackers to freely abuse the system. If Apple bans end-users for abuse there will be far fewer problems.
- simondotau 5y agoThis is the big one. But how can Apple ban users for abuse if they themselves cannot know which user is responsible for any particular request? If they can tie individual users to abusive activity then their claims of being a truly private relay service are bogus.
- musicale 5y agoWorking as intended.
- GekkePrutser 5y agoGreat. RIBA is a really poor method that causes a lot of false positives for expats like myself. I'm really happy that more people will suffer this digital discrimination because it will mean it will go away. I live in Spain, I'm from the Netherlands and have lived in Ireland as well, leading to tons of "soft block" nightmares.