5 ms·
Did it actually break risk based authentication though? Sure, legitimate users will be using Apple's Relay, but what's stopping attackers from using it? If the
by TurningCanadian 5y ago
Did it actually break risk based authentication though? Sure, legitimate users will be using Apple's Relay, but what's stopping attackers from using it? If the users of the service are choosing to be indistinguishable from attackers, then that's on them.
I think of it like reputation in real life. If you come knocking on my door, and I can see and recognize you, I'll open it. If you cover up my peephole or hide yourself so that I can't recognize you, why would I even let you know I'm home? Even if you tell me who you are, shouldn't I be worried that someone is impersonating you?
At the very least I'd expect users from anonymizing IPs to have to jump through some extra hoops like captcha and 2FA.
- cratermoon 5y agoIt broke it in the sense that it removed a signal that would allow the service to distinguish legit users from possibly malicious ones. In the case of a legit user that has in the past always authenticated from an IP address or address block geolocated to say, Seattle, the service can look at any authentication attempt from elsewhere as anomalous and raise additional challenges. However, with Relay, that signal is lost. Legit users and malicious parties become indistinguishable. The service can't tell if traffic from the relay is from a customer or an attacker. What to do? Trust everything? Not good. Treat everything as potentially malicious? Safe, but makes the user experience worse. To use your analogy, if you look through your peephole and can't tell if the person is your best friend or your worst enemy, how do you react? If you assume it's your best friend, you could be in trouble. If you treat the visitor like your worst enemy, you've pissed off your best friend.
- ffo 5y agoThank you, this really well summarises my article.
- cratermoon 5y agoIn my previous work we used the term "progressive authentication" for something similar. If the authentication attempt matched previous patterns, assume it's OK. If one or more of the signals is different but not obviously suspicious, present an additional challenge. This would be the case if the user lived in, for example, Seattle, and the login came from a place like the bay area, which they have previously visited. If it's clearly anomalous, provide all challenges and possible even block the attempt. This would be the case if, for example, an obvious bot script running coming from an address that resolved to an AWS instance in Hong Kong.
- TurningCanadian 5y agoWhy would my visitor be surprised that I'm suspicious though? They're choosing to be suspicious. Another analogy I could make is someone that is blocking their caller ID. Should they be surprised that fewer people will take their call? They're lumping themselves in with spammers. I think Apple -- and anonymizing proxy/VPN services in general -- should be communicating that to their customers.
- patch_cable 5y agoThe difference between Apple and other anonymizing proxy/VPN services will be the size of the user base. Websites will have to choose if they're willing to provide a worse UX to Apple customers.
- djrogers 5y agoWhoah there Nelly! That’s a huge leap from ‘using built in privacy protection features of my phone’ to ‘choosing to be suspicious’. Why should everyone between me and my data have access to an IP address that is tied to my personal data? And when did choosing to not allow that become a shady thing to do? — edited autocorrect of ruins to features
- TurningCanadian 5y agoIt comes back to reputation. In the real world, we build up a reputation and people can choose to trust us based on it. That also means that they get to know us. I personally like being able to interact with people that I've built up a positive relationship with. Why doesn't that carry over to the virtual world though? I think everyone's view is tinted by the over-collection of data that some companies are doing. A real-life analogy would be having someone record everything that you do. We've come to accept that to an extent when going into stores, but probably wouldn't hang out with a friend that did that. I don't think the best solution to that is to put a bag over yourself and change your voice so that you're anonymous but still hang out with that friend -- I think it's to tell your friend that you don't want to be recorded. If some service is recording you too invasively, don't do business with them. If you don't know who is recording you, get your government to pass a law like GDPR. If you want to live in a world without reputation, there will be drawbacks. Attackers will be indistinguishable from regular users, so you have to treat regular users as if they could be attackers; you can't have a tiered approach. The person banned for posting threats (or worse) or otherwise misbehaving on a message platform will be indistinguishable from a new account. The brute force attack will be indistinguishable from the legitimate user. Etc. To throw out the whole concept of reputation so that you can be perfectly anonymous seems like the wrong solution to the problem.
- meepmorp 5y agoIIRC, in one of the WWDC talks, Apple's advice is stop relying on IP address as a signal of the user's location. Either make use of the location APIs on the platform or work out something different.
- wyager 5y agoTrusting location APIs is also silly, as those can be spoofed easily. What Apple is really doing here is subverting the entire concept of geo-blocking services, which is great.
- cratermoon 5y agoMany APIs can be spoofed. If a system is trusting a third party service for security purposes, that needs to be subject to some close scrutiny. Using location as one signal of many is reasonable, and in some legal regimes, at least for now, required. Using location as the sole signal is foolish, and never was sufficiently reliable for anything but the most casual security check. See for example https://splinternews.com/how-an-internet-mapping-glitch-turned-a-random-kansas-f-1793856052 https://splinternews.com/how-an-internet-mapping-glitch-turn...
- adrianstoll 5y agoThis does not prevent geo-blocking, because the relay's IP is still in the same region as the user.
- jimmydorry 5y agoExcept when it isn’t like in the OP’s article. Also, when datacentres inevitably go down, traffic will be rerouted, potentially to other countries.
- 2OEH8eoCRo0 5y ago>If the users of the service are choosing to be indistinguishable from attackers, then that's on them. No. It's not on me to justify my use-case. How the hell did we get here?
- __david__ 5y ago> If you cover up my peephole or hide yourself so that I can't recognize you, why would I even let you know I'm home? Even if you tell me who you are, shouldn't I be worried that someone is impersonating you? Perhaps… but if the culture changes and _everyone_ starts covering the peephole, regardless of their intentions, you'll eventually stop looking because you know it's pointless. That doesn't necessarily mean you'll just open your door willy-nilly, it just means you'll come up with some alternative way of having your visitors prove their unmaliciousness.
- TurningCanadian 5y agoHow would that alternative way of proving their unmaliciousness/identity not be a reinvention of the peephole?