15 ms·
Apple’s new Private Relay is leaking your original address through WebRTC
- cwizou 5y agoNot terribly surprising as I believe WebRTC has been a known issue for leaking your IP for a long time with VPNs. With that said I confirmed it does indeed leak my IP on iPad. The surprising part is that Apple sidestepped the issue. Side note: tried to test it on my Mac but for some reason it wanted me to "upgrade" to iCloud+, despite being an Apple One customer. Guess that's because the macOS betas are fairly out of cycle compared to the iOS ones and (presumably) their infra.
- mercacona 5y agoYou do need iCloud+, which is not included in Apple One despite the extra iCloud GB.
- bredren 5y agoHuh? This is surprising to me. I was just about to consolidate to apple one.
- gjsman-1000 5y agoI expect that for clarity's sake this will be changed when iCloud+ officially launches.
- mercacona 5y agoSome webs says it’s included, but in Beta 1 wasn’t and I didn’t look further. It make sense it’s just an update in the branding.
- djrogers 5y agoNo, it’s included - there’s just a beta glitch the first time (or two) you try to turn it on.
- aaomidi 5y agoAfter you press the upgrade button it realizes you have it and opens the gates.
- cwizou 5y agoThanks for the tip, tried a few times but no luck. I did use relay previously so could be a random bug.
- floatingatoll 5y agoIf you haven’t tried it yet, quit all Apple apps, sign out of iCloud in System Preferences, reboot (do not skip this step), sign back in at System Preferences and see if that heals it.
- coldcode 5y agoCan you turn it off, there are some options in the Develop menu in Safari regarding WebRTC. Not sure its enough though.
- nceqs3 5y agoIcloud private relay is great. I really hope Apple expands it too all traffic and not just safari.
- Sean-Der 5y agoYou can do lots of suprising things with ICE in the browser. I was really excited to find[0]. Go to this[1] JSFiddle and type in `$hostname.local` or a device on your network. I have a `WDMyCloud.local` for example. I think you could make something really interesting. A web page could make a pretty unique fingerprint of you by all the IoT/Printers/$X devices on your network. [0] https://github.com/rtcweb-wg/mdns-ice-candidates/issues/121 https://github.com/rtcweb-wg/mdns-ice-candidates/issues/121 [1] https://jsfiddle.net/10eq2rzh/ https://jsfiddle.net/10eq2rzh/
- fsckboy 5y agoofftopic: what's the non-routable TLD we're all supposed to be using now instead of .local? was it .lan? I tried googling with ddg:) but it's a noisy search
- ComputerGuru 5y agoThis was just discussed [0] last week, actually! The tl;dr is that there’s no great alternative to registering an actual domain name and using it (or a subdomain of it) for your network. The only viable TLD otherwise is .arpa [0]: https://news.ycombinator.com/item?id=28192247 https://news.ycombinator.com/item?id=28192247
- thetinguy 5y ago.Home.arpa not just .arpa
- ComputerGuru 5y agoThanks for the correction.
- ace2358 5y agoIsn’t it a double address like .home.lan or some such?
- 5y ago
- echelon 5y agoOne outcome of the CSAM debacle is that security researchers will be poking lots of new holes in Apple.
- eugeniub 5y agoWebRTC has been having these problems for at least 6 years straight. At what point can we call this a deliberate back door?
- acdha 5y agoWhen there’s evidence that it’s either deliberate or a back door? Those words have specific meanings and WebRTC doesn’t fit that description.
- elliekelly 5y agoI agree it’s not a back door but if you’ve been put on notice of a serious security flaw then after a certain amount of time I do think your failure to take corrective action is “deliberate”.
- crtasm 5y agoShould at least warn you, "this site wants to use WebRTC, this will reveal your real IP address. OK?"
- acdha 5y agoHow serious is it, really? The vast majority of users will connect to a web server with their IP anyway so I’d assume it’s more a question of weighting it behind other privacy improvements — for example, ad blocking and tracker protection are probably making more of a difference for most people.
- YLYvYkHeB2NRNT 5y agoI just tested this on my android device with an always on VPN and kill switch that's on. Even the egress IP is not leaked - Only the local 10.x.x.x addresses are.
- lostmsu 5y agoWhen you're not connected to WiFi you likely have a public IPv4 from the mobile provider.
- TroisM 5y agoApple is a privacy nightmare... a bit like google is evil.
- isatty 5y agoWhat critical functionality/common website will I break by disabling webrtc on all my devices?
- Boltgolt 5y agoMost video or audio calling sites for starters
- sysadm1n 5y agoThis is why I have a VPN router. All traffic is VPN-ified to/from the wifi signal, and you don't have to risk having your real / naked IP exposed. You can even route another VPN over that VPN for a sort of fake Tor with no problems. Check out GL.iNEt routers: https://www.gl-inet.com/ https://www.gl-inet.com/ You can even get little travel routers that you can use when traveling. No affiliation, just pointing out something many don't even see as an option they have.
- collsni 5y agoI do this too. I also use dns over tls for my VPN network. Non VPN network uses root hints. Two ssids one two different vlans. One VPN, one web.
- femiagbabiaka 5y ago#ad you don’t need specialized hardware to do this
- nathancahill 5y agoNo, but GL.iNet routers come with a 1-click solution. It's really handy, cheap and capable. Of course, you can install OpenWRT etc on any router as well. Just not quite as easy. Also no affiliation, but I love the little travel routers.
- Grustaf 5y agoWhat does this mean? Is this only relevant for users of WebRTC, whatever that is, or for everyone?
- easrng 5y agoWebRTC is a JavaScript API, so this is relevant to anyone who uses the web. (Assuming, of course, they have JS enabled.)
- Grustaf 5y agoAlright, so in practice Hide my email doesn’t work, the sites you sign up at will still receive your real email. That seems incredibly badly implemented by Apple. But how can the browser even have your email? Or is Apple leaking in from their systems somehow?
- epse 5y agoIt's not about hide my email, it's about their proxy leaking your ip
- firebaze 5y ago"Private Relay".
- viktorcode 5y agoCorrect me if I’m wrong, but isn’t it stated in the description that private relay works only with http(s) transport protocol in Safari? WebRTC doesn’t get through the tunnel by design.