7 ms·
An investigation into Apple’s new Relay network
- gigel82 4y ago> Therefore, we could show that a single entity can observe both ingress and egress traffic and use techniques similar to The Onion Router (TOR) attacks to combine ingress client addresses with server addresses. This issue breaks Apple’s promise to prevent a single party from seeing both addresses on the network level.
- colechristensen 4y agoThis kind of centralization I trust much less than just letting things go through my ISP. Way easier for the FBI and NSA to get information in bulk from Akamai than to target me at my ISP.
- olliej 4y agoGetting a warrant on your ISP is demonstrably trivial (see many many cases over the years). All of your traffic goes through your ISP so you’re comparing a mechanism that endeavors to avoid allowing either end of the connection to know the target of the other, that is encrypted and so opaque to your isp. Vs your isp knowing every site you go to? Or you could get a random VPN service, in which case you have another single company to serve a warrant, only unlike the relay case that vpn knows just as much as your original ISP.
- buildbot 4y agoIts actually US law even - the lawful intercept system. Gor example: https://www.ss8.com/understanding-5g-standards-for-lawful-intercept/ https://www.ss8.com/understanding-5g-standards-for-lawful-in... “ As lawful interception takes place in the core network, and the initial 5G NR deployments leveraged the existing 4G EPC network, carriers were able to continue using their existing and compliant lawful interception systems to support their 5G NR deployments. Therefore, Law Enforcement Agencies (LEAs) considered 5G systems as nothing new, just “4G on steroids”. And from a Lawful Interception standpoint, they were right. Those initial systems supported the existing handover specifications such as 3GPP TS 33.106, 33.107 and 33.108 and could only support up to 1Gbps per subscriber bandwidth, since the Evolved Packet Core (EPC) was still 4G and there were capacity limitations on the EPC. Law”
- buildbot 4y agoIts incredibly easy to target ISPs, there’s a USA law the enforces it.
- angio 4y agoMy ISP is not in the US though :)
- pnpnp 4y agoI'm really amazed at what Apple has created with private relay. I see people complain, but I do _not_ see it as a replacement for Tor. What it does provide is the first private (again, not Tor-level private) VPN that incentivizes sites to allow the traffic. How does it do this? - traffic is legitimate with a high degree of certainty (it's tied to an iCloud account that can be blocked, and more or less must be run on Apple hardware) - sites that block private relay are potentially blocking a large audience of Apple users With more anonymous VPNs there are fewer potential repercussions against malicious traffic, and it's harder to prevent users from abusing the system.
- braingenious 4y ago> traffic is legitimate with a high degree of certainty (it's tied to an iCloud account that can be blocked Wait… what? The traffic on this private relay can be traced back to your iCloud account? By Apple? By any website you visit? What are you talking about?
- donavanm 4y agoAFAIK only existing iCloud users on apple OS devices can use private relay. Apple doesn't need/care about the content of your session (it's routed through 3Ps). But what they can do is drop support for your icloud account, which prevents you from using private relay. Transitively tying it to active apple hardware IDs, via iCloud, also means theres a significant real cost to setting up to use this service. There's basically no way bulks scammers/scraping/manipulation/etc can afford that cost for their disposable use cases. This compares VERY unfavorably to the costs of farming gmail/microsoft/ISP accounts, from the scammers perspective.
- braingenious 4y ago> But what they can do is drop support for your icloud account, which prevents you from using private relay. How does Apple tie your traffic to your iCloud account? They have repeatedly stated that they cannot see what any account is doing.
- quartz 4y agoRelatedly I recently learned that Apple also has a "protect mail activity" option that seems to use private relay under the hood for email content. You can use this feature without actually enabling private relay for your whole machine. I discovered this because pihole blocks private relay by default and I was getting an error in the mail app that it wasn't able to protect my activity: https://apple.stackexchange.com/questions/429899/why-am-i-seeing-your-network-settings-prevent-content-from-loading-privately-i https://apple.stackexchange.com/questions/429899/why-am-i-se... Have to say I'm a big fan of apple trying to bring more of these features to average users. I had just finished prototyping my own mail server to do exactly what "hide my email" does when apple announced that feature and was very happy to be able to throw that code out in favor of something built into my mail client (although it was actually pretty fun to learn dovecot and postfix).
- threeseed 4y agoFrom Mail.app: Protect Mail Activity helps protect your privacy by preventing email senders, including Apple, from learning information about your Mail activity. When you receive an email in the Mail app, rather than downloading remote content when you open an email, Protect Mail Activity downloads remote content in the background by default — regardless of whether you engage with the email. Apple does not learn any information about the content. In addition, Protect Mail Activity routes all remote content downloaded by Mail through two separate relays operated by different entities. The first knows your IP address but not the remote Mail content you receive. The second knows the remote Mail content you receive but not your IP address, instead providing a generalised identity to the destination. This way, no single entity has the information to identify both you and the remote Mail content you receive. Senders can’t use your IP address as a unique identifier to connect your activity across websites or apps to build a profile about you. If you choose to disable Protect Mail Activity, the Hide IP Address feature will still mask your IP address using the same two-separate-internet-relays design.
- odysseus 4y agoCan’t spammers still learn if you opened the mail by using unique per-recipient image file names?
- supernova87a 4y agoThis is basically a VPN for everyone using an Apple device, right? The question I have is whether Apple keeps (or can be compelled by law enforcement to produce) the logs of who you are and what you have browsed?
- supriyo-biswas 4y agoA VPN that only works with Safari and apps using the native HTTP libraries to make unencrypted HTTP requests.
- LeoPanthera 4y agoDo you have a citation for this? That is not my experience. With iCloud Relay enabled, all outgoing traffic seems to go through the relay.
- 58028641 4y agoFrom iOS Settings App: Private Relay hides your IP address and browsing activity in Safari and protects your unencrypted internet traffic so that no one-including Apple-can see both who you are and what sites you're visiting
- ec109685 4y agoEncrypted safari traffic goes through the relay.
- lathiat 4y agoEncrypted safari traffic is an exception. But encrypted app traffic does not. They made it a few years ago they all apps had to use encryption. Long before private relay came out. I have wondered if this was why.
- justsomeadvice0 4y ago
- robbywashere_ 4y agoVery fancy! Currently in Thailand, defeated by: “Private Relay is not available in Thailand due to local laws and regulations.“ “Privacy is a fundamental human right.” Unless local laws and regulations say otherwise.
- buildbot 4y agoWell yeah, there are plenty of places without humans rights and sometimes the laws enforce that.
- whynotminot 4y agoDo you expect Apple to violate the laws of your country?
- phantomathkg 4y agoNot the author, but I would say, Expected? No. For a global company without backbone. Wish? Yes.
- gggggg5 4y agoThere are fairly successful companies like Telegram and Signal, who are aggressively using technical measures to evade censorship. Apple certainly could do this.
- supernova87a 4y agoSure, but not if they wish to keep on operating (i.e. selling things, and manufacturing things as part of their business) legally in that country.
- gggggg5 4y agoThere are significant costs associated with something as visible as banning the sales of Apple devices. Governments are certainly capable of doing this, but the cost-benefit analysis does not necessarily add up.
- gigatexal 4y ago“ The ingress addresses are in two ASes: Apple’s own AS and the Akamai-PR AS. This is the same AS also present in the egress address collection and appears only to be used for Private Relay. We used a laptop with an active Private Relay session to prove that the ingress and egress address can be within the same AS and that both addresses were reachable behind the same last hop router address. Therefore, we could show that a single entity can observe both ingress and egress traffic and use techniques similar to The Onion Router (TOR) attacks to combine ingress client addresses with server addresses. This issue breaks Apple’s promise to prevent a single party from seeing both addresses on the network level.”
- xyzzy123 4y agoOne take is that what Apple want to do is increase the value of tracking and targeting offered by Apple and decrease the value of everyone else's. Still a net win.
- hinata08 4y ago>the egress layer, are operated by third-party entities. Currently, these are Akamai, Cloudflare, and Fastly. Great After forbidding privacy by blocking tor and proxy traffic, now CloudFlare is going to red carpet Apple devices only. I've never had issues with Akamai or the like even on Tor. It's it CloudFlare, they're here to undermine the web neutrality in some way. Are these companies rebuilding a more private internet? We need some RFC or standard for what they are doing, not just a registration and relay service run by Apple and CloudFlare.
- comprev 4y agoVodafone Ireland has disabled support for Relay, or at least on my business mobile account.
- jbverschoor 4y agoTime to migrate to T-Mobile
- jen20 4y agoThis is as sure a sign as any that they are hostile and it’s time to move.
- comprev 4y agoThey've been a reliable provider both in Ireland and roaming abroad so I'm hesitant to switch. I always use a VPN anyway so the Relay situation is not a massive deal breaker for me.
- Bluecobra 4y agoOne really cool thing I discovered with Private Relay is that it will proxy an IPv4 address to IPv6. For example if you Google “what is my ip” you should see an IPv6 address in Google.