5 ms·
Relatedly I recently learned that Apple also has a "protect mail activity" option that seems to use private relay under the hood for email content. You can use
by quartz 4y ago
Relatedly I recently learned that Apple also has a "protect mail activity" option that seems to use private relay under the hood for email content. You can use this feature without actually enabling private relay for your whole machine.
I discovered this because pihole blocks private relay by default and I was getting an error in the mail app that it wasn't able to protect my activity: https://apple.stackexchange.com/questions/429899/why-am-i-seeing-your-network-settings-prevent-content-from-loading-privately-i https://apple.stackexchange.com/questions/429899/why-am-i-se...
Have to say I'm a big fan of apple trying to bring more of these features to average users. I had just finished prototyping my own mail server to do exactly what "hide my email" does when apple announced that feature and was very happy to be able to throw that code out in favor of something built into my mail client (although it was actually pretty fun to learn dovecot and postfix).
- threeseed 4y agoFrom Mail.app: Protect Mail Activity helps protect your privacy by preventing email senders, including Apple, from learning information about your Mail activity. When you receive an email in the Mail app, rather than downloading remote content when you open an email, Protect Mail Activity downloads remote content in the background by default — regardless of whether you engage with the email. Apple does not learn any information about the content. In addition, Protect Mail Activity routes all remote content downloaded by Mail through two separate relays operated by different entities. The first knows your IP address but not the remote Mail content you receive. The second knows the remote Mail content you receive but not your IP address, instead providing a generalised identity to the destination. This way, no single entity has the information to identify both you and the remote Mail content you receive. Senders can’t use your IP address as a unique identifier to connect your activity across websites or apps to build a profile about you. If you choose to disable Protect Mail Activity, the Hide IP Address feature will still mask your IP address using the same two-separate-internet-relays design.
- odysseus 4y agoCan’t spammers still learn if you opened the mail by using unique per-recipient image file names?
- snotrockets 4y agoThey’ll learn you received it, not when you opened it (as the image is downloaded either way), and won’t be able to get any metadata (ip based location, browser headers). Gmail uses a similar technique to mask metadata, though iirc they do download the images only when the email is first read by the recipient.
- odysseus 4y agoIf you don't open the email, and don't have the preview pane on, how would the image get downloaded either way? If you do open the email, and the spammer maps, say, snotrockets@example.com to a unique AD-SRE21234.JPG filename and that image within the email is displayed, no matter if it goes through Apple's relay or not, wouldn't the spammer then be able to validate your address is both valid and actively opening spam mail at whatever time you opened it?
- justsomehnguy 4y agoThe only thing they could know if its were actually delivered. Image download would happen from a 3rd party and as soon as its received. So actual usability is quite low. They would spam you anyway, though.
- acdha 4y agoThey can tell that you used an Apple device to receive the email. They can't tell whether you actually opened it, or when, or where. Not seeing the IP is also important for preventing linking: if you have data from other sources (your website, apps, etc.) this can link that activity to an identity for as long as your IP doesn't change. It's not perfect but that's the kind of thing advertisers like because they can see that, say, session A on a desktop computer which generated the email lead to session B on a phone which opened it and consider that all future activity linked to the session IDs from either client is the same person even when your phone moves to another network.