4 ms·
This is basically a VPN for everyone using an Apple device, right? The question I have is whether Apple keeps (or can be compelled by law enforcement to produc
by supernova87a 4y ago
This is basically a VPN for everyone using an Apple device, right? The question I have is whether Apple keeps (or can be compelled by law enforcement to produce) the logs of who you are and what you have browsed?
- supriyo-biswas 4y agoA VPN that only works with Safari and apps using the native HTTP libraries to make unencrypted HTTP requests.
- LeoPanthera 4y agoDo you have a citation for this? That is not my experience. With iCloud Relay enabled, all outgoing traffic seems to go through the relay.
- 58028641 4y agoFrom iOS Settings App: Private Relay hides your IP address and browsing activity in Safari and protects your unencrypted internet traffic so that no one-including Apple-can see both who you are and what sites you're visiting
- ec109685 4y agoEncrypted safari traffic goes through the relay.
- lathiat 4y agoEncrypted safari traffic is an exception. But encrypted app traffic does not. They made it a few years ago they all apps had to use encryption. Long before private relay came out. I have wondered if this was why.
- justsomeadvice0 4y agoAgreed, we can only speculate; personally I would be surprised if that was the "long-term" plan instead of just a push at the time to enforce industry best practices on its apps. My hunch would be such a move might be disruptive to certain apps (banking?) and they are allowing more time before tunneling everything, but this is just a guess.
- 4ad 4y agoSee my other comment about how iCloud Private Relay works. There are basically almost no security measures that prevent you from using it with other apps. This leads me to speculate that Apple intends to eventually enable this globally, so they don't really bother now with trying to lock it down too much.
- deleted 4y ago[deleted]
- 4ad 4y agoIt's a whitelist of apps that are tunnelled through the relay, but apps don't have to use any sort of special networking library, pure Berkley sockets work just fine through the relay. Also, anything that attempts to use port 80 goes through the relay, it doesn't have to be HTTP, as I said, plain BSD sockets work. This whitelist is implemented using the regular macOS/iOS per-app firewall. Not only this is accessible to users, but the whitelist matches based on the Mach-O UUID, which is an arbitrary number put in by the linker... The restriction on which apps can use iCloud Private Relay is trivially defeatable.
- astrange 4y agoIt's more secure than a VPN; the relay is run by two separate companies and neither of them can see enough traffic to know both those things, for either HTTP or DNS. Findings in the article aside, of course.
- supernova87a 4y agoI guess my question is, sure, someone could to lengths to observe the in + out, but does Apple (and the other entity) decline to keep logs such that they at least could not be compelled to give up data that could link the two? If the RIAA gets a court order to reveal who streamed something, shared illegally, etc. would they be able to comply?
- angio 4y agoAre these two companies based in two different jurisdictions? In other words, is the non-apple company US-based or not?
- sgerenser 4y agoNon Apple companies are Cloudflare, Akamai and Fastly.
- olliej 4y agoThe whole point of private relay is that apple does not have access to what sites you're loading. The article does a good unbiased description, but you can think of it as a single hop tor - enough to stop apple from knowing what you are loading, and enough to stop the egress point from knowing who is making a given request. Someone who can monitor all the entry points and exit points can probably tie the connection together, but someone in that position can probably also do that for any other vpn service (Nord, proton, etc - though those providers don't have any privacy options).
- KingLancelot 4y ago[dead]