3 ms·
I believe all OP is trying to say is that Apple controls ingress nodes, which the customer connects (authenticating with iCloud) to as the first hop; the destin
by justsomeadvice0 4y ago
I believe all OP is trying to say is that Apple controls ingress nodes, which the customer connects (authenticating with iCloud) to as the first hop; the destination and content of the packets is encrypted to the second hop and cannot be decrypted by them. But if Apple wants to stop your iCloud account from sending traffic through the relay it can do so at any moment. This should not be surprising, it's not an "open" relay but a premium service.
- braingenious 4y agoI am aware of the part of the reasoning you’ve described. What I’m trying to figure out is how “Apple can ban users” translates to “website owners will trust that traffic more.” Apple literally cannot ban you for malicious or fraudulent traffic (assuming you believe them), so what is the difference between this and any other paid VPN service? Those also cost money.
- justsomeadvice0 4y agoOh I see. Yea TBH I'm not sure what happens sure if hop 2 (e.g. Cloudflare) reports fraud/abuse "up" to Apple; whether Apple takes action or not. It would certainly be technically possible but would require cooperation between the two companies, that's the only guarantee I can find. Private access tokens are a real solution here, so maybe Apple does nothing in such a scenario and expects end sites to verify those.
- justsomeadvice0 4y agoI read a bit more, here is how it works, from the white paper: https://www.apple.com/icloud/docs/iCloud_Private_Relay_Overview_Dec2021.pdf https://www.apple.com/icloud/docs/iCloud_Private_Relay_Overv... > Authorization is performed by presenting a valid, anonymous token based on RSA blind signatures. These signatures are sent as one-time-use tokens to each proxy when establishing a connection, separating legitimate from illegitimate devices. The proxies can validate the tokens with a public key to validate that the user is legitimate, without actually identifying the user. > The following fields related to anonymous token issuance are logged as a part of Private Relay’s fraud prevention and anti-abuse measures, but cannot be correlated with connection information: > • iCloud account, software version, and request timestamp Sounds like both Apple and Cloudflare hops get the token. But Apple stashes a mapping of the token->iCloud account on its end, presumably to deal with fraud requests from Cloudflare. So my understanding then is if Apple gets a fraud/abuse request for someone's token from Cloudflare, it can and will banish your iCloud account from the service. Edit: on closer reading I think I was wrong... The stated logged data could just be to rate limit the tokens you can request. It doesn't say they log the token itself, and they do say "cannot be correlated with connection information". So it seems you are right!