6 ms·
Do you have something more recent than a leak from over 2 years ago that has long been fixed? I'm curious why iCloud Private Relay is theatre at the moment.
by fh9302 3y ago
Do you have something more recent than a leak from over 2 years ago that has long been fixed? I'm curious why iCloud Private Relay is theatre at the moment.
- lapcat 3y ago[flagged]
- JumpCrisscross 3y ago> It was advertised as being private, but it wasn't Signal had a bug once. Herego, it’s a scam?
- lapcat 3y ago> Signal had a bug once. Are you referring to this? https://www.forbes.com/sites/daveywinder/2019/10/05/signal-messenger-eavesdropping-exploit-confirmedwhat-you-need-to-know/?sh=d3fe2487dc11 https://www.forbes.com/sites/daveywinder/2019/10/05/signal-m... It was a bad bug in the Android client, to be sure, but it didn't bypass Signal encryption.
- shuckles 3y agoAnd a VPN leaks a lot of information about your network activity to the operator, so by your standard it is privacy theater. Do you see why you’re coming across as having inconsistent standards and thereby perhaps an axe to grind? iCloud Private Relay is used for all network activity from Safari which does not seem like a “limited amount of activity.”
- lapcat 3y ago> And a VPN leaks a lot of information about your network activity to the operator, so by your standard it is privacy theater. A VPN isn't designed to keep your IP address hidden from the operator. iCloud Private Relay doesn't hide your IP address from Apple either. That's not the point, and everyone knows this in advance. The point is to keep your IP address hidden from the request destination servers.
- shuckles 3y agoYour logic is that any flaw in an implementation renders it useless. In the case of VPNs, operators can and do share information about clients to destination servers, law enforcement, and more out of band. Just because it involves a spreadsheet and not a WebRTC request does not mean it can be forgiven if you're going around making absolutist claims regarding efficacy.
- lapcat 3y ago> Your logic is that any flaw in an implementation renders it useless. I didn't say that. It's a straw man.
- shuckles 3y agoYou said that iCPR is privacy theatre because of a resolved security bug from 2 years ago. Please spell out the implication of that claim for me then.
- lapcat 3y ago> Please spell out the implication of that claim for me then. I'll spell out my views below, but I want to start by noting that I don't agree with the way you've characterized them. Going all the way back to your initial reply, I don't like the way this leading question was phrased: > What specific features do you allege exist just to mislead the general public? I think Hanlon's razor is a false dilemma. With a big company like Apple, there's typically a combination of bureaucratic incompetence and marketing exaggeration. Clearly, Apple leadership has decided to make privacy a consumer differentiator for their products, so they have a financial incentive to hype privacy features as much as possible. As a consequence, Apple management would be eager to be pitched any and all privacy features from engineering; these may even lead to bonuses and promotions, though that's purely speculation on my part. Regardless of the personal motivations of employees, the company is pursuing privacy features in earnest and isn't intending for them to be fake. Nonetheless, the company also has the unfortunate habit of shipping half-baked features and implementations. This is driven largely by the artificial, forced march of the annual release schedule, which demands that great new features be continually announced at a certain time, whether they're ready or not. The situation is not unique to privacy features either; Apple's entire software product line is suffering in quality. Engineering simply doesn't have enough time to do things right, which results in new features that are superficial and/or flawed. You could say it's marketing-driven incompetence. Several commenters have mentioned that all software has bugs, as if that were somehow profound, or as if I were somehow ignorant of software development as a software developer. (I actually had to spend some time fixing a bug before I wrote this reply.) But not all bugs are created equal. From my perspective, a bug that's discovered relatively quickly by someone else is worse than a bug that's discovered only years later, in the sense that it suggests insufficient QA on the part of the developers, who themselves should have noticed the bug before it shipped. And a bug in the primary functionality of a product or feature is worse than a bug in a more obscure part of the software. This is why I'm not impressed by the length of time since a bug was fixed; if a feature or product was shipped with an obvious, fundamental flaw in its main functionality, that's a stain on the reputation of the developers. And if they keep making such mistakes, why should you ever trust them to be competent? No bug fix can fix the bug writers. I don't want to focus too much on iCloud Private Relay, though. It wasn't what I had in mind when I was writing my original comment, and I don't even use iCloud Private Relay myself. I mostly don't use a VPN, except on rare occasions. I've discussed iCloud Private Relay here only because you asked me about it. It's been a busy afternoon/evening for me, so I've kind of run out of steam now on this comment, but I promised I would reply.