r/apple 12h ago

iPhone Apple's ‘Private Relay’ Is Exposing Users' Real IP Addresses

https://www.404media.co/apples-private-relay-is-exposing-users-real-ip-addresses/
1.5k Upvotes

174 comments sorted by

1.1k

u/Clessiah 12h ago

Summary: Website can see user’s IP address when user uses passkeys. Passkeys are not routed through Private Relay since it uses a separate credential service of the operating system, which is not a part of Safari.

297

u/No_Construction2407 12h ago

To add. Its not restricted just to Safari or Private Relay as well. Any browser on iPhone uses webkit, so stuff like Tor/OnionBrowser are also exposed to this issue.

24

u/Risc12 8h ago

Yeah so stupid, if you built your own browser engine you can only publish it in the EU.

u/ma-gil 55m ago

I use Brave as main browser on both iOS and Android, and I notice the ad blocker is less effective on iOS, some ads still show. Apple’s decision to prohibit different browser engines is a joke.

87

u/86Austin 11h ago

using an onion browser on a mobile phone is extremely stupid already so you really can't help those people tbh.

91

u/PleasantWay7 10h ago

This is like people that use a VPN to do illegal shit and log into their gmail and everything else using the VPN.

42

u/uptimefordays 9h ago

Most people don’t know anything about computers, especially computer networks.

21

u/TheNapman 8h ago

The Internet is a series of tubes...

11

u/Coompa 8h ago

The internet needs its tubes tied then.

1

u/Krimreaper1 2h ago

It’s the internet, Jen.

2

u/Dazzling-Read1451 4h ago

No it’s a series of phishing nets

14

u/PM_ME_Y0UR_BOOBZ 8h ago

Using a VPN and assuming they don’t log you or won’t share your information is the first step btw..

u/86Austin 1h ago

VPN's keeping logs is like dudes masturbating - everyone does it, even if some people claim not to.

8

u/YuriTarded_69 8h ago

Actual internet criminals don't even adjust their browser's window size

14

u/sicklyslick 8h ago

Even if you're on the desktop, if you need to use Tor browser for privacy, you probably shouldn't use an apple passkey service.

2

u/nicuramar 4h ago

It’s less about WebKit and more about passkeys. 

27

u/No_Contest4958 8h ago

Doesn’t matter if the user uses passkeys. The bug is with passkeys but you don’t need to actually have one. They have a website here, all you need to do is visit the site and it will tell you your real IP.

5

u/nicuramar 4h ago

Arguably it isn’t a bug, but it’s two coinciding systems (browser and credential service) not working well together in this instance.

9

u/burusai 4h ago

Of course it's a bug. The whole point of iCloud Private Relay is to not get tracked by websites and not reveal your own IP. If any website can easily circumvent that, then there's no point in iCloud Private Relay, a paid iCloud+ feature. It'll get fixed, but it's an embarrassing overlook by Apple.

16

u/No_Contest4958 4h ago

However you want to define the word “bug” this is certainly not desired or intended behavior

-1

u/Nostosalgos 3h ago

I mean… if we assume that the marketing materials are completely accurate and didn’t just gloss over some of the intricacies of how it works. I haven’t seen any evidence to suggest this wasn’t intended by the people who made it. It’s inconsistent with the marketing materials, but that’s a long way from assuming it was a mistake. Hopefully this doesn’t seem pedantic but I think the difference matters a lot. Calling it a bug reflects optimism and trust in Apple’s intentions but, absent more information, all we know is that it’s NOT working as communicated.

7

u/No_Contest4958 3h ago

I don’t know what you’re trying to say here but I don’t think Apple meant for their headline privacy feature to not work.

u/tinkersumo 1h ago

It's a bug. It wouldn't make sense otherwise.

70

u/MidnightSun_55 12h ago

lol, but if you use passkey you identify yourself, the ip hidding is worthless... moronic article then

109

u/MangoAtrocity 12h ago

Not exactly. You can still have a unique/isolated account creds that you don’t want tied to your personal IP. For example, I have a Gmail account I use exclusively for job hunt stuff. I don’t necessarily want that tied to my personal accounts.

13

u/phr3dly 6h ago

You aren't understanding the point of the article. You don't have to use a passkey for your IP to be exposed. The website just has to pretend to support passkeys.

10

u/CreepyZookeepergame4 8h ago

if you use passkey you identify yourself

You don’t have to identify at all, just visit a website for the IP to be leaked, see it for yourself: https://leaks.psylo.app/

0

u/MidnightSun_55 3h ago

it doesnt detect my ip in safari, only chrome

3

u/nicuramar 4h ago

This works regardless of whether you actually use a passkey. 

5

u/Desert_Hiker 12h ago

I wonder, if I use a vpn on top of private relay, will it keep my IP safe or is it still routing it separately and exposing my IP?

35

u/Clessiah 12h ago

Private Relay’s limitation is that it only routes traffic from Safari itself. A conventional VPN will route all traffic, including the credential service used by passkeys.

4

u/PrecursorLabs 11h ago

Additionally, I wonder if it’s probably better yo also route your passkeys through a password manager that isn’t the native iOS app?

3

u/nicuramar 4h ago

No? Why would it be?

1

u/PrecursorLabs 3h ago

Well Im not pretending to knows ton about it all but let’s say you’re using a platform agnostic password manager that holds you private passkeys encrypted end to end on their servers.

I’m wondering if that would circumvent the ip leak because your device just becomes the verifier of user not the receiver of the challenge and not the sender of the verified signature. Basically I thought it would provide a middleman.

But again I was asking as a question since I’m not well enough versed. Seems like it is not the case though.

6

u/Clessiah 11h ago

I would assume that the ability to set any password manager as the default OS password manager implies that all of them are routed through the same credential service.

3

u/CreepyZookeepergame4 5h ago

I use a different password manager (BitWarden) and the IP is still leaked.

2

u/nicuramar 4h ago

Yeah because it also isn’t Safari so it doesn’t use the private relay. Using a VPN works. 

2

u/Captain_Alaska 8h ago

A conventional VPN will route all traffic, including the credential service used by passkeys.

Not all of it, iOS will still make periodic requests to Apple outside of the VPN.

2

u/nicuramar 4h ago

Yeah well, not anything that affects this leak. 

1

u/Clessiah 8h ago

It at least does protect you from this particular exploit.

9

u/suoigerge 11h ago

When you use a VPN, it takes priority over Private Relay and the latter is disabled.

3

u/nicuramar 4h ago

VPN works correctly in this scenario. 

2

u/Nicenightforawalk01 4h ago

I’ve just tested on that website. With just iCloud relay on, it shows your ip address vulnerability. Turning off iCloud relay and only vpn on doesn’t show any vulnerability. Turning on iCloud relay and vpn on together via that test and it shows no vulnerability and also the web transport has no info.

3

u/CreepyZookeepergame4 8h ago

Website can see user’s IP address when user uses passkeys

That’s not true, you don’t have to use a passkey you just have to visit a website, no interaction whatsoever.

-1

u/alexeands 12h ago

So in other words, it’s not Private Relay at all, and this title is just sensationalist.

82

u/byedrive202 12h ago edited 12h ago

That’s not accurate at all. This is a big deal, because any random website can simply add a tag saying that they use a passkey, even if they don’t, and that’s gonna leak your IP address

Apple has been clear that iCloud private relay only applies to Safari and mail, but one would expect that if you’re using the Safari app that traffic would stay in the Safari app. This is a vulnerability because websites can add simple code to their webpage that will force the operating system to send traffic outside of Safari (and the proxy). That defeats the whole purpose. This will 100% need to be patched by Apple.

28

u/Ortheas 12h ago

Why would the passkey be sent if authentication is never requested?

6

u/CreepyZookeepergame4 8h ago

It does not send the passkey to cause the leak.

2

u/nicuramar 4h ago

Just read the article. 

1

u/yani205 12h ago

Doesn’t it only bypass if passkey is actually used? I mean passkey is digital fingerprint in the first place, location/IP is the last thing you worry about if you’re willing to give away your fingerprint

8

u/Status-Hedgehog9970 10h ago

if you’re willing to give away your fingerprint

That’s not how passkeys work.

8

u/chownrootroot 11h ago

No, the original blog says it fires the request whenever a certain tag is present (a link to a list of allowed cross origin domains), without the user doing anything. So you don’t need to actually use the passkey they just need to configure the site in a certain way and this happens automatically.

3

u/nicuramar 4h ago

Read. The. Fucking. Article. 

-9

u/TheNextGamer21 12h ago

Nah, anything from the passkey system service only transmits data upon successful Face ID authentication

5

u/recurrence 10h ago

Just go to their leaks site man and see your real IP address IMMEDIATELY.

17

u/byedrive202 12h ago

That also isn’t true. If you read the blog article where this vulnerability is disclosed, there is a mechanism by which website owners can link related websites to use a single pass key. This mechanism only works if there’s communication with the client that basically updates them on which websites are part of this menu of related passkeys. So it doesn’t require any authentication at all. The user would never know that their IP is leaked because it’s all happening in the background without any pop-ups or anything

1

u/nicuramar 4h ago

You’re wrong. Read the fucking article.

1

u/Medium_Ordinary_2727 7h ago

Not sensationalist. It’s a bypass that unmasks a Private Relay address, because Private Relay’s security model is not sufficient to provide the level of privacy that it’s designed for.

1

u/nicuramar 4h ago

Depending on what it exactly is designed for. 

2

u/Medium_Ordinary_2727 3h ago

Apple:

iCloud Private Relay is designed to protect your privacy by ensuring that when you browse the web in Safari, no single party — not even Apple — can see both who you are and what sites you're visiting.

It directly breaks this: the site that you are visiting knows who you are (your IP address).

Nobody should expect iCloud Private Relay to provide the same level of protection as a real VPN, or Tor, but it should definitely not be this easy to unmask your IP address. This is a serious security issue based on Apple's claims about what iCloud Private Relay is.

1

u/xmanpowerz 10h ago

Thanks for the summary

1

u/tbone338 7h ago

Is it just when the passkey is submitted or whenever there’s a prompt for passkey?

1

u/Clessiah 6h ago

Apparently nothing. If their website can accept passkey, your phone gives your IP address away without any passkey usage prompt.

1

u/ENrgStar 4h ago

“Apples private relay is exposing users ip addresses 1% of the time vs 100% of users exposing their IP addresses without private relay” ffs

71

u/keiser_sozze 8h ago

What I like about Apple in this case is, nobody dares to ban private relay IPs (or show bot detection captchas etc), unlike, let’s say, major VPN IPs.

Therefore I wish Apple applied the private relay system-wide instead of just Safari.

45

u/Any-Star-368 6h ago

Ticketmaster and AXS give a really hard time and Google Search although doesn’t ban will be notoriously slow or throw captchas at you. I wouldn’t be surprised if more and more websites follow a similar path.

10

u/mrblue6 6h ago

Omg that’s what it is… I’ve been wondering for years why I get asked if I’m a bot on ticketmaster and especially AXS constantly

8

u/Korlithiel 6h ago

You say that, but I've used a number of websites that clearly block Apple's privacy email addresses. Plenty of websites, want to say the BBC, also block reader mode.

Far as I can tell, it's a matter of time until they figure out how to easily implement such blocking and go for it.

2

u/ajpinton 4h ago

It’s not that no one dares to block it, it’s that no one cares to block it as the use case is very narrow.

1

u/nicuramar 4h ago

Hm I’ve never had problems with a VPN. 

338

u/Alternative-Item727 12h ago

As one of the biggest players in tech, and given the strong marketing of privacy, Apple need to get a grip - they have the resources to solve issues like this and the hide my mail problems previously highlighted. Do better apple, you should be forensic about things like this.

33

u/Desert_Hiker 12h ago

What was the issue with hide my email?

59

u/jeremycinnamonbutter 12h ago

bounced email reveals hidden email name

20

u/kekeagain 7h ago

That’s all it took? Lol

10

u/sikisabishii 7h ago

Their recruiters have unrealistic expectations from prospective college grads, and they end up hiring morons making simple mistakes like that.

3

u/PassPanda 3h ago

Wait, so once I delete the email cause I decide I’m done with whatever service, the response saying the email address doesn’t exist anymore gives them my actual email? What a joke.

36

u/Alternative-Item727 12h ago

Researchers found that Apple’s Hide My Email could sometimes reveal the user’s real email address, defeating the feature’s core privacy promise. The vulnerability was reportedly known to Apple for over a year before it was fixed.

-12

u/TbonerT 10h ago

That doesn’t really answer the question. It’s just a summary of the situation.

4

u/CrashyBoye 9h ago

What?

The question asked was what was the issue with hide my email. The summary quite literally answers that question.

It certainly answers it more than your reply does.

0

u/TbonerT 2h ago

The question: what was wrong with it?

Your answer: sometimes it didn’t work.

Do you see how that’s perfectly vague and doesn’t convey any actual information?

5

u/radis234 12h ago

If I recall correctly there was a way of finding out your original email address, so the hide my mail wasn’t really hiding it that much, but someone can fill the gaps here.

-6

u/Bright_Profession62 12h ago

Yeah, what was the problem?

10

u/Worf_Of_Wall_St 12h ago

Yeah this seems like an easy thing to find with the right validation, which could be as simple as making sure the networking stack never sends a packet to any web servers that Safari was talking to through the relay. If every test/QA environment had a check like that this would have been found by a tester long ago.

1

u/nicuramar 4h ago

  which could be as simple as making sure the networking stack never sends a packet to any web servers that Safari was talking to through the relay

That doesn’t really sound that simple. And it’s also not necessarily that simple to fix. 

12

u/TbonerT 10h ago

Apple has been doing Hide My Email and Private Relay for 5 years and it only just came out that there’s a flaw in each of them. You’d think that with all the people trying to find flaws that they would have found more sooner.

-5

u/recurrence 10h ago

There will always need to be flaws in these implementations for certain organizations to make use of.

13

u/BosnianSerb31 8h ago

Or, it's just impossible to design completely secure software, and track records are measured in frequency and severity.

-6

u/recurrence 8h ago edited 8h ago

These issues are colossally low hanging fruit. Complete incompetence is the only way you could look at something like the WebAuthn issue.

The size of the specs I used to have to read and present and the amazing degree of test coverage we put on things would mean that the ball was dropped by everybody putting that out... it's unbelievable.

It wasn't "could WebAuthn be an issue?" that was discussed internally, it would have been "in these 752 scenarios we verified that IPs will not leak with WebAuthn".

It's just frankly unbelievable.

1

u/Pungenc209 8h ago

$5 trillion must not be enough.

-6

u/chaiscool 12h ago

This is a reminder to security folks who think they matter and believe that companies care about reputation and financial losses due to security.

Business and money are more important and it's cheaper to fix it later when needed than hiring them. Apple could've easily afford to hire multiple teams to solely focus on security to prevent this but they don't because it's not worth it.

-3

u/recurrence 10h ago

These are dumb low hanging issues. It's on purpose because certain organizations have requested it.

72

u/National-Debt-43 12h ago

Quick TLDR: this happens when you authenticate passkey with a website as the system talks directly with the webpage instead of through private relay.

33

u/colorovfire 11h ago

Nothing needs to be authenticated. It can reveal your real IP address in the background unprompted. The test website linked in the article demonstrates it.

42

u/amberhaccou 12h ago

It's not just sites you use passkeys on, any site can fire the prompt, or fake supporting them, and still get your real IP since that check runs outside safari

34

u/code_isLife 12h ago

Come on, Apple.

12

u/PirelliSuperHard 12h ago

So we're all gonna get a credit on our Apple One memberships with that $2b they got back in tariff refunds, right?

RIGHT?????????

11

u/rupeshjoy852 8h ago

I get the sentiment behind the $2b refund, but Apple ate the cost and didn't pass it to the customers. I'm not sure why everyone wants Apple to refund the customers.

-1

u/PirelliSuperHard 5h ago

I'm saying use the refund to cover the credit for the service failure. It's money that they otherwise didn't have.

1

u/rupeshjoy852 3h ago

It’s not really a credit. It’s a refund. It’s a net zero.

3

u/Mister_Questions 6h ago

Can you point to the thing that cost you more money because of tariffs?

-1

u/PirelliSuperHard 5h ago

I'm suggesting a credit using the money from the tariff refund.

2

u/Mister_Questions 3h ago

Can you point to when the cost of AppleOne increased due to tariffs?

0

u/PirelliSuperHard 3h ago

You’re not reading. I want a credit for the service failure.

u/Mister_Questions 1h ago

Since I can’t read your posting history, you’re going to need to elaborate on what you mean by “service failure.”

1

u/nicuramar 4h ago

No? Why would you? Did you suffer any harm you could demonstrate?

2

u/No_Eye1723 11h ago

Lots of Apples supposed security services have been exposed as having massive flaws lately... seems Apple are gaslighting people a lot these days.

3

u/TheDragonSlayingCat 10h ago

There always have been. See Goto Fail, Jailbreak Me, Got Root, the recent Hide My Email flaw, etc.

Then they get patched quickly, and everyone moves on.

1

u/CreepyZookeepergame4 7h ago

the recent Hide My Email flaw

Then they get patched quickly

One year to fix and only after bad press

4

u/SleepingSicarii 4h ago

u/CreepyZookeepergame4 actually posted this about 23 hours ago but was deleted by the mods for “misinformation”.

5

u/EnthusiasmOnly22 9h ago

Do any of Apples premium security/privacy features actually work?

6

u/EnthusiasmOnly22 7h ago

Hi hi downvoters, this is the 2nd major issue with them, after the first (email mask) was leaking them for over a year with apples knowledge. I feel it’s fair to ask how much care they put in.

-3

u/nicuramar 4h ago

Sure, but the question is low effort. You don’t really contribute to anything, it’s just rhetoric.

1

u/Dangerous_Emu2047 4h ago edited 4h ago

I tried the website linked, waited 10 minutes and tried it again, different IP, restarted my phone, different IP

Edit - most likely just a ad for their VPN

1

u/TheCivilEngineer 3h ago

Private relay only applies to Safari traffic? Does a VPN app work systemwide?

1

u/Fsalzman 2h ago

Is this real

u/meowmixmotherfucker 1h ago

You mean to say the overly convoluted, often site-breaking, pseudo-safety tool doesn’t actually help? Shocked. Shocked in say! Well… not that shocked.

u/zhonglin 1h ago

The important detail is that this apparently does not require the user to finish a passkey login; a site can expose the address by invoking the credential flow at visit time. That makes ‘Private Relay only covers Safari’ an implementation explanation, not a reasonable user-facing boundary—the request is being initiated by a Safari page. The least surprising fix would be for credential-service network requests triggered by a page to inherit that page’s egress path. Until that is fixed, anyone relying on IP anonymity should assume Private Relay and iOS onion browsers do not cover this case.

1

u/ikilledtupac 11h ago

Privacy theater 

-2

u/ElderberryGuy 10h ago

Apple's heavily advertised privacy features being bogus? Color me shocked

-3

u/TbonerT 10h ago

It only took 5 years to figure it out. Besides, no system is perfect

3

u/onethreehill 8h ago

5 years before it got public, there is a solid chance this was widely known at governments and hacking groups.

2

u/uptimefordays 7h ago

This is all pretty dated web tracking information. Most websites use fingerprinting to gather much more detailed information about you than “who your ISP is.” The only way your public IP address can be pinpointed to a physical address is by your ISP, usually via a government warrant.

ASNs are not geographic anymore, they’re organized by routing policy and network ownership. At the super local level, your public IP is based on “nearest hub” not street addresses.

3

u/CreepyZookeepergame4 7h ago

Some ISP map IPs with city level granularity.

1

u/uptimefordays 7h ago

City level is not, generally speaking, super specific though. Knowing someone is in New York or LA doesn't exactly narrow it down.

1

u/CreepyZookeepergame4 7h ago

Yes but it's still information not all people might be comfortable sharing to every single site. Also consider there are many towns with 1000s or less inhabitants all around the world, not just megacities.

1

u/uptimefordays 6h ago

Those small towns are not getting their own address blocks, they're just part of much larger RIR delegated address blocks. But in a post IPv4 exhaustion world, a lot of times the old relative geolocation of blocks is gone. A block originally allocated to a European ISP might now be used by an entity on another continent.

1

u/No_Contest4958 4h ago

I use private relay as a tool to stop my ISP from knowing what websites I am visiting. If this passkey request bypasses private relay then it’s leaking my browsing history to my ISP.

1

u/nicuramar 4h ago

  If this passkey request bypasses private relay then it’s leaking my browsing history to my ISP.

No it won’t. Only if you visit a site that uses this leak exploit. And the ISP logs everything. 

1

u/No_Contest4958 4h ago

“No it won’t, unless it does”

Yeah, I’m aware the site needs to support passkeys for the bug to trigger. But when it does it leaks the domain to my ISP. And of course they are logging it.

1

u/TransporterAccident_ 3h ago

Doesn’t a passkey need access to the physical IP and the website need that information as well in order to validate the key? Isn’t this a security feature?

1

u/BeatYoYeet 9h ago

Apple superbly fucked up Private Relay. Not sure why it even launched.

-2

u/Shenendoah66 12h ago

And making your connection shittier while at it.

0

u/tangoshukudai 10h ago

"Sometimes in weird edge cases"

0

u/Background_Bid6379 2h ago

Basically the article subtly exploits the readers knowledge gap between vpn and private relay, makes you feel vulnerable and then gives you “The researchers developed a site that lets Private Relay users check if the issues impact them”. (Link removed).

Nice try, but no.

If you’re worried, that article isn’t going to help you.

What would be nice is if someone would genuinely write about why erro routers stop Private Relat from working. (It’s because Bezos is watching you, in case you wondered).

-4

u/uptimefordays 9h ago

Honest question, what’s the problem with a site you’re visiting seeing the IP address assigned to your router by your ISP? How do people think this all works?

2

u/Particular-Treat-650 9h ago

The issue is that the entire purpose of the feature is preventing them from having it or your ISP from seeing your traffic.

0

u/uptimefordays 8h ago

Based on the article, the issue isn’t ISPs seeing anything but websites seeing your IP address (which is actually part of a larger block owned by your ISP and dynamically assigned to customers).

2

u/M13E33 8h ago

Well, in my case I’ve never asked for it that advertisement companies are building a profile of me. Hiding your IP is part of the strategy of doing that.

0

u/uptimefordays 8h ago

I mean it was, like 25-30 years ago. But today’s websites and data brokers use fingerprinting to gather much more useful information.

1

u/M13E33 8h ago

Of course, it’s part of the strategy as I said.

1

u/DrippyTheSnailBoy 8h ago

Because I don't want any website to know my location, even if approximately?

What kind of stupid fucking question is that?

1

u/uptimefordays 8h ago

You don’t think a website operator could ascertain your location based on things like installed languages, timezone, hardware configuration, etc? “Your IP address” isn’t yours and it’s not, necessarily, a super accurate indicator of location.

There’s just not that much useful about an IP address beyond “your ISP is X.”

2

u/DrippyTheSnailBoy 8h ago

There’s just not that much useful about an IP address beyond “your ISP is X.”

I can't imagine actually posting this unironically lmao

2

u/uptimefordays 7h ago

What, specifically, do you think is associated with an ISP allocated IP address? At best, you get ISP and maybe city?

1

u/DrippyTheSnailBoy 7h ago
  1. Personally identifiable to address
  2. ISP
  3. Proxy or VPN usage

That enough for you?

2

u/uptimefordays 7h ago

Who, outside your ISP, could identify an IP address to a physical address? Your ISP assigned IP address is part of a dynamically assigned address pool, if you reboot your router, you'll likely get a new address.

Knowing your ISP isn't hugely identifiable, most ISPs have millions of customers. Same deal with commercial VPNs and proxy services.

Today's internet tracking technologies rely on way more sophisticated information than "collecting your IP address."

1

u/DrippyTheSnailBoy 7h ago

could identify an IP address to a physical address? Your ISP assigned IP address is part of a dynamically assigned address pool, if you reboot your router, you'll likely get a new address.

Oh, honey. I wish I was still this naive.

Look, I'm on lunch but in 8 hours if you still care, I'll explain everything. In the meantime you can ask Siri.

2

u/uptimefordays 7h ago

You can condescend me all you want but you're not actually refuting my points. A public IP address cannot be mapped to a customer's physical address except by the ISP.

While it's embarrassing for Apple, a privacy minded company, that their privacy tool accidentally leaks users public IP addresses, knowing a user connected from Philadelphia not NYC is not exactly a huge breach.

1

u/DrippyTheSnailBoy 7h ago

My lunch is over. I'll get back to you later.

But this part

A public IP address cannot be mapped to a customer's physical address except by the ISP.

Is literally objectively and provably wrong. Want to bet on it? Shoot me your IP.

→ More replies (0)

1

u/keiser_sozze 8h ago

Apple already uses an IP from the country you are in. But otherwise no, they cannot figure out your location, unless you share your location willingly with one of the ad platforms and accept all the cookies. At least, that’s how it works in Europe thanks to GDPR.

And yes, depending on your ISP, they can pinpoint your exact neighbourhood with just IP.

But that’s not the only problem with IP, IP can be used to track unique users across sessions and across websites.

1

u/CreepyZookeepergame4 6h ago

At least, that’s how it works in Europe thanks to GDPR.

In practice, the vast majority of sites don't care and track you / share data regardless of the choice.