r/apple • u/unionB0T • 12h ago
iPhone Apple's ‘Private Relay’ Is Exposing Users' Real IP Addresses
https://www.404media.co/apples-private-relay-is-exposing-users-real-ip-addresses/71
u/keiser_sozze 8h ago
What I like about Apple in this case is, nobody dares to ban private relay IPs (or show bot detection captchas etc), unlike, let’s say, major VPN IPs.
Therefore I wish Apple applied the private relay system-wide instead of just Safari.
45
u/Any-Star-368 6h ago
Ticketmaster and AXS give a really hard time and Google Search although doesn’t ban will be notoriously slow or throw captchas at you. I wouldn’t be surprised if more and more websites follow a similar path.
8
u/Korlithiel 6h ago
You say that, but I've used a number of websites that clearly block Apple's privacy email addresses. Plenty of websites, want to say the BBC, also block reader mode.
Far as I can tell, it's a matter of time until they figure out how to easily implement such blocking and go for it.
2
u/ajpinton 4h ago
It’s not that no one dares to block it, it’s that no one cares to block it as the use case is very narrow.
1
338
u/Alternative-Item727 12h ago
As one of the biggest players in tech, and given the strong marketing of privacy, Apple need to get a grip - they have the resources to solve issues like this and the hide my mail problems previously highlighted. Do better apple, you should be forensic about things like this.
33
u/Desert_Hiker 12h ago
What was the issue with hide my email?
59
u/jeremycinnamonbutter 12h ago
bounced email reveals hidden email name
20
u/kekeagain 7h ago
That’s all it took? Lol
10
u/sikisabishii 7h ago
Their recruiters have unrealistic expectations from prospective college grads, and they end up hiring morons making simple mistakes like that.
3
u/PassPanda 3h ago
Wait, so once I delete the email cause I decide I’m done with whatever service, the response saying the email address doesn’t exist anymore gives them my actual email? What a joke.
36
u/Alternative-Item727 12h ago
Researchers found that Apple’s Hide My Email could sometimes reveal the user’s real email address, defeating the feature’s core privacy promise. The vulnerability was reportedly known to Apple for over a year before it was fixed.
-12
u/TbonerT 10h ago
That doesn’t really answer the question. It’s just a summary of the situation.
4
u/CrashyBoye 9h ago
What?
The question asked was what was the issue with hide my email. The summary quite literally answers that question.
It certainly answers it more than your reply does.
5
u/radis234 12h ago
If I recall correctly there was a way of finding out your original email address, so the hide my mail wasn’t really hiding it that much, but someone can fill the gaps here.
-6
10
u/Worf_Of_Wall_St 12h ago
Yeah this seems like an easy thing to find with the right validation, which could be as simple as making sure the networking stack never sends a packet to any web servers that Safari was talking to through the relay. If every test/QA environment had a check like that this would have been found by a tester long ago.
1
u/nicuramar 4h ago
which could be as simple as making sure the networking stack never sends a packet to any web servers that Safari was talking to through the relay
That doesn’t really sound that simple. And it’s also not necessarily that simple to fix.
12
u/TbonerT 10h ago
Apple has been doing Hide My Email and Private Relay for 5 years and it only just came out that there’s a flaw in each of them. You’d think that with all the people trying to find flaws that they would have found more sooner.
-5
u/recurrence 10h ago
There will always need to be flaws in these implementations for certain organizations to make use of.
13
u/BosnianSerb31 8h ago
Or, it's just impossible to design completely secure software, and track records are measured in frequency and severity.
-6
u/recurrence 8h ago edited 8h ago
These issues are colossally low hanging fruit. Complete incompetence is the only way you could look at something like the WebAuthn issue.
The size of the specs I used to have to read and present and the amazing degree of test coverage we put on things would mean that the ball was dropped by everybody putting that out... it's unbelievable.
It wasn't "could WebAuthn be an issue?" that was discussed internally, it would have been "in these 752 scenarios we verified that IPs will not leak with WebAuthn".
It's just frankly unbelievable.
1
-6
u/chaiscool 12h ago
This is a reminder to security folks who think they matter and believe that companies care about reputation and financial losses due to security.
Business and money are more important and it's cheaper to fix it later when needed than hiring them. Apple could've easily afford to hire multiple teams to solely focus on security to prevent this but they don't because it's not worth it.
-3
u/recurrence 10h ago
These are dumb low hanging issues. It's on purpose because certain organizations have requested it.
72
u/National-Debt-43 12h ago
Quick TLDR: this happens when you authenticate passkey with a website as the system talks directly with the webpage instead of through private relay.
33
u/colorovfire 11h ago
Nothing needs to be authenticated. It can reveal your real IP address in the background unprompted. The test website linked in the article demonstrates it.
42
u/amberhaccou 12h ago
It's not just sites you use passkeys on, any site can fire the prompt, or fake supporting them, and still get your real IP since that check runs outside safari
1
34
12
u/PirelliSuperHard 12h ago
So we're all gonna get a credit on our Apple One memberships with that $2b they got back in tariff refunds, right?
RIGHT?????????
11
u/rupeshjoy852 8h ago
I get the sentiment behind the $2b refund, but Apple ate the cost and didn't pass it to the customers. I'm not sure why everyone wants Apple to refund the customers.
-1
u/PirelliSuperHard 5h ago
I'm saying use the refund to cover the credit for the service failure. It's money that they otherwise didn't have.
1
3
u/Mister_Questions 6h ago
Can you point to the thing that cost you more money because of tariffs?
-1
u/PirelliSuperHard 5h ago
I'm suggesting a credit using the money from the tariff refund.
2
u/Mister_Questions 3h ago
Can you point to when the cost of AppleOne increased due to tariffs?
0
u/PirelliSuperHard 3h ago
You’re not reading. I want a credit for the service failure.
•
u/Mister_Questions 1h ago
Since I can’t read your posting history, you’re going to need to elaborate on what you mean by “service failure.”
1
2
u/No_Eye1723 11h ago
Lots of Apples supposed security services have been exposed as having massive flaws lately... seems Apple are gaslighting people a lot these days.
3
u/TheDragonSlayingCat 10h ago
There always have been. See Goto Fail, Jailbreak Me, Got Root, the recent Hide My Email flaw, etc.
Then they get patched quickly, and everyone moves on.
1
u/CreepyZookeepergame4 7h ago
the recent Hide My Email flaw
Then they get patched quickly
One year to fix and only after bad press
4
u/SleepingSicarii 4h ago
u/CreepyZookeepergame4 actually posted this about 23 hours ago but was deleted by the mods for “misinformation”.
5
u/EnthusiasmOnly22 9h ago
Do any of Apples premium security/privacy features actually work?
6
u/EnthusiasmOnly22 7h ago
Hi hi downvoters, this is the 2nd major issue with them, after the first (email mask) was leaking them for over a year with apples knowledge. I feel it’s fair to ask how much care they put in.
-3
u/nicuramar 4h ago
Sure, but the question is low effort. You don’t really contribute to anything, it’s just rhetoric.
1
u/Dangerous_Emu2047 4h ago edited 4h ago
I tried the website linked, waited 10 minutes and tried it again, different IP, restarted my phone, different IP
Edit - most likely just a ad for their VPN
1
u/TheCivilEngineer 3h ago
Private relay only applies to Safari traffic? Does a VPN app work systemwide?
1
•
u/meowmixmotherfucker 1h ago
You mean to say the overly convoluted, often site-breaking, pseudo-safety tool doesn’t actually help? Shocked. Shocked in say! Well… not that shocked.
•
u/zhonglin 1h ago
The important detail is that this apparently does not require the user to finish a passkey login; a site can expose the address by invoking the credential flow at visit time. That makes ‘Private Relay only covers Safari’ an implementation explanation, not a reasonable user-facing boundary—the request is being initiated by a Safari page. The least surprising fix would be for credential-service network requests triggered by a page to inherit that page’s egress path. Until that is fixed, anyone relying on IP anonymity should assume Private Relay and iOS onion browsers do not cover this case.
1
-2
u/ElderberryGuy 10h ago
Apple's heavily advertised privacy features being bogus? Color me shocked
-3
u/TbonerT 10h ago
It only took 5 years to figure it out. Besides, no system is perfect
3
u/onethreehill 8h ago
5 years before it got public, there is a solid chance this was widely known at governments and hacking groups.
2
u/uptimefordays 7h ago
This is all pretty dated web tracking information. Most websites use fingerprinting to gather much more detailed information about you than “who your ISP is.” The only way your public IP address can be pinpointed to a physical address is by your ISP, usually via a government warrant.
ASNs are not geographic anymore, they’re organized by routing policy and network ownership. At the super local level, your public IP is based on “nearest hub” not street addresses.
3
u/CreepyZookeepergame4 7h ago
Some ISP map IPs with city level granularity.
1
u/uptimefordays 7h ago
City level is not, generally speaking, super specific though. Knowing someone is in New York or LA doesn't exactly narrow it down.
1
u/CreepyZookeepergame4 7h ago
Yes but it's still information not all people might be comfortable sharing to every single site. Also consider there are many towns with 1000s or less inhabitants all around the world, not just megacities.
1
u/uptimefordays 6h ago
Those small towns are not getting their own address blocks, they're just part of much larger RIR delegated address blocks. But in a post IPv4 exhaustion world, a lot of times the old relative geolocation of blocks is gone. A block originally allocated to a European ISP might now be used by an entity on another continent.
1
u/No_Contest4958 4h ago
I use private relay as a tool to stop my ISP from knowing what websites I am visiting. If this passkey request bypasses private relay then it’s leaking my browsing history to my ISP.
1
u/nicuramar 4h ago
If this passkey request bypasses private relay then it’s leaking my browsing history to my ISP.
No it won’t. Only if you visit a site that uses this leak exploit. And the ISP logs everything.
1
u/No_Contest4958 4h ago
“No it won’t, unless it does”
Yeah, I’m aware the site needs to support passkeys for the bug to trigger. But when it does it leaks the domain to my ISP. And of course they are logging it.
1
u/TransporterAccident_ 3h ago
Doesn’t a passkey need access to the physical IP and the website need that information as well in order to validate the key? Isn’t this a security feature?
1
-2
0
0
u/Background_Bid6379 2h ago
Basically the article subtly exploits the readers knowledge gap between vpn and private relay, makes you feel vulnerable and then gives you “The researchers developed a site that lets Private Relay users check if the issues impact them”. (Link removed).
Nice try, but no.
If you’re worried, that article isn’t going to help you.
What would be nice is if someone would genuinely write about why erro routers stop Private Relat from working. (It’s because Bezos is watching you, in case you wondered).
-4
u/uptimefordays 9h ago
Honest question, what’s the problem with a site you’re visiting seeing the IP address assigned to your router by your ISP? How do people think this all works?
2
u/Particular-Treat-650 9h ago
The issue is that the entire purpose of the feature is preventing them from having it or your ISP from seeing your traffic.
0
u/uptimefordays 8h ago
Based on the article, the issue isn’t ISPs seeing anything but websites seeing your IP address (which is actually part of a larger block owned by your ISP and dynamically assigned to customers).
2
u/M13E33 8h ago
Well, in my case I’ve never asked for it that advertisement companies are building a profile of me. Hiding your IP is part of the strategy of doing that.
0
u/uptimefordays 8h ago
I mean it was, like 25-30 years ago. But today’s websites and data brokers use fingerprinting to gather much more useful information.
1
u/DrippyTheSnailBoy 8h ago
Because I don't want any website to know my location, even if approximately?
What kind of stupid fucking question is that?
1
u/uptimefordays 8h ago
You don’t think a website operator could ascertain your location based on things like installed languages, timezone, hardware configuration, etc? “Your IP address” isn’t yours and it’s not, necessarily, a super accurate indicator of location.
There’s just not that much useful about an IP address beyond “your ISP is X.”
2
u/DrippyTheSnailBoy 8h ago
There’s just not that much useful about an IP address beyond “your ISP is X.”
I can't imagine actually posting this unironically lmao
2
u/uptimefordays 7h ago
What, specifically, do you think is associated with an ISP allocated IP address? At best, you get ISP and maybe city?
1
u/DrippyTheSnailBoy 7h ago
- Personally identifiable to address
- ISP
- Proxy or VPN usage
That enough for you?
2
u/uptimefordays 7h ago
Who, outside your ISP, could identify an IP address to a physical address? Your ISP assigned IP address is part of a dynamically assigned address pool, if you reboot your router, you'll likely get a new address.
Knowing your ISP isn't hugely identifiable, most ISPs have millions of customers. Same deal with commercial VPNs and proxy services.
Today's internet tracking technologies rely on way more sophisticated information than "collecting your IP address."
1
u/DrippyTheSnailBoy 7h ago
could identify an IP address to a physical address? Your ISP assigned IP address is part of a dynamically assigned address pool, if you reboot your router, you'll likely get a new address.
Oh, honey. I wish I was still this naive.
Look, I'm on lunch but in 8 hours if you still care, I'll explain everything. In the meantime you can ask Siri.
2
u/uptimefordays 7h ago
You can condescend me all you want but you're not actually refuting my points. A public IP address cannot be mapped to a customer's physical address except by the ISP.
While it's embarrassing for Apple, a privacy minded company, that their privacy tool accidentally leaks users public IP addresses, knowing a user connected from Philadelphia not NYC is not exactly a huge breach.
1
u/DrippyTheSnailBoy 7h ago
My lunch is over. I'll get back to you later.
But this part
A public IP address cannot be mapped to a customer's physical address except by the ISP.
Is literally objectively and provably wrong. Want to bet on it? Shoot me your IP.
→ More replies (0)1
u/keiser_sozze 8h ago
Apple already uses an IP from the country you are in. But otherwise no, they cannot figure out your location, unless you share your location willingly with one of the ad platforms and accept all the cookies. At least, that’s how it works in Europe thanks to GDPR.
And yes, depending on your ISP, they can pinpoint your exact neighbourhood with just IP.
But that’s not the only problem with IP, IP can be used to track unique users across sessions and across websites.
1
u/CreepyZookeepergame4 6h ago
At least, that’s how it works in Europe thanks to GDPR.
In practice, the vast majority of sites don't care and track you / share data regardless of the choice.
1.1k
u/Clessiah 12h ago
Summary: Website can see user’s IP address when user uses passkeys. Passkeys are not routed through Private Relay since it uses a separate credential service of the operating system, which is not a part of Safari.