p.enthalabs

iCloud+ Hide My Email addresses will remain on icloud.com

developer.apple.com · Read Story HN original

Comments

Good! Was there ever a compelling reason why they went for this switch initially?
Yes, to fully fix a certain class of bug on their infra.
Do you know any more about it or have a link where I can read more?
I’ll try to add more later, but it is believed that multiple times, a bug in some random API has allowed for the “hidden” Apple account to be revealed because they resolve hide my emails to the original internally. Using a separate namespace would be the universal fix.

A mitigation for the cause of https://www.404media.co/apple-hide-my-email-vulnerability-re...

This doesn't follow. The bounce message used to (effectively) say,

> abc@icloud.com forwards to real@gmail.com

If they switched the new domain and did nothing else, it would say:

> abc@privaterelay.appleid.com forwards to real@gmail.com

That's no better. Fixing that privacy leak is unrelated to whatever the destination domain is.

No, using a different domain makes it easy to across the board add a rule: don’t treat as Apple ID.
I'm not sure if I'm following. Apple is capable of creating a lookup table, or an atomic database read query.
Good. What else can really be said? Only way for it to work and not be trivially blocked is to mix with legit emails.
A lot of places also don't really like icloud addresses in general. This is one of Apple's better offerings though.
Good. This would have made blocking them trivial.
That was a stupid idea (the prev one)
I'm glad they listened - I use this feature extensively and would like to continue to
I've noticed a chilling new trend of apple listening to the community.
Anyone have a theory why this even made it to this point? the switch was such obviously a bad idea. just corporate weirdness that no one there bothered to raise their hand and be like "uh, are we really doing this?" or was there a story here that anyone knows about?
Maybe hidemyemail allows easily creating many accounts on a site. And some big site didn't like it.

The "Sign-up via Apple" button and creating an iCloud email yourself have a slightly higher barrier than creating a new throwaway hidemyemail email (1 API call w/o captcha/phone verification or whatever).

We might find out later this year if some site starts blocking @icloud.com but keeps allowing @private.icloud.com.

It does, and I know a friend of a friend who uses them for Walmart accounts to bot pokemon drops. Those and office aliases.
It's email reputation, it the always the answer with this kind of stuff.

My guess is that the bounce rate got too high and bot farms were using iCloud addresses like this.

The bounce rate of what, exactly?

Because the bounce rate of Hide My Email addresses being deliverable is going to rise over time, by design.

Whenever I start getting spam at an address that's been leaked, I deactivate it. I've done the same with my oldest gmail account, but the work required there is notably higher.

If they were moved to plain old icloud.com, I could absolutely see a bunch of companies starting to filter out all icloud.com email addresses to avoid private relay. Either just because they’re jerks or from bounce issues.

Keeping it on a subdomain fixes that problem, to some degree. If the user is named ffjvhtu57325cjdjvg501a2@icloud.com no one is going to think that’s a real address. It’s very obviously a private one. So it’s not like they were “camouflaged.“

It’s a little odd they’re switching the subdomain though.

Right, but I'm asking "what bounce issues?"

Like for my usage there are no bounce issues with the ~400 legitimate providers that I have Hide My Email addresses from. The only ones with bounce issues are the spammers who've acquired leaked addresses that I've deactivated.

If you merely deactivate your email address rather than closing your account or changing your notification settings or whatever, then the next time a legitimate service goes to send you a legitimate email that you asked for, it will bounce. In some sense this "shouldn't matter", as in a purely P2P system the only people who would notice are the sender and Apple -- and Apple knows what is going on, so should not penalize senders the way, say, Google would if they see you sending a ton of email to their domains and they all bounce -- but people tend to use services to help send email and centrally pool their reputation (such as mailchimp) and so these services themselves then watch the bounce rate of their individual customers and either charge them more or ban their access due to the bounce rate increase.
Is Apple really stupid enough that they BOUNCE emails after you deactivate, rather than just silent discard? What's the point of bouncing unwanted emails these days? It's not like these bounces go to humans who go "Oh, gee! This address must not work. Allow me to go and figure out how to contact him!" It's just a stream of full-on spam with completely fake return addresses, and crap from email campaign software.
I mean my hope is to get the senders' IP/accounts/email reputation flagged for having additional bounces.
Hide My Email already uses plain old @iCloud.com as the domain.

They are not changing the subdomain. There isn’t one. The announcement is they are leaving it as-is.

The email addresses for sign-in with Apple do use the @private.iCloud.com subdomain, but again, that’s not a change.

> If they were moved to plain old icloud.com, I could absolutely see a bunch of companies starting to filter out all icloud.com email addresses to avoid private relay.

I couldn't. "Uses Apple products" is one of the more reliable signals of willingness and ability to spend money on stuff online.

Hide My Email addresses are not just a random string at icloud.com. They use plausibly-human names, probably generated by a language model. There’s no easy-to-check pattern.

They’re not switching the subdomain. They’re keeping it the same. That’s the news.

They’re switching the subdomain for the “Sign in with Apple” sign ups, which is not the same service.

> Hide My Email addresses are not just a random string at icloud.com. They use plausibly-human names, probably generated by a language model.

why would random selection from sets of predefined strings and joining them using a "." need any LLM involvement? Oh you need to check if it already taken... maybe for that? I'd use a database though...

These days some people would even generate GUIDs with some language model, I guess...

It’s probably not an LLM, nor a small transformer-based model, but it is a language model. Probably the kind that powered auto-correct before GPT.

The generated words agree in grammatical gender and plural forms, so by definition it’s a language model.

Whoever operates the smtp servers for icloud.com complained loudly enough that their job was too hard because of all the traffic, but not loudly enough for someone smart enough to hear about it, until it was announced to the public.
Hmm it’s almost as if people are paying good money for iCloud+ or something. They aren’t google and shouldn’t be retiring their services as if they’re giving them away for free
While I applaud this specific change, Apple has been known to stick to their guns and I used to believe they were almost always in the right for doing so because it led to better outcomes. So my take is that it's chilling because Apple has so lost their way that they can't figure out these obviously stupid directions internally before making a fool of themselves to the public (and I agree with that take).
My guess is Ternus is starting to take more and more control. Tim was pretty absent and phoning it in the past few years.
Using icloud.com domain for legit and hidden adresses is such a typical Apple strategy of holding their own users and "others" (ie. other web services, other users etc) hostage simultaneously. But at least here it is actually a good reason that works for the user.
how is the user being held hostage? you can redirect hide my email addresses to any domain
Marketing turds can't just block registrations from all of @icloud.com.
That doesn’t explain how the user is held “hostage” by Apple
Hostage may be a bad analogy. More like a game of chicken. Imagine you are a regular @icloud.com email user. Apple is basically saying "I dare you to block all @icloud.com email and lose all these customers"
you could say the same thing about AWS or Cloudflare hosting anybody and everybody. Spain actually started blocking a bunch of their IP blocks during football matches due to a poorly thought out legal decision.
So the website is being "held hostage", not the user.
The user is held hostage as much as the platforms because it's used as "currency" to force other sites to do things they may not want to, i.e. create accounts using private emails, and the platforms are held hostage by these same users expecting to be able to create accounts using their legit or private icloud emails. It looks like some kind of "who will break first", is there a service big enough to be able to block all icloud emails and it'd be a sufficient inconvenience to force apple to rethink how private email works ?
Can they block registrations from @private.icloud.com?
Yes, they would have been able to if the proposal had gone ahead.
I think the other answers are misinterpreting your question. A user is held "hostage" because unlike fastmail where the format is word.salad@yourdomain; if you ever wanted to ditch iCloud completely, you'd have to go through every single account you used it for and update the email. As someone who has shed his gmail account I can tell you it's not easy to update email address on every site you've ever used it on. The issue people are raising is that apple doesn't let you use your own domain, and generate random emails at that domain. Not my complaint, but I can see the perspective.
I mean, that is no different than any other provider.

If you want to degoogle, you still have to go to each site and change your staticuser@gmail.com individually.

Most users already do not use custom domains if that's the catch.

Yes you can do word.salad@yourdomain with fastmail but that ius no different to other mail providers.

What the above comments re fastmail is about their masked email service this gives addresses like <random>@fastmail.com so this is the same lockin as Apple with the same benefits of noone is going to block that domain.

Case in point: many websites block all VPN except iCloud Private Relay. Thank you Apple!
Seriously, Apple is "big tech," but they are the only one that appears to give a crap about privacy at all. And really, they put a lot of money and effort into it.

We need to give kudos when they are due.

Apple's Private Cloud Compute should have won some kind of Nobel Privacy Prize, which for some reason does not yet exist.

The person you're replying to is saying "Sites I use block all VPNs besides Apple's subscription service VPN" - I'm not sure they're not blocking it just because they fervently believe in Apple's privacy commitments and engineering :)

Only pointing this out because I love Apple's privacy story and don't want your reply to be misconstrued as sarcasm, and thus the reason why it enjoys a singular exemption is because its ineffective.

I’ve never been under the impression that privacy relay is anything like a true VPN. I mostly thought it stopped BS that happens on public WiFi and public sniffing. It’s meant to protect you only until you get to a major carriers infrastructure.
The design is supposed to be better than a true VPN, because neither Apple nor the exit node (Akamai, Cloudflare, Fastly) are supposed to know both who you are and what you’re doing. Of course, Apple pays them for this service, so they could exchange info.
It is a VPN in the sense that your traffic flows privately through a third party. This is what most people refer to when they say VPN.

It is not a VPN only in the technical approach.

It's something of a "private relay", you might say.
They don't block it because of the publicity it would generate. Social factors matter.

"We blocked people for using special hacker privacy tools. Stop using the special tools if you want service." versus "we blocked people for using the most popular kind of end device. Buy a second, really obscure brand of device if you want service."

(In the US, that is. Outside the US, Android devices are more popular but Apple still has the plurality because there's only one of it)

Apple is luxury big tech.

In this day and age, privacy is luxury, so that's what they sell.

I don't think there are any ethical motivations for them (or any other large corporation - none of them have morals so they cannot act morally). It's just that there's a market niche, so it will be filled by someone.

money from advertising basically dwarf user lifetime purchase of privacy tax you mentioned
The ad business has a lot of people chasing after the same ad spend.

Superbowl ads, TV ads, radio ads, print ads, billboard ads, public transit ads, youtube ads, podcast ads, search ads, e-mail ads, social media ads, in-app ads, in-store ads, sports team sponsorship, individual athlete sponsorship, stadium naming, product placement ads, elevator ads, cinema ads, bathroom ads.

And Coca-Cola doesn't increase their advertising budget just because someone finds a new place to slap ads on - they just re-allocate their spending.

Sure, Google and Facebook make a good chunk of money from ads. But it's a very, very competitive business.

yet and they still dwarf

if any, Apple user are the most expensive ads money industry willing to pay for

It’s an additional layer of wall for their walled garden to keep the technically proficient users that are more likely to hop walls.
Technically proficient users can figure out their own solutions for throwaway emails e.g. aforementioned Fastmail.
Sure, but technically proficient users often have other things they want to spend their time on, outside of exercising technical proficiency on every single thing.

Heck, I don’t even do my own oil changes anymore despite it being easy. Life gets busy, you know?

Many systems out there have specific exceptions from their VPN policy for iCloud emails and iCloud private relay. Places that would immediately block fastmail because of its alias feature will not block iCloud because too many people use it. Market share is real power. You can ban 0.1% of your customers, you can't ban 30% of your customers.
Privacy is the niche they know Google can never follow.

Apple sells hardware, Google is an ad company.

They still don't let me install uBlock origin + noscript. Whitelisting per-domain and per-site what can run Javascript does more for my privacy than anything else, and I can do that with firefox on linux and android, but on iOS I'm not allowed to install firefox.

There's obviously no real technical limitation since if you live in the EU you can sideload an alternative browser in theory (though apple has made it unrealistic in practice since they're ignoring the spirit of the law and instead doing their darndest to resist giving users even a whit of freedom).

They also don’t allow you to install Windows executables. They do allow you to run adblockers designed for Safari, like Wipr, and there are any number of noscript-alikes, like StopTheScript. I’m not saying that to be snarky, but to say that different platforms have different ways of doing things.

And Firefox is in the iOS App Store. I know what you meant to say, and that it’s not the same as Firefox on Android, but it’s wrong to say you’re not allowed to install Firefox.

Since Apple specifically disallows using other web engines on the App Store, I have bad news for you : Firefox on the App Store is just a reskinned safari and as such, a lot of features cannot be implemented because they depend on the web rendering engine.
That would be news to me if it wasn’t what I already said, that iOS Firefox isn’t the same as Android Firefox.
It sounds like their point is that it's not Firefox at all, inasmuch as you can't use the most popular Firefox extensions.
ublock origin is supported by Safari
ublock origin _lite_

https://github.com/gorhill/uBlock/wiki/uBlock-Origin-works-b...

I also can't use Safari because I want my tabs and bookmarks to sync between my desktop machine (linux) and my phone (iOS), and Safari is the only major browser which can't do that.

Not to mention Safari is just an inferior browser which seems possibly designed to hold back Progressive Web Apps so that everyone has to make app-store apps and tithe a percent of all profits to apple.

PWAs hold themselves back, they don’t need any help from Safari.
The only thing Safari seems inferior at is draining batteries.
Well there’s UBlock for Safari, yeah it’s not UBlock Origin but it’s not that nothing is available. https://apps.apple.com/gb/app/ublock-origin-lite/id674534269...

Also Brave supports per site JavaScript blocking on iOS.

So there’s more privacy tools available than you think/assume.

Only thing I wish they were 20 years sooner.
> but they are the only one that appears to give a crap about privacy at all.

they advertise that they do. that is not the same as doing

Apple literally wanted to scan all your photos and automatically report you to law enforcement if a fuzzy hash happened to match an opaque database.

no one is saying Apple is the saint. It's just better in comparison to other big techs who want your privacy as much and don't even pretend to care
I think that pretending to care is much much worse than not caring.
I don't think websites block Google's VPN either, although that's not quite as popular as Apple's VPN solution.
Google VPN is only on Pixel phones now. It also only available in few countries.

Its only upside was a fact that it was actual VPN for all the apps while AFAIK private relay limited to Safari.

Private Relay also works because it's on by default for everyone paying for iCloud (including everyone just on the 0.99/month tier for photo backup) - so Apple can use it across their apps (e.g. loading images in Apple Mail) and it doesn't let you single out privacy conscious users!
I worked at a place that was contractually mandated to block VPNs except iCloud Private Relay and we had a special exception in the code for this.
thank god -.-
I don't understand how this changes anything. IIRC, the complaints were about Apple making the Hide My Email addresses different than regular ones.

They're now saying the new domain will be private.icloud.com. Isn't it just as targetable?

It's talking about two different services:

> Sign in with Apple addresses, previously issued on privaterelay.appleid.com, will be issued on private.icloud.com.

> iCloud+ Hide My Email addresses will remain on icloud.com.

Sign in with Apple is Apple's SSO, like Sign in with Google. Services have to support this one explicitly, and it already had a special subdomain, so the specific subdomain is simply changing.

Hide My Email is the manually generated ones, for websites that accept an arbitrary email address. This is the one where it's valuable for the relays to be identical to genuine iCloud addresses, otherwise websites could try to block it and force you to use a more revealing email address, undermining privacy.

One of the best things about it. Also being able to add several emails per custom domain for free.

Whole thing is 99c a month. Makes Gmail seem like a joke in comparison.

Until you get an email from an iCloud address on Gmail and see it go right to spam haha. Suddenly Gmail is cheap again

Maybe it's because I live in a country where e-mai isn't really used that much for personal communication, but wouldn't this mainly be a gmail issue? If mails I wanted ended up in the spam folder I'd not use gmail. I mean, I pay for protonmail, so I wouldn't use gmail to begin with, but if mails I wanted ended up in my protonmail spamfolder and I couldn't do anything about it, then I'd switch away from protonmail.
You are 100% correct and yet the masses still prefer it.

World’s a twisted place!

I would guess the average Gmail user doesn’t know that it reports virtually all iCloud as Spam - believing instead that it’s genuinely being filtered by quality engineering at Google.

If you’re talking about people with the technical sophistication to consider software services based on their technical merits, then sure. Your average user couldn’t even tell you the first thing about which non-content-based criteria might inform a spam score… or have even heard of a spam score. So they will absolutely not blame Gmail if another provider’s email gets spam flagged… they’d probably just think “why don’t they just get a Gmail account,” à la iMessage users/green texts.
Best thing to do with Gmail spam is to make an auto filter to mark all spam as not spam.

Took me only one missed dentist appointment several years ago to get that idea. Now I'm just getting profits. No other spam since I'm using email aliases.