TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Apple's “iCloud Private Relay” broke risk based authentication

191 pointsby mffapalmost 4 years ago

20 comments

marcinzmalmost 4 years ago
I find authentication the least problematic place where risk based on ip is used. Etsy, for example, will suspend your seller account if it sees too many logins from different IPs or if it's from an IP it has flagged before. It also has terrible seller customer service so it could take weeks to get it un-suspended. Heard of some people using Private Relay getting hit by this during the beta so hopefully Etsy gets rid of that system.
评论 #27762907 未加载
评论 #27764577 未加载
评论 #27764484 未加载
评论 #27762999 未加载
评论 #27767688 未加载
评论 #27761382 未加载
评论 #27761704 未加载
评论 #27763209 未加载
csunbirdalmost 4 years ago
&gt; As of writing this blog I was in Switzerland and the IP used to egress my traffic was in a region located in the US. If this also tends to change a lot and fast you can basically throw away IP addresses as data of your RIBA.<p>Wait, so my data will be routed to US servers, as an EU resident, where the data protection laws are not as strong as where I live? This is a really bad idea, as US is known to tap any data they can get on their soil.
评论 #27762314 未加载
评论 #27761339 未加载
评论 #27761350 未加载
评论 #27761352 未加载
评论 #27762706 未加载
评论 #27764211 未加载
评论 #27762045 未加载
评论 #27765676 未加载
评论 #27761291 未加载
mindslightalmost 4 years ago
I hadn&#x27;t known there was a term for this braindead idea that websites should hassle you based on your IP address. Of course there has to be a term, compartmentalization is necessary for getting good people to do bad things.<p>It&#x27;s fantastic that Apple is continuing to mitigate commercial surveillance. It&#x27;s easy to discriminate against us lone individuals who hide our IP addresses, but Apple&#x27;s market is too big to reject. If they&#x27;re successful here, I&#x27;ll have to consider buying a Mac purely for their VPN service.<p>Perhaps they&#x27;ll take on CAPTCHAs next.
评论 #27762780 未加载
评论 #27763677 未加载
donmcronaldalmost 4 years ago
When Google Workplace locks users because of this, and I’m fairly sure they will because they’re super aggressive with IPs that change via VPN, they&#x27;ll bounce incoming mail for that user.<p>Have fun everyone!
评论 #27761415 未加载
评论 #27764869 未加载
peteretepalmost 4 years ago
Good. As someone who moves around a lot esp to countries where I need to use a VPN, this bullshit is the bane of my life
rhexsalmost 4 years ago
Thank you. Can someone please break security questions next so I don’t have to store four passwords instead of one to login to my accounts?<p>Please kill opt-out-less 2FA while you’re at it. (Thanks Amazon, been enjoying that change!)
评论 #27767673 未加载
评论 #27762843 未加载
grishkaalmost 4 years ago
Good. This will finally make everyone treat all IP addresses equally.
评论 #27764922 未加载
TurningCanadianalmost 4 years ago
Did it actually break risk based authentication though? Sure, legitimate users will be using Apple&#x27;s Relay, but what&#x27;s stopping attackers from using it? If the users of the service are choosing to be indistinguishable from attackers, then that&#x27;s on them.<p>I think of it like reputation in real life. If you come knocking on my door, and I can see and recognize you, I&#x27;ll open it. If you cover up my peephole or hide yourself so that I can&#x27;t recognize you, why would I even let you know I&#x27;m home? Even if you tell me who you are, shouldn&#x27;t I be worried that someone is impersonating you?<p>At the very least I&#x27;d expect users from anonymizing IPs to have to jump through some extra hoops like captcha and 2FA.
评论 #27762686 未加载
评论 #27763401 未加载
评论 #27764394 未加载
james_pmalmost 4 years ago
We&#x27;re anticipating having to make some changes to our fraud scoring which uses things like location vs. credit card address as signals.
评论 #27762401 未加载
评论 #27763378 未加载
outloudvialmost 4 years ago
I thought Private Relay will not change the geo-region of users (e.g., proxy to IPs of the same country) in order to let online streaming companies (e.g,. Netflix) happy. This is different from what said in this post. Is it no longer the case or never the case?
评论 #27762068 未加载
评论 #27763026 未加载
gkopalmost 4 years ago
Author, since you “dearly recommend” a related blog post of yours, <i>please link to that post</i>.
评论 #27761709 未加载
评论 #27761696 未加载
vmceptionalmost 4 years ago
“Welcome back! Hey looks like you are using a new device, how about we just ignore that greeting and use this other separate login process every fucking session”
评论 #27763365 未加载
ReGenGenalmost 4 years ago
It will be interesting to see if Apple allows hackers to freely abuse the system. If Apple bans end-users for abuse there will be far fewer problems.
评论 #27768117 未加载
GekkePrutseralmost 4 years ago
Great. RIBA is a really poor method that causes a lot of false positives for expats like myself. I&#x27;m really happy that more people will suffer this digital discrimination because it will mean it will go away.<p>I live in Spain, I&#x27;m from the Netherlands and have lived in Ireland as well, leading to tons of &quot;soft block&quot; nightmares.
tyingqalmost 4 years ago
I would guess that the RIBA vendors will adjust as more people start using it.
aborsyalmost 4 years ago
Not quite on topic of this post, but does anyone know how much Private Relay impact iPhone’s battery life?<p>OpenVPN has a noticeable impact.
评论 #27767614 未加载
评论 #27765638 未加载
jarymalmost 4 years ago
&quot;But please stop relying on RIBA for the plain authentication of a user!&quot;<p>Well I&#x27;m not sure everyone will be happy to do that. Tying session tokens to source IP addresses is usually not a bad practice and is rarely the only mitigation used.
评论 #27761329 未加载
评论 #27762374 未加载
评论 #27761340 未加载
musicalealmost 4 years ago
Working as intended.
donohoealmost 4 years ago
Just occurred to me that Apple’s upcoming iCloud Private Relay will break nearly all GDPR solutions. Am guessing this has been written up already be someone. Any good perspectives?
评论 #27761802 未加载
评论 #27761804 未加载
tester89almost 4 years ago
&gt; IMO = In My Opinion is a blog format where a author reflects his own opinion<p>Did they just reïnvent opinion pieces?
评论 #27761277 未加载