We need to give kudos when they are due.
Apple's Private Cloud Compute should have won some kind of Nobel Privacy Prize, which for some reason does not yet exist.
There's obviously no real technical limitation since if you live in the EU you can sideload an alternative browser in theory (though apple has made it unrealistic in practice since they're ignoring the spirit of the law and instead doing their darndest to resist giving users even a whit of freedom).
And Firefox is in the iOS App Store. I know what you meant to say, and that it’s not the same as Firefox on Android, but it’s wrong to say you’re not allowed to install Firefox.
https://github.com/gorhill/uBlock/wiki/uBlock-Origin-works-b...
I also can't use Safari because I want my tabs and bookmarks to sync between my desktop machine (linux) and my phone (iOS), and Safari is the only major browser which can't do that.
Not to mention Safari is just an inferior browser which seems possibly designed to hold back Progressive Web Apps so that everyone has to make app-store apps and tithe a percent of all profits to apple.
In this day and age, privacy is luxury, so that's what they sell.
I don't think there are any ethical motivations for them (or any other large corporation - none of them have morals so they cannot act morally). It's just that there's a market niche, so it will be filled by someone.
they advertise that they do. that is not the same as doing
Apple literally wanted to scan all your photos and automatically report you to law enforcement if a fuzzy hash happened to match an opaque database.
Only pointing this out because I love Apple's privacy story and don't want your reply to be misconstrued as sarcasm, and thus the reason why it enjoys a singular exemption is because its ineffective.
They were planning to change it to a custom domain, which would allow sites to easily filter out and reject "Hide my email" users based on the email.
They have now reverted their plans to change this, meaning "hide my email" is still "@icloud.com".
Whole thing is 99c a month. Makes Gmail seem like a joke in comparison.
Until you get an email from an iCloud address on Gmail and see it go right to spam haha. Suddenly Gmail is cheap again
Took me only one missed dentist appointment several years ago to get that idea. Now I'm just getting profits. No other spam since I'm using email aliases.
World’s a twisted place!
I would guess the average Gmail user doesn’t know that it reports virtually all iCloud as Spam - believing instead that it’s genuinely being filtered by quality engineering at Google.
Yes, vendor lock in sucks, but I have $20k worth of apple hardware already so that ship has sailed and overall Im pretty happy with it.
Now if they could completely remove liquid glass...
The toplevel “Hide My Email” iCloud feature is a different thing, can be done independently of a SIWA flow (you can just go into settings and make more addresses, all it needs is a name and a notes field) and uses @icloud.com in order to make your anonymized email address look indistinguishable from other iCloud users.
The former is “filterable”, yes, but it’s moot because you only get those if you offer Sign In With Apple in the first place, and if you want real emails, you would already know to just… not do that.
The latter is very much not filterable.
The confusing thing though, is that when a user uses Sign In With Apple, they are offered two options: “share my email” which gives the site your real address, and “hide my email” which gives an @private.appleid.com address. But this “hide my email” option is a totally different thing from the separate “hide my email” service, which lets you make arbitrarily many @icloud.com private aliases to forward to your real address. Critically, the latter toplevel Hide My Email feature works with sites that don’t use Sign In With Apple. It’s just stupidly unfortunate that Apple calls both of these features “hide my email.”
[0]: https://developer.apple.com/app-store/review/guidelines/#sig...
My guess is that the bounce rate got too high and bot farms were using iCloud addresses like this.
Because the bounce rate of Hide My Email addresses being deliverable is going to rise over time, by design.
Whenever I start getting spam at an address that's been leaked, I deactivate it. I've done the same with my oldest gmail account, but the work required there is notably higher.
Keeping it on a subdomain fixes that problem, to some degree. If the user is named ffjvhtu57325cjdjvg501a2@icloud.com no one is going to think that’s a real address. It’s very obviously a private one. So it’s not like they were “camouflaged.“
It’s a little odd they’re switching the subdomain though.
I couldn't. "Uses Apple products" is one of the more reliable signals of willingness and ability to spend money on stuff online.
They’re not switching the subdomain. They’re keeping it the same. That’s the news.
They’re switching the subdomain for the “Sign in with Apple” sign ups, which is not the same service.
They are not changing the subdomain. There isn’t one. The announcement is they are leaving it as-is.
The email addresses for sign-in with Apple do use the @private.iCloud.com subdomain, but again, that’s not a change.
Like for my usage there are no bounce issues with the ~400 legitimate providers that I have Hide My Email addresses from. The only ones with bounce issues are the spammers who've acquired leaked addresses that I've deactivated.
The "Sign-up via Apple" button and creating an iCloud email yourself have a slightly higher barrier than creating a new throwaway hidemyemail email (1 API call w/o captcha/phone verification or whatever).
We might find out later this year if some site starts blocking @icloud.com but keeps allowing @private.icloud.com.
They're now saying the new domain will be private.icloud.com. Isn't it just as targetable?
> Sign in with Apple addresses, previously issued on privaterelay.appleid.com, will be issued on private.icloud.com.
> iCloud+ Hide My Email addresses will remain on icloud.com.
Hide My Email is the manually generated ones, for websites that accept an arbitrary email address. This is the one where it's valuable for the relays to be identical to genuine iCloud addresses, otherwise websites could try to block it and force you to use a more revealing email address, undermining privacy.
rtwnj6tj7@privaterelay.appleid.com
> Starting later this year, new Sign in with Apple addresses, previously issued on privaterelay.appleid.com, will be issued on private.icloud.com. Existing addresses on privaterelay.appleid.com will continue to work and forward mail to users without interruption.
> After further consideration and reviewing community feedback, iCloud+ Hide My Email addresses will remain on icloud.com.
A lot of those are Hide My Email aliases that, by design, you can’t tell apart from real human addresses.
A mitigation for the cause of https://www.404media.co/apple-hide-my-email-vulnerability-re...
> abc@icloud.com forwards to real@gmail.com
If they switched the new domain and did nothing else, it would say:
> abc@privaterelay.appleid.com forwards to real@gmail.com
That's no better. Fixing that privacy leak is unrelated to whatever the destination domain is.
If you dig more you could find the bug, but AFAIK it was that if you sent a large attachment, the bounce email would contain your real address.
Comments about lock-in aren’t wrong, but it has to be this way. You can make arbitrary email addresses at your own domain, but anybody who feels like it can trivially automatically detect that those are all you.
Personally I use unique at own domain only where I’m identifying myself anyway, like my bank, and Fastmail masked email where I’m not. For most things it’s not actually that terrible to accept a small risk that they’re offline for a day between your being booted without warning and you changing your email address with them.
I continue to use it everywhere for a few reasons:
- if someone emails me acting all friendly like we've had some previous relationship but it's sent to linked@mydomain or github@mydomain I know they've just scraped my contact details and it's spam
- similarly, if a vendor leaks or sells my data and I start receiving marketing from somewhere I don't expect it's easier to trace the source of the leak (and in some cases just blackhole that entire email address)
- I already use a password manager and have different passwords on every site, but having a different email address too raises the barrier further for someone trying to script an automated attack based off some other pwned data set.
This is exactly why I do it, it's eye opening to see exactly which companies leaked your address. As a result of being able to blackhole the leaked addresses I no longer get any spam, the Dvorak dream.
I actually caught a company outright selling my address to AWS of all places, I didn't even know Amazon purchased mailing lists.
AWS were crafty because they didn't directly sell a service, they only offered "resources" for "business leaders" because they knew nothing about what I might need.
Explore the AWS [REDACTED] where business leaders can access eBooks, guides, and customer stories to find practical advice on building or improving upon a data strategy. Learn how you can leverage data as a strategic asset, make better decisions with insights from data, and innovate faster.
I use my gmail address for everything and I don't really get spam (except from services I've subscribed to legitimately but haven't bothered to configure to not send promotional mail).
I never really get promotional mail from 3rd parties at all.
Is this just gmail filters being very good?
Whereas a Fastmail masked email or iCloud relay is still in the backend tied to your real account and identity which means it provides privacy generally for you but is traceable enough that it is unappealing for predators.
Same thoughts. I'm annoyed with the number of services that blocks alias domains.
At least I don't see services attempting to block @icloud.com domains.