Using icloud.com domain for legit and hidden adresses is such a typical Apple strategy of holding their own users and "others" (ie. other web services, other users etc) hostage simultaneously. But at least here it is actually a good reason that works for the user.
Seriously, Apple is "big tech," but they are the only one that appears to give a crap about privacy at all. And really, they put a lot of money and effort into it.
We need give kudos when they are due.
Apple's Private Cloud Compute should have won some kind of Nobel Privacy Prize, which for some reason does not yet exist.
The person you're replying to is saying "Sites I use block all VPNs besides Apple's subscription service VPN" - I'm not sure they're not blocking it just because they fervently believe in Apple's privacy commitments and engineering :)
Only pointing this out because I love Apple's privacy story and don't want your reply to be misconstrued as sarcasm, and thus the reason why it enjoys a singular exemption is because its ineffective.
Maybe it's because I live in a country where e-mai isn't really used that much for personal communication, but wouldn't this mainly be a gmail issue? If mails I wanted ended up in the spam folder I'd not use gmail. I mean, I pay for protonmail, so I wouldn't use gmail to begin with, but if mails I wanted ended up in my protonmail spamfolder and I couldn't do anything about it, then I'd switch away from protonmail.
If you’re talking about people with the technical sophistication to consider software services based on their technical merits, then sure. Your average user couldn’t even tell you the first thing about which non-content-based criteria might inform a spam score… or have even heard of a spam score. So they will absolutely not blame Gmail if another provider’s email gets spam flagged… they’d probably just think “why don’t they just get a Gmail account,” à la iMessage users/green texts.
You are 100% correct and yet the masses still prefer it.
World’s a twisted place!
I would guess the average Gmail user doesn’t know that it reports virtually all iCloud as Spam - believing instead that it’s genuinely being filtered by quality engineering at Google.
I think the post is very explicit. First sentence:
> Starting later this year, new Sign in with Apple addresses, previously issued on privaterelay.appleid.com, will be issued on private.icloud.com. Existing addresses on privaterelay.appleid.com will continue to work and forward mail to users without interruption.
Hmm it’s almost as if people are paying good money for iCloud+ or something. They aren’t google and shouldn’t be retiring their services as if they’re giving them away for free
While I applaud this specific change, Apple has been known to stick to their guns and I used to believe they were almost always in the right for doing so because it led to better outcomes. So my take is that it's chilling because Apple has so lost their way that they can't figure out these obviously stupid directions internally before making a fool of themselves to the public (and I agree with that take).
Anyone have a theory why this even made it to this point? the switch was such obviously a bad idea. just corporate weirdness that no one there bothered to raise their hand and be like "uh, are we really doing this?" or was there a story here that anyone knows about?
Because the bounce rate of Hide My Email addresses being deliverable is going to rise over time, by design.
Whenever I start getting spam at an address that's been leaked, I deactivate it. I've done the same with my oldest gmail account, but the work required there is notably higher.
If they were moved to plain old icloud.com, I could absolutely see a bunch of companies starting to filter out all icloud.com email addresses to avoid private relay. Either just because they’re jerks or from bounce issues.
Keeping it on a subdomain fixes that problem, to some degree. If the user is named ffjvhtu57325cjdjvg501a2@icloud.com no one is going to think that’s a real address. It’s very obviously a private one. So it’s not like they were “camouflaged.“
It’s a little odd they’re switching the subdomain though.
Like for my usage there are no bounce issues with the ~400 legitimate providers that I have Hide My Email addresses from. The only ones with bounce issues are the spammers who've acquired leaked addresses that I've deactivated.
If you merely deactivate your email address rather than closing your account or changing your notification settings or whatever, then the next time a legitimate service goes to send you a legitimate email that you asked for, it will bounce. In some sense this "shouldn't matter", as in a purely P2P system the only people who would notice are the sender and Apple -- and Apple knows what is going on, so should not penalize senders the way, say, Google would if they see you sending a ton of email to their domains and they all bounce -- but people tend to use services to help send email and centrally pool their reputation (such as mailchimp) and so these services themselves then watch the bounce rate of their individual customers and either charge them more or ban their access due to the bounce rate increase.
Is Apple really stupid enough that they BOUNCE emails after you deactivate, rather than just silent discard? What's the point of bouncing unwanted emails these days? It's not like these bounces go to humans who go "Oh, gee! This address must not work. Allow me to go and figure out how to contact him!" It's just a stream of full-on spam with completely fake return addresses, and crap from email campaign software.
Maybe hidemyemail allows easily creating many accounts on a site. And some big site didn't like it.
The "Sign-up via Apple" button and creating an iCloud email yourself have a slightly higher barrier than creating a new throwaway hidemyemail email (1 API call w/o captcha/phone verification or whatever).
We might find out later this year if some site starts blocking @icloud.com but keeps allowing @private.icloud.com.
Sign in with Apple is Apple's SSO, like Sign in with Google. Services have to support this one explicitly, and it already had a special subdomain, so the specific subdomain is simply changing.
Hide My Email is the manually generated ones, for websites that accept an arbitrary email address. This is the one where it's valuable for the relays to be identical to genuine iCloud addresses, otherwise websites could try to block it and force you to use a more revealing email address, undermining privacy.
I’ll try to add more later, but it is believed that multiple times, a bug in some random API has allowed for the “hidden” Apple account to be revealed because they resolve hide my emails to the original internally. Using a separate namespace would be the universal fix.
We need give kudos when they are due.
Apple's Private Cloud Compute should have won some kind of Nobel Privacy Prize, which for some reason does not yet exist.
Only pointing this out because I love Apple's privacy story and don't want your reply to be misconstrued as sarcasm, and thus the reason why it enjoys a singular exemption is because its ineffective.
They were planning to change it to a custom domain, which would allow sites to easily filter out and reject "Hide my email" users based on the email.
They have now reverted their plans to change this, meaning "hide my email" is still "@icloud.com".
Whole thing is 99c a month. Makes Gmail seem like a joke in comparison.
Until you get an email from an iCloud address on Gmail and see it go right to spam haha. Suddenly Gmail is cheap again
World’s a twisted place!
I would guess the average Gmail user doesn’t know that it reports virtually all iCloud as Spam - believing instead that it’s genuinely being filtered by quality engineering at Google.
rtwnj6tj7@privaterelay.appleid.com
> Starting later this year, new Sign in with Apple addresses, previously issued on privaterelay.appleid.com, will be issued on private.icloud.com. Existing addresses on privaterelay.appleid.com will continue to work and forward mail to users without interruption.
My guess is that the bounce rate got too high and bot farms were using iCloud addresses like this.
Because the bounce rate of Hide My Email addresses being deliverable is going to rise over time, by design.
Whenever I start getting spam at an address that's been leaked, I deactivate it. I've done the same with my oldest gmail account, but the work required there is notably higher.
Keeping it on a subdomain fixes that problem, to some degree. If the user is named ffjvhtu57325cjdjvg501a2@icloud.com no one is going to think that’s a real address. It’s very obviously a private one. So it’s not like they were “camouflaged.“
It’s a little odd they’re switching the subdomain though.
They are not changing the subdomain. There isn’t one. The announcement is they are leaving it as-is.
The email addresses for sign-in with Apple do use the @private.iCloud.com subdomain, but again, that’s not a change.
Like for my usage there are no bounce issues with the ~400 legitimate providers that I have Hide My Email addresses from. The only ones with bounce issues are the spammers who've acquired leaked addresses that I've deactivated.
The "Sign-up via Apple" button and creating an iCloud email yourself have a slightly higher barrier than creating a new throwaway hidemyemail email (1 API call w/o captcha/phone verification or whatever).
We might find out later this year if some site starts blocking @icloud.com but keeps allowing @private.icloud.com.
They're now saying the new domain will be private.icloud.com. Isn't it just as targetable?
> Sign in with Apple addresses, previously issued on privaterelay.appleid.com, will be issued on private.icloud.com.
> iCloud+ Hide My Email addresses will remain on icloud.com.
Hide My Email is the manually generated ones, for websites that accept an arbitrary email address. This is the one where it's valuable for the relays to be identical to genuine iCloud addresses, otherwise websites could try to block it and force you to use a more revealing email address, undermining privacy.
A mitigation for the cause of https://www.404media.co/apple-hide-my-email-vulnerability-re...
> abc@icloud.com forwards to real@gmail.com
If they switched the new domain and did nothing else, it would say:
> abc@privaterelay.appleid.com forwards to real@gmail.com
That's no better. Fixing that privacy leak is unrelated to whatever the destination domain is.
If you dig more you could find the bug, but AFAIK it was that if you sent a large attachment, the bounce email would contain your real address.