Posted by K7PJP 7 hours ago
They're now saying the new domain will be private.icloud.com. Isn't it just as targetable?
> Sign in with Apple addresses, previously issued on privaterelay.appleid.com, will be issued on private.icloud.com.
> iCloud+ Hide My Email addresses will remain on icloud.com.
Hide My Email is the manually generated ones, for websites that accept an arbitrary email address. This is the one where it's valuable for the relays to be identical to genuine iCloud addresses, otherwise websites could try to block it and force you to use a more revealing email address, undermining privacy.
Sign in with Apple email addresses are email addresses for the Sign in with Apple button.
rtwnj6tj7@privaterelay.appleid.com
> Starting later this year, new Sign in with Apple addresses, previously issued on privaterelay.appleid.com, will be issued on private.icloud.com. Existing addresses on privaterelay.appleid.com will continue to work and forward mail to users without interruption.
> After further consideration and reviewing community feedback, iCloud+ Hide My Email addresses will remain on icloud.com.
A lot of those are Hide My Email aliases that, by design, you can’t tell apart from real human addresses.
A mitigation for the cause of https://www.404media.co/apple-hide-my-email-vulnerability-re...
> abc@icloud.com forwards to real@gmail.com
If they switched the new domain and did nothing else, it would say:
> abc@privaterelay.appleid.com forwards to real@gmail.com
That's no better. Fixing that privacy leak is unrelated to whatever the destination domain is.
If you dig more you could find the bug, but AFAIK it was that if you sent a large attachment, the bounce email would contain your real address.