Become a MacRumors Supporter for $50/year with no ads, ability to filter front page stories, and private forums.
There is such an easy solution for this. Just create an email account that you don't care and use that one. I have many and one specific for websites that ask you for an email address and I do not want to get emails from them. Easy and they can send me whatever they want. I also have an email for online shopping only. Yes, they can send all the crap they want and I also don't care.
HME is not really for keeping junk out of your inbox because it all gets forwarded to your email inbox anyway.

The real value of HME is using random email addresses to stop data brokers cross-referencing you across all the different platforms you use to map your behavioural patterns.

It’s not really about ads anymore; anyone, including governments buy this data.
 
99% of all Apple claims about its services are "trust me bro". No one can verify. The myth "Privacy, That’s iPhone" has been debunked multiple times but still people fall for the marketing mumbo jumbo. The only thing that you can verify and indeed is working as intended is the Mail privacy on Mail app. As for the E2EE ADP, I hope you know that is NOT zero knowledge because it uses convergent encryption.

The iCloud email (especially the custom domains where the DKIM fails unless you send email from iCloud.com) is an afterthought and a way to give more value to their (mediocre at best) iCloud offering + to lock more people on the ecosystem with the alias emails.
 
This has me wondering what else there might be if they can't get this issue right.
Exactly. For all the growth we have seen in their stock price, the lack of consistency with regard to internal priorities is starting to show. This would not have been allowed to stand if the leadership consistently advocated for, and held every employee accountable to customer privacy as a matter of corporate identity. Marketing the privacy angle rings hollow otherwise.
 
This is very unfortunate. I painstakingly decoupled each of my vendor (Amazon, Target, etc.) accounts to individual HideMy addresses, sandboxing them on a 1 to 1 basis. That way, if there is a data breach, I can easily retire the specific address associated with that particular vendor account and create a new one with minimal effort and no collateral damage. I currently have 81 unique HideMy address that forward to my main iCloud account. Ugh.
Is there a limit to HideMy emails? I like your system. My system is using an old AOL account for everything not important and trying my best to hide my Apple email.
 
As others have said, this sort of thing really breaks Apple’s privacy ‘brand promise’.

Not fixing it after a year is not a good look.

And given that Apple practices ‘privacy through obscurity’:

Is private relay actually doing what Apple says?

Ditto will the Apple Intelligence Secure Enclave?
 
I am honestly shocked anyone actually uses iCloud for email. The silent filtering, and Apple's refusal to address it, alone is enought to not use it. Add to that the horrible webmail experience for times when you are not on a Apple device, lackluster Apple Mail app and its just a non-starter.
 
As others have said, this sort of thing really breaks Apple’s privacy ‘brand promise’.

Not fixing it after a year is not a good look.

And given that Apple practices ‘privacy through obscurity’:

Is private relay actually doing what Apple says?

Ditto will the Apple Intelligence Secure Enclave?
Believing Apple's privacy stance is anything but Marketing is just nonsense. There is plenty of proof out there about how Apple allows app vendors to collect way more information than most people are aware of. Is it less than Google....sure but it is not anything like what their marketing says.
 
This is very unfortunate. I painstakingly decoupled each of my vendor (Amazon, Target, etc.) accounts to individual HideMy addresses, sandboxing them on a 1 to 1 basis. That way, if there is a data breach, I can easily retire the specific address associated with that particular vendor account and create a new one with minimal effort and no collateral damage. I currently have 81 unique HideMy address that forward to my main iCloud account. Ugh.
I did same. (I ended maxing out the available HME addresses at 750 ((and am pissed that I found out Apple lied about unlimited addresses only after I’d moved all accounts into HME)).

If I get non related email on that address I assume breach.

If that happens, or there’s a breach, I change both HME e/m the p/w for good measure.

Further, I created a new Gmail account for use as the HME forward to inbox.

FWIW more info on where spammers/hackers are going now (with the help of AI):

I didn’t use my main .max/.me/.iCloud e/m for anything but Apple.

I had long assumed like 10-15 years ago, that some clever hacker would start coupling my breached Yahoo zyx@ part to my @icloud because folks are kinda consistent (and in the old days I was too, just using the firstname.lastname format). Last week I received my first iCloud.com spam based on that commonality.
 
I am honestly shocked anyone actually uses iCloud for email. The silent filtering, and Apple's refusal to address it, alone is enought to not use it. Add to that the horrible webmail experience for times when you are not on a Apple device, lackluster Apple Mail app and its just a non-starter.
Silent filtering???

I’ve not had any problems except the 750 address limit in HME. I’m on all Apple equipment tho.
 
  • Like
Reactions: centauratlas
There is such an easy solution for this. Just create an email account that you don't care and use that one. I have many and one specific for websites that ask you for an email address and I do not want to get emails from them. Easy and they can send me whatever they want. I also have an email for online shopping only. Yes, they can send all the crap they want and I also don't care.
This does nothing to handle the issue of having all online accounts tied to a single or a few emails.

If you get weird spam on an email address you don’t know where the breach occurred.
 
I stopped using iCloud a year ago when suddenly approx 18 000 emails were deleted (randomly) from my account. I did get them back after some calls to Apple, but since then I haven’t trusted them (i decided to switch to Proton instead).
 
My guess is that it is something like one or more of these:

1.
p=reject; v=DMARC1 where the SPF or DKIM no longer match the from address at the recipient server. Since SPF failed (sent from a different IP since it was forwarded) only DKIM is left. Then you use a broken DKIM key - e.g. incorrect private key to sign the body hash. Since iCloud doesn't verify it, it is then sent on to gmail for example. Since p=reject and the DKIM fails, you get a hard bounce. [edit: 85-90% of inbox providers are using SPF/DKIM/DMARC now, so while it wouldn't get *all* it would get a lot]

or
2. A .exe or .bat attachment that is bounced (vs spammed) at some places, e.g. gmail. (https://support.google.com/mail/answer/6590?hl=en&rd=1 )
However would this work everywhere? Probably not since it would have to have similar spam filters. However this could be another way to reveal it.

or
3. Perhaps exploit header lengths. Make it 58KB or so, which goes under the iCloud header limit. iCloud then adds the ARC headers which adds enough overhead to it to be rejected by the recipient server because the header size is now above their (e.g. gmail) limit.

I guess we'll see...I try to avoid dealing with SPF and DKIM etc as much as possible. lol
 
Last edited:
HME is not really for keeping junk out of your inbox because it all gets forwarded to your email inbox anyway.

The real value of HME is using random email addresses to stop data brokers cross-referencing you across all the different platforms you use to map your behavioural patterns.
What are you talking about? The idea is to sign up with the HME address and when you notice you're getting spammed, you inactivate it.

Otherwise, it's true it limits cross-referencing.
 
I stopped using iCloud a year ago when suddenly approx 18 000 emails were deleted (randomly) from my account. I did get them back after some calls to Apple, but since then I haven’t trusted them (i decided to switch to Proton instead). I have 400+ HME addresses.
Good for you, but HME is not limited to forwarding for iCloud email addresses. I use another domain.
 
  • Like
Reactions: centauratlas
This has me wondering what else there might be if they can't get this issue right.
Sounds like the Visa situation to me. An attacker friendly with and working with the victim to ensure the results they’re looking for happens, can absolutely set up a scenario where what they claim is being done actually gets accomplished. That does not accurately represent what happens in the real world with actual attackers and unsuspecting victims, though.

In the Visa case, those presenting the video would say that Apple/Visa “hasn’t gotten it right”, but if it’s right enough for the case of unknown attacker/unsuspecting victim while still not right enough for friendly attacker/willing victim, it’s still right enough.
 
Believing Apple's privacy stance is anything but Marketing is just nonsense. There is plenty of proof out there about how Apple allows app vendors to collect way more information than most people are aware of. Is it less than Google....sure but it is not anything like what their marketing says.
What does their marketing say?
 
  • Like
Reactions: Robert.Walter
Believing Apple's privacy stance is anything but Marketing is just nonsense. There is plenty of proof out there about how Apple allows app vendors to collect way more information than most people are aware of. Is it less than Google....sure but it is not anything like what their marketing says.
What does their marketing say?

"Privacy. That's Apple."

"Privacy is a fundamental human right. It’s also one of our core values. Which is why we design our products and services to protect it. That’s the kind of innovation we believe in."


Source: https://www.apple.com/privacy/
 
Register on MacRumors! This sidebar will go away, and you'll see fewer ads.