Become a MacRumors Supporter for $50/year with no ads, ability to filter front page stories, and private forums.
What a joke of a lawsuit that will go nowhere. The feature works as advertised, it never claims your real email identity is completely protected.

Does this not sound like something that most Apple customers would interpret as such a claim?


"Hide My Email is a service that's included with an iCloud+ subscription. With Hide My Email, you can generate unique, random email addresses that automatically forward to your personal inbox, so you can keep your personal email address private."
 
You don't have to be doing something wrong or illegal to expect privacy.

Discovery for this will be very interesting to see if the claim that Apple knew and still advertised it as safe, when in fact they knew it was not.
It was safe. The disposable email addresses are for donations or shopping, not so you can stalk and harass people.
 
the day after the inital disclosure of the vulnerability via 404 media, sans isc podcast nonchalantly disclosed how to perform the exploit. im not sure if its detailed in any write ups, but apparently you just send an email with an oversized attachment and wait for the bounce back which will contain the actual address behind the "hidden" email address. good luck!


 
  • Like
Reactions: Heelpir8
I know one person that cannot get my iCloud sent emails. have to my Gmail address
I thought I was the only one with this problem. Certain individuals just cannot receive emails sent from my iCloud address. At the same time, there are certain (different) individuals I cannot receive emails from.

There’s also been an issue where emails are received, are supposedly in the inbox, but only show up when searched for. This happens across devices. The only reason I knew this was happening was that I was expecting the email and thought to search for it.

How do you screw up something as basic as email?
 
  • Like
Reactions: Unami
That when known bugs go unresolved for over a year, the PR narrative is more important than the actual functional effects.
There is no narrative and a handful of MR posters made up that Apple wasn’t about privacy because of a bug.
Very happy to see this lawsuit and hope to join the class action. I wonder though if the plaintiff actually knows what the vulnerability is or how it works? Reading the document doesn't seem like it.
Remember the FaceTime bug? It didn’t turn out as many thought it would.
 
Their real email address IS hidden, except for one very particular, very unlikely case that has never happened in the wild before.

Never happened in the wild that we know of. All HME email addresses are apparently vulnerable and the exploit can be carried out within 5 minutes.

I'd think it's very possible that someone has figured it out and didn't announce that they're taking advantage of it.

the day after the inital disclosure of the vulnerability via 404 media, sans isc podcast nonchalantly disclosed how to perform the exploit. im not sure if its detailed in any write ups, but apparently you just send an email with an oversized attachment and wait for the bounce back which will contain the actual address behind the "hidden" email address. good luck!



Seems like something that wouldn't have been hard for wrongdoers to have already figured out and taken advantage of.

Your blog/service/site receives the Apple HME address from the user, you bounce an oversized attachment off of it and voila, it's off to the races with the real email address behind it.
 
hquest at yahoo dot com
Well done maintaining a consistent nick for…god knows how long.

Anything else, other than showing my age (who tf still uses yahoo?!)

You’d be sad and alarmed to know. Not sure who even owns/runs Yahoo anymore.
Your turn. Unless you have things to hide. Like your cowardice.

I think you’re missing the point, so I’ll ignore the attempt at the ad hominem.

Privacy and security are different but related. The main thing I have to “hide” by using Apple’s service is from people who just want to annoy me beyond the purpose I wanted from them.

To be fair, what I said is slightly different. My point is that by making it public, you invite potential issues you simply wouldn’t have without having done that. Basic opsec. Simply avoiding unnecessary information leakage.
 
  • Like
Reactions: dg1974 and HQuest
I worked in software development for 30+ years. Finding a software problem is much easier than fixing it. As an analogy, editing is easier than writing, criticizing is easier than creating, suing is easier than solving problems. Apple will eventually fix the issue. Duh! In the meantime, Hide My Email hides my email address. When I want to cut off a sender using a "hide my" address, first I unsubscribe. If that does not work, I disable the "hide my" address. Poof! Emails from the sender get returned or go into the bit bucket. The feature may not be perfect, but it works well. "Hide my" is a tool. Use it correctly and it works as advertised. Want a perfect solution? Stop using email. A class action law suit related to a software flaw costs all of us and benefits mostly the lawyers who file the suits. Apple has already started the fix. The folks who found the error may just be seeking publicity.
 
Last edited:
the day after the inital disclosure of the vulnerability via 404 media, sans isc podcast nonchalantly disclosed how to perform the exploit. im not sure if its detailed in any write ups, but apparently you just send an email with an oversized attachment and wait for the bounce back which will contain the actual address behind the "hidden" email address. good luck!


I worked in software development for 30+ years. Finding a software problem is much easier than fixing it. As an analogy, editing is easier than writing, criticizing is easier than creating, suing is easier than solving problems. Apple will eventually fix the issue. Duh! In the meantime, Hide My Email hides my email address. When I want to cut off a sender using a "hide my" address, first I unsubscribe. If that does not work, I disable the "hide my" address. Poof! Emails from the sender get returned or go into the bit bucket. The feature may not be perfect, but it works well. "Hide my" is a tool. Use it correctly and it works as advertised. Want a perfect solution? Stop using email. A class action law suit related to a software flaw costs all of us and benefits mostly the lawyers who file the suits. Apple has already started to fix. The folks who found the error may just be seeking publicity.

Is not being able to bounce an email with an oversized attachment off of a HME address in order to harvest the user's supposedly protected email address an unreasonable ask of Apple?
 
  • Like
Reactions: Samplasion
There is no narrative and a handful of MR posters made up that Apple wasn’t about privacy because of a bug.

Remember the FaceTime bug? It didn’t turn out as many thought it would.
There is a narrative from Apple about privacy. When one of the big privacy features has a bug they’ve ignored for at least a year, it’s clear the PR is more important than function.
 
There is a narrative from Apple about privacy. When one of the big privacy features has a bug they’ve ignored for at least a year, it’s clear the PR is more important than function.
So it’s about the length of time and not the narrative? What’s the line in the sand for the length of time?
 
  • Disagree
Reactions: dg1974
They are not currently blocking the subdomain "privaterelay.appleid.com," so why would they suddenly start when Apple changes the subdomain?
Some companies and websites do reject Apple’s private relay email addresses but most do allow them

Barely anyone uses private relay in comparison to the normal hide my email addresses that look like any other real email though

Once they start getting a huge flood of private.iCloud.com email addresses I’m sure more companies will block it and the ones blocking private relay emails definitely will
 
I’m pretty disappointed and upset about this too. Apple dropped the ball on this one. Especially for a company that touts their unbeatable privacy and security.

They’ve never said it was perfect, I doubt they’ve even said it was unbeatable (but it is clearly the most privacy safe platform) and all software has bugs.
 
Imagine people trying to sue a lock manufacturer because someone someone figured out how to pick/bypass the lock.
I don't have to imagine that, it already happened. People won those lawsuits, Kryptonite also did a free exchange program.

 
House of bugs, broken guidelines design but instead of fixing we will proceed to licking investors a$€s - it is road to nowhere… if nothing will change it will ends very badly
 

Attachments

  • IMG_4679.jpeg
    IMG_4679.jpeg
    106.3 KB · Views: 14
I'm a DJ and sometimes I have people who need to send me a song for a gig or performance, and there is at least one person I know who simply CAN NOT email me her music to my iCloud email. I just never receive it. I don't know if iCloud thinks it's protecting me from something or what but there is nothing I can do to make that email come to my account, not even my spam folder. I had to get a separate Gmail account just for this purpose.
Yep. Same issue. But I run into this on other services too. Or they won’t deliver verification emails.
 
  • Like
Reactions: TrailorSwift
Another day, another lawsuit. Looking forward to my $.50 check that'll get here long after I've forgotten about it.
 
  • Like
Reactions: I7guy
Register on MacRumors! This sidebar will go away, and you'll see fewer ads.