tenthousandthings
Contributor
The lawsuit’s damages hinge on the fact that your Apple email address can be used to identify you — the same is true of any email address that is associated with you.
The lawsuit reads more like an industry attempt to use the inherent insecurity of email to undermine the effectiveness Apple’s “privacy” marketing, rather than an attempt to address a data breach, which is what this really is. The only exposed data is your Apple email address and nothing else.
“Hide My Email” and “Sign In With Apple” are not encryption schemes, they are email-forwarding schemes. Apple’s defensive tactics against the exploit have not been (and will likely never be) explained, but they could be focused on preventing systematic exploitation of multiple private relay addresses. The lawsuit claims Apple has done nothing because it’s (apparently) still possible to do this one address at a time, but I wouldn’t jump to conclusions about what that means.
It will be interesting to see how Apple responds to this.
The lawsuit reads more like an industry attempt to use the inherent insecurity of email to undermine the effectiveness Apple’s “privacy” marketing, rather than an attempt to address a data breach, which is what this really is. The only exposed data is your Apple email address and nothing else.
“Hide My Email” and “Sign In With Apple” are not encryption schemes, they are email-forwarding schemes. Apple’s defensive tactics against the exploit have not been (and will likely never be) explained, but they could be focused on preventing systematic exploitation of multiple private relay addresses. The lawsuit claims Apple has done nothing because it’s (apparently) still possible to do this one address at a time, but I wouldn’t jump to conclusions about what that means.
It will be interesting to see how Apple responds to this.