Become a MacRumors Supporter for $50/year with no ads, ability to filter front page stories, and private forums.
The lawsuit’s damages hinge on the fact that your Apple email address can be used to identify you — the same is true of any email address that is associated with you.

The lawsuit reads more like an industry attempt to use the inherent insecurity of email to undermine the effectiveness Apple’s “privacy” marketing, rather than an attempt to address a data breach, which is what this really is. The only exposed data is your Apple email address and nothing else.

“Hide My Email” and “Sign In With Apple” are not encryption schemes, they are email-forwarding schemes. Apple’s defensive tactics against the exploit have not been (and will likely never be) explained, but they could be focused on preventing systematic exploitation of multiple private relay addresses. The lawsuit claims Apple has done nothing because it’s (apparently) still possible to do this one address at a time, but I wouldn’t jump to conclusions about what that means.

It will be interesting to see how Apple responds to this.
 
I worked in software development for 30+ years. Finding a software problem is much easier than fixing it. As an analogy, editing is easier than writing, criticizing is easier than creating, suing is easier than solving problems. Apple will eventually fix the issue. Duh! In the meantime, Hide My Email hides my email address. When I want to cut off a sender using a "hide my" address, first I unsubscribe. If that does not work, I disable the "hide my" address. Poof! Emails from the sender get returned or go into the bit bucket. The feature may not be perfect, but it works well. "Hide my" is a tool. Use it correctly and it works as advertised. Want a perfect solution? Stop using email. A class action law suit related to a software flaw costs all of us and benefits mostly the lawyers who file the suits. Apple has already started the fix. The folks who found the error may just be seeking publicity.
Well said. The Full Employment Act for the legal profession on the prowl for Class Action suits to file. If the action gets certified off they go expecting the sued party to settle rather than potentially pay more to fight. Large piece of any settlement to those law firms bringing the action.
 
Some companies and websites do reject Apple’s private relay email addresses but most do allow them

Barely anyone uses private relay in comparison to the normal hide my email addresses that look like any other real email though

Once they start getting a huge flood of private.iCloud.com email addresses I’m sure more companies will block it and the ones blocking private relay emails definitely will
If “barely anyone uses private relay,” how did you come to the conclusion that Apple changing their subdomain will result in a “huge flood of private.iCloud.com email addresses”?

So it’s about the length of time and not the narrative? What’s the line in the sand for the length of time?
Apple claims to value privacy above nearly all else. A bug in a key privacy feature has gone ignored for at least a year, with no comment from Apple. Apple has continued to tout privacy. We are just following Apple’s own behavior: PR over function.
 
If “barely anyone uses private relay,” how did you come to the conclusion that Apple changing their subdomain will result in a “huge flood of private.iCloud.com email addresses”?


Apple claims to value privacy above nearly all else. A bug in a key privacy feature has gone ignored for at least a year, with no comment from Apple. Apple has continued to tout privacy. We are just following Apple’s own behavior: PR over function.
Okay, from your post it’s a year for the line in the sand. I’ll give them a year and a half.
 
If “barely anyone uses private relay,” how did you come to the conclusion that Apple changing their subdomain will result in a “huge flood of private.iCloud.com email addresses”?


Apple claims to value privacy above nearly all else. A bug in a key privacy feature has gone ignored for at least a year, with no comment from Apple. Apple has continued to tout privacy. We are just following Apple’s own behavior: PR over function.
Private.iCloud.com is a new thing that Apple will start to use for any new hide my email accounts that we create/use, which previously could not be identified as such because they only used an iCloud.com extension and looks just like any other personal iCloud email.

Hence the flood of new emails with the “private” part added (and many people do use apple’s hide my email capability)

“Private relay” is a totally different thing that not nearly as many people use that always had an obvious extension that says privaterelay in the extension and it does indeed get blocked by some sites already, even though it’s not nearly as common/popular, but since it’s easily identified it gets blocked by a some sites occasionally.

Hide my email will now become much more easily identified like private relay was but at a much larger scale than private relay so more sites and companies are likely to take notice and try to prevent its use for certain things like registering an account etc

I use separate hide my email accounts for every new account I open
 
Last edited:
Okay, from your post it’s a year for the line in the sand. I’ll give them a year and a half.
I’m glad you agree.

Private.iCloud.com is a new thing that Apple will start to use for any new hide my email accounts that we create/use, which previously could not be identified as such because they only used an iCloud.com extension and looks just like any other personal iCloud email.

Hence the flood of new emails with the “private” part added (and many people do use apple’s hide my email capability)

“Private relay” is a totally different thing that not nearly as many people use that always had an obvious extension that says privaterelay in the extension and it does indeed get blocked by some sites already, even though it’s not nearly as common/popular, but since it’s easily identified it gets blocked by a some sites occasionally.

Hide my email will now become much more easily identified like private relay was but at a much larger scale than private relay so more sites and companies are likely to take notice and try to prevent its use for certain things like registering an account etc

I use separate hide my email accounts for every new account I open
Apple currently uses a special sub-domain, "privaterelay.appleid.com." Almost no websites have blocked this. Can you provide any evidence that changing to "private.icloud.com" will result in most websites suddenly blocking an Apple subdomain?
 
I’m glad you agree.


Apple currently uses a special sub-domain, "privaterelay.appleid.com." Almost no websites have blocked this. Can you provide any evidence that changing to "private.icloud.com" will result in most websites suddenly blocking an Apple subdomain?
Can you provide evidence that almost no websites block it?

As I’ve already clarified, private relay, email addresses are nowhere near as common as hide my email addresses and once they implement this new change the hide my email addresses will become very obvious in large numbers. The reason not that many websites care to block the private relay emails is because there aren’t that many of them going around.

G2A, OpenAI/ChatGPT, Reddit, Atlassian, HubSpot, and PledgeBox/Indiegogo all block or have issues with private relay email addresses currently to name a few and after this change takes affect that means hide my email addresses will also be blocked by all the same sites. Hide my email addresses and private relay email addresses will be indistinguishable as both are merged into using this new format.

To imply that companies will somehow start to care even less about blocking them instead of becoming more concerned about them when they start seeing waaaay more of them being used is just plain ignorance
 

Apple Sued Over Reported 'Hide My Email' Flaw​

"there are no known instances of it being exploited"

Given those two things, this seems like a naked attempt at a money grab.
 
  • Like
Reactions: Vahn21
Can you provide evidence that almost no websites block it?

As I’ve already clarified, private relay, email addresses are nowhere near as common as hide my email addresses and once they implement this new change the hide my email addresses will become very obvious in large numbers. The reason not that many websites care to block the private relay emails is because there aren’t that many of them going around.

G2A, OpenAI/ChatGPT, Reddit, Atlassian, HubSpot, and PledgeBox/Indiegogo all block or have issues with private relay email addresses currently to name a few and after this change takes affect that means hide my email addresses will also be blocked by all the same sites. Hide my email addresses and private relay email addresses will be indistinguishable as both are merged into using this new format.

To imply that companies will somehow start to care even less about blocking them instead of becoming more concerned about them when they start seeing waaaay more of them being used is just plain ignorance
Please read the original article, which is clearly talking about a substantial increase in blocking. If, as you contend, blocking is already happening on a widespread basis, please provide evidence.

As I’ve already explained, Apple already uses a special subdomain for private e-mail addresses, privaterelay.appleid.com. I see no evidence only a small number of people use this. I also see no evidence those websites block these e-mail addresses with this subdomain. Can you share how you determined they blocked this subdomain. Regardless, that does not represent a substantial number of websites.

To imply that somehow companies will start blocking Apple e-mail addresses simply because Apple changed the subdomain is an extraordinary claim. Again, you’re welcome to provide evidence.
 
Does this not sound like something that most Apple customers would interpret as such a claim?


"Hide My Email is a service that's included with an iCloud+ subscription. With Hide My Email, you can generate unique, random email addresses that automatically forward to your personal inbox, so you can keep your personal email address private."
Not to me it doesn't, I wouldn't comment otherwise. Like i said, the feature works, your email address is private but nothing is foolproof and people shouldn't expect it to be. It isn't easy to see your real email address, there is no known instance of this issue occurring.
 
I don't have to imagine that, it already happened. People won those lawsuits, Kryptonite also did a free exchange program.

This honestly isn't a good example. Some were not successful, others were primarily due to evidence disclosed regarding their knowledge of the flaw years ago. While its sad a lock can be picked with a ballpoint pen, let me know when lock manufacturers do something about locks being picked by paperclips which are just readily available as a ballpoint pen.

There are countless locks out there that are easy to bypass or pick, the average lock can be picked in as little as seconds to mere minutes with or without a ballpoint pen, does that mean they should all be sued?

Hide my email is not comparable - even if Apple knew there was a possibility of their design being circumvented, it wouldn't necessarily support a lawsuit. And just because a lawsuit succeeds doesn't mean it was warranted or wasn't frivolous - there are countless frivolous lawsuits that succeed

If you think any security measure in existence doesn't have flaws or that the designer of said security measure doesn't know there is going to be circumvention methods, you should re-assess your perspective.

Nothing is foolproof, Claude Mythos really bears that out though its not like this wasn't already obvious.
 
Not to me it doesn't, I wouldn't comment otherwise. Like i said, the feature works, your email address is private but nothing is foolproof and people shouldn't expect it to be. It isn't easy to see your real email address, there is no known instance of this issue occurring.
the day after the inital disclosure of the vulnerability via 404 media, sans isc podcast nonchalantly disclosed how to perform the exploit. im not sure if its detailed in any write ups, but apparently you just send an email with an oversized attachment and wait for the bounce back which will contain the actual address behind the "hidden" email address. good luck!



I'd bet this has already been exploited in the wild. It's extremely easy to discover and do.

Is not being able to bounce an email with an oversized attachment off of a HME address in order to harvest the user's supposedly protected email address an unreasonable ask of Apple?
 
Ok…so security researcher claimed a theoretical bug, with no real world cases of this happening?

Wouldn’t there need to be proof of [actual] damages to those suing, not just a theoretical ‘there might be damages in the future’ for a claim to proceed?
 
Register on MacRumors! This sidebar will go away, and you'll see fewer ads.