Become a MacRumors Supporter for $50/year with no ads, ability to filter front page stories, and private forums.
"but it is not a VPN that masks all traffic from a device. Passkeys use the WebAuthn standard, which stores a private key on your device, not the Safari browser. The request the system sends to the website isn't protected by Private Relay and can leak your IP address."

Ok?

It's not a real VPN therefore your IP shouldn't be masked at all times. No one has the expectation that your IP is private. So what's the issue?

Sounds to me just more complaining. 🤦‍♂️
BZZZZZZ FAIL.

You're not grasping it.

Imagine the following:

Someone sells you a device which advertises itself as being able to scramble your voice so that your voice is anonymous.

You purchase the device, and you start speaking, feeling safe, believing that your voice is being hidden.

However you find out, that if the person you're talking to simply asks, "What's your name?"
You're forced to answer using your real un-scrambled voice.

Taken from their website: https://support.apple.com/en-au/102602

Normally when you browse the web, information contained in your web traffic, such as your DNS records and IP address, can be seen by your network provider and the websites you visit. This information could be used to determine your identity and build a profile of your location and browsing history over time.

iCloud Private Relay is designed to protect your privacy by ensuring that when you browse the web in Safari, no single party — not even Apple — can see both who you are and what sites you're visiting.


Private Relay is a real split-tunnel vpn solution. But Apple slipped up in NOT having the Passkey subsystem utilise the tunnel.

For the people here that are saying, "Private Relay isn't a real VPN", you should be using a real VPN... well here's a fact for you.

VPN services such as NordVPN are not real interface level services on iOS. That's why there's features such as NordVPN's "VPN bypass prevention" that attempts to force all apps to communicate via the VPN. However it can't override system level services. So in theory, a site requesting a Passkey (system level services) may also resolve your real IP.

iOS has a history of sending out system services out via the WAN and not via VPN.

I hope that helps you see the gaping flaw in your logic.
 
Last edited:
I kind of thought private relay was a kind of “hides some stuff, sometimes” thing that reduced your internet footprint and made it harder to connect the dots.

It doesn’t make you invisible, and there are plenty of times when I am warned it’s not available at all.
yes especially when apps aren't tunneled through private relay. i dont know of a single person who only uses safari and mail on iphones for the past 10 years.
 
There is just one reason this happens, and no Apple won't be fixing it because they lack the skill to do so at this point in time.
It’s hard to imagine they lack the skill, but they certainly lack the desire and commitment to customers.
I'm not even sure what they're doing over there anymore.
A question that comes to mind often.
Have been using Apple's products since the Apple II.
Over several decades using Apple laptops, I’ve observed and experienced a gradual decline.
Not because of just this. It's just Apple in 2026.
...and Apple in 2025, 2024, 2023 and so on
So true, although my cross platform workflow involves Windows and Linux, I prefer macOS as my primary laptop of choice. As such the decline is quite noticeable and disappointing.
The M-series is great, but I'd expect a multi-trillion dollar corporation to be doing just a bit more…
Well said!
For many years now, Apple isn't the Apple many of us know or knew and grew up with. They have just dropped the entire ball at this point. Again, this isn't about private relay passkey leaks. It's just about the company and its products, services and attitude in the past many years.
Having began with a PowerBook 170 upon it’s release and upgrading frequently buying nearly every new model through my present M4 Max 16” MacBook Pro, it’s been an interesting experience.
Sad state of things all around that I never thought I'd see from this company.
Yes indeed, I did not expect the current state of affairs to be like they are presently.
 
Typical American reaction… courts… cue the class action lawfare.

Years before the Snowden revelations I had a relative working at 🇨🇦 CSIS who simply told me never to do anything online or in a text message risky because it could be front page news the next day.

All your international phone call call and text messages are already monitored by your government.
Americans won't know this but if you know someone is Canadian and know their email, you can send an e-transfer and you can find out their full name.
 
No doubt Apple will eventually fix the issue by having Passkeys and WebAuthn route through iCloud‌ Private Relay. The question is will they release the fix for all devices that support Passkeys and WebAuthn?

Unlike fixing the Hide My Email issue, which was done server-side, this looks like they'll have to fix it on-device/OS. WebAuthn was first introduced in iOS 13/macOS 10.15 Catalina, iCloud Private Relay first introduced in iOS 15/macOS 12 Monteray, and Passkeys first introduced in iOS 16/macOS 13 Ventura. Most of those OS are no longer receiving regular updates. It'll be interesting to see if Apple considers this issue, which basically trivially makes iCloud Private Relay useless for protecting your IP address, important enough to issue special security updates for these older unsupported OS.

Hopefully Apple also does a security audit to see if there are other system functions similar to Passkeys/WebAuthn that websites can call without user permission/notification that are outside WebKit and not protected by iCloud Private Relay.
 
I know there’s actual reasons to be concerned but all this worry about your IP getting out reminds me of the paranoia from the early internet days when people thought some guy online saying “I know your IP address” was like picking up the phone and hearing “I know where you live”
 
Even with active VPN in iOS, certain traffic is transmitted outside the tunnel.
Mullvad solved that already by force All app option but they warn you to turn it off when updating app or you will lose internet access for everything, Mullvad is the only vpn trust worthy
 
Looks like this warrants another class-action lawsuit. The security incompetence of Apple's paid iCloud services is pretty stark.
What is your theory of the case. Remember we all agreed to the terms and conditions (not unique to Apple):

B. YOU EXPRESSLY ACKNOWLEDGE AND AGREE THAT, TO THE EXTENT PERMITTED BY APPLICABLE LAW, USE OF THE APPLE SOFTWARE AND ANY SERVICES PERFORMED BY OR ACCESSED THROUGH THE APPLE SOFTWARE IS AT YOUR SOLE RISK AND THAT THE ENTIRE RISK AS TO SATISFACTORY QUALITY, PERFORMANCE, ACCURACY AND EFFORT IS WITH YOU.
 
Ouch! Needs to be fixed for sure.

Another thing… Google search hates private relay. Because so many users present the same IP address, they get upset about suspicious activity and are always prompting me to go through a captcha. It’s getting quite tiresome.
This happens to me as well, and I agree that it is d@mned annoying. I think Google are doing it punitively, for surely they know the IP addresses associated with Apple's servers for private relay. I am considering switching to DuckDuckGo for my default search engine...
 
This happens to me as well, and I agree that it is d@mned annoying. I think Google are doing it punitively, for surely they know the IP addresses associated with Apple's servers for private relay. I am considering switching to DuckDuckGo for my default search engine...
Agreed - I use Kagi and have used DDG with Private Relay - no problems.
 
Ouch! Needs to be fixed for sure.

Another thing… Google search hates private relay. Because so many users present the same IP address, they get upset about suspicious activity and are always prompting me to go through a captcha. It’s getting quite tiresome.

Google has probably known about this exploit after discovering it as part of its passport implementation with Apple device users that have google accounts and is just putting on a show to make Private Relay users think it doesn’t really know your IP address.
 
  • Like
Reactions: LV426
Anyone download this to “test” for leaks. There is no test feature. This looks like some kind of browser, hard to tell exactly.
 
Anyone download this to “test” for leaks. There is no test feature. This looks like some kind of browser, hard to tell exactly.
The test website is also advertising the researcher's own app. It is a web browser that cost $70 a year. While the information leak he authored is accurate, I find the website link in bad taste and a conflict of interest.
 
Mullvad solved that already by force All app option but they warn you to turn it off when updating app or you will lose internet access for everything, Mullvad is the only vpn trust worthy
A couple of VPN providers have such "Kill Switches" for non tunneled traffic. But I doubt they can override routing of iOS self generated traffic. Needs to be tested in any case.
 
Register on MacRumors! This sidebar will go away, and you'll see fewer ads.