insomniac86
macrumors 6502a
BZZZZZZ FAIL."but it is not a VPN that masks all traffic from a device. Passkeys use the WebAuthn standard, which stores a private key on your device, not the Safari browser. The request the system sends to the website isn't protected by Private Relay and can leak your IP address."
Ok?
It's not a real VPN therefore your IP shouldn't be masked at all times. No one has the expectation that your IP is private. So what's the issue?
Sounds to me just more complaining. 🤦♂️
You're not grasping it.
Imagine the following:
Someone sells you a device which advertises itself as being able to scramble your voice so that your voice is anonymous.
You purchase the device, and you start speaking, feeling safe, believing that your voice is being hidden.
However you find out, that if the person you're talking to simply asks, "What's your name?"
You're forced to answer using your real un-scrambled voice.
Taken from their website: https://support.apple.com/en-au/102602
Normally when you browse the web, information contained in your web traffic, such as your DNS records and IP address, can be seen by your network provider and the websites you visit. This information could be used to determine your identity and build a profile of your location and browsing history over time.
iCloud Private Relay is designed to protect your privacy by ensuring that when you browse the web in Safari, no single party — not even Apple — can see both who you are and what sites you're visiting.
Private Relay is a real split-tunnel vpn solution. But Apple slipped up in NOT having the Passkey subsystem utilise the tunnel.
For the people here that are saying, "Private Relay isn't a real VPN", you should be using a real VPN... well here's a fact for you.
VPN services such as NordVPN are not real interface level services on iOS. That's why there's features such as NordVPN's "VPN bypass prevention" that attempts to force all apps to communicate via the VPN. However it can't override system level services. So in theory, a site requesting a Passkey (system level services) may also resolve your real IP.
iOS has a history of sending out system services out via the WAN and not via VPN.
I hope that helps you see the gaping flaw in your logic.
Last edited: