Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Private Relay was always a sketchy proposition; if privacy is your concern, you're almost always better off using a VPN.

Yes, granted, Apple could always extract (and to some extent probably is) your history directly via OS hooks, but the "Private" relay gives them a completely opaque off-device way to centrally track what everyone is visiting, which is just another data point feeding into their rapidly-growing advertisement business.

Paranoid? Maybe, but after the whole on-device scanning fiasco I view Apple in the same category as Google, Facebook and Microsoft when it comes to privacy guarantees.



> Yes, granted, Apple could always extract (and to some extent probably is) your history directly via OS hooks, but the "Private" relay gives them a completely opaque off-device way to centrally track what everyone is visiting

Err, no it doesn't - that's the whole point of the way it's engineered. All Apple sees is your IP address with none of the request details, and your IP is obscured before being sent to the second relay (Cloudflare, fastly, etc) , who only see the request detail with no origin/requestor information.

[1] https://www.apple.com/privacy/docs/iCloud_Private_Relay_Over...


The purpose of private relay is more to prevent ISPs/Cell carriers from vacuuming up your data and selling it in probably totally identifiable ways to the lowest sketchy bidder.

All the big carriers have already been sued by FCC for selling location data without permission[1], and even last month Verizon is trying to justify collecting more data on everything you use your phone for[2]. Apple's business model is less gross than ISPs and their partnership with Cloudflare to prevent even themselves from being able to access traffic logs is an extra plus

[1] https://www.nytimes.com/2020/02/27/technology/fcc-location-d... [2] https://www.theverge.com/2021/12/17/22841372/verizon-custom-...


> if privacy is your concern, you're almost always better off using a VPN

I am really skeptical of this. Not that ISPs are extremely trustworthy, but they're at least bound by some state mandated privacy protections which <Foreign VPN Provider> is not.


Valid concerns, you need to pick your VPN carefully if using a public provider. In my case, I relay everything to a VM I trust that is running a firewall and AdGuard for DNS ad-blocking.

The system may not work for everyone (for example, streaming services optimize based on your location, which will break down if the VM lives in some cloud), but I use my phone for music, browsing and email (not video consumption) so it works for me.


The thing is, I already have to trust Apple because they can do anything they want on my device. Why would I want to add a third party to that, especially one that runs a VPN service?


Give credit where credit is due. I haven't owned an Apple device since my trusty IIgs and am not a fan of Disneyland computing in general, but I may seriously ponder buying a Mac mini simply to gain access to their popular VPN that will be impractical for websites to block or CAPTCHA-hell.


The entire point of private relay is that neither Apple nor the third party CDN can match the destination website to an individual.

If your argument is “they probably aren’t doing what they say they’re doing” and so you shouldn’t use their tools, then you better start writing your own operating system from scratch and designing and fabbing your own silicon, because there’s no guarantee any of these companies or open source projects aren’t compromised.


Apple is also capturing DNS queries, so they minimally have that as a data point.

Regardless, the more general concern that parent seems to make is what is to stop Apple in the future from monetizing this data? I think the only thing protecting us as consumers is their policy. And as we all know policies can change very simply with a change to the terms of service.


I will eat my hat if Apple doesn't enter the ad market big-time in a couple of years. All the signs point to them building a massive privacy-invading trove of data on their customers to exploit.

Of course, their PR will spin it up as "privacy focused, totally anonymous, personalized advertisement" and some will just gobble that up as gospel.

I don't trust any of these fuckers any more... :)


I think 2 things are stopping apple from entering that market in earnest.

1. Privacy is a differentiator for Apple’s business. Google et al can’t compete and win on privacy. Apple can use this to win at recruiting and win at selling their ecosystem.

2. Apple’s hitting revenue/ growth targets. Other r&d investments better align with their ecosystem so there is no business driver today to enter this market.

Having said that I won’t be surprised if Apple misses a few qrtly earning targets and decides to enter the ad market.




I believe Apple now supports ODoH (oblivious DNS over HTTPS) although I do not know if it is used for private relay.



To quote the relevant section:

“ODoH sends DNS queries through the first internet relay, so the DNS server cannot identify the user issuing a query. Each query itself is padded and encrypted using Hybrid Public Key Encryption (HPKE) to help ensure that the first internet relay cannot tell the domain name a user is looking up.”

Apple is the “first internet relay” and they seem to explicitly state that they don’t see the DNS queries themselves.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: