Apple's iCloud Private Relay may not be as secure as you believe.
Your actual IP address may be exposed, and passkeys are to blame.
If you're paying for iCloud+ and using Private Relay to mask your IP address while surfing the web, this information is important for you. Recent research conducted by security experts Tommy Mysk and Talal Haj Bakry, initially reported by 404 Media, indicates that Private Relay does not conceal your IP address as effectively as Apple suggests.
How does the leak occur?
Private Relay is designed to route your Safari traffic through a two-hop relay, ensuring that no one, including Apple, can link your identity with the websites you visit. The issue arises from the functioning of passkeys. When a site requests your device to validate a passkey, your iPhone's credential service retrieves the validation file directly, circumventing both Safari and Private Relay. Since this request doesn't go through your browser's secured traffic, the website can see your actual IP address instead of the relay's.
Talal Haj Bakry and Tommy Mysk / Mysk Blog
Mysk elaborated on the extent of the issue, stating to 404 Media that "any website that supports, or claims to support, passkeys" can obtain this data, even when Private Relay is enabled. The researchers also pointed out in their own blog post that because the fetch originates from the “device’s real IP address either way,” there is currently no workaround while using Safari with Private Relay activated.
Should you be concerned?
This isn’t the first instance of privacy issues with Apple’s iCloud+ services. Recently, it was revealed that Apple’s Hide My Email feature was inadvertently disclosing users’ real email addresses, a flaw the company reportedly was aware of for over a year before addressing it.
On the bright side, traditional VPNs are not impacted since they encrypt all device traffic at the system level rather than just browser traffic. If you're using Private Relay for sensitive activities, it might be advisable to switch to a full VPN until Apple resolves this issue. Apple has informed 404 Media that it is investigating the researchers’ findings, raising hopes for a fix soon.
Rachit is an experienced technology journalist with over ten years of expertise in the consumer technology arena.
WhatsApp is simplifying the process for channel admins to label AI-generated posts.
Because not every image in your preferred channel is as genuine as it appears.
WhatsApp already allows channel admins to designate sponsored posts with a paid partnership label, a feature that began rolling out last month on Android and iOS. Now, the app is developing a similar feature for AI-generated content. The goal is to keep followers informed when an image or video wasn’t taken with a camera, but instead created by an AI tool.
How will the new AI label function?
Read more
Meta has run ads featuring AI-generated child sexual abuse content, continuing a history of child safety issues.
Meta’s ad platform hosted child abuse images for nine consecutive months.
Meta’s advertising service has done something it previously vowed to prohibit. According to an investigation by Wired, over the past nine months, Meta has run multiple paid ads containing explicit AI-generated child sexual abuse images, some of which remained online even after the company was directly alerted about them.
If this feels familiar, it’s likely because you’ve read about it before. Just weeks prior to this latest finding, a separate investigation by the BBC uncovered Instagram running paid ads promoting child sexual abuse materials in India, directing users to Telegram channels that sold illegal content.
Read more
This new technology may help make identifying counterfeit products easier for everyone.
Your smartphone could soon inform you if the product you purchased is fake.
Counterfeit products are becoming increasingly advanced, compelling brands to depend on costly authentication systems that frequently require specialized scanners or proprietary hardware. Researchers now believe that smartphones could handle much of this verification process. A team has created a new printing system that produces responsive anti-counterfeit labels that are more durable, easier to mass-produce, and can be verified using just a phone. The research was published in the International Journal of Materials and Product Technology.
At first glance, this technology may appear to be just another step forward in product security. In reality, it tackles one of the major drawbacks of current anti-counterfeit systems: accessibility. If authentication can only be accomplished with expensive tools, it becomes challenging to implement on a large scale. By allowing verification through smartphones, this technology could make counterfeit detection feasible for manufacturers, retailers, and even consumers.
Read more
Other articles
Apple's iCloud Private Relay may not be as secure as you believe.
Recent studies indicate that Apple's iCloud Private Relay may inadvertently expose your actual IP address via passkeys, and Apple has announced that it is currently looking into the matter.
