I’ll try to add more later, but it is believed that multiple times, a bug in some random API has allowed for the “hidden” Apple account to be revealed because they resolve hide my emails to the original internally. Using a separate namespace would be the universal fix.
I’ll try to add more later, but it is believed that multiple times, a bug in some random API has allowed for the “hidden” Apple account to be revealed because they resolve hide my emails to the original internally. Using a separate namespace would be the universal fix.
A mitigation for the cause of https://www.404media.co/apple-hide-my-email-vulnerability-re...
This doesn't follow. The bounce message used to (effectively) say,
> abc@icloud.com forwards to real@gmail.com
If they switched the new domain and did nothing else, it would say:
> abc@privaterelay.appleid.com forwards to real@gmail.com
That's no better. Fixing that privacy leak is unrelated to whatever the destination domain is.
No, using a different domain makes it easy to across the board add a rule: don’t treat as Apple ID.
I'm not sure if I'm following. Apple is capable of creating a lookup table, or an atomic database read query.
https://news.ycombinator.com/item?id=48559935
If you dig more you could find the bug, but AFAIK it was that if you sent a large attachment, the bounce email would contain your real address.