This is a huge selling point. Private email relays often get blocked, the only lasting solution is to put them on the same domain as, and in the same format as, a significant number of non-private email addresses. As far as I’m aware the only other provider doing this is Fastmail.
Comments about lock-in aren’t wrong, but it has to be this way. You can make arbitrary email addresses at your own domain, but anybody who feels like it can trivially automatically detect that those are all you.
Personally I use unique at own domain only where I’m identifying myself anyway, like my bank, and Fastmail masked email where I’m not. For most things it’s not actually that terrible to accept a small risk that they’re offline for a day between your being booted without warning and you changing your email address with them.
Totally agree with unique at own domain isn't actually privacy. It wouldn't take much of a paper trail to work out the details.
I continue to use it everywhere for a few reasons:
- if someone emails me acting all friendly like we've had some previous relationship but it's sent to linked@mydomain or github@mydomain I know they've just scraped my contact details and it's spam
- similarly, if a vendor leaks or sells my data and I start receiving marketing from somewhere I don't expect it's easier to trace the source of the leak (and in some cases just blackhole that entire email address)
- I already use a password manager and have different passwords on every site, but having a different email address too raises the barrier further for someone trying to script an automated attack based off some other pwned data set.
I configured about a dozen domains to have MX records for the mailinator disposable inbox service for about a decade for free as a gift and the domains were toxic for any other email use case for years afterwards… they were so abused you couldn’t even sign up for most web services with any email associated by the time I stopped renewing them… there are still GitHub lists of disposable email addresses that list to blacklist those domains (and many other), so, I agree. If the big providers don’t offer disposable email addresses there is no good option.
Using icloud.com domain for legit and hidden adresses is such a typical Apple strategy of holding their own users and "others" (ie. other web services, other users etc) hostage simultaneously. But at least here it is actually a good reason that works for the user.
Seriously, Apple is "big tech," but they are the only one that appears to give a crap about privacy at all. And really, they put a lot of money and effort into it.
We need to give kudos when they are due.
Apple's Private Cloud Compute should have won some kind of Nobel Privacy Prize, which for some reason does not yet exist.
They still don't let me install uBlock origin + noscript. Whitelisting per-domain and per-site what can run Javascript does more for my privacy than anything else, and I can do that with firefox on linux and android, but on iOS I'm not allowed to install firefox.
There's obviously no real technical limitation since if you live in the EU you can sideload an alternative browser in theory (though apple has made it unrealistic in practice since they're ignoring the spirit of the law and instead doing their darndest to resist giving users even a whit of freedom).
In this day and age, privacy is luxury, so that's what they sell.
I don't think there are any ethical motivations for them (or any other large corporation - none of them have morals so they cannot act morally). It's just that there's a market niche, so it will be filled by someone.
The person you're replying to is saying "Sites I use block all VPNs besides Apple's subscription service VPN" - I'm not sure they're not blocking it just because they fervently believe in Apple's privacy commitments and engineering :)
Only pointing this out because I love Apple's privacy story and don't want your reply to be misconstrued as sarcasm, and thus the reason why it enjoys a singular exemption is because its ineffective.
I’ve never been under the impression that privacy relay is anything like a true VPN. I mostly thought it stopped BS that happens on public WiFi and public sniffing. It’s meant to protect you only until you get to a major carriers infrastructure.
The design is supposed to be better than a true VPN, because neither Apple nor the exit node (Akamai, Cloudflare, Fastly) are supposed to know both who you are and what you’re doing. Of course, Apple pays them for this service, so they could exchange info.
Hostage may be a bad analogy. More like a game of chicken. Imagine you are a regular @icloud.com email user. Apple is basically saying "I dare you to block all @icloud.com email and lose all these customers"
I suspect many people actually feel better about Apple owning this fuckup and reversing it than they would have Apple hadn't fucked up in the first place.
Maybe it's because I live in a country where e-mai isn't really used that much for personal communication, but wouldn't this mainly be a gmail issue? If mails I wanted ended up in the spam folder I'd not use gmail. I mean, I pay for protonmail, so I wouldn't use gmail to begin with, but if mails I wanted ended up in my protonmail spamfolder and I couldn't do anything about it, then I'd switch away from protonmail.
If you’re talking about people with the technical sophistication to consider software services based on their technical merits, then sure. Your average user couldn’t even tell you the first thing about which non-content-based criteria might inform a spam score… or have even heard of a spam score. So they will absolutely not blame Gmail if another provider’s email gets spam flagged… they’d probably just think “why don’t they just get a Gmail account,” à la iMessage users/green texts.
You are 100% correct and yet the masses still prefer it.
World’s a twisted place!
I would guess the average Gmail user doesn’t know that it reports virtually all iCloud as Spam - believing instead that it’s genuinely being filtered by quality engineering at Google.
private.icloud.com (née privaterelay.appleid.com) is the address for “Sign In With Apple”, which is an oauth-style service that sites opt into to let you use your Apple ID to sign in. Sites offering this as a signup option are already aware it gives users an option to use a private anonymized email address.
The toplevel “Hide My Email” iCloud feature is a different thing, can be done independently of a SIWA flow (you can just go into settings and make more addresses, all it needs is a name and a notes field) and uses @icloud.com in order to make your anonymized email address look indistinguishable from other iCloud users.
The former is “filterable”, yes, but it’s moot because you only get those if you offer Sign In With Apple in the first place, and if you want real emails, you would already know to just… not do that.
The latter is very much not filterable.
The confusing thing though, is that when a user uses Sign In With Apple, they are offered two options: “share my email” which gives the site your real address, and “hide my email” which gives an @private.appleid.com address. But this “hide my email” option is a totally different thing from the separate “hide my email” service, which lets you make arbitrarily many @icloud.com private aliases to forward to your real address. Critically, the latter toplevel Hide My Email feature works with sites that don’t use Sign In With Apple. It’s just stupidly unfortunate that Apple calls both of these features “hide my email.”
Others have addressed the validity of your comment, but I’d like to discuss another aspect. Even if it is filter, I think most people would not want to filter. Apple makes it very easy to use private relay and many people that buy Apple products do use private relay. Even if you know, it’s a private relay email address, surely you want a user who buys expensive technology products to use your website in almost all circumstances.
iCloud Hide My Email sharing the same domain with normal email (icloud.com) is the reason why I use iCloud over other email alias services like simplelogin and addy.
Anyone have a theory why this even made it to this point? the switch was such obviously a bad idea. just corporate weirdness that no one there bothered to raise their hand and be like "uh, are we really doing this?" or was there a story here that anyone knows about?
Because the bounce rate of Hide My Email addresses being deliverable is going to rise over time, by design.
Whenever I start getting spam at an address that's been leaked, I deactivate it. I've done the same with my oldest gmail account, but the work required there is notably higher.
If they were moved to plain old icloud.com, I could absolutely see a bunch of companies starting to filter out all icloud.com email addresses to avoid private relay. Either just because they’re jerks or from bounce issues.
Keeping it on a subdomain fixes that problem, to some degree. If the user is named ffjvhtu57325cjdjvg501a2@icloud.com no one is going to think that’s a real address. It’s very obviously a private one. So it’s not like they were “camouflaged.“
It’s a little odd they’re switching the subdomain though.
Hide My Email addresses are not just a random string at icloud.com. They use plausibly-human names, probably generated by a language model. There’s no easy-to-check pattern.
They’re not switching the subdomain. They’re keeping it the same. That’s the news.
They’re switching the subdomain for the “Sign in with Apple” sign ups, which is not the same service.
> If they were moved to plain old icloud.com, I could absolutely see a bunch of companies starting to filter out all icloud.com email addresses to avoid private relay.
I couldn't. "Uses Apple products" is one of the more reliable signals of willingness and ability to spend money on stuff online.
Like for my usage there are no bounce issues with the ~400 legitimate providers that I have Hide My Email addresses from. The only ones with bounce issues are the spammers who've acquired leaked addresses that I've deactivated.
If you merely deactivate your email address rather than closing your account or changing your notification settings or whatever, then the next time a legitimate service goes to send you a legitimate email that you asked for, it will bounce. In some sense this "shouldn't matter", as in a purely P2P system the only people who would notice are the sender and Apple -- and Apple knows what is going on, so should not penalize senders the way, say, Google would if they see you sending a ton of email to their domains and they all bounce -- but people tend to use services to help send email and centrally pool their reputation (such as mailchimp) and so these services themselves then watch the bounce rate of their individual customers and either charge them more or ban their access due to the bounce rate increase.
Is Apple really stupid enough that they BOUNCE emails after you deactivate, rather than just silent discard? What's the point of bouncing unwanted emails these days? It's not like these bounces go to humans who go "Oh, gee! This address must not work. Allow me to go and figure out how to contact him!" It's just a stream of full-on spam with completely fake return addresses, and crap from email campaign software.
Maybe hidemyemail allows easily creating many accounts on a site. And some big site didn't like it.
The "Sign-up via Apple" button and creating an iCloud email yourself have a slightly higher barrier than creating a new throwaway hidemyemail email (1 API call w/o captcha/phone verification or whatever).
We might find out later this year if some site starts blocking @icloud.com but keeps allowing @private.icloud.com.
Hmm it’s almost as if people are paying good money for iCloud+ or something. They aren’t google and shouldn’t be retiring their services as if they’re giving them away for free
While I applaud this specific change, Apple has been known to stick to their guns and I used to believe they were almost always in the right for doing so because it led to better outcomes. So my take is that it's chilling because Apple has so lost their way that they can't figure out these obviously stupid directions internally before making a fool of themselves to the public (and I agree with that take).
this opens some crazy "apple developer" dialog on my mac rather than a web page. I had to crank up chrome to read it. And it makes no sense, I have no clue what a sign on with apple address is. I guess I'm glad my hide my email addresses won't change because that would be a PITA.
Sign in with Apple is Apple's SSO, like Sign in with Google. Services have to support this one explicitly, and it already had a special subdomain, so the specific subdomain is simply changing.
Hide My Email is the manually generated ones, for websites that accept an arbitrary email address. This is the one where it's valuable for the relays to be identical to genuine iCloud addresses, otherwise websites could try to block it and force you to use a more revealing email address, undermining privacy.
I think the post is very explicit. First sentence:
> Starting later this year, new Sign in with Apple addresses, previously issued on privaterelay.appleid.com, will be issued on private.icloud.com. Existing addresses on privaterelay.appleid.com will continue to work and forward mail to users without interruption.
That's the Sign in with Apple domain, not the Hide My Email domain. HME is remaining at icloud.com instead of moving to private.icloud.com as well. From the linked article:
> After further consideration and reviewing community feedback, iCloud+ Hide My Email addresses will remain on icloud.com.
I’ll try to add more later, but it is believed that multiple times, a bug in some random API has allowed for the “hidden” Apple account to be revealed because they resolve hide my emails to the original internally. Using a separate namespace would be the universal fix.
This is a huge selling point. Private email relays often get blocked, the only lasting solution is to put them on the same domain as, and in the same format as, a significant number of non-private email addresses. As far as I’m aware the only other provider doing this is Fastmail.
Comments about lock-in aren’t wrong, but it has to be this way. You can make arbitrary email addresses at your own domain, but anybody who feels like it can trivially automatically detect that those are all you.
Personally I use unique at own domain only where I’m identifying myself anyway, like my bank, and Fastmail masked email where I’m not. For most things it’s not actually that terrible to accept a small risk that they’re offline for a day between your being booted without warning and you changing your email address with them.
Totally agree with unique at own domain isn't actually privacy. It wouldn't take much of a paper trail to work out the details.
I continue to use it everywhere for a few reasons:
- if someone emails me acting all friendly like we've had some previous relationship but it's sent to linked@mydomain or github@mydomain I know they've just scraped my contact details and it's spam
- similarly, if a vendor leaks or sells my data and I start receiving marketing from somewhere I don't expect it's easier to trace the source of the leak (and in some cases just blackhole that entire email address)
- I already use a password manager and have different passwords on every site, but having a different email address too raises the barrier further for someone trying to script an automated attack based off some other pwned data set.
I configured about a dozen domains to have MX records for the mailinator disposable inbox service for about a decade for free as a gift and the domains were toxic for any other email use case for years afterwards… they were so abused you couldn’t even sign up for most web services with any email associated by the time I stopped renewing them… there are still GitHub lists of disposable email addresses that list to blacklist those domains (and many other), so, I agree. If the big providers don’t offer disposable email addresses there is no good option.
> This is a huge selling point.
Same thoughts. I'm annoyed with the number of services that blocks alias domains.
At least I don't see services attempting to block @icloud.com domains.
Using icloud.com domain for legit and hidden adresses is such a typical Apple strategy of holding their own users and "others" (ie. other web services, other users etc) hostage simultaneously. But at least here it is actually a good reason that works for the user.
Case in point: many websites block all VPN except iCloud Private Relay. Thank you Apple!
Seriously, Apple is "big tech," but they are the only one that appears to give a crap about privacy at all. And really, they put a lot of money and effort into it.
We need to give kudos when they are due.
Apple's Private Cloud Compute should have won some kind of Nobel Privacy Prize, which for some reason does not yet exist.
They still don't let me install uBlock origin + noscript. Whitelisting per-domain and per-site what can run Javascript does more for my privacy than anything else, and I can do that with firefox on linux and android, but on iOS I'm not allowed to install firefox.
There's obviously no real technical limitation since if you live in the EU you can sideload an alternative browser in theory (though apple has made it unrealistic in practice since they're ignoring the spirit of the law and instead doing their darndest to resist giving users even a whit of freedom).
Apple is luxury big tech.
In this day and age, privacy is luxury, so that's what they sell.
I don't think there are any ethical motivations for them (or any other large corporation - none of them have morals so they cannot act morally). It's just that there's a market niche, so it will be filled by someone.
It’s an additional layer of wall for their walled garden to keep the technically proficient users that are more likely to hop walls.
money from advertising basically dwarf user lifetime purchase of privacy tax you mentioned
The person you're replying to is saying "Sites I use block all VPNs besides Apple's subscription service VPN" - I'm not sure they're not blocking it just because they fervently believe in Apple's privacy commitments and engineering :)
Only pointing this out because I love Apple's privacy story and don't want your reply to be misconstrued as sarcasm, and thus the reason why it enjoys a singular exemption is because its ineffective.
I’ve never been under the impression that privacy relay is anything like a true VPN. I mostly thought it stopped BS that happens on public WiFi and public sniffing. It’s meant to protect you only until you get to a major carriers infrastructure.
The design is supposed to be better than a true VPN, because neither Apple nor the exit node (Akamai, Cloudflare, Fastly) are supposed to know both who you are and what you’re doing. Of course, Apple pays them for this service, so they could exchange info.
how is the user being held hostage? you can redirect hide my email addresses to any domain
Marketing turds can't just block registrations from all of @icloud.com.
That doesn’t explain how the user is held “hostage” by Apple
Hostage may be a bad analogy. More like a game of chicken. Imagine you are a regular @icloud.com email user. Apple is basically saying "I dare you to block all @icloud.com email and lose all these customers"
I wish I could set up "Sign in with Apple" on a blog without paying $99/yr for a developer license.
Is your audience very Apple heavy?
I'm glad they listened - I use this feature extensively and would like to continue to
I use hide my email and single use credit card numbers all the time, its a fantastic system combined with some basic email forwarding rules.
Yes, vendor lock in sucks, but I have $20k worth of apple hardware already so that ship has sailed and overall Im pretty happy with it.
Can someone explain the backstory behind this? I'm reading some of the comments here and I feel like I'm missing something here.
For the "hide my email" feature, Apple currently and has always used "@icloud.com". This masks you amongst all iCloud users.
They were planning to change it to a custom domain, which would allow sites to easily filter out and reject "Hide my email" users based on the email.
They have now reverted their plans to change this, meaning "hide my email" is still "@icloud.com".
I suspect many people actually feel better about Apple owning this fuckup and reversing it than they would have Apple hadn't fucked up in the first place.
One of the best things about it. Also being able to add several emails per custom domain for free.
Whole thing is 99c a month. Makes Gmail seem like a joke in comparison.
Until you get an email from an iCloud address on Gmail and see it go right to spam haha. Suddenly Gmail is cheap again
Maybe it's because I live in a country where e-mai isn't really used that much for personal communication, but wouldn't this mainly be a gmail issue? If mails I wanted ended up in the spam folder I'd not use gmail. I mean, I pay for protonmail, so I wouldn't use gmail to begin with, but if mails I wanted ended up in my protonmail spamfolder and I couldn't do anything about it, then I'd switch away from protonmail.
If you’re talking about people with the technical sophistication to consider software services based on their technical merits, then sure. Your average user couldn’t even tell you the first thing about which non-content-based criteria might inform a spam score… or have even heard of a spam score. So they will absolutely not blame Gmail if another provider’s email gets spam flagged… they’d probably just think “why don’t they just get a Gmail account,” à la iMessage users/green texts.
You are 100% correct and yet the masses still prefer it.
World’s a twisted place!
I would guess the average Gmail user doesn’t know that it reports virtually all iCloud as Spam - believing instead that it’s genuinely being filtered by quality engineering at Google.
it will still be on "private.icloud.com". Just as filterable...
private.icloud.com (née privaterelay.appleid.com) is the address for “Sign In With Apple”, which is an oauth-style service that sites opt into to let you use your Apple ID to sign in. Sites offering this as a signup option are already aware it gives users an option to use a private anonymized email address.
The toplevel “Hide My Email” iCloud feature is a different thing, can be done independently of a SIWA flow (you can just go into settings and make more addresses, all it needs is a name and a notes field) and uses @icloud.com in order to make your anonymized email address look indistinguishable from other iCloud users.
The former is “filterable”, yes, but it’s moot because you only get those if you offer Sign In With Apple in the first place, and if you want real emails, you would already know to just… not do that.
The latter is very much not filterable.
The confusing thing though, is that when a user uses Sign In With Apple, they are offered two options: “share my email” which gives the site your real address, and “hide my email” which gives an @private.appleid.com address. But this “hide my email” option is a totally different thing from the separate “hide my email” service, which lets you make arbitrarily many @icloud.com private aliases to forward to your real address. Critically, the latter toplevel Hide My Email feature works with sites that don’t use Sign In With Apple. It’s just stupidly unfortunate that Apple calls both of these features “hide my email.”
Not arbitrarily many aliases - there's a limit of (as of two or three weeks ago) 768.
Others have addressed the validity of your comment, but I’d like to discuss another aspect. Even if it is filter, I think most people would not want to filter. Apple makes it very easy to use private relay and many people that buy Apple products do use private relay. Even if you know, it’s a private relay email address, surely you want a user who buys expensive technology products to use your website in almost all circumstances.
It won't. The news here is that it won't.
iCloud Hide My Email sharing the same domain with normal email (icloud.com) is the reason why I use iCloud over other email alias services like simplelogin and addy.
I've noticed a chilling new trend of apple listening to the community.
My guess is Ternus is starting to take more and more control. Tim was pretty absent and phoning it in the past few years.
Anyone have a theory why this even made it to this point? the switch was such obviously a bad idea. just corporate weirdness that no one there bothered to raise their hand and be like "uh, are we really doing this?" or was there a story here that anyone knows about?
It's email reputation, it the always the answer with this kind of stuff.
My guess is that the bounce rate got too high and bot farms were using iCloud addresses like this.
The bounce rate of what, exactly?
Because the bounce rate of Hide My Email addresses being deliverable is going to rise over time, by design.
Whenever I start getting spam at an address that's been leaked, I deactivate it. I've done the same with my oldest gmail account, but the work required there is notably higher.
If they were moved to plain old icloud.com, I could absolutely see a bunch of companies starting to filter out all icloud.com email addresses to avoid private relay. Either just because they’re jerks or from bounce issues.
Keeping it on a subdomain fixes that problem, to some degree. If the user is named ffjvhtu57325cjdjvg501a2@icloud.com no one is going to think that’s a real address. It’s very obviously a private one. So it’s not like they were “camouflaged.“
It’s a little odd they’re switching the subdomain though.
Hide My Email addresses are not just a random string at icloud.com. They use plausibly-human names, probably generated by a language model. There’s no easy-to-check pattern.
They’re not switching the subdomain. They’re keeping it the same. That’s the news.
They’re switching the subdomain for the “Sign in with Apple” sign ups, which is not the same service.
> If they were moved to plain old icloud.com, I could absolutely see a bunch of companies starting to filter out all icloud.com email addresses to avoid private relay.
I couldn't. "Uses Apple products" is one of the more reliable signals of willingness and ability to spend money on stuff online.
Hide My Email already uses plain old @iCloud.com as the domain.
They are not changing the subdomain. There isn’t one. The announcement is they are leaving it as-is.
The email addresses for sign-in with Apple do use the @private.iCloud.com subdomain, but again, that’s not a change.
Right, but I'm asking "what bounce issues?"
Like for my usage there are no bounce issues with the ~400 legitimate providers that I have Hide My Email addresses from. The only ones with bounce issues are the spammers who've acquired leaked addresses that I've deactivated.
If you merely deactivate your email address rather than closing your account or changing your notification settings or whatever, then the next time a legitimate service goes to send you a legitimate email that you asked for, it will bounce. In some sense this "shouldn't matter", as in a purely P2P system the only people who would notice are the sender and Apple -- and Apple knows what is going on, so should not penalize senders the way, say, Google would if they see you sending a ton of email to their domains and they all bounce -- but people tend to use services to help send email and centrally pool their reputation (such as mailchimp) and so these services themselves then watch the bounce rate of their individual customers and either charge them more or ban their access due to the bounce rate increase.
Is Apple really stupid enough that they BOUNCE emails after you deactivate, rather than just silent discard? What's the point of bouncing unwanted emails these days? It's not like these bounces go to humans who go "Oh, gee! This address must not work. Allow me to go and figure out how to contact him!" It's just a stream of full-on spam with completely fake return addresses, and crap from email campaign software.
Maybe hidemyemail allows easily creating many accounts on a site. And some big site didn't like it.
The "Sign-up via Apple" button and creating an iCloud email yourself have a slightly higher barrier than creating a new throwaway hidemyemail email (1 API call w/o captcha/phone verification or whatever).
We might find out later this year if some site starts blocking @icloud.com but keeps allowing @private.icloud.com.
It does, and I know a friend of a friend who uses them for Walmart accounts to bot pokemon drops. Those and office aliases.
Hmm it’s almost as if people are paying good money for iCloud+ or something. They aren’t google and shouldn’t be retiring their services as if they’re giving them away for free
While I applaud this specific change, Apple has been known to stick to their guns and I used to believe they were almost always in the right for doing so because it led to better outcomes. So my take is that it's chilling because Apple has so lost their way that they can't figure out these obviously stupid directions internally before making a fool of themselves to the public (and I agree with that take).
this opens some crazy "apple developer" dialog on my mac rather than a web page. I had to crank up chrome to read it. And it makes no sense, I have no clue what a sign on with apple address is. I guess I'm glad my hide my email addresses won't change because that would be a PITA.
I don't understand how this changes anything. IIRC, the complaints were about Apple making the Hide My Email addresses different than regular ones.
They're now saying the new domain will be private.icloud.com. Isn't it just as targetable?
It's talking about two different services:
> Sign in with Apple addresses, previously issued on privaterelay.appleid.com, will be issued on private.icloud.com.
> iCloud+ Hide My Email addresses will remain on icloud.com.
Sign in with Apple is Apple's SSO, like Sign in with Google. Services have to support this one explicitly, and it already had a special subdomain, so the specific subdomain is simply changing.
Hide My Email is the manually generated ones, for websites that accept an arbitrary email address. This is the one where it's valuable for the relays to be identical to genuine iCloud addresses, otherwise websites could try to block it and force you to use a more revealing email address, undermining privacy.
Good. What else can really be said? Only way for it to work and not be trivially blocked is to mix with legit emails.
A lot of places also don't really like icloud addresses in general. This is one of Apple's better offerings though.
I'm a bit confused - when i see these signups, they look like this to me:
rtwnj6tj7@privaterelay.appleid.com
How many sign ups you have with an @icloud.com address?
A lot of those are Hide My Email aliases that, by design, you can’t tell apart from real human addresses.
I think the post is very explicit. First sentence:
> Starting later this year, new Sign in with Apple addresses, previously issued on privaterelay.appleid.com, will be issued on private.icloud.com. Existing addresses on privaterelay.appleid.com will continue to work and forward mail to users without interruption.
That's the Sign in with Apple domain, not the Hide My Email domain. HME is remaining at icloud.com instead of moving to private.icloud.com as well. From the linked article:
> After further consideration and reviewing community feedback, iCloud+ Hide My Email addresses will remain on icloud.com.
Good. This would have made blocking them trivial.
Good! Was there ever a compelling reason why they went for this switch initially?
Yes, to fully fix a certain class of bug on their infra.
Do you know any more about it or have a link where I can read more?
I’ll try to add more later, but it is believed that multiple times, a bug in some random API has allowed for the “hidden” Apple account to be revealed because they resolve hide my emails to the original internally. Using a separate namespace would be the universal fix.
A mitigation for the cause of https://www.404media.co/apple-hide-my-email-vulnerability-re...
This doesn't follow. The bounce message used to (effectively) say,
> abc@icloud.com forwards to real@gmail.com
If they switched the new domain and did nothing else, it would say:
> abc@privaterelay.appleid.com forwards to real@gmail.com
That's no better. Fixing that privacy leak is unrelated to whatever the destination domain is.
No, using a different domain makes it easy to across the board add a rule: don’t treat as Apple ID.
https://news.ycombinator.com/item?id=48559935
If you dig more you could find the bug, but AFAIK it was that if you sent a large attachment, the bounce email would contain your real address.
That was a stupid idea (the prev one)
thank god -.-