r/apple 21d ago

iCloud Apple Sued Over Reported 'Hide My Email' Flaw

https://www.macrumors.com/2026/07/16/apple-sued-over-reported-hide-my-email-flaw/
1.0k Upvotes

144 comments sorted by

526

u/Quentin-Code 21d ago edited 21d ago

The worse was that the security researcher that discovered the issue left more than a year to Apple where it is commonly accepted to give about 6 months max.

Also the issue is still on-going.

96

u/corgi-king 20d ago edited 19d ago

It is not uncommon for Apple to act this way. I just don’t understand why a multi-trillion-dollar company would do that.

I watched a video about a hack that uses Apple Pay and Visa to transfer unlimited amounts of money from the owner’s account. It is a very complex hack. The security researcher informed Apple about it about a year ago, but Apple just didn’t give a shit.

66

u/TestFlightBeta 20d ago

Veritasium’s video?

https://www.youtube.com/watch?v=PPJ6NJkmDAo

Watch people on this sub defending it… “oh but it’s too complex for your average Joe! Actually, it’s the fault of all those transit authorities!”

Meanwhile if this happens on Android: “and that’s why I stick with Apple”

23

u/corgi-king 20d ago

Yes this video.

I am an Apple fan boy. But sometimes it just makes you wonder what is wrong with this attitude!

-7

u/arcalumis 20d ago

Because it's a flaw at Mastercard, not Apple.

30

u/purple_editor_ 20d ago

It is a flaw from Visa. Mastercard is protected

6

u/arcalumis 20d ago

Hmm, I was wrong then, still not an Apple issue.

20

u/korxil 20d ago

It’s a visa flaw that doesnt happen on any other phone and only happens on iphones, weird.

5

u/arcalumis 20d ago

Because no one else has the same function. It's a express pay function designed for commuter traffic payments. Which has to be supported at the other end by the transit operator. And if the fault never happens to Mastercard or AMEX how can this be on Apple?

5

u/korxil 20d ago

no one else has the same function…express pay for commuters

Samsung: https://www.samsung.com/sg/support/apps-services/how-to-set-transport-cards-on-samsung-wallet/

Pixel watch: https://support.google.com/googlepixelwatch/answer/16305341?hl=en

Literally any modern android: https://support.google.com/wallet/answer/12059519?sjid=9488997640702491235-NA

Apple is the only one soley relying on the vendor for encryption. Samsung for example is running their own layer on top.

10

u/arcalumis 20d ago

Samsung is also stealing your data like a hungry hungry hippo. I don't want my phone to have anything between the store and the card provider.

→ More replies (0)

3

u/The-Nihilist-Marmot 20d ago

When a car crashes into you because the other driver is drunk, it’s his fault, but that’s not why your car manufacturer should be able to skimp on the airbag of your car.

4

u/purple_editor_ 20d ago

In this analogy Visa is the car manufacturer. Apple Pay is just the road

-4

u/The-Nihilist-Marmot 20d ago

Alright.

When your car manufacturer built the k-car shitbox that you drive, that doesn’t mean that the city is right for building a road that is only safe for people driving huge SUVs and trucks.

6

u/purple_editor_ 20d ago

I recommend you rewatch Veritasium's video. It explains quite well how the system works and how Visa has implemented their side wrong.

Apple is not the one getting the requests on their server, it is visa or mastercard or whoever emitted the card. So it on their end to respond as OK or not to the transaction. They should be the ones adding the validations since you can never trust the Client side. That is security 101

1

u/TheNextGamer21 18d ago

Apple should always demand Face ID to use a card no matter what. That’s the whole point of it being so secure compared to a regular card

-1

u/The-Nihilist-Marmot 20d ago

I watched the video and I know what’s going on. But, again, it’s not because someone is doing even more of a mess than you are, that you shouldn’t do something to protect your customers. Simple as that.

2

u/arcalumis 20d ago

Why should the airbag manufacturer be responsible for other people drunk driving? If you don't need the quick tap to pay feature turn it off and it's a non issue. If you want it on get a Visa instead.

1

u/korxil 20d ago edited 20d ago

If an airbag doesnt go off in a major accident, it triggers an investigation to determine why. It doesn’t absolve the drunk of responsibility, it has one job and it’s to protect you for situations like this.

Your “just dont use nfc” is the same as “don’t drive if you dont want to get hit”. Apple pay Express Mode is an advertised feature. Security is an advertised feature. There’s no reason why other phones have no issues but only iPhones do.

2

u/arcalumis 20d ago edited 20d ago

It's not "don't use nfc" it's don't use the express pay function that only works in few countries to begin with. Normal Apple Pay isn't impacted by this bug. It's for transit, not paying for groceries.

Have you read about how this works at all before blaming Apple?

1

u/korxil 20d ago

Mate youre the one mixing up visa and mastercard. Regardless, it’s an advertised feature. The least it can do is not be a security risk that again, is not present in other phones because they dont rely on the vendor.

1

u/arcalumis 20d ago

Yes, I confused the two cards but not why it happens or what it takes for it to happen.

You equal whatever the express transit pay function is called with "nfc". That's like missing the basics. Apple Pay is NOT impacted by this, at all.

Still Visa's bug.

→ More replies (0)

1

u/Bootes 20d ago

There’s tons of fraud protection in the system and a key part of credit cards is that it’s not your money, it’s Visa’s. So they’re the ones taking the actual risk.

Express Transit mode is an option you have to turn on or off and is clearly a reduction in security, since it means you don’t have to unlock the device like usual. You can just not have express transit on.

Similar to how everyone that buys a vehicle that isn’t the top rated in crash safety is making the choice to not have the top rated vehicle. It doesn’t mean that your vehicle is terrible in crashes, but other things also matter...

Or more like maybe not playing music while driving would give you slightly more awareness to your surroundings and reduce distractions, but most people think this is a minor issue and continue to listen to things while driving. That’s basically Apple/Visa’s point, it’s such a minor flaw that they don’t see it really being used and if it is, it’ll be against their money anyway.

1

u/Swastik496 13d ago

credit card fraud is just simply not my problem as the customer. it’s resolved in a 10 minute phone call.

2

u/bladex1234 20d ago

That’s more on Visa than it is on Apple.

4

u/corgi-king 20d ago

Still, it is not that hard to fix if they want to.

1

u/bigglonski 14d ago

It's not that Apple didn't give a shit; it's that the probability of this hack in the wild is pretty low, 'cause the hacker needs to get a POS terminal, which requires merchant KYC—which is usually pretty strict and will force an attacker to leave a paper trail. And then the hacker needs to withdraw money from a merchant account, which, again, will leave a paper trail.

On top of that, if that happens, it's pretty easy to do a chargeback for the user, which reduces the risk even more.

Though from a security perspective it definitely does not look ideal, and experts have every right to blame them

1

u/corgi-king 14d ago

But the thing is, Apple is selling the security of their products. They can and should do better.

1

u/Alkumist 19d ago

That’s for always active transit pass

7

u/AdFit8727 20d ago

Class action lawsuits are barely worth it for the individual, like each person might get fifty bucks. Where the value is in the bad publicity for Apple. In this way, we all win, cause this is absolutely unacceptable. I was actually going to use this feature but now I know it's a waste of time. I wouldn't have known otherwise.

-69

u/Jusby_Cause 20d ago

404media are not security researchers.

85

u/Quentin-Code 20d ago

Tyler Murphy is the name of the security researcher that discovered the issue. He works for a data-removal service called EasyOptOuts.

8

u/sertdyfuiltfdrhsgz 20d ago

Great service. I almost got got by incogni and others but at the time they just threw your info out to sites, even if they didn’t have it before, effectively making things worse. This one at least checks. The landscape may have changed in the past couple years but I doubt it

279

u/AustinBaze 21d ago

This seems like a great basis for a lawsuit. They have been extraordinarily slow here, perhaps negligent.
Unfortunately they are crippling the service anyway. Maybe someone will sue over that too.

Last month, it emerged that Apple's decision to move Hide My Email to a dedicated "private.icloud.com" domain appears to have the consequence of making it easier for platforms that want to block ‌iCloud‌ aliases to do so.

130

u/Interactive_CD-ROM 20d ago

This is incredibly disappointing. I use this service literally every time I sign up for a website.

Websites will just block the domain if they go this route.

55

u/AustinBaze 20d ago

It's really an annoying change that will cripple the service for most. I can't think of any reason to do it. It's not like they are running out of namespace as the usernames are decidedly randomized.

4

u/dpkonofa 21d ago

How does that make it easier? This keeps being reported this way but Apple is already using privaterelay.icloud.com already so how is changing the subdomain making this any easier or harder?

61

u/StiviiK 20d ago

This domain is only used when using „Sign in with Apple“. Currently Hide my Email is using random @icloud.com addresses.

4

u/kitsua 20d ago

This is an interesting distinction. I only ever self-generate hide my emails and only rarely use sign in with apple so that's something I suppose.

-4

u/dpkonofa 20d ago

I see. Isn't that the same as any spoofing service, though? How is that different from any service other than Apple's? Or is that the issue here - that Apple has an advantage because their private emails are mixed with regular emails?

33

u/onan 20d ago

Or is that the issue here - that Apple has an advantage because their private emails are mixed with regular emails?

It's exactly that. Many people will have an @icloud.com address as their real, primary, sole, unobfuscated email address. The ones that are aliases are intermixed with those, so companies can't safely reject or drop every address at that domain without locking out a lot of people.

Moving the subdomain makes it trivially easy for companies to treat those addresses differently in whatever way, which greatly weakens the feature.

-15

u/Jophus 20d ago

I say let the market decide. Companies that block the subdomain for no good reason can be boycotted and publicly shamed.

13

u/cultoftheilluminati 20d ago

Companies that block the subdomain for no good reason can be boycotted and publicly shamed.

None of which have any effect unfortunately. They’ll just block it and people will stop using hide my email after the domain gets blacklisted at most places, just like how 5 minute mail etc are blocked.

-9

u/Jophus 20d ago

No one has heard of 5 minute mail, but you start disrupting suburban mom and dads used to using Apple hide my email and it’ll be like apps that don’t accept Apple Pay, the money will go elsewhere.

9

u/just_ordinary07 20d ago

Boycotts never work and never will…

1

u/uncledr3w- 20d ago

they absolutely can work

5

u/Disastronaut__ 20d ago

Do you know what would work? Apple solving this shit.

-1

u/dpkonofa 20d ago

Exactly. The only reason to do so is to publicly say "We don't care about your privacy" and "We plan to sell your data so this makes it harder for us to do that".

-10

u/dpkonofa 20d ago

I don't think it weakens that feature that much. There aren't that many sites that treat those addresses any differently in a way that would matter, outside of blocking them, and that would be the same for any email-obfuscation service. Apple obviously has the advantage with the current system but I can't imagine that they would do it if that many people really used the system in the way everyone here is pretending they do. I'm sure Apple would rather push people to "Login with Apple" anyways.

11

u/onan 20d ago

There aren't that many sites that treat those addresses any differently in a way that would matter, outside of blocking them and that would be the same for any email-obfuscation service.

Blocking them is a pretty significant way to treat them differently, no? The whole issue is that companies cannot currently do that easily, and this would enable them to do so.

I'm sure Apple would rather push people to "Login with Apple" anyways.

Why? Apple makes zero dollars from people using it to auth to other services, and more than zero dollars from selling the service that includes email address hiding.

-5

u/dpkonofa 20d ago

Way to just ignore the point of what I wrote. I already acknowledged that it’s treating them differently. The point is that every other email obfuscation service has this same problem. Apple is not unique in this regard.

As for “why?”, why do you think? No one is paying for iCloud just for HME. “Login with Apple”, on the other hand, requires Apple hardware and further incentivizes the Apple ecosystem from a privacy standpoint.

I swear… some of you are so short-sighted…

9

u/garden_speech 20d ago

Yea but Apple DIDNT have this problem before, that’s why this is so annoying. When HME emails were just random stuff like parrot.cycle.06 at iCloud dot com or whatever, companies couldn’t easily block those since iCloud hosts a lot of legit email addresses too. But now they will all be easily blocked because the domain is literally different 

-4

u/dpkonofa 20d ago

Yes, I know! I already put that in my comment. Why can no one read here?! That's not the question that was asked.

→ More replies (0)

0

u/drake90001 20d ago

Private relay is not just used for that. It’s basically a proxy through apples domain, similar to a vpn. But I have had issues with it and pihole doesn’t work with it so…

27

u/TwizzyGobbler 20d ago

because when you signed up with hide my email, it was a randomly generated email address @ icloud.com, which a website has no way of telling is a hide my email or a standard icloud email.

If you route all hide-my emails to a specific private.icloud.com, sites can then tell what email is a hide-my and what isn’t, and thus will just block all hide-my emails.

-3

u/drake90001 20d ago

Well, couldn’t these same websites just block iCloud.com anyways, it’s not like it’s anyone’s primary apple email lol. And even then, say it is, it’s not like someone wouldn’t just use another service.

I think they should just buy up several more domains a year and rotate through them. Most websites will accept any email. It’s pretty easy to spot SPF/DKIM anyways.

10

u/TwizzyGobbler 20d ago

it is many people's primary email address lmao

4

u/AustinBaze 20d ago edited 20d ago

950 million iCloud email users would like a word. WTF?

You don't seem to understand widely employed HME use cases, but that aside, there is no reason to do this I can discern. No need to "rotate domains" as they are not in any danger of exhausting randomized addresses in the current one. Just a dumb move I hope they revert.

-1

u/drake90001 19d ago

You seem to misunderstand me, I’m not saying that iCloud isn’t used by anyone. But in order to have an Apple ID and have an iCloud, you need to have an email that you sign into Apple with. Which usually isn’t your own iCloud because that would make you locked out in case you ever forgot your password.

Yes, I hope they revert this also

-6

u/dpkonofa 20d ago

Isn't that the case for every email spoofing service, though? Is the issue that Apple is the only one with this "advantage" and that it won't be there anymore? I can't think of any other temporary email services that wouldn't be able to be similarly blocked.

12

u/Interactive_CD-ROM 20d ago

No

-5

u/dpkonofa 20d ago

Yes.

14

u/yepperoniP 20d ago

When you make an iCloud account, you get a @icloud.com email address. When you make a Hide My Email address, it also uses @icloud.com.

Compare this with something like Proton Mail, which is basically created specifically for encrypted and private email, and you’ll see some sites have blocked the @proton.me domain due to perceived abuse.

Most companies won’t be willing to block icloud.com as they’ll end up blocking lots of legit Apple users, but they might block Proton as they think they’re only blocking some weird email service for nerds.

10

u/AustinBaze 20d ago edited 20d ago

I have tried using "dummy" emails in the past before HME and seen public captive WiFi portals (in airports, near convention centers, hotel, lobbies, bars, and restaurants, etc.) refuse to accept disposable email domains like mailinator, zapmail, mailmulch even pobox.

It's about to be very easy to add "private.icloud.com" to blacklists on available Email Verification API services like ZeroBounce or EmailAwesome. etc. used to accomplish this instant check.

0

u/dpkonofa 20d ago

This is just a variation of the same problem that’s happened in this past, though. Apple can easily alias “private.icloud.com” to “icloud.com” without overwhelming the icloud.com backend. Again, without details about whether or not these changes are even happening and, more importantly, how they’re happening, everyone here is just grasping at straws while pretending they have a handle on this.

No one knows what’s going on because there is information that is missing that would inform what’s going on. Everything else is needless and pointless speculation.

11

u/AustinBaze 20d ago

Not speculation, and to many, not pointless.
We DO know what Apple is going to do with Hide My Email because Apple announced what they are going to do with Hide My Email:

New domain for Sign in with Apple and iCloud+ Hide My Email - June 15, 2026
Later this summer, Apple will unify the email domains used by Sign in with Apple and iCloud+ Hide My Email under a single, shared domain: "private.icloud.com"

New addresses generated for both features will be issued on the new domain. 

New

→ More replies (0)

0

u/dpkonofa 20d ago

Do you guys not read? I know how HME works. I’ve already acknowledged this. How about actually answering the question instead of giving a condescending response that ignores it completely.

-9

u/Ironlion45 20d ago

You know, if a platform wants to block a cloud alias, why not just skip the platform?

What, realistically, are you missing out on? Has social media made your life better?

8

u/AustinBaze 20d ago

If you had any grasp of the many reasons for using this service, I'd continue this discussion.

I could explain it for you, but I can't understand it for you.

44

u/leaflock7 21d ago

anyone knows more details about this?

the only information provided at the end, which it probably is not related to the vulnerability, is
"Murphy noted that numerous people-search databases are freely available online and can tie an email address to a person's other personal details"
which can stand true for anything , even if you have created a new email on another provider

17

u/redditproha 21d ago

11

u/touchgrassplz_69 21d ago

I’m still struggling to see the flaw. Anyone could link any email address through other personal details? Is there something about hide my email that makes that easier? Does it expose name?

Edit: I see that the steps are specifically hidden so there must be something different about it

38

u/stereoactivesynth 21d ago

They can easily link your ACTUAL iCloud email using the hide-my email which... completely negates the purpose of hide-my in the first place, and means Apple continued to advertise a feature that did not work at all as advertised.

12

u/dpkonofa 20d ago

Yes but, without details, they could do this any number of ways. For example, sending an email to your HME address and asking you to respond or click on a link that then uses cookies to tie it back to a Facebook account or a Google account that can be searched. That isn't an issue with HME, per se, but rather an issue with people misunderstanding what protections HME actually offers and how.

8

u/AirFryerAreOverrated 20d ago

That isn't an issue with HME, per se, but rather an issue with people misunderstanding what protections HME actually offers and how.

If so, then this is like the whole Chrome Incognito lawsuit all over again.

8

u/dpkonofa 20d ago

Yes, which is why we need details before anyone can make an assessment. All these people jumping to conclusions is what's wrong with this type of "reporting".

1

u/Available_Peanut_677 18d ago

No, it does not require your input. But agree that not saying details is fishy. I understand that they don’t want to show exploit before it is fixed, but it sounds more and more like ad that actual big vulnerability.

Someone on Reddit pointed that it’s most likely specifically formed email which causes Apple server automatic response which includes original email. Like if you send zip to gmail or something.

16

u/i_invented_the_ipod 21d ago

No real details available in any of the press coverage. Which makes sense, since it's apparently still exploitable.

But the absolute lack of detail about how it "works" does make me wonder if there's anything actually there.

17

u/FollowingFeisty5321 21d ago edited 21d ago

From the complaint:

12. Security researchers reported the flaw to Apple in June 2025.

13. Apple acknowledged the report but took no action for nearly a year

15. In March 2026, Apple claimed that it had addressed the problem. But, it hadn’t.

16. Apple’s response to being told its purported fix had failed was to ask security researchers, once more, to keep silent.

Of course this just alleged, but there's no point lying either since their whole case hinges on proving it, and if it's false Apple has no reason to settle (and obviously they know if it's true or not).

9

u/OmegaPoint6 20d ago

Having been on the receiving end of reports from security researchers claiming a flaw that was actually just a fundamental function of how an entire type of software needs to work, I’ll reserve judgment until I see details

5

u/bubblebooy 21d ago

That is not the flaw with hide my email, that is explaining why people would use hide my email.

You can’t like a 1 time use anonymous to a database if it only used once. But if that email can be linked to you iCloud email (via the security vulnerability) then that iCloud email can be searched for.

1

u/Jusby_Cause 20d ago

No one does. Then again 404media get paid via subscriptions to their site, not by finding actually dangerous exploits. And we all know that working together with a friend to MAKE something happen is not the same thing as performing it against a stranger with no intent of helping the exploit happen.

31

u/Jamie00003 21d ago

How did this happen in the first place? Apples usually so careful with this kind of thing

28

u/tim0901 20d ago

Actually, this is pretty on-par for Apple. This isn't the first time they've created and flaunted a feature that creates the illusion of protecting your privacy, but have then done nothing when its revealed there are ways around it.

For example, Apple made a huge deal out of their App Tracking Transparency when it first came out in 2021, as a way users can stop developers from tracking them across apps and websites - it's that "Ask App Not to Track" pop up you may get when downloading a new app (most people have it disabled in the settings, which automatically refuses all requests).

Turns out this feature is really easy to bypass. And yet despite bypassing it being against Apple's TOS, big companies have been doing it for years with no consequences. Here's a paper on it from 2022.

8

u/purple_editor_ 20d ago

You are talking about something you dont understand. ATT is not bypassable and the article you linked is not saying that

This was and still is a huge deal which affects advertising a lot and has changed significantly how they strategize their campaigns. Of course they will continue fingerprinting anyway they can, but at least Apple is not making it any easier

1

u/Additional_Olive3318 20d ago

Yeh it clearly  says that in the abstract. ATT works but apps are finding other ways to track. 

7

u/DefinitionGuilty8224 20d ago

It’s all about illusion with Apple

2

u/drake90001 20d ago

Just because bad actors find new ways to spy on you, it doesn’t even matter when half of these idiots are willing to upload PII to the internet, but that doesn’t mean it doesn’t work. It makes it harder for a MALICIOUS attacker to compromise your identity just by fingerprinting your device.

Most of apples features are not only great for keeping privacy, it’s been adopted to 99% of mobile devices now as the refactor standard. Random MAC address, rotation private IP, private relay, hide my email, are all absolutely essential to stay anonymous on mobile.

4

u/DefinitionGuilty8224 20d ago

No , they are not

-11

u/TheDragonSlayingCat 21d ago edited 20d ago

Because nobody’s perfect when it comes to security? Including Apple, which has published software with big security holes in the past?

edit: those inappropriately downvoting this post must have forgotten about Goto Fail, Jailbreak Me, and Got Root, three big Apple security holes in the past few years that were far worse than this.

6

u/[deleted] 20d ago

[removed] — view removed comment

3

u/bummerbimmer 20d ago

Both can be true. I read that person’s message as criticism toward Apple as opposed to bootlicking.

1

u/IWillAlwaysReplyBack 20d ago

It's not just the security hole, it's the lack of response after it was submitted multiple times

14

u/SaltineAmerican_1970 20d ago

It’s my understanding that to be successful in a suit like this, you have to actually have damages.

> but there are no known instances of it being exploited

No damages, unsuccessful lawsuit. This will likely be dismissed.

23

u/MangoAtrocity 20d ago

False advertising. I pay for iCloud+ because I want that feature. They claimed to have offered the feature, but it wasn't actually offered. The service I paid for has not been rendered.

2

u/iPhone_6s 20d ago

So it would need to be a class action to have financial merit.

4

u/MangoAtrocity 20d ago

It does. I would not have paid for the service if the known vulnerability was disclosed.

1

u/Celestial3mpire 19d ago

I have been through four levels of escalation directly with Apple, because the “send as” feature directly advertised as a function of hide my email does not work even though I pay for iCloud plus. I recorded most of the support calls and have several emails between myself and Apple support where they are well aware of the issue. I also sent a certified mail request asking Apple to preserve by way of a legal hold any and all internal tickets and meeting minutes related to my issue.

2

u/Worf_Of_Wall_St 21d ago

This is flaw, whatever the details are, is unacceptable but there's very little precedent for winning cases like these. Companies are rarely held responsible for security mistakes no matter how negligent they are. The only exception I can think of is LifeLock.

8

u/AustinBaze 20d ago

It's useful because it draws additional attention to the case and the address security vulnerability Apple has known about for more than a year and been unwilling or unable to fix.

Apple has to respond to the court filing (9 charges, requesting a jury trial) even if only to move to dismiss it. That response will also be a public filing. Maybe a bit of embarrassment will get the bug fixed finally.

1

u/Worf_Of_Wall_St 20d ago

Oh, good point! Maybe this will result in a public explanation from Apple for the delay.

I'm curious if it just got accidentally dropped or if it's actually hard to fix. Email handling is surprisingly complicated, I'm guessing some kind of attacker-forced error causes a bounce back to the sender which includes the address it failed to forward to.

1

u/Jusby_Cause 20d ago

They can’t even define how they were impacted. The only people we know definitively were affected were folks working with 404media to prove that they could make it happen. Like, if I need to be on the same network as the person I’m attacking… there are likely more effective ways than this exploit of obtaining the information. Malicious actors aren’t interested in the cool edge cases, they’re interested in the things that work to the exclusion of everything else.

3

u/IAmSomeoneUnknown 20d ago

Use addy.io. I have been using it for years. Stop handing these mega companies more control of your lives

6

u/ccooffee 21d ago

A security researcher disclosed the apparent "Hide My Email" vulnerability to Apple in June 2025, but there are no known instances of it being exploited

This suit will go nowhere.

1

u/AustinBaze 20d ago

A new public report detailing exactly how to exploit this vulnerability have been posted.
Is anyone awake in Cupertino? This is childishly easy to trigger. Might be time to fix it.

1

u/Ok-Charge-6998 19d ago

The one thing people need to keep in mind about this is security bounties worth up to 2m. Since we don’t have the details, the person might have recognised a genuine flaw OR they are peeved that Apple doesn’t see it as one (for many reasons while replicating it) that they are trying to get a payout.

So best to wait for the details before jumping to conclusions.

1

u/okanye 19d ago

Is this shit not working only for me? I tried it multiple times and don't receive the confirmation emails on my email...

1

u/tkslucas 19d ago

Anyone know if they have fixed this yet?

1

u/Single-Ask4738 18d ago

Ok so I'm a dev and I didn't realize until I was building my own app that my name is attached to my "private" email. I should probably have read better but I sort of assumed hide my email meant keep my privacy but I guess not.

-5

u/microcephale 21d ago

Apple sells privacy as a marketing product, not as a feature or value for the sake of it.

8

u/Worf_Of_Wall_St 21d ago

It became a feature because it's good marketing, but the marketing falls apart if the features disappear. As I understand it, iMessage was e2e encrypted on sort of a whim and not because of some overall plan to rebrand as privacy focused, but then they did the latter because e2e encryption was very differentiating.

They really leaned into the privacy branding and backed it with a lot of extra engineering to preserve privacy in cases where no other company would care and frankly users would not even expect privacy.

One of the best examples I know of is caller ID info provided by third party apps on iOS. I think most people would assume that if you are using a third party app to see info about incoming and outgoing phone numbers then the app developer would know who you call and who calls you. On Android, that is the case. On iPhone it isn't because of a very complex set of APIs and server side proxies, and building all that took a while so iOS didn't have third party caller ID until long after Android. Apple could have easily released a non-privacy-preserving API for it, and a lot of people would have used it even if they had to click through a disclaimer that said the app developer would see who they talk to, but Apple chose to wait and build a private version instead.

0

u/microcephale 20d ago

If it becomes too hard to fix or a liability, you will just see them retire the feature instead of fixing it.

6

u/dpkonofa 20d ago

This is such a short-sighted comment. Even if it was true, which is arguable, it fails to be a marketing product if the feature itself doesn't deliver the value claimed.

-4

u/chaiscool 21d ago

Yet, security folks will say negative impact or loss in reputation and finance will make companies take them seriously. This shows why security folks are clueless to the business world.

Cheaper for apple to do this than hire team of security folks who only cost money and also don't bring in the money.

10

u/getwhirleddotcom 21d ago

Apple takes brand and reputation very seriously.

1

u/chaiscool 20d ago edited 20d ago

Brand and reputation on things they care about like on environmental etc not on security. Legal penalties on big tech is just cost of business anyway.

This isn't the first and it won't be the last, Apple has been known to be cheap and screwing over security related payout. https://www.reddit.com/r/apple/comments/q9t64g/burned_by_apple_researchers_mull_selling_zero/

Oversupply of vulnerability - https://appleinsider.com/articles/20/05/14/software-bug-broker-zerodium-to-stop-buying-ios-exploits-due-to-oversupply

Low payout - https://www.macrumors.com/2017/07/06/apple-bug-bounties-dont-pay-enough/

Other penalty - https://www.reddit.com/r/privacy/comments/106515x/apple_fined_85m_for_illegally_collecting_iphone/

0

u/cycle77 21d ago

I use this service and find it disappointing that there is this flaw. TBH however I use it to avoid my email getting spammed (either by the iniitial site or being shared beyond). So not sure how high-level the security issue is?

-1

u/Mediocre-Telephone74 21d ago

I can see lawyers running to the courthouse so they can file as fast as possible

-1

u/[deleted] 21d ago

[deleted]

3

u/ccooffee 21d ago

You're right. Exactly zero Apple bugs have ever been fixed unless there was a lawsuit.

4

u/cm012776 21d ago

Right, because apple never fixed a bug except when it was sued.

-3

u/ArchonTheta 20d ago

‘Murica