{"id":18047,"date":"2022-02-02T10:47:34","date_gmt":"2022-02-02T18:47:34","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2022\/02\/02\/news-11780\/"},"modified":"2022-02-02T10:47:34","modified_gmt":"2022-02-02T18:47:34","slug":"news-11780","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2022\/02\/02\/news-11780\/","title":{"rendered":"Apple\u2019s Private Relay Roils Telecoms Around the World"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/media.wired.com\/photos\/61ddf650f355cd4b7989ff3d\/master\/pass\/Security-Apple-Private-Relay-1331041563.jpg\"\/><\/p>\n<p><strong>Credit to Author: Matt Burgess| Date: Tue, 11 Jan 2022 21:31:20 +0000<\/strong><\/p>\n<p class=\"BylineWrapper-iiTsTb hAGfXd byline bylines__byline\" data-testid=\"BylineWrapper\" itemprop=\"author\" itemtype=\"http:\/\/schema.org\/Person\"><span itemprop=\"name\" class=\"BylineNamesWrapper-dbkCxf erRIa-D\"><span data-testid=\"BylineName\" class=\"BylineName-cKXFOb UCAzg byline__name\"><a class=\"BaseWrap-sc-TURhJ BaseText-fFzBQt BaseLink-gZQqBA BylineLink-eZnyPI eTiIvU mEZDb fNdcwQ bKZMMS byline__name-link button\" href=\"\/author\/matt-burgess\">Matt Burgess<\/a><\/span><\/span><\/p>\n<p>To revist this article, visit My Profile, then <a href=\"\/account\/saved\">View saved stories<\/a>.<\/p>\n<p>To revist this article, visit My Profile, then <a href=\"\/account\/saved\">View saved stories<\/a>.<\/p>\n<p><span class=\"lead-in-text-callout\">When Apple pushed<\/span> <a href=\"https:\/\/www.wired.com\/story\/apple-iphone-ios-15-ipados-15-new-features\/\">iOS 15<\/a> out to more than a billion devices in September, the software update included the company\u2019s first VPN-like feature, <a href=\"https:\/\/www.wired.com\/story\/new-privacy-security-features-ios-15-macos-monterey\/\">iCloud Private Relay<\/a>. The subscription-only privacy tool makes it harder for anyone to snoop on what you are doing online, by routing traffic from your device through multiple servers. But the tool has faced pushback from mobile operators in Europe\u2014and more recently, by T-Mobile in the US.<\/p>\n<p class=\"paywall\">As Private Relay has rolled out over the past few months, scores of people have started to complain that their mobile operators appear to be restricting access to it. For many, it\u2019s impossible to turn the option on if your plan includes content filtering, such as parental controls. Meanwhile in Europe, mobile operators Vodafone, Telefonica, Orange, and T-Mobile have griped about how Private Relay works. In August 2021, according to a report by the <a data-offer-url=\"https:\/\/www.telegraph.co.uk\/business\/2022\/01\/09\/apple-fire-iphone-encryption-tech\/\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/www.telegraph.co.uk\/business\/2022\/01\/09\/apple-fire-iphone-encryption-tech\/&quot;}\" href=\"https:\/\/www.telegraph.co.uk\/business\/2022\/01\/09\/apple-fire-iphone-encryption-tech\/\" rel=\"nofollow noopener\" target=\"_blank\"><em>Telegraph<\/em><\/a>, the companies complained the feature would cut off their access to metadata and network information and suggested to regulators that it should be banned.<\/p>\n<p class=\"paywall\">\u201cPrivate Relay will impair others to innovate and compete in downstream digital markets and may negatively impact operators\u2019 ability to efficiently manage telecommunication networks,\u201d bosses from the companies wrote in a letter to European lawmakers. However, Apple says that Private Relay doesn\u2019t stop companies from providing customers with fast internet connections, and security experts say there\u2019s been little evidence showing Private Relay will cause problems for network operators.<\/p>\n<p class=\"paywall\">Apple\u2019s Private Relay isn\u2019t a <a href=\"https:\/\/www.wired.com\/story\/best-vpn\/\">VPN<\/a>\u2014which carriers freely allow\u2014but it has some similarities. The option, which is still in beta and is only available to people who <a href=\"https:\/\/www.wired.com\/story\/how-to-icloud-new-security-features\/\">pay for iCloud+<\/a>, aims to stop the network providers and the websites you visit from seeing your IP address and DNS records. That makes it harder for companies to build profiles about you that include your interests and location, in theory helping to reduce the ways you\u2019re targeted online.<\/p>\n<p class=\"paywall\">To do this, Private Relay routes your web traffic through two relays, known as nodes, when it leaves your iPhone, iPad, or Mac. Your traffic passes from Safari into the first relay, known as the \u201cingress proxy,\u201d which is owned by Apple. There are multiple different ingress proxies around the world, and they\u2019re based in multiple locations, Apple says in a <a data-offer-url=\"https:\/\/www.apple.com\/privacy\/docs\/iCloud_Private_Relay_Overview_Dec2021.PDF\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/www.apple.com\/privacy\/docs\/iCloud_Private_Relay_Overview_Dec2021.PDF&quot;}\" href=\"https:\/\/www.apple.com\/privacy\/docs\/iCloud_Private_Relay_Overview_Dec2021.PDF\" rel=\"nofollow noopener\" target=\"_blank\">white paper<\/a>. This first relay is able to see your IP address and the Wi-Fi or mobile network you are connected to. However, Apple isn\u2019t able to see the name of the website that you\u2019re trying to visit.<\/p>\n<p class=\"paywall\">The second relay your web traffic passes through, known as the \u201cegress proxy,\u201d is owned by a third-party partner rather than Apple itself. While it can see the name of the website you\u2019re visiting, It doesn\u2019t know the IP address you\u2019re browsing from. It instead assigns you another IP address that\u2019s near where you live or within the same country, depending on your Private Relay settings.<\/p>\n<p class=\"paywall\">The result is, neither relay knows both your IP address and the details of what you\u2019re looking at online\u2014whereas a typical a VPN provider will <a href=\"https:\/\/www.wired.co.uk\/article\/free-vpn-android-ios-privacy\">process all your data<\/a>. Also unlike a VPN, Apple\u2019s system doesn\u2019t let you change your device\u2019s geographic location to avoid regional blocks on content from Netflix and others.<\/p>\n<p class=\"paywall\">Private Relay\u2019s potential scale, relative to VPNs, may have prompted telecom concerns. \u201cIt is far more accessible than a VPN that you have to download and register for and set up separate payment for,\u201d says Nader Henein, a research vice president specializing in privacy and data protection at Gartner. Apple has made Private Relay opt-in while it is still in beta, although it\u2019s still potentially available to <a data-offer-url=\"https:\/\/9to5mac.com\/2021\/04\/28\/apple-services-hit-660-million-subscribers\/\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/9to5mac.com\/2021\/04\/28\/apple-services-hit-660-million-subscribers\/&quot;}\" href=\"https:\/\/9to5mac.com\/2021\/04\/28\/apple-services-hit-660-million-subscribers\/\" rel=\"nofollow noopener\" target=\"_blank\">millions of subscribers<\/a>. (Apple has bent to some local laws and not made Private Relay available in China, Belarus, Kazakhstan, Saudi Arabia, and a handful of other countries.) \u201cThe concern is that a lot of people are just going to switch it on, and it&#x27;s going to obscure a large part of the network from the network operators,\u201d Henein adds.<\/p>\n<p class=\"paywall\">However, he says if telecoms companies do imagine they\u2019ll lose sight of how people are using their networks, they should present their evidence transparently by making their modeling public. Equally, Henein says, to address questions about European \u201cdata sovereignty,\u201d Apple should make clear what companies it has partnered with for the feature\u2014it says they are some of the largest content delivery networks\u2014and the locations of the relays.<\/p>\n<p class=\"paywall\">\u201cWhile I agree that in certain custom ways this potentially might complicate some technology planning or management, in general we must stress that there is no issue here,\u201d says Lukasz Olejnik, an independent privacy researcher and consultant. He says that while network operators are likely to lose access to metadata that can describe where users connect to their services, this shouldn\u2019t be a barrier to them understanding what\u2019s happening more broadly across their networks. \u201cTelecom operators should already be comfortable with network neutrality, so simply managing the lower technical layers of the networks,\u201d Olejnik says. \u201cIt should not be their problem with what happens in the upper layers.\u201d<\/p>\n<p class=\"paywall\">Multiple mobile network operators have not responded to questions about their plans for Private Relay at the time of writing. It is unclear whether the companies have changed their positions since complaining to European regulators last summer. In a statement to <a data-offer-url=\"https:\/\/9to5mac.com\/2022\/01\/10\/t-mobile-block-icloud-private-relay\/\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/9to5mac.com\/2022\/01\/10\/t-mobile-block-icloud-private-relay\/&quot;}\" href=\"https:\/\/9to5mac.com\/2022\/01\/10\/t-mobile-block-icloud-private-relay\/\" rel=\"nofollow noopener\" target=\"_blank\">9to5Mac<\/a>, T-Mobile US said any limits on Private Relay have happened across its network because accounts have parental controls enabled and content filtering isn\u2019t compatible with Apple\u2019s tool. The publication says some users have seen the block despite not having filtering enabled. Other reports say that Private Relay clashes with <a data-offer-url=\"https:\/\/tmo.report\/2022\/01\/t-mobile-blocking-icloud-private-relay-for-some-but-its-not-what-you-think\/\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/tmo.report\/2022\/01\/t-mobile-blocking-icloud-private-relay-for-some-but-its-not-what-you-think\/&quot;}\" href=\"https:\/\/tmo.report\/2022\/01\/t-mobile-blocking-icloud-private-relay-for-some-but-its-not-what-you-think\/\" rel=\"nofollow noopener\" target=\"_blank\">T-Mobile&#x27;s existing content filtering<\/a>. Within Private Relay\u2019s settings, Apple says that networks that need to audit traffic or perform content filtering will block access to Private Relay. It says this may include companies, schools, or mobile network operators.<\/p>\n<p class=\"paywall\">\u201cPrivate Relay makes it impossible to enable the potential security protections, like ones aimed at parental settings aimed at children,\u201d Olejnik says. \u201cBut this should be a conscious decision left to the user.\u201d A <a data-offer-url=\"https:\/\/community.ee.co.uk\/t5\/Apple\/iCloud-Private-Relay-How-it-might-impact-your-online-experience\/td-p\/1077555\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/community.ee.co.uk\/t5\/Apple\/iCloud-Private-Relay-How-it-might-impact-your-online-experience\/td-p\/1077555&quot;}\" href=\"https:\/\/community.ee.co.uk\/t5\/Apple\/iCloud-Private-Relay-How-it-might-impact-your-online-experience\/td-p\/1077555\" rel=\"nofollow noopener\" target=\"_blank\">guide<\/a> from UK mobile network EE says that because it can\u2019t see what you\u2019re browsing, it isn\u2019t able to moderate content for those with parental control settings turned on\u2014it also says data plans with unlimited access to some games, music, and video will not operate properly. In evidence submitted to the UK\u2019s parliament, network operator BT Group, which owns EE, <a data-offer-url=\"https:\/\/committees.parliament.uk\/writtenevidence\/38771\/html\/\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/committees.parliament.uk\/writtenevidence\/38771\/html\/&quot;}\" href=\"https:\/\/committees.parliament.uk\/writtenevidence\/38771\/html\/\" rel=\"nofollow noopener\" target=\"_blank\">said<\/a> Private Relay would pose \u201csignificant challenges\u201d if it is needed to block websites or services under the UK\u2019s <a href=\"https:\/\/www.wired.co.uk\/article\/online-harms-white-paper-uk-analysis\">planned internet safety laws<\/a>. However, many of these concerns apply equally to traditional VPNs too.<\/p>\n<p class=\"paywall\">\u201cFrom a state security perspective, it creates the same obfuscation as does any VPN,\u201d Henein says. If law enforcement wanted to ask for people\u2019s online activity, then there isn\u2019t much change. \u201cThe network operators will not be able to help you in the same way as if that person were using a VPN.\u201d<\/p>\n<p><a href=\"https:\/\/www.wired.com\/story\/icloud-private-relay-blocking\" target=\"bwo\" >https:\/\/www.wired.com\/category\/security\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/media.wired.com\/photos\/61ddf650f355cd4b7989ff3d\/master\/pass\/Security-Apple-Private-Relay-1331041563.jpg\"\/><\/p>\n<p><strong>Credit to Author: Matt Burgess| Date: Tue, 11 Jan 2022 21:31:20 +0000<\/strong><\/p>\n<p>Security experts say there&#8217;s little reason for the criticism from Europe\u2019s mobile operators and US limitations over the VPN-like iCloud tool.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10378,10607],"tags":[714,21382],"class_list":["post-18047","post","type-post","status-publish","format-standard","hentry","category-security","category-wired","tag-security","tag-security-privacy"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/18047","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=18047"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/18047\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=18047"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=18047"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=18047"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}