|
|
|
|
|
by aimazon
516 days ago
|
|
The counter point is that anyone who cares about being anonymous is using methods to disguise their identity that cannot be compromised by this attack, e.g: a VPN. Plus, there are much more effective versions of this attack, like sending a link to an endpoint that you control -- getting someone to click a link isn't hard if you're considered trustworthy enough to send them notifications. And less technical versions, like correlating when the user is online vs. offline with timezones around the world. The method that both Apple and Cloudflare use in their own privacy software (iCloud Private Relay for apple, WARP for Cloudflare) is specifically based on the idea that your region is not information that reveals your identity. If you enable Apple Private Relay, your origin IP will be obscured but the IP your traffic is routed through will be in the same country -- same principle. https://www.apple.com/icloud/docs/iCloud_Private_Relay_Overv... This attack is academically interesting and novel but it's not "deanonymization". |
|
Yes unless Apple is doing Apple things and ignores VPNs for things like push notifications…
https://x.com/mysk_co/status/1579997801047822336