Get ready for iCloud Private Relay

RSS for tag

Discuss the WWDC21 session Get ready for iCloud Private Relay.

View Session

Posts under wwdc21-10096 tag

52 Posts
Sort by:
Post not yet marked as solved
1 Replies
202 Views
When will this be out of beta and stable enough to use?
Posted
by
Post not yet marked as solved
0 Replies
219 Views
I am trying to receive a email from private relay email but it does not seem to work. I can send email to private relay email but person received this email cannot reply back. I have set up SPF and DKIM for the domain and registered the domain in apple developer account(email communication). Is there anything else I should do to debug this?
Posted
by
Post not yet marked as solved
1 Replies
233 Views
I have added SPF(TYPE DOMAIN) record in apple account , but the emails which users are getting are going in their spam folder through private relay. How can we resolve this , so that all emails will go in inbox instead of spam.
Post not yet marked as solved
0 Replies
311 Views
Process: Xcode [1587] Path: /Applications/Xcode.app/Contents/MacOS/Xcode Identifier: com.apple.dt.Xcode Version: 13.1 (19466) Build Info: IDEFrameworks-19466000000000000~20 (13A1030d) App Item ID: 497799835 App External ID: 844664792 Code Type: X86-64 (Native) Parent Process: ??? [1] Responsible: Xcode [1587] User ID: 501 Date/Time: 2022-03-29 10:23:49.635 +0800 OS Version: macOS 11.5.1 (20G80) Report Version: 12 Bridge OS Version: 5.5 (18P4759a) Anonymous UUID: C651A600-7A6C-460E-9CE3-2E55CF2ED3D6 Sleep/Wake UUID: C50EB53F-CBBF-4E86-9F83-66EE17220ABE Time Awake Since Boot: 3600 seconds Time Since Wake: 3000 seconds System Integrity Protection: enabled Crashed Thread: 0 Dispatch queue: com.apple.main-thread Exception Type: EXC_CRASH (SIGABRT) Exception Codes: 0x0000000000000000, 0x0000000000000000 Exception Note: EXC_CORPSE_NOTIFY Application Specific Information:
Posted
by
Post not yet marked as solved
0 Replies
217 Views
Hello, I'm the administrator of the dns server. I am writing a question because I am curious about the resolver server used by Icloud Private Relay. If the ip is changed from Relay2 of Icloud Private Relay, which resolver server will you use to dns query? Do you use cloudflare,akmai,fastly resolver server? Or do you use Apple's own resolver server? Also, do you have official documents related to apple, cloudflare, akmai, and fastly? It doesn't matter if it's not related to the content of the post. If you know anything about this, please reply. I can't speak English or other foreign languages well. Thank you for your help. Thank you.
Posted
by
Post not yet marked as solved
1 Replies
335 Views
I'm working on building functionality for an app using the Network Extension to setup an EncryptedDNS resolver for certain domains relevant to my app. I need to detect whether the iphone user has Private Relay enabled in order to determine how my app behaves while setting up the encryptedDNS resolver. What APIs can I use to determine if Private Relay is active? Is it available as a preference? I can't find any documentation around this.
Posted
by
Post marked as solved
2 Replies
756 Views
Dear Apple, I use Little Snitch (An application firewall) to manage exactly what websites/domains apps should be allowed internet access. And which sites shouldn't have any access. Like in Safari or Mail ... I don't grand access to hostnames that include anything that can be derived to have an association to "Tracking" ... say: Little Snitch works like a charm. Or to say: It works until you don't enable "iCloud Private Relay". With iCloud Private Relay turned on, it circumvents Little Snitch granting access to every site/hostname without checking with my "Application Firewall" - if it's allowed to have access to said site or not. I guess this is because iCPR is 1st in the hierarchy over Little Snitch. And it makes sense. If you don't have an Application Firewall running ... you want iCPR to be the 1st to intercept all connection activities. But for us who do have an Application Firewall ... it doesn't. I wish to go into "Set Service Order" and drag Little Snitch to be 1st in this list ... then iCPR ... and then Ethernet 1 ... etc etc. This way, I could 1st block any access to any "Tracking site" ... don't even let the app connect to it! Since, why should they even have my data? Any data about me?! ... Even if it "anonymised", it's best to not give them any data at all. Null ... zilch! :-) Could you please add/tweak this "Set Service Order" to allow/grant us, the users to choose how we would like to filter our connections. cheers, Daniel
Posted
by
Post not yet marked as solved
0 Replies
301 Views
I have a transactional welcome email sent to users. In testing users replying back to my sender address, I received a delivery error from one user via private email relay service - "550 Relay is not allowed". Can someone pleasee advise? Replies have worked for other users using Apple's same private email relay service...and domains have also already been registered/verified.
Posted
by
Post not yet marked as solved
0 Replies
354 Views
When Private Relay is on I get most of the time Akamai DNS servers, rarely Cloudflare. The problem is that those servers don't have DNSSEC. It is a server problem or a Private Relay "feature"? Tnx
Posted
by
Post not yet marked as solved
1 Replies
357 Views
While working to use the iOS on an enterprise network, both the App Store and the Music app on iOS 15 do not connect to the Apple backend services if DoH access is unavailable. Restrictions were applied on a lab environment with a set of Cisco NGFW firewalls running FTD 7.0.1 and FTD 7.1. Restrictions on the DNS end, for restricting access to the iCloud Private Relay (as per "Allow for network audits" section) and to the DoH address (using the same methodology as above) were attempted, in a combination with the security appliance, to no avail. Tested on different devices running iOS 15.1, 15.1.1 and 15.2. Traffic inspection was not enabled on this lab. The test account is an active iCloud+ subscription. The security appliances were running with Snort3 IPS, however no IPS policies were present on any of the access control lists, nor configured on the appliances. While the DNS configuration at the iOS device states "DNS requests are being routed by iCloud Private Relay for this Wi-Fi network", ultimately there seems this option is not being respected. Although not thoroughly tested, it appears macOS 12.1 is also affected with at least the Music app, and a HomePod (15.1.1) is also unable to play songs with DoH restricted from the DNS view: Siri answers the request but doesn't play the requested songs.
Posted
by
Post not yet marked as solved
1 Replies
796 Views
In the user interface, Apple says: iCloud Private Relay keeps your internet activity private Private Relay hides your IP address and browsing activity in Safari and protects your unencrypted internet traffic so that no one-including Apple-can see both who you are and what sites you're visiting BUT when I look at the Apple IT support documentation the above is contradicted. Based on it, what would be true is: iCloud Private Relay keeps your WEB activity private Private Relay hides your IP address and browsing activity in Safari and protects your unencrypted WEB and UNENCRYPTED APP traffic. In addition to the corrections I made above, the rest of it (below) is just…terribly problematic! I’m not even sure how to correct it but it’s wrong. Agreed? I mean any aware user is (likely) going to know that if you tell a website like your bank) who you are, while using iCloud private relay (IPR), it will know who and where you are. But they’ll also know your IP, since Apple is saying only to us that encrypted internet traffic doesn’t go through IPR. This would include HTTPS, SMTPS, IMAPS, GOPHERS, … And even a fairly savvy user reading the following isn’t going to realize that Apple is not fixing the Panopticon problem, meaning that as is, the following part is generally false and de deceiving: …so that no one-including Apple-can see both who you are and what sites you're visiting. What’s a customer going to think when they realize that our apps aren’t delivering what Apple‘s promising because it’s inconsistent about what is promising to who? Is there already discussion going on about this? seems like a big issue… Fortunately, Apple is saying the product is in beta, so they will likely be extra open to and relatively responsive to feedback. But I wanted to talk with other developers about it so that’s why am bringing it up here. Maybe I’m misunderstanding stuff.
Posted
by
Post not yet marked as solved
2 Replies
545 Views
Since enabling my iCloud Privacy Relay my encrypted traffic is suffering a DNS blockage caused by my Routers settings. This is stopping my private network connecting. I have remotely accessed my router and run through the Apple security prompts but all seems to be as stated but they is no reference to the issue caused by DNS? I see a load of similar issues but will someone post a relay in ‘stupid’ as I have no idea what they are going on about!!
Posted
by
Post not yet marked as solved
0 Replies
239 Views
Is the egress list for Private relay also used by Mail Privacy protection?
Posted
by
Post not yet marked as solved
0 Replies
374 Views
Hi, We are implementing a flow where the end-user starts a session in the Safari browser, switches to an app and then returns to the Safari browser. The whole process should take less than 30 seconds, but if iCloud Private Relay is turned on, the IP address is changing in that short timeframe. In this case from 104.28.45.4 to 104.28.45.5. This does not seem to match with the description in: https://developer.apple.com/support/prepare-your-network-for-icloud-private-relay “Additionally, the relay IP address will remain stable during a browsing session from a device, to make sure you will see a consistent address while a user is interacting with your website.” -Anders
Posted
by
Post not yet marked as solved
0 Replies
322 Views
Worry about that Private relay address(Beta) have problems. I created about 30 address and received many emails. Some address is connected with third party' s account, for example google, Yahoo, blog, shopping, payment app and so on. When you use private relay address ONLY for receive informations from any service or products, this address work well and convenient in secure and protected your privacy.  But if you need to reply to incoming mail, Mail header send to the receiver all information which includes original Apple Id cloud address. Because Mail Header is designed so from the beginning of history of the internet.  If it happen to need any support of certain service by mail (even you use contact form on the web), you need to answer to the massage for going on. But you should not to reply by mail app, because private relay address system is not designed for such situations. So when I receive support mail through private relay in secure and protected, I come back to the form on the web or Homepage to reply. How this service will update in the future I will check. I hope to we can clear such cases well.
Posted
by
Post not yet marked as solved
0 Replies
246 Views
When i activate realy my internal dns domains not working, how to resolve?
Posted
by
Post not yet marked as solved
1 Replies
405 Views
Is there a rough idea of how often the egress-ip-ranges.csv will change so we can determine how often to update our list? And what kind of growth can we expect? It seems to have grown by about 5 MB in the last couple of months. I'm wondering if that is due to it being new or if we should expect steady growth at that rate.
Posted
by