“Hide My Email” Vulnerability Exposes Real Addresses

I suspect it’s so they can remove restrictions on what kind of iCloud usernames you can create for yourself. Right now, they need to ensure that new accounts never conflict with current or future private addresses.

By moving the private addresses into a special sub-domain, it removes this issue. New accounts still need to be checked so they don’t conflict with existing private addresses in the icloud.com domain, but this can now be handled in the same way they’d check for conflicts with user addresses. No need to worry about future private addresses conflicting, because they’re now in another domain.

2 Likes

So simply to increase the supply then? Well ok, I guess – though surely there’s still tons of random alias availability (say under 15 characters) on the current vanilla icloud.com domain… maybe they’re future-proofing themselves or something?

I just looked at my collection of 56 hide-my-email addresses, and some are already using private.iCloud.com - in fact, I think it goes back a year ago, everything since then is using that subdomain.

What’s interesting is that all of the iCloud ones use two random words with some numbers and punctuation (periods and dashes) as the left part of the email address, while the private.iCloud ones are all simply 10 random alphanumeric characters to the left of the @.

1 Like

I know of web services where they have actually gone through the effort of not letting you sign up if you use a mailinator address. At least for those sites, they apparently did not see the required effort as prohibitive for what they were trying to achieve.

I just made a new one today and it ends in @icloud.com. All of mine are @icloud.com except for one that is @privaterelay.appleid.com which is connected to a site where I use “Login with Apple”.

FWIW, for many years, I’ve used a free email address from a European provider to sign up for forums and mailing lists. Several of them wouldn’t accept that address because of reportedly high volumes of spam originating from that domain.

1 Like

Yes, but note that there’s a difference here.

Apple is not giving away free e-mail addresses to the world. Every one of their private addresses maps directly to an iCloud customer. The recipient may not have the customer’s ID, but Apple does and can shut down customers who use these addresses for abuse and fraud.

This is different from “freemail” services where people can create hundreds of accounts that aren’t tied to any specific person who could be held responsible for abuse.

3 Likes

Well looks like we’ll have to see how the newer private.icloud.com domain aliases work out in the real world en masse, before judging if there are problems with them on some services out there.

I could never be bothered with using things like this, mainly as I use my iCloud email only really for Apple services rather than email – instead using another email service as my main home/non-work email including services logins, in order that few companies/organisations would ever know about my iCloud email address in the first place. Especially as I use iCloud Drive to store almost all my docs now, so I don’t want my iCloud email address always out there to all and sundry.

PS. Today I learned of Mailinator, lol! :slight_smile:

Oh! That may be why I have so many. I haven’t had a need for hide my email lately.

Lots of them. Try using a masked email address with ssa.gov (or its login partners login.gov or id.me).

My thought exactly. If a site wants to block me for using a private email address you’d have to question what they plan doing with it.

There’s a huge difference between a random web site like TidBITS, or Amazon and one whose purpose is specifically for ID validation.

The former shouldn’t care about throwaway mailboxes. The latter absolutely should.

It’s the same reason you typically can’t mail-order expensive luxury items and have them shipped to a PO box.

1 Like

I don’t, but I’ll admit a slight irritation when I see them, since it feels like people will just shut them off rather than unsubscribing cleanly as they should when they want to leave. I also don’t like it when people mark TidBITS as spam as a way of unsubscribing. And I REALLY don’t like it when people dispute a TidBITS membership charge rather than just asking for a refund (which we’re always happy to give), since that actually costs us money and reputation for no reason.

2 Likes

How do you tell by looking at an email address that it is a throwaway?

The usernames are always things like corn.summit.6s5

1 Like