281 天前
Apple 有个 iCloud Private Relay ,这种东西一定会有隐私问题,Apple:
> When Private Relay is enabled, your requests are sent through two separate, secure internet relays.
> Your IP address is visible to your network provider and to the first relay, which is operated by Apple. Your DNS records are encrypted, so neither party can see the address of the website you’re trying to visit.
> The second relay, which is operated by a third-party content provider, generates a temporary IP address, decrypts the name of the website you requested, and connects you to the site.
Apple 提供弱密码和已泄露密码检测:
> Your device may also inform you of passwords that may have been compromised in a data leak. This feature uses strong cryptographic techniques to regularly check derivations of your passwords against a list of leaked passwords in a secure and private way that doesn’t reveal to Apple your accounts or passwords. Apple will send to your device a list of common passwords that are present in data leaks. For your passwords that are not in this list, your device will send information calculated from your passwords to Apple to check if the passwords may be present in a data leak. You will be warned about your passwords determined to possibly be in a data leak. Your actual passwords are never shared with Apple, and Apple does not store the information calculated from your passwords. You can disable this feature at any time by going to Settings > Passwords > Security Recommendations.
Apple 还和 Cloudflare 它们一起搞了 ODoH 和 Private Access Tokens:
> ODoH adds a layer of public key encryption, as well as a network proxy between devices and DNS servers. The combination of these two added elements is designed such that only the user has access to both the DNS messages and their original IP address at the same time.
> Apple never learns which app or website that you're signing in to, and can't access your browsing history. The token issuance server knows only that you passed the verification, and never learns information about your device or Apple ID. The only information given to the app or website is the private access token.
所以我觉得 Apple 更在意的是有没有办法合法地把锅甩给第三方服务,不能甩出去就推进隐私方案,并没觉得会是死局,这本来也是该领域面临的问题。