iCloud+ Hide My Email addresses will remain on icloud.com

(developer.apple.com)

129 points | by K7PJP 2 hours ago ago

26 comments

  • hollow-moe an hour ago ago

    Using icloud.com domain for legit and hidden adresses is such a typical Apple strategy of holding their own users and "others" (ie. other web services, other users etc) hostage simultaneously. But at least here it is actually a good reason that works for the user.

  • joshuat an hour ago ago

    I'm glad they listened - I use this feature extensively and would like to continue to

  • postalcoder an hour ago ago

    I've noticed a chilling new trend of apple listening to the community.

    • cush 11 minutes ago ago

      Hmm it’s almost as if people are paying good money for iCloud+ or something. They aren’t google and shouldn’t be retiring their services as if they’re giving them away for free

    • nate an hour ago ago

      Anyone have a theory why this even made it to this point? the switch was such obviously a bad idea. just corporate weirdness that no one there bothered to raise their hand and be like "uh, are we really doing this?" or was there a story here that anyone knows about?

      • jofzar 37 minutes ago ago

        It's email reputation, it the always the answer with this kind of stuff.

        My guess is that the bounce rate got too high and bot farms were using iCloud addresses like this.

        • Marsymars 29 minutes ago ago

          The bounce rate of what, exactly?

          Because the bounce rate of Hide My Email addresses being deliverable is going to rise over time, by design.

          Whenever I start getting spam at an address that's been leaked, I deactivate it. I've done the same with my oldest gmail account, but the work required there is notably higher.

          • MBCook 26 minutes ago ago

            If they were moved to plain old icloud.com, I could absolutely see a bunch of companies starting to filter out all icloud.com email addresses to avoid private relay. Either just because they’re jerks or from bounce issues.

            Keeping it on a subdomain fixes that problem, to some degree. If the user is named ffjvhtu57325cjdjvg501a2@icloud.com no one is going to think that’s a real address. It’s very obviously a private one. So it’s not like they were “camouflaged.“

            It’s a little odd they’re switching the subdomain though.

      • super256 44 minutes ago ago

        Maybe hidemyemail allows easily creating many accounts on a site. And some big site didn't like it.

        The "Sign-up via Apple" button and creating an iCloud email yourself have a slightly higher barrier than creating a new throwaway hidemyemail email (1 API call w/o captcha/phone verification or whatever).

        We might find out later this year if some site starts blocking @icloud.com but keeps allowing @private.icloud.com.

        • pests 17 minutes ago ago

          It does, and I know a friend of a friend who uses them for Walmart accounts to bot pokemon drops. Those and office aliases.

  • xaviervn an hour ago ago

    I don't understand how this changes anything. IIRC, the complaints were about Apple making the Hide My Email addresses different than regular ones.

    They're now saying the new domain will be private.icloud.com. Isn't it just as targetable?

    • NobodyNada an hour ago ago

      It's talking about two different services:

      > Sign in with Apple addresses, previously issued on privaterelay.appleid.com, will be issued on private.icloud.com.

      > iCloud+ Hide My Email addresses will remain on icloud.com.

    • LoganDark an hour ago ago

      Sign in with Apple is Apple's SSO, like Sign in with Google. Services have to support this one explicitly, and it already had a special subdomain, so the specific subdomain is simply changing.

      Hide My Email is the manually generated ones, for websites that accept an arbitrary email address. This is the one where it's valuable for the relays to be identical to genuine iCloud addresses, otherwise websites could try to block it and force you to use a more revealing email address, undermining privacy.

  • delduca an hour ago ago

    That was a stupid idea (the prev one)

  • NotThatFast an hour ago ago

    One of the best things about it. Also being able to add several emails per custom domain for free.

    Whole thing is 99c a month. Makes Gmail seem like a joke in comparison.

    Until you get an email from an iCloud address on Gmail and see it go right to spam haha. Suddenly Gmail is cheap again

    • Quothling 25 minutes ago ago

      Maybe it's because I live in a country where e-mai isn't really used that much for personal communication, but wouldn't this mainly be a gmail issue? If mails I wanted ended up in the spam folder I'd not use gmail. I mean, I pay for protonmail, so I wouldn't use gmail to begin with, but if mails I wanted ended up in my protonmail spamfolder and I couldn't do anything about it, then I'd switch away from protonmail.

      • NotThatFast 20 minutes ago ago

        You are 100% correct and yet the masses still prefer it.

        World’s a twisted place!

        I would guess the average Gmail user doesn’t know that it reports virtually all iCloud as Spam - believing instead that it’s genuinely being filtered by quality engineering at Google.

  • amazingamazing an hour ago ago

    Good. What else can really be said? Only way for it to work and not be trivially blocked is to mix with legit emails.

    • jambalaya8 an hour ago ago

      A lot of places also don't really like icloud addresses in general. This is one of Apple's better offerings though.

  • prism56 an hour ago ago

    Good! Was there ever a compelling reason why they went for this switch initially?

    • floam an hour ago ago

      Yes, to fully fix a certain class of bug on their infra.

      • culi an hour ago ago

        Do you know any more about it or have a link where I can read more?

        • gruez an hour ago ago

          https://news.ycombinator.com/item?id=48559935

          If you dig more you could find the bug, but AFAIK it was that if you sent a large attachment, the bounce email would contain your real address.

        • floam 24 minutes ago ago

          I’ll try to add more later, but it is believed that multiple times, a bug in some random API has allowed for the “hidden” Apple account to be revealed because they resolve hide my emails to the original internally. Using a separate namespace would be the universal fix.

  • floam an hour ago ago

    Good. This would have made blocking them trivial.

  • trueno an hour ago ago

    thank god -.-