Tech

Apple closes privacy gap in “Hide Email” – details and possible further problems | News

“Hide my email” is intended to help protect your valuable digital identity from spam and tracking. If a service asks for registration via email, iCloud+ offers to create an alias – this is only used to communicate with that one provider. Users can delete the address at any time and thus protect themselves from further contact from the service. But there was the possibility of finding the real address through detours. Apple has known about the error for over a year and has only now been able to fix it. The discoverers now revealed how the gap could be exploited.

In retrospect, the method seems surprisingly trivial: attackers only had to send a message to the email alias, which was automatically rejected as spam. The rejection to the sender’s mail server then contained the real address; A look at log files is enough to determine whether Hide-my-Email-Address is a real address. Since the rejection already takes place on Apple’s mail servers, the user is not aware of this spying and cannot even discover any evidence of it.

Logs can stay for a long time
This scam no longer works since July 7, 2026. However, the discoverer points out that previously created aliases may have been compromised long ago: Due to rejections in the past, many aliases can probably be subsequently resolved by evaluating server log files and thus find out the real iCloud email addresses.

Tricks with the command line
That’s not all: Jeff Johnson, developer of the “StopTheMadness” browser extension, may have found another way to decrypt the aliases created by iCloud+. Using the command line tool curl, he managed to send an email that simulated an origin from Apple’s “Hide my Email”. If the content of a message entices the recipient to respond, it will be sent from the iCloud account with the personal address – even if the triggering email went to another account. The only clue that might alert users that something amiss is going on: A banner indicates (incorrectly) that this message was forwarded from Hide My Email.

An email sent via the command line can fool Apple Mail into thinking that a message was sent via Apple’s anonymization service. (Source: Jeff Johnson)

Source link

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button
Close

Adblock Detected

kindly turn off ad blocker to browse freely