Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I’ll try to add more later, but it is believed that multiple times, a bug in some random API has allowed for the “hidden” Apple account to be revealed because they resolve hide my emails to the original internally. Using a separate namespace would be the universal fix.

A mitigation for the cause of https://www.404media.co/apple-hide-my-email-vulnerability-re...



This doesn't follow. The bounce message used to (effectively) say,

> [email protected] forwards to [email protected]

If they switched the new domain and did nothing else, it would say:

> [email protected] forwards to [email protected]

That's no better. Fixing that privacy leak is unrelated to whatever the destination domain is.


No, using a different domain makes it easy to across the board add a rule: don’t treat as Apple ID.


I'm not sure if I'm following. Apple is capable of creating a lookup table, or an atomic database read query.




Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: