Hacker Newsnew | past | comments | ask | show | jobs | submit | floam's commentslogin

They don’t seem to be in contact with the people who actually fixed it.

I don’t follow. Fair use is a copyright defense, and nobody is suggesting distillation attacks are just a copyright violation are they?

Aren’t they alleging these other companies directly entered into a contract and violated the terms, and in cases where question, answer pairs were obtained without such agreement, it was accomplished by outright wire fraud or theft?


Are you suggesting that worldwide copyright violation is more acceptable than contract breach between companies?

com.apple.private.uexc as well?


Same id numbers you use when downloading them. While you might know what a particular URL is available in, I’m not sure I’ve seen an encyclopedic enumeration of the possibilities


That’s surprisingly self-aware, and encouraging.


The article mentioned fertilizer - that’s not straightforward to control and precisely account for.


Yes, to fully fix a certain class of bug on their infra.


Do you know any more about it or have a link where I can read more?


I’ll try to add more later, but it is believed that multiple times, a bug in some random API has allowed for the “hidden” Apple account to be revealed because they resolve hide my emails to the original internally. Using a separate namespace would be the universal fix.

A mitigation for the cause of https://www.404media.co/apple-hide-my-email-vulnerability-re...


This doesn't follow. The bounce message used to (effectively) say,

> abc@icloud.com forwards to real@gmail.com

If they switched the new domain and did nothing else, it would say:

> abc@privaterelay.appleid.com forwards to real@gmail.com

That's no better. Fixing that privacy leak is unrelated to whatever the destination domain is.


No, using a different domain makes it easy to across the board add a rule: don’t treat as Apple ID.


I'm not sure if I'm following. Apple is capable of creating a lookup table, or an atomic database read query.


https://news.ycombinator.com/item?id=48559935

If you dig more you could find the bug, but AFAIK it was that if you sent a large attachment, the bounce email would contain your real address.


Good. This would have made blocking them trivial.


How.. do people find out they’re diabetic before organs are borderline failing?


There are actually periodic tests for people over 40 in the UK. The GP comment is wrong.


I tried your tool just now, on my iPhone. I am really kind of stuck and frustrated. I cannot get that first box, the one you can type into, that’s on a grid into a state where I can interact with it.

Stuff is jumping around after I try to move the canvas around, unexpected stuff. I can’t figure it out.


Oof, apologies. I have not done any work at all on mobile to make this work.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: