It’s specifically set up so apple doesn’t know the content of the request and cloud flare doesn’t know who made the request. It’s like tor-light
Private Relay doesn't let Apple see the request now, but that doesn't mean it won't. They also don't need to see the request to deny exit point access to any number of sites they arbitrarily decide not to foward any traffic to.
Your neighbours might be nice now, but in the future they might spy on you for the Russians!
If we condemned everyone for things they might do one day, everybody would be behind bars.
There's literally draft legislation in the UK that will cause these negative impacts, so we're not talking tin foil hattery here.
The best thing you can do to avoid draconian legislation is to make the legislation unworkable by having too many points where the control would need to be exercised.
The more you have centralised points that choke traffic, then the more likely it is that such legislation will get passed, and the more likely it is that it will have a generally powerful effect.
I don't need to have my car engine explode before realising that doing general maintenance is a good idea.
I don't see how Apple doing it now with a privacy focus does anything to change or realign government incentives to do it later.
Broadly cost. China's moderation and censorship of the internet is very expensive, and requires significant scale, and only works because most of the companies involved are at least partly state owned in the first place.
The more you have a small amount of centralised points you can target, the lower the costs to implement sweeping measures against all traffic and the higher the technical possibility.
The UK already has a draft law on the table that will effectively ban any sites that do not meet the requirements of the state regulator, and the legislation notes that a useful way of forcing sites to comply is that the Apple App Store and Google Play mean that if you can force them to delist applications then you've done 95% of the job. They are centralised points that make bad legislation more plausible.
We don't want that to get even worse than it is.
I don't buy it. The points are already pretty centralized. We only have, like, 4 big telecom companies and they already make usuriously fat margins that can absorb the cost. You also don't really need to cut things off at the App Store level, as SESTA/FOSTA has shown, to push activity too deep underground to be found on mainstream services. Just ad hoc enforcement and a pervasive climate of fear is enough.
Finally you can always just turn it off - it asks you the first time as well, it is explicitly opt in, and isn’t available in countries that have strict censorship laws.
I mean they do, Apple can switch provider at any point, and Apple is the legal entity controlling the service. Cloudflare will do whatever Apple contracts them to do. Any legislation will target Apple.
The UK Online Safety Bill will almost certainly require Apple to censor it. I don't think it's at all certain such legislation would apply to Cloudflare - Cloudflare do not offer a consumer service that I buy (well, they do offer 1.1.1.1 but that has a fairly small amount of users and is irrelevant).
> Finally you can always just turn it off - it asks you the first time as well, it is explicitly opt in, and isn’t available in countries that have strict censorship laws.
The problem is that Apple are going to have to restrict the number of countries a lot or start doing more control. The US is very unusual for example in not requiring ISPs to block access to the Pirate Bay. European law is pretty settled that all member states need ISPs to do blocking in trademark cases in some circumstances. And yes, a VPN provider already bypasses this, but laws tend to ignore when they don't work for 5% of the population, in a way legislators suddenly can't ignore when 40% of the population is sailing past the blocks.
Although in general actually I think you’re right. Free world security services should be working to secure our communications and protect us from identity theft. Hopefully the rise of ransomware as a systemic economic threat will wake them up to the fact their primary job is actually to protect us.