Apple is working on iPhone-to-Windows copy-paste. The planned feature will allow EU users to copy content on their iPhone and paste it onto their PC, but I really hope Apple lowers its walled garden to enable this worldwide
Apple's "Hide My Email" has been revealing people's real email addresses for over a year.
The feature is literally called Hide My Email. Apple, what?
For those of you who actually want to hide your email, check the tweet below 👇
Re: Responsible Disclosure
We found ourselves in a bit of a dilemma with these DNS and IP leaks in WebKit and how to handle them responsibly.
We first became aware of a DNS leak in Psylo in late June 2026 after a user reported it. During our investigation, we found two additional issues that expose a device’s real IP address. All three leaks are in WebKit, meaning they affect not only Psylo, but also every iOS browser that relies on a proxy, including iOS Tor browsers, as well as Apple iCloud Private Relay.
In an ideal world, we’d report the issues to Apple, they acknowledge the issue, and ship a fix in a timely manner. Unfortunately, our past experience with Apple tells us that reporting this issue would involve months of delays, inconsistent communication, and in some cases, denying the issue’s impact entirely.
We weren’t willing to wait months, or upwards of a year, sitting on bugs that undermine the core privacy guarantees of Psylo and iOS Tor browsers while saying or doing nothing. A year’s timeline not an exaggeration either: Researchers at EasyOptOut reported to Apple in June 2025 that iCloud Hide My Email leaks real email addresses behind private aliases, and Apple got around to it in July 2026, just about 13 months later.
So now we’re left with a difficult question: if we were to report the issues to Apple, what should we do in the meantime?
Should we knowingly leave our users exposed while waiting for a system-level fix? We didn’t think that was acceptable or fair to our users. Or should we quietly ship our own mitigations without telling anyone? We didn’t think that was acceptable either. Security fixes deserve transparency, especially when they involve tradeoffs.
Our mitigations disable WebTransport (a relatively new web standard) and WebAuthn (the web standard behind passkeys) by default. Since this can affect website compatibility, we believe users deserve to know why those APIs are disabled and understand the implications of re-enabling them.
So how do you do responsible disclosure when the vulnerability directly affects your own users, and when a platform-level fix is both uncertain and likely many months away?
We decided to first reach out privately to the Tor Project and the developers of Onion Browser for iOS. As soon as we had working mitigations for all three leaks in Psylo, we shared our findings and solutions with them so they could evaluate similar protections for their own users. We also made sure they were okay with us releasing the fix for Psylo right now.
It’s also worth noting that these leaks do not affect VPNs. Users who are concerned can reduce their exposure today by using a VPN while waiting for platform-level fixes. This is also Onion Browser’s long-standing recommendation that users pair it with their Orbot Tor VPN app, since there have been similar IP leaks in WebKit in the past.
Grok 4.5 is very good for vibe math in the field of Programming Language Theory. It's keeping up with Sol 5.6 and is way more fun to use than Fable/Opus 5 which love to spend hours creating superfluous documents (Claude code) or constantly nags me to "Continue" (web).
@deanwball Picture an executive a taco company saying this sort of thing about a new brand of tacos coming onto the market, speculating about the geopolitical and societal disruptions they anticipate as a result of advances in tacos.