hello, I'm writing to seek clarification on Apple account security, particularly regarding potential risks of compromise, implemented safeguards, and residual risks with corresponding mitigation strategies. We would appreciate your insights on the following specific points:
iCloud Keychain Access: Is an Apple ID login strictly required to access iCloud Keychain? We understand that a compromise of iCloud Keychain is unlikely unless a malicious actor successfully takes over the legitimate user's Apple ID. Is this understanding correct?
Passkey Theft Methods and Protections: What are the conceivable methods a malicious actor might employ to steal a legitimate user's passkey, and how are these attempts protected against?
Impact of Apple ID Compromise on Passkeys: If a malicious actor successfully compromises a legitimate user's Apple ID, is it accurate to assume that the legitimate user's passkeys would then synchronize to the attacker's device, potentially allowing them to log in using their own biometrics?
Authorization Flow on Legitimate User's Device: Could you please detail the authorization flow that occurs on the legitimate user's device? We are particularly interested in the types of authentication involved and the conditions under which they are triggered.
Detection and Additional Authentication for Unauthorized Login: How are attempts to log in to an Apple ID from an unrecognized device or browser detected, and what additional authentication steps are implemented in such scenarios?
Thank you for your time and assistance in addressing these important security questions.
Sign in with Apple
RSS for tagDiscuss how to provide users the ability to sign in to your apps and websites using their Apple ID.
Selecting any option will automatically load the page
Post
Replies
Boosts
Views
Created
We are experiencing an issue with Apple’s Private Email Relay service for Sign in with Apple users.
Our setup details are as follows:
• Domain: joinalyke.com
• Domain successfully added under “Sign in with Apple for Email Communication”
• SPF verified
• DKIM enabled (2048-bit Easy DKIM via AWS SES)
• Emails are being sent from S***@joinalyke.com
Amazon SES confirms that emails sent to users’ @privaterelay.appleid.com addresses are successfully delivered (Delivery events recorded in SES and no bounce reported).
However, users are not receiving the forwarded emails in their actual inboxes.
Since:
SES shows successful delivery,
SPF and DKIM are properly configured,
Domain is registered in the Apple Developer portal,
we suspect that the Private Email Relay service may be blocking or not forwarding these emails.
Could you please investigate whether:
Our domain or IP reputation is being blocked or filtered,
There are additional configuration requirements,
The relay service is rejecting emails after acceptance,
There are content-related filtering policies we should review.
We are happy to provide message IDs, timestamps, and sample relay email addresses if required.
Topic:
Privacy & Security
SubTopic:
Sign in with Apple
Hello,
We are building a new app that would be kinda extension of the other and we want to let our community share the same account in between.
We use Apple Sign in and we want Appel sign in system to give the same identity when people use apple relay. One of our app is alreadey released, can we still do it to share the same Apple login?