@dalias @sarahjamielewis @evacide
In a quirk of how passkeys work — a broadly secure alternative to usernames and passwords which use the WebAuthn standard — a user’s device makes a web request outside of the browser itself. Meaning, that request essentially bypasses Private Relay and exposes a user’s real IP address, even though to them it may look like they are simply interacting with a website as normal.
Side-channel leak, support should never have been present for using an external program that cannot guarantee it will go through Tor.
Such support is only acceptable on Whonix (or similar), anything else would require passkey support to be built into the browser.
Because all web browsers on iOS have to use Apple’s WebKit engine, the researchers also found the issues impact at least one Tor browser, called OnionBrowser.
For two of those leaks, the issues are “entirely based on how iOS and WebKit work and solely in Apple's hands. (That's the part that's kind of dire),” Mike Tigas, the creator of OnionBrowser, told 404 Media.
It's not Tor Browser and what it's doing is utterly irresponsible.
have to use Apple’s WebKit engine
How are they enforcing this?