A long time ago, like back in 2015-ish, ACLU used a service created by Einar Otto Stangvik from Norway called starttls.info (doesn’t exist anymore), based on my idea. It was simple; create a service similar to ssllabs.com, but for checking if mailservers for a given domain supported RFC 3207. An internet standard for opportunistic email encryption between two mailservers. ACLU reached out to big tech, among them legal team at Apple . “Hey, you don’t support RFC 3207 STARTTLS, which provide much better security & privacy for mail users of iCloud.com.” Apple deployed support within a few days.
Looking at email security at iCloud now, it seems Apple haven’t followed up since 2015 on their promise of proper security & privacy for their customers.
I now use Dutch Internet Standards Platform (Internet.nl) for scanning domains and their mailservers for correct support, implementation & compliance with a range of Internet standards. As a free service to use for compliance testing, the Dutch government says you either need to implement these security standards, or you need to write a “PhD level” risk analysis to explain why you chose not to be compliant. Easy choice in my humble opinion.
So testing icloud.com, I was really surprised and somewhat terrified to see a score of only 52%. I’m not sure this means Apple cannot provide services for, or Dutch government sector are not allowed to use iCloud for email whatsoever. Oh, and the Netherlands are not the only ones asking for compliance with these standards!
In September 2024 the White House, through the Office of the National Cyber Director (ONCD) released a Roadmap to Enhance Internet Routing Security, pushing for widespread adoption of RPKI. As you can see from the screenshot below, this is still not fully implemented for iCloud, and other security standards are missing as well.
Quick explanation:
- IPv6 is the next-generation type of IP adresses on the Internet. Want to stay stuck in the past? Stay with IPv4 only, like Apple currently does.
- DNSSEC guarantees that the IP addresses you get in return when asking to connect to iCloud doesn’t get manipulated before reaching you, so you actually connect to the correct servers. This security feature is missing at Apple.
- DMARC, DKIM & SPF (in place at Apple) are standards to reduce risk of spam/phishing that looks like it is coming from iCloud, as well as reporting about it.
- STARTTLS & DANE. While the first is in place at iCloud, DANE is not. STARTTLS is “opportunistic unauthenticated encryption”, while DANE provides “mandatory authenticated encryption”. Apple has only STARTTLS, Microsoft & Cloudflare has both. DANE is like “a thousand times” better than just STARTTLS!
- RPKI is an Internet standard to prevent traffic from being redirected through network operators & countries we are not friends with, as a simple explanation. Currently it is fully possible for any internet network operator, including hostile countries, to “kidnap” traffic going to Apple iCloud for the purpose of eavesdropping and manipulation. Not exactly something we want happening in todays geopolitical climate, is it?
I was surprised and disappointed to see Apple lagging so far behind on email security for iCloud, and the risks this exposes their customers for.
So I simply wonder if this is something the ACLU or Electronic Frontier Foundation (EFF) could look into?
I’m not quite sure if I will actually reach the correct people at Apple with an article like this on Linkedin.
Originally published on LinkedIn.
