frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

Apple Fixes Hide My Email Vulnerability After 404 Media Coverage

https://www.404media.co/apple-fixes-hide-my-email-vulnerability-after-404-media-coverage/
71•arto•2h ago

Comments

lapcat•1h ago
> Apple told 404 Media it deployed a patch for the issue on July 3, which the company says has fully resolved the issue.

> Now Apple says it has been fixed, we can add that, in simple terms, it required sending a target Hide My Email user a message that got rejected as spam.

I would note that Mac Mail app (I haven't tested iOS Mail) still has an Apple Account email address disclosure vulnerability, though this requires the user to reply to a maliciously crafted email. The vulnerability affects all users of Mail app, even if they don't use Hide My Email! https://lapcatsoftware.com/articles/2026/7/9.html

argee•53m ago
I have a question I wasn’t sure how to ask HN that is tangentially related to this. I’m the developer of an app where people can add other users to their workspaces, via email. The way this currently works is that your email gets added to the workspace and then when you log in with that email, you get access.

Now, this of course fails with “hide my email”. What’s the appropriate/standard way to handle this? Should I be using urls with invite codes instead of associating the email itself with access? I’m a little hesitant to do that since the code would have to persist in session and the business logic would have to occur on the login portal, since the mobile/desktop apps don’t share web cookies. Is deep linking the answer?

Rumudiez•44m ago
email addresses are not good primary or foreign keys, so yes you should be using IDs of one form or another. this shouldn't affect your authentication scheme (cookies vs bearer tokens or what have you), just authorization. if you've muddied the two, you'll have some debt to resolve and this issue could just be a valuable tip-off to that
hawtads•31m ago
I think OP is referring to the initial sign up based on an invite link, not the database storage itself.

It depends whether you want to check the invite code against the invitee's email. It very much depends on the application. For most use cases, just verifying the code is fine and accept any email addresses that posses it.

Essentially ask yourself this, if you change the UI a bit and allow any user to sign up with any email, and the workspace joining is done via a code they enter after login, is that acceptable for your product design and security posture.

a9ex•45m ago
So how did the vulnerability work exactly?
culi•35m ago
https://archive.ph/O4pKL
j79•5m ago
Looks like that was the original article, which didn't have much details about how the exploit worked.

> 404 Media is not revealing the exact details of the vulnerability because it can still be exploited as of Monday, when 404 Media verified the issue with one of our own hidden email addresses.

However, based on the current article:

> Now Apple says it has been fixed, we can add that, in simple terms, it required sending a target Hide My Email user a message that got rejected as spam. “We don't know how often hidden email addresses were leaked in email logs. For many major email hosts, the leak was triggered simply by an email being automatically rejected as spam, even if it was a legitimate message. Such emails probably didn't make it to your inbox, so you can’t review your spam folder to learn whether you were affected,” Murphy and EasyOptOut co-founder Ben Weiner said in a new statement.

My guess is that if an e-mail was rejected as Spam, the response had the actual e-mail included. However, based on the next paragraph:

> “The bug that caused Apple's Hide My Email to leak hidden email addresses to senders has been fixed. However, we don't think the risk to Hide My Email users has been eliminated. Because non-malicious emails could bounce, revealing your hidden email address, and because mail transfer logs are often retained, we'd assume that any hidden email address linked to a Hide My Email address created before July 7, 2026, may have been exposed and could still be in third-party logs,” they added.

It seems even bounced e-mails could leak your actual e-mail.

90k Flock cameras have gone up in the US: What they track and how to check

https://www.zdnet.com/article/flock-ai-cameras-risks-us-how-to-find-nearby-what-they-track/
1•CrankyBear•19s ago•0 comments

MentraOS no longer needs a cloud relay

https://mentraglass.com/blogs/blog/mentra-roadmap-update-moving-to-miniapps-on-the-phone
1•genzcash•19s ago•0 comments

Greedy is optimal for single-pass semi-streaming matching

https://arxiv.org/abs/2607.14656
1•MarcoDewey•1m ago•0 comments

Is fine-tuning still needed? LLMs, RAG, & LoRA – IBM Technology [video]

https://www.youtube.com/watch?v=-W2JdSl1v48
1•me_bx•1m ago•0 comments

Apple Private Cloud Compute SoC 3 audit reports

https://support.apple.com/guide/certifications/apple-private-cloud-compute-soc-3-audit-apc95a31b9...
1•throwfaraway4•2m ago•0 comments

Show HN: Tokenmaxx – CLI that merges usage across Claude Code and Codex accounts

https://github.com/RubricLab/tokenmaxx
3•sarimmalik•4m ago•0 comments

I built an AI agent I can't turn off. Now it won't listen to me

https://andrewrussell.substack.com/p/i-built-an-ai-agent-i-cant-turn-
1•aruss•4m ago•0 comments

Measuring the Impact of High Availability on Managed Postgres Performance

https://clickhouse.com/blog/postgresbench-ha
1•saisrirampur•4m ago•0 comments

A Taxonomy of Omnicidal Futures Involving Artificial Intelligence (2025)

https://arxiv.org/abs/2507.09369
1•measurablefunc•4m ago•0 comments

Database Detective: Minor Crimes Division

https://store.steampowered.com/app/3950130/Database_Detective_Minor_Crimes_Division/
1•evo_9•5m ago•0 comments

Show HN: Statgate, statistically calibrated ship/block CI gates for LLM evals

https://github.com/yashchimata/statgate
1•yashchimata•5m ago•0 comments

Gemini 3.6 Flash

https://twitter.com/OfficialLoganK/status/2079590123038204255
1•tosh•5m ago•0 comments

Show HN: I left Figma to build a diffusion-based UI design tool

https://diffui.ai/blog/show-hn
3•jjcm•5m ago•1 comments

Show HN: Web-based Jujutsu revset explorer and debugger

https://juju.bi/tools/revset
1•pksunkara•6m ago•0 comments

The Unity CLI: manage Unity from your terminal

https://unity.com/blog/meet-the-unity-cli
1•nateb2022•8m ago•0 comments

Work Officially Begins on 2 World Trade Center

https://www.designdevelopmenttoday.com/news/news/22970950/work-officially-begins-on-2-world-trade...
1•geox•9m ago•0 comments

Buzz: Where humans and agents work together

https://block.xyz/inside/introducing-buzz-where-humans-and-agents-work-together
1•srameshc•9m ago•0 comments

Framework for building agent-friendly CLIs

https://github.com/tokyo-corp/tokyo
2•misterchocolat•10m ago•0 comments

The secret Trump administration battle to fight Chinese AI

https://www.axios.com/2026/07/20/ai-us-china-open-source-kimi
2•koolhead17•11m ago•0 comments

AI Consensus circulates your prompt thru Claude, GPT and Gemini until consensus

https://shipdiary.dev/t/8a9c9114bac40fa8f1ec6cf7
1•AIConsensus•11m ago•0 comments

Show HN: Language Model Builder (an app to learn about and build models)

https://languagemodelbuilder.com/
1•felixrieseberg•12m ago•0 comments

The fastest coding agent for offline usage?

https://github.com/gni/maquis
1•opensecurity•15m ago•1 comments

Against Claudefishing – AI detection feature on Substack

https://post.substack.com/p/against-claudefishing
2•pixelesque•15m ago•0 comments

Separating Description from Interpretation to Preserve Theoretical Reusability

https://zenodo.org/records/21362371
1•ErystelaThevale•16m ago•0 comments

Fly Up the Delaware

https://www.inquirer.com/news/inq2/delaware-river-islands-pennsylvania-new-jersey-20260721.html
1•caditinpiscinam•17m ago•0 comments

Kubernetes won the container decade. Google's Agent Substrate wants the next one

https://thenewstack.io/kubernetes-ai-agent-runtime/
2•ryan_j_naughton•17m ago•0 comments

The Floating Piers

https://en.wikipedia.org/wiki/The_Floating_Piers
1•simonebrunozzi•21m ago•0 comments

Peekinduck: AI voice agents that run B2B SaaS demos, onboarding, and support

https://peekinduck.ai/
1•cgchen•21m ago•0 comments

J-Space Oddity: Do VLMs Dream of Text Tokens?

https://ykumar.me/blog/j-space-oddity/
1•ykumards•21m ago•0 comments

Pixar Bears Brunt of Disney Studio Layoffs as Company Axes Several Hundred

https://variety.com/2026/film/news/pixar-layoffs-disney-studios-several-hundred-employees-1236817...
1•ourmandave•23m ago•0 comments