Posted in

Apple Splits Browsing Traffic to Deny Any Single Tracker Full View

No single party gets to see both who you are and what you're looking at online - that's the premise behind iCloud Private Relay, the privacy feature Apple built into iOS 15. Rather than funneling traffic through one tunnel the way a conventional VPN does, Private Relay divides each web request across two independent relays, so that neither Apple nor its infrastructure partners can assemble a complete picture of a user's identity and browsing destinations.

The distinction matters because conventional VPNs, for all their benefits, still concentrate trust in a single operator. A VPN provider typically sees your real IP address and the sites you visit, even if it promises not to log that information. Users have long had to take that promise on faith, which is one reason the market for privacy tools has diversified so quickly - services such as one such provider compete largely on the strength of their no-logging claims and jurisdictional protections. Private Relay sidesteps the trust problem architecturally: it splits the two pieces of sensitive information - identity and destination - between separate entities that cannot compare notes.

Two Hops, Two Keys

The system works through an ingress proxy, run by Apple, and an egress proxy, run by a third-party content delivery network such as Cloudflare, Fastly, or Akamai. Each web request is encrypted in layers using public-key cryptography, a technique conceptually related to onion routing. The outer layer is encrypted with the ingress proxy's key; the inner layer, containing the actual destination address, is encrypted separately with the egress proxy's key. Apple's server can authenticate the user and strip the outer layer, but it cannot read the inner one. The egress proxy can decrypt the destination but never learns the user's original IP address, substituting a generalized address tied to a broader region instead.

Built for Speed, Not Just Secrecy

Unlike older VPN tunneling protocols, Private Relay runs on QUIC, a UDP-based transport layer standard, combined with the MASQUE framework for lightweight, multiplexed proxying. This pairing reduces connection latency and allows a device to switch between Wi-Fi and cellular networks without breaking the session - a practical advantage over legacy tunneling methods that often stumble during network handoffs.

What It Does, and Doesn't, Solve

Private Relay narrows what internet service providers, network observers, and visited websites can learn about a user, but it isn't a full substitute for a VPN or for Tor-level anonymity. It only covers Safari traffic and certain system requests, not every app on the device, and it requires an iCloud+ subscription. Its architecture reflects a broader shift in the privacy landscape: rather than asking users to trust one company completely, newer designs distribute trust across multiple independent operators, a model likely to influence how browsers and operating systems approach traffic privacy going forward.