Live data from Hacker News

Apple Sign In

techcrunch.com

151–160 of 544 posts

Re: Apple Sign In

#151
post #58

Sounds like a good time to remind people about Telegram having a similar function for quite some time now. And just yesterday they announced a feature to simplify logging into web sites using TG bots: https://telegram.org/blog/privacy-discussions-web-bots It might be a personal choice, but for stuff when privacy is really important I'd definitely pick Telegram over Apple, no matter how much the latter claims to keep…

Telegram is unencrypted by default. All standard messages are stored on the server. Telegrams secret chat mode (end-to-end encryption) uses home made cryptography, and has been panned by experts in past. All group chat is in the clear and stored on the server. This is not the case with imessage. Comparing Telegram to iMessage, telegram is not in the same league as Apple. I don't trust either from TLA's or well funded…

It‘s not homemade crypto. It‘s just not the latest and greatest modern crypto but it has no glaring weakness.

Re: Apple Sign In

#152

Earlier quoted context omitted.

From the web page, I cannot tell what pricing is going to be - looks like you go out of your way to not scare off potential users. I can't find pricing information at all via Google searches, either. That's something I really dislike. Perhaps it's a necessary evil.

It’s at the bottom of the landing page: https://idbloc.co/#pricing The goal is to explain the concept ahead of the pricing as I think it’s quite novel to most users.

That page should have some sort of indication that it's scrollable since browsers increasingly don't show visible scrollbars until you're already scrolling. Something like Bootstrap's scrollspy might be useful since it could also show you the sections further down before you scroll through the intermediate sections.

Re: Apple Sign In

#153

Earlier quoted context omitted.

But will it be lower friction than login with Google or Facebook? It feels like it's more common for someone to have an account from one of those two than from Apple, and so "sign on with Apple" will never be able to be the only SSO option, while Google or Facebook could be. If the better (for the site) SSO options also have near-universal market penetration, what's the incentive to add Apple?

It's lower friction in that instead of having to click through an OAuth screen (and possibly re-enter your Google password), you just auth with FaceID/TouchID. And if you're writing an iOS app, then obviously the user has an Apple account.

I'm on Android, so I don't know how it works on iOS devices, but is reentering the Google credentials common? On my Android phone I doubt I had to enter my password more than 5 times in 2 years.

And the OAuth screen would be required anyway, as they have also shown on stage.

Re: Apple Sign In

#154
post #113
post #3

Disposable, anonymous email forwarding is a massive step forward for privacy. I know we've all been doing it for a while, but this on a consumer level is fantastic.

My first thought was: Bye bye mailinator.com

I use mailinator to have some privacy from my email provider.

Re: Apple Sign In

#155
post #136

I updated my AppleID since I haven't used it in years (have other devices) in anticipation of implementing this as soon as it's available on a site I'm working on. It appeared they offered two-factor authentication to get away from those 1990's type of security questions. Ah, not so fast - 2FA is only enabled with Apple devices. Poor play there, Apple. This service looks like something sorely needed - bring the rest…

FIDO U2F or TOTP. On the other hand it‘s perfectly understandable that they use his to sell their hardware.

Re: Apple Sign In

#156

Maybe I'm cynical, but this looks more like a data hording scheme than a protect my privacy enhancement. If I use Google to sign in, Google and the app has that data and can monetize it. Now if I sign in using Apple, they are going to have the data to monetize. They may keep the app from getting my information, but that means that their data is better than someone else's data, so it is more valuable. Also, they are g…

Who do you trust more _not_ to do sketchy stuff with your data, Apple or Google? For me it's unequivocally Apple.

How about 'neither of them'? Trusting Google with your data is like trusting a fox with guarding your hen house, trusting Apple with your data is trusting a fox which claims it turned vegetarian.

Run your own mail server and you'll have all the addresses you care to use, using any scheme you might think off. I've been doing this for decades now and it just plain works. A day or so to get the thing setup, 8 hours of maintenance per year and you're done. Use Google-free Android devices in your pocket, Linux or *BSD on your lap and in the server/broom cupboard and those foxes can claim to be vegans for all I care.

Re: Apple Sign In

#158
post #3

Disposable, anonymous email forwarding is a massive step forward for privacy. I know we've all been doing it for a while, but this on a consumer level is fantastic.

In case anyone needs something similar today: Outlook already allows you to create ephemeral top-level aliases, i.e. XXXX@outlook.com. You can use this to sign up, then delete the alias. It can't be traced back to your account and nobody blocks @outlook.com. https://account.live.com/names/Manage (not to take away from this announcement at all; just to provide some context. it's an often overlooked feature which peopl…

Microsoft's email management has some neat perks here: You can change which one's the primary as well. It's entirely possible for you to change the email address of your Microsoft account, by adding an alias, making it primary, and then deleting the original. In fairness, there are some quirks with this, my old email address would still get sent some receipts or some newsletters because the configuration for service A, B, or C was buried somewhere else in the account. But generally speaking, it works pretty well.

As someone who changed their name but had to keep their Google account with the old one because of how much Google account data/purchases can't be moved to a new account, this felt positively revolutionary. Google accounts can only have one Gmail address for their entire lifetime.

Re: Apple Sign In

#159
post #155
post #136

I updated my AppleID since I haven't used it in years (have other devices) in anticipation of implementing this as soon as it's available on a site I'm working on. It appeared they offered two-factor authentication to get away from those 1990's type of security questions. Ah, not so fast - 2FA is only enabled with Apple devices. Poor play there, Apple. This service looks like something sorely needed - bring the rest…

FIDO U2F or TOTP. On the other hand it‘s perfectly understandable that they use his to sell their hardware.

Google doesn't limit who can login by their device manufacturer, but the supposed privacy focused company does?
Post reply on HN