Live data from Hacker News

Apple Sign In

techcrunch.com

171–180 of 544 posts

Re: Apple Sign In

#171
post #58

Sounds like a good time to remind people about Telegram having a similar function for quite some time now. And just yesterday they announced a feature to simplify logging into web sites using TG bots: https://telegram.org/blog/privacy-discussions-web-bots It might be a personal choice, but for stuff when privacy is really important I'd definitely pick Telegram over Apple, no matter how much the latter claims to keep…

Telegram is unencrypted by default. All standard messages are stored on the server. Telegrams secret chat mode (end-to-end encryption) uses home made cryptography, and has been panned by experts in past. All group chat is in the clear and stored on the server. This is not the case with imessage. Comparing Telegram to iMessage, telegram is not in the same league as Apple. I don't trust either from TLA's or well funded…

Plain wrong. It's not end-to-end encrypted by default, that's true. But all chats are encrypted with key portions distributed between different jurisdictions in case some country gets funny ideas.

Chat archives are stored encrypted, not in plain text. Please cite your sources if you claim otherwise.

Re: Apple Sign In

#172
post #151

Earlier quoted context omitted.

Telegram is unencrypted by default. All standard messages are stored on the server. Telegrams secret chat mode (end-to-end encryption) uses home made cryptography, and has been panned by experts in past. All group chat is in the clear and stored on the server. This is not the case with imessage. Comparing Telegram to iMessage, telegram is not in the same league as Apple. I don't trust either from TLA's or well funded…

It‘s not homemade crypto. It‘s just not the latest and greatest modern crypto but it has no glaring weakness.

[citation needed]..

But it’s absolutely homemade by math PhDs (not crypto specialists). And if you search for ‘telegram security’ you’ll find any number of articles pointing out a bunch of weaknesses. It’s also only half open source.

Re: Apple Sign In

#173
post #159
post #155

Earlier quoted context omitted.

FIDO U2F or TOTP. On the other hand it‘s perfectly understandable that they use his to sell their hardware.

Google doesn't limit who can login by their device manufacturer, but the supposed privacy focused company does?

Yep, the privacy focused company makes money selling hardware rather than ads.

Re: Apple Sign In

#174

Can’t services just disallow/block this address? Fun thing is, Apple themselves block name+addon@gmail.com addresses when using their dev console. You can bet that some companies will disallow Apple’s signature private passwords similarly if they can, in the name of ‘security’ or what have you. Or am I being too cynical? Feel free to CMV. EDIT: best response addressing this seems to be ‘The addresses are only generat…

Is that block a recent thing? It might be different as for my on GSuite account I can add the name+addon@mydomain.com - it might just be a difference between the "public" Gmail system vs the Gsuite Gmail system. In which case, my question is completely invalid and feel free to ignore ;)

Note: This comes from my own developer account having 3 name+addon@ accounts live, and working with things like ApplePay etc for testing.

Re: Apple Sign In

#175
This single feature shown off today at WWDC has solidified my forever lock-in on all things Apple and especially iOS: no longer will my email be sold needlessly or be spammed and my logging into to different web properties sold to marketers and ad networks and data aggregators. I trust Apple a whole lot more becaUe they charge and arm-and-a-leg for high end hardware and soon services because the products and services are the products not their users.

Re: Apple Sign In

#176
post #113
post #3

Disposable, anonymous email forwarding is a massive step forward for privacy. I know we've all been doing it for a while, but this on a consumer level is fantastic.

My first thought was: Bye bye mailinator.com

As if everybody uses Apple.

Re: Apple Sign In

#177
post #123

Earlier quoted context omitted.

For a start, I don't own, and don't want Apple devices. Also, stories about FISA overreach, PRISM, the rest of the alphabet soup plus gag orders do not particularly inspire confidence.

then use signal. friends don't let friends use telegram. Signal gives you all of this without the snake oil that telegram is selling you.

You use pretty strong language and have your facts wrong (in the post above when you say chats are stored in plain text). What's your angle?

Also, we are discussing web login options here which afaik Signal doesn't support.

Re: Apple Sign In

#178
post #177

Earlier quoted context omitted.

then use signal. friends don't let friends use telegram. Signal gives you all of this without the snake oil that telegram is selling you.

You use pretty strong language and have your facts wrong (in the post above when you say chats are stored in plain text). What's your angle? Also, we are discussing web login options here which afaik Signal doesn't support.

My angle is stopping folks using and recommending telegram. Where are my facts wrong?

Re: Apple Sign In

#179
Am I correct that TechCrunch page violates GDPR? I don't see any option to opt-out from being tracked. There is OK button and manage option link, but I can't manage anything, I can only agree for tracking...

Re: Apple Sign In

#180
I'm not an Apple user, and don't own any of their products, but this is a great step forward for privacy. I'm happy to see companies prioritizing privacy for users.

That being said, any company that actually cares about collecting users' identities (you know, the ones you'd actually want to use this for) will definitely block @privaterelay.appleid.com from being used. Apple would've been better off using a well-known domain and having both private and non-private addresses on it, like @me.com .

Post reply on HN