Live data from Hacker News

Apple Sign In

techcrunch.com

201–210 of 544 posts

Re: Apple Sign In

#201
post #3

Disposable, anonymous email forwarding is a massive step forward for privacy. I know we've all been doing it for a while, but this on a consumer level is fantastic.

In case anyone needs something similar today: Outlook already allows you to create ephemeral top-level aliases, i.e. XXXX@outlook.com. You can use this to sign up, then delete the alias. It can't be traced back to your account and nobody blocks @outlook.com. https://account.live.com/names/Manage (not to take away from this announcement at all; just to provide some context. it's an often overlooked feature which peopl…

I dont think thats quite the same thing as an Identity Service, its just a component. In Microsoft's world im either using my Microsoft Account to sign in OR using throwaway email addresses, not both.

.

Apple can get way ahead of the competition by combining about 3 things.

1) Ephemeral email addresses

2) OAuth or apples equivalent tokens

3) Keychain autogenerate and auto-populate

If all those products are integrated correctly, this becomes the SINGLE sign on of single sign ons. If a service supports Apple OAuth, your name is hidden, and you only have one Apple password to remember. If the service doesnt support Apple Tokens, then apple fills in a private email address and a random password, and abstracts away the fact that the service doesnt support Apple Tokens. The user experience is nearly the same regardless. Tokens and randomly generated passwords should be managed from the same interface, allowing you to either revoke access (token) or cycle the key (both.)

I've felt it for a while, but the banking industry needs to arrive at something similar. Chase, BoA, WF, and Citi should turn Zelle into a banking OAuth Identity Service.

Re: Apple Sign In

#202
This is neat. But I'd have thought the lower-hanging fruit anti-spam wise for Apple would've been to add a "mark as spam" button next to push notifications so users can start reporting all the apps that abuse push notifications to send them advertisements.

Re: Apple Sign In

#203
post #146

While I like this for privacy purpose this is pretty nafarious. There is no mechanism by which you can use this sign-on without Apple. That means you are stuck with these specialized accounts you would need to re-setup once you leave apple. Just another lock-in. This is definitely not the first time apple does anything like this. If apple really cared they would make a tool for any device or operating system to enabl…

... if you looked at the screenshot of the app they showed it also had sign up without using Apple Sign in and just using a email address.

You might be misunderstanding what the poster was talking about -- it's not that you'll need an Apple ID to sign up for a site, it's that once you sign up with an Apple ID, you might not have a way to link your account to a different email address. That effectively means that you'd need to recreate your account when you move away from Apple.

Of course, the other side of that is that sites are probably going to have ways to link accounts, and it likely won't be a huge deal. They certainly have no motivation to help Apple with lock in. It's not going to be any different from the process that exists today for moving associating an email with an account you created through Google/Github signin.

Still, it would be nice to have a way to use this without an iPhone, or it will be a (small) extra piece of friction you just have to deal before moving ecosystems, rather than piecemeal after getting a new phone.

Also note that the same exact concerns exist with Google/Facebook sign in, it's just that they aren't tied to a physical device so you only need to worry about losing them if you're making a conscious decision to delete your account.

Re: Apple Sign In

#204
post #8

Finally an excuse to delete my Facebook account completely. SSO was the only reason I was still using it. I do wonder how many sites will actually implement it.

Isn't your reason not to use Facebook an even greater reason to not use their sso?

Re: Apple Sign In

#205

This is a huge move. Apple striking at the core of Facebook's play to own your identity, which they had with Facebook Connect but have completely fudged out with countless breaches of user privacy and trust. I used to be the biggest fanboy of facebook connect, but now I have to say: Go Apple.

Apple ID as SSO, iMessage Profile, Memoji, and Apple Pay. Apple is near FB Messenger parity, now that it functions as an account for external services. It's an extremely strong move on Apple's part, especially considering how close to it they have been for a while. They sure like taking their time sometimes.

Re: Apple Sign In

#206

Can’t services just disallow/block this address? Fun thing is, Apple themselves block name+addon@gmail.com addresses when using their dev console. You can bet that some companies will disallow Apple’s signature private passwords similarly if they can, in the name of ‘security’ or what have you. Or am I being too cynical? Feel free to CMV. EDIT: best response addressing this seems to be ‘The addresses are only generat…

they can block it but when you have 90million people using it, why would you?

Re: Apple Sign In

#207
post #177

Earlier quoted context omitted.

You use pretty strong language and have your facts wrong (in the post above when you say chats are stored in plain text). What's your angle? Also, we are discussing web login options here which afaik Signal doesn't support.

My angle is stopping folks using and recommending telegram. Where are my facts wrong?

Like I said, the chats are stored (or are claimed to be stored) in an encrypted form. But I think I understand why it may count as "stored unencrypted" in your eyes. Still, Signal won't cut it. It's too inconvenient to use, and while maybe it provides better security it's like a very strong password policy in a company that entices users to just write down passwords on Post-it notes.

I couldn't get my friends use Signal, it's not there yet in terms of user friendliness (hell, I wouldn't use it). But Telegram works for me, and I consider it a substantial improvement over Whatsapp. YMMV.

Re: Apple Sign In

#208

This single feature shown off today at WWDC has solidified my forever lock-in on all things Apple and especially iOS: no longer will my email be sold needlessly or be spammed and my logging into to different web properties sold to marketers and ad networks and data aggregators. I trust Apple a whole lot more becaUe they charge and arm-and-a-leg for high end hardware and soon services because the products and services…

As soon as Keychain can abstract away passwords completely (rando generation, never need to show the user the password), so an end user cant tell if a site supports Apple SSO or if Apple is just emulating SSO, Apple deserves to be crowned the Identity Winner.

Re: Apple Sign In

#209
post #201

Earlier quoted context omitted.

In case anyone needs something similar today: Outlook already allows you to create ephemeral top-level aliases, i.e. XXXX@outlook.com. You can use this to sign up, then delete the alias. It can't be traced back to your account and nobody blocks @outlook.com. https://account.live.com/names/Manage (not to take away from this announcement at all; just to provide some context. it's an often overlooked feature which peopl…

I dont think thats quite the same thing as an Identity Service, its just a component. In Microsoft's world im either using my Microsoft Account to sign in OR using throwaway email addresses, not both. . Apple can get way ahead of the competition by combining about 3 things. 1) Ephemeral email addresses 2) OAuth or apples equivalent tokens 3) Keychain autogenerate and auto-populate If all those products are integrated…

Why do users need to have a 3rd party managing their identity? It seems like it would be _safer_ if users could setup their own OAuth infra which would then be certified for use with other systems. For people who lack the expertise or will to roll their own infra then they can use something like Apple ID.

Re: Apple Sign In

#210
post #21

Someone who is not apple should do this and charge for it. I'd pay $10 for something like that

Don't Fastmail aliases already work the same way?

That's $5 a month for 600 private email addresses, which (for me at least) is more than enough to cover all of the services I use.

Unless they're easier to re-associate with your main account for some technical reason I'm not aware of?

Post reply on HN