Live data from Hacker News

Apple Sign In

techcrunch.com

441–450 of 544 posts

Re: Apple Sign In

#441
post #374

Earlier quoted context omitted.

"+merchant" doesn't do squat to prevent bad actors from selling your email address. Anyone so inclined to sell your address would just strip off the postfix since they know it's unnecessary per the spec.

Per what spec? Having “a+b” deliver to address “a” is Gmail specific, as far as I know.

Gmail ignores (or ignored?) dots on the left of the @, so some.person@gmail.com and someperson@gmail.com and s.om.e.person@gmail.com all went to the same inbox. That is gmail-specific.

Re: Apple Sign In

#442
post #331

Earlier quoted context omitted.

Thank you. I can see that. But if anyone really is curious about the meaning and needs clarification, I believe it’s best to ask.

I would have never thought you meant the former. I believe it’s better to be more clear and evident in your writing.

Same here.

Re: Apple Sign In

#443

Earlier quoted context omitted.

Therefore, anyone offering Facebook/Google login will also have to accept Apple's anonymized forwarded email addresses, like fc452bd5ea@privaterelay.appleid.com.

But this explicitly doesn’t work as an SSO. How can I tie that back to the actual email address they would have used to create an account using their FB / Google account? This sounds like a tremendous headache that I really don’t want to worry about. But Apple is looking to leverage their power in the app market to force me to implement a tool I may not be interested in as a merchant? I despise being strong armed. I…

“Tremendous headache” - put your toys back in your pram!

This is a brilliant move by Apple, and why my next phone will be another iPhone.

If you don't want to implement it you can kiss good bye to my business.

Re: Apple Sign In

#444
post #208

Earlier quoted context omitted.

As soon as Keychain can abstract away passwords completely (rando generation, never need to show the user the password), so an end user cant tell if a site supports Apple SSO or if Apple is just emulating SSO, Apple deserves to be crowned the Identity Winner.

There is a session on WebAuthN on Thursday.

if you are attending, could you share your learnings and how can we, outside the conference, can have access to the information displayed?

Re: Apple Sign In

#445

I develop apps myself and I am 100% onboard with using this instead of offering the signup with google or facebook buttons (can offer those as secondary options). I might even push users slightly to use this instead of others as it gives my apps a bit of extra trust worthiness imo. Only question I have is if it's possible to integrate this on websites and for non-apple products too? Because I would like my app which…

On the presentation they said it would be available on web and android.

Thanks, I was reading the docs and apparently it will be available for websites too and comes with a JS library which will let me use it on Android too. I am quite excited for this as a developer.

Re: Apple Sign In

#446
post #374

Earlier quoted context omitted.

Per what spec? Having “a+b” deliver to address “a” is Gmail specific, as far as I know.

It’s called subaddress extension: https://tools.ietf.org/html/rfc5233 Can confirm what parent poster is saying, we remove them on signup.

I wonder whether that's GDPR compliant. If I give you permission to contact me on me+alias@example.com and you strip off +alias and then contact me on me@example.com, you've inferred data about me I haven't explicitly given you. One could argue that's in a similar ballpark to running a geoIP lookup and then sending me mail through the post.

Re: Apple Sign In

#447

Earlier quoted context omitted.

No, you're clearly correct. But Apple pushing this does give it a sense of legitimacy and blocking signups from this service might just cause less signups than actually forcing people to use their real address. If Apple makes this extremely user friendly and quick to use than blocking it will cause a loss of signups.

Devils advocate: ‘Error: We love Apple and anonymity but we require a real email address to prevent fraud and to properly secure your account. Please enter your real email address.’

> ‘Error: We love Apple and anonymity but we require a real email address to prevent fraud and to properly secure your account. Please enter your real email address.’

GDPR would probably want to know specifically why you need someone's real email address.

Re: Apple Sign In

#448
post #374

Earlier quoted context omitted.

Per what spec? Having “a+b” deliver to address “a” is Gmail specific, as far as I know.

It’s called subaddress extension: https://tools.ietf.org/html/rfc5233 Can confirm what parent poster is saying, we remove them on signup.

> we remove them on signup.

But why?

Re: Apple Sign In

#449
post #370

Earlier quoted context omitted.

It’s the users who are being given power here over their own data. Yeah it’s tough but it’s been a long time coming.

I trust apple w/ my data way more than the EU

A non-sequitur if I ever saw one.

Re: Apple Sign In

#450
post #433

Earlier quoted context omitted.

Therefore, anyone offering Facebook/Google login will also have to accept Apple's anonymized forwarded email addresses, like fc452bd5ea@privaterelay.appleid.com.

How will this work if I use non-Apple products (and GOD BEWARE !) move from say an iPhone to an Android or an overpriced Macbook to a PC? Once I chose to use Apple-Sign In will I be locked into the ecosystem? Will there be 'Apple-Sign In' for Android?

I expect the disposable email will end up in Keychain, and you can export from there. Not the most user-friendly thing, but doable. Well, at least on a Mac.
Post reply on HN