Earlier quoted context omitted.
"+merchant" doesn't do squat to prevent bad actors from selling your email address. Anyone so inclined to sell your address would just strip off the postfix since they know it's unnecessary per the spec.
Per what spec? Having “a+b” deliver to address “a” is Gmail specific, as far as I know.
Apple Sign In
441–450 of 544 posts
Re: Apple Sign In
#442Earlier quoted context omitted.
Thank you. I can see that. But if anyone really is curious about the meaning and needs clarification, I believe it’s best to ask.
I would have never thought you meant the former. I believe it’s better to be more clear and evident in your writing.
Re: Apple Sign In
#443Earlier quoted context omitted.
Therefore, anyone offering Facebook/Google login will also have to accept Apple's anonymized forwarded email addresses, like fc452bd5ea@privaterelay.appleid.com.
But this explicitly doesn’t work as an SSO. How can I tie that back to the actual email address they would have used to create an account using their FB / Google account? This sounds like a tremendous headache that I really don’t want to worry about. But Apple is looking to leverage their power in the app market to force me to implement a tool I may not be interested in as a merchant? I despise being strong armed. I…
This is a brilliant move by Apple, and why my next phone will be another iPhone.
If you don't want to implement it you can kiss good bye to my business.
Re: Apple Sign In
#444Earlier quoted context omitted.
As soon as Keychain can abstract away passwords completely (rando generation, never need to show the user the password), so an end user cant tell if a site supports Apple SSO or if Apple is just emulating SSO, Apple deserves to be crowned the Identity Winner.
There is a session on WebAuthN on Thursday.
Re: Apple Sign In
#445I develop apps myself and I am 100% onboard with using this instead of offering the signup with google or facebook buttons (can offer those as secondary options). I might even push users slightly to use this instead of others as it gives my apps a bit of extra trust worthiness imo. Only question I have is if it's possible to integrate this on websites and for non-apple products too? Because I would like my app which…
On the presentation they said it would be available on web and android.
Re: Apple Sign In
#446Earlier quoted context omitted.
Per what spec? Having “a+b” deliver to address “a” is Gmail specific, as far as I know.
It’s called subaddress extension: https://tools.ietf.org/html/rfc5233 Can confirm what parent poster is saying, we remove them on signup.
Re: Apple Sign In
#447Earlier quoted context omitted.
No, you're clearly correct. But Apple pushing this does give it a sense of legitimacy and blocking signups from this service might just cause less signups than actually forcing people to use their real address. If Apple makes this extremely user friendly and quick to use than blocking it will cause a loss of signups.
Devils advocate: ‘Error: We love Apple and anonymity but we require a real email address to prevent fraud and to properly secure your account. Please enter your real email address.’
GDPR would probably want to know specifically why you need someone's real email address.
Re: Apple Sign In
#448Earlier quoted context omitted.
Per what spec? Having “a+b” deliver to address “a” is Gmail specific, as far as I know.
It’s called subaddress extension: https://tools.ietf.org/html/rfc5233 Can confirm what parent poster is saying, we remove them on signup.
But why?
Re: Apple Sign In
#449Re: Apple Sign In
#450Earlier quoted context omitted.
Therefore, anyone offering Facebook/Google login will also have to accept Apple's anonymized forwarded email addresses, like fc452bd5ea@privaterelay.appleid.com.
How will this work if I use non-Apple products (and GOD BEWARE !) move from say an iPhone to an Android or an overpriced Macbook to a PC? Once I chose to use Apple-Sign In will I be locked into the ecosystem? Will there be 'Apple-Sign In' for Android?