Live data from Hacker News

Apple Sign In

techcrunch.com

461–470 of 544 posts

Re: Apple Sign In

#461

Earlier quoted context omitted.

Lol, I doubt it. Apple is years late and sucks at doing the leg work of getting third parties to adopt its suck. Look at Apple Pay which was launched at the perfect time.

Apple Pay, the market leader? https://www.similartech.com/compare/apple-pay-vs-google-pay

Interesting site since neither Apply pay or Google pay is available in lots of the countries on that map.

(Data is mostly correct though)

Re: Apple Sign In

#462
post #434

Earlier quoted context omitted.

I don't think that really means what you think it means. It's very similar to the way "Apple Pay has a Web API"—websites may implement it for authentication BUT it won't allow users on a Linux/Windows machine to Pay, either. This is the same thing. You'll need to use Safari on a Mac, or it won't appear.

From the developer documentation, "Sign In with Apple works natively on iOS, macOS, tvOS, and watchOS. And it works in any browser, which means you can deploy it on your website and in versions of your apps running on other platforms" The "works in any browser" and "apps running on other platforms" parts seem to suggest it will work fine on Linux or Windows machines or even Android devices.

Thank you for the clarification.

Re: Apple Sign In

#463
post #33

Earlier quoted context omitted.

Companies could absolutely disallow / block it. However they most likely won't for the same reason that people who are upset about Apple's 30% App Store cut still develop apps for iOS: they have their customers spend far more on average than other phone / OS users.

So a company would put a sign in with Apple button in their app, but disallow you from using it?

Won't pass review.

Re: Apple Sign In

#464

Earlier quoted context omitted.

It’s called subaddress extension: https://tools.ietf.org/html/rfc5233 Can confirm what parent poster is saying, we remove them on signup.

I wonder whether that's GDPR compliant. If I give you permission to contact me on me+alias@example.com and you strip off +alias and then contact me on me@example.com, you've inferred data about me I haven't explicitly given you. One could argue that's in a similar ballpark to running a geoIP lookup and then sending me mail through the post.

It seems rude (like if I told you to drop off a package at my back door and you put it by the front door), but I given the existence of RFC 5233 I don't see how this would be "data about me I haven't explicitly given you".

Also, if you try to mail people based on GeoIP data, you're going to have a bad time.

Re: Apple Sign In

#465

Earlier quoted context omitted.

The Telegram service has the capability to get the plain text of your chats, without any interaction with you. I think that's what the parent wanted to say. I think saying "chats are stored in plain text" is a reasonable way to convey that message and I think "plain wrong" is an overstatement.

> think saying "chats are stored in plain text" is a reasonable way to convey that message If I keep your messages encrypted in my database and your keys on another unonnected database in another building, would it then be fair to say that I store your messages in plaintext? No. They are encrypted. It is a matter of fact. The word you are looking for is "not E2E encrypted" which can be a problem, but a different and…

>If I keep your messages encrypted in my database and your keys on another unonnected database in another building, would it then be fair to say that I store your messages in plaintext?

If you can still access them, I don't think it is fair (or maybe rather: it is misleading) to say that you store them encrypted.

Re: Apple Sign In

#466
post #184

Earlier quoted context omitted.

Yep, the privacy focused company makes money selling hardware rather than ads.

So, the privacy draw is just another gimmick to them, and not a supposed part of their DNA?

If you're not paying them, they need to pay for you to use their services. And to do that, they will want to make their money back on that.

It is a good thing that they're not giving their services away for free; they're putting their money where their mouth is. If you look at all the companies that give their stuff away for free, they do it to collect data for advertising, and they make money from advertising, in most cases (unless they're using investor money to fund you).

Apple is not an advertising company, and I do not see any problem in them using this to draw in customers. It is a major selling point for Apple that they respect your privacy. They do a lot of their ML stuff on-device to preserve your privacy, they encrypt your data on their servers or anonymise it whenever possible, they do a lot to prevent apps from tracking you like limiting location access and other data, etc.

Re: Apple Sign In

#467

Earlier quoted context omitted.

But this explicitly doesn’t work as an SSO. How can I tie that back to the actual email address they would have used to create an account using their FB / Google account? This sounds like a tremendous headache that I really don’t want to worry about. But Apple is looking to leverage their power in the app market to force me to implement a tool I may not be interested in as a merchant? I despise being strong armed. I…

You can’t, that’s the idea. What do you need it for?

Sending invoices, GDPR exports, validating that a user contacting you is a certain account, etc.

Re: Apple Sign In

#468

Earlier quoted context omitted.

You can’t, that’s the idea. What do you need it for?

Sending invoices, GDPR exports, validating that a user contacting you is a certain account, etc.

You send information to the apple address, that's what its for. You can still send it invoices or a magic link, the user gets it and clicks on it, nothing is changed in that regard. The difference is they can turn off that email address and never hear from you again if that is what they want.

Re: Apple Sign In

#469

Earlier quoted context omitted.

I wonder whether that's GDPR compliant. If I give you permission to contact me on me+alias@example.com and you strip off +alias and then contact me on me@example.com, you've inferred data about me I haven't explicitly given you. One could argue that's in a similar ballpark to running a geoIP lookup and then sending me mail through the post.

It seems rude (like if I told you to drop off a package at my back door and you put it by the front door), but I given the existence of RFC 5233 I don't see how this would be "data about me I haven't explicitly given you". Also, if you try to mail people based on GeoIP data, you're going to have a bad time.

It's about permission. If I give a company a certain set of contact details, and they run some process to find other ways to contact me that seems unfair and beyond what I've given permission for. The fact that it's trival to find my real email from an alias I think is irrelevant - it's still an abuse of trust. Like I say, I can see a correlation with more invasive methods of finding other ways to contact me that I hadn't granted the company (imagine if they start contacting you on social media just because they could look up your profile from your name).

You could argue that a major feature of the GDPR is to legislate that just because a company can do something, doesn't mean it's allowed to do it.

Re: Apple Sign In

#470
post #440
post #433

Earlier quoted context omitted.

How will this work if I use non-Apple products (and GOD BEWARE !) move from say an iPhone to an Android or an overpriced Macbook to a PC? Once I chose to use Apple-Sign In will I be locked into the ecosystem? Will there be 'Apple-Sign In' for Android?

this is the same problem you get from any identity provider — what happens when you finally delete your facebook? — it's just more obvious with Apple. With a 97% satisfaction rate, most iPhone users don’t want to go anywhere else… but yes, if you want to stay free, you should always create credentials directly with any app or service you use, when possible. That said, the concept of "Apple Sign-In" for Android and ot…

Yes, but while I can choose to log in with facebook, or google, or whatever, it appears that Apple are mandating that app providers use the Apple sign-in, which means app users no longer get to choose.

Unless I'm misunderstanding what the mandatory part is.

Post reply on HN