Live data from Hacker News

Apple Sign In

techcrunch.com

501–510 of 544 posts

Re: Apple Sign In

#501

Earlier quoted context omitted.

They care for privacy only for people who are willing to pay their high prices though.

Are you implying that Apple should care about the privacy of people who are not their customers? How would that work?

op mentioned apple core is privacy. i implies that they care it only for their high end customers. They could anytime do a low end mobile if privacy was their core. Their core is like any other business get maximum profits.

Re: Apple Sign In

#502
post #499

Earlier quoted context omitted.

True, but Facebook’s overwhelming majority of users is completely irrelevant now that their brand is irreparably tarnished. People will still use Facebook for a long time, but nobody other than a few diehards and people who work there want FB to own their identity. I believe that particular grand vision is dead for FB despite their user base.

No one is gonna buy an iPhone to "sign in with apple". No one is gonna make a group chat on iMessage where half the people aren't able to join anyway. Apple should release iMessage for Android.

people buy iphones to use imessage. an imessage group with non imessage people just turns into mms.

Re: Apple Sign In

#503

Earlier quoted context omitted.

Fb and G screwed themselves by: forcing users to submit real cell phone numbers (no forwarding numbers allowed) and real names. I’m laughing all the way to the apple oauth signup. So tired of G and Fb abusing users

Apple now requires 2FA for new accounts created on an iPhone and for 2FA they require a phone number.

but you can just go to icloud.com, sign up, and then type that into your phone. a pretty easy workaround.

Re: Apple Sign In

#504

Earlier quoted context omitted.

"+merchant" doesn't do squat to prevent bad actors from selling your email address. Anyone so inclined to sell your address would just strip off the postfix since they know it's unnecessary per the spec.

One of the many advantages of using a hosted solution with your own domain is that you can receive email from arbitrary addresses in the same inbox. For example merchant1@inboxname.mydomain.com gets sent to my inbox at Fastmail. inboxname@mydomain.com doesn't exist, so there's no way to get my "real" email address from what I give out to merchants. If I start getting spam on an address, whoops, you and everyone you s…

This is called subdomain addressing or subdomain stripping in case anyone wants to look up how to do this with your hosting provider.

Re: Apple Sign In

#505

Earlier quoted context omitted.

> think saying "chats are stored in plain text" is a reasonable way to convey that message If I keep your messages encrypted in my database and your keys on another unonnected database in another building, would it then be fair to say that I store your messages in plaintext? No. They are encrypted. It is a matter of fact. The word you are looking for is "not E2E encrypted" which can be a problem, but a different and…

>If I keep your messages encrypted in my database and your keys on another unonnected database in another building, would it then be fair to say that I store your messages in plaintext? If you can still access them, I don't think it is fair (or maybe rather: it is misleading) to say that you store them encrypted.

If you cannot trust me it doesn't matter.

If you trust me but are worried that someone else might break into the server it makes a huge difference.

Re: Apple Sign In

#506
post #32

Earlier quoted context omitted.

Presumably such services won't implement Sign In With Apple in the first place. People will accept it because they want the sheer quantity of users Apple provides. The useful thing about Apple is that they can force people to do things they don't particularly want to do, like accept anonymous e-mail addresses or stop using Flash. (unfortunately this is also the bad thing about Apple)

One other thing that seems powerful is that users that use Sign In With Apple have some guarantee of quality; with Apple using FaceId to authenticate, there's some amount of guarantee that you're not a bot.

Since when do Apple IDs require 3-D cameras to log in to? Mine only needs a password. I don't think my MacBook even does 3D face recognition.

Re: Apple Sign In

#507

Earlier quoted context omitted.

Are you implying that Apple should care about the privacy of people who are not their customers? How would that work?

op mentioned apple core is privacy. i implies that they care it only for their high end customers. They could anytime do a low end mobile if privacy was their core. Their core is like any other business get maximum profits.

Apple's premium price is exactly what allows them to focus on privacy.

Google/Facebook/etc. are able to offer you cheap products and services because they're selling your privacy to the highest bidder.

Apple is not doing this (because they care about privacy), so they need to charge a much higher price for similar products.

This is somewhat of a chicken and egg problem (did Apple care about privacy and charge a premium price, or did charging a premium price allow them to start caring about privacy?), but that's arguably not important. What's important is that Apple cares about privacy when their competitors do not.

Re: Apple Sign In

#509

Earlier quoted context omitted.

> My first thought was: Bye bye mailinator.com Mailinator can be pretty hard to use, since so many sites can detect the addresses and block their use. I've pretty much given up on it, and use Fastmail's very easy aliasing features with my domain. It's not quite as private, but it's a lot more reliable.

If I recall correctly, mailinator lets you host your own DNS record that sends mail to them. While I have never had any problems, back in the day I had nospam.jrock.us forward to mailinator and that worked every time. The truly clever programmer could open an SMTP session to the mail exchangers specified in your email address, and reject you because they point to mailinator. I know of 0 programmers in the world that…

> If I recall correctly, mailinator lets you host your own DNS record that sends mail to them.

While I'm sure that works. The main reason I'd use mailinator is for privacy (i.e. not exposing anything associated to me). If I have to use my domain, rather than their free ones, I'm still identifying my domain, so I might as well use my own aliases with my own mail system.

Domains are cheap, and mailinator really ought to register and discard a bunch of $1 specials on a regular basis.

Re: Apple Sign In

#510
post #363

Earlier quoted context omitted.

You can create/generate & save new login on the fly from the sign-in screen. At least with 1Password. It's clunkier than I think is strictly necessary, but it is effective.

Is that through a keyboard? Can the browser pass what I type to 1pass?

Yep, works through the keyboard. Click on the login or password field, then it gives you a key icon to get into 1Password, where you are prompted to generate a password and provide a username. Then you tell it to autofill that into the form. A little clunky but effective.
Post reply on HN