Live data from Hacker News

Apple Successfully Implements OpenID Connect with Sign in with Apple

openid.net

91–100 of 121 posts

Re: Apple Successfully Implements OpenID Connect with Sign in with Apple

#91
post #79

Earlier quoted context omitted.

I wish there was an easy way to save a hackernews comment for later

Click on the 'X minutes ago' permalink on the comment, and then select 'favorite'. It will show up under 'favorited ... comments' linked from your profile page while logged in.

More generally, and as hinted to by floatingatoll, the the 'X minutes ago' is also a permalink meaning after you click on it you can bookmark it in any bokmarking system you use. (I use pinboard.in)

Also FWIE, going to the permalink for a comment also gives you access to the flag feature.

Re: Apple Successfully Implements OpenID Connect with Sign in with Apple

#92

Earlier quoted context omitted.

What value would they enter at what prompt in order to activate the Apple Accounts process? For example, "openid.apple.com" or "some_email_address@openid.apple.com" or ...?

`OpenID Connect` (OIDC) is not `OpenID`, despite the confusingly similar name. For the most part, `OpenID Connect` prefers to the wall full of Sign-In Options buttons/logos for determining ID Provider, instead of a user entering some specific address (as `OpenID` used to) and a lookup process, because there is more ceremony involved in establishing trust between an ID Provider and Relying Party as OIDC is built on to…

Yes, there is a way to do the dynamic functionality of OpenID 2.0 on Connect by using Metadata, WebFinger, and Dynamic Client Registration, but most of the large providers do not support all three of these.

Google (for instance) wants a relying party to do some amount of registration/click through first in a web browser before their site can rely on Google. Apple (for their part) hangs your ability to support Sign in with Apple off of an app registration, which requires a developer or enterprise account and thus an annual fee.

Re: Apple Successfully Implements OpenID Connect with Sign in with Apple

#93
post #53

Earlier quoted context omitted.

> why 99% of git usage is on Github, Gitlab or Bitbucket I doubt it.

I don’t.

There are a lot of corporate or "free" projects that are on self-hosted platforms; plus, there are a number of other players with smaller but non-negligible share such as SourceForge.

Re: Apple Successfully Implements OpenID Connect with Sign in with Apple

#94
post #57

Shameless plug (but I hope that's okay, again): IRMA Authentication is an open-source app [1] and protocol that offers privacy-friendly attribute based authentication and signing using Camenisch and Lysyanskaya's Idemix [2]. It's currently heavily focused towards The Netherlands, where citizens can obtain attributes such as name, home address and age. These attributes can then be selectively disclosed directly to a s…

Is there an HN post about this?

Re: Apple Successfully Implements OpenID Connect with Sign in with Apple

#95
post #81

Earlier quoted context omitted.

Click on the 'X minutes ago' permalink on the comment, and then select 'favorite'. It will show up under 'favorited ... comments' linked from your profile page while logged in.

Oh! Very nice! Thank you!

Favorites also works on stories (which you may already know).

Re: Apple Successfully Implements OpenID Connect with Sign in with Apple

#96
post #82
post #57

Shameless plug (but I hope that's okay, again): IRMA Authentication is an open-source app [1] and protocol that offers privacy-friendly attribute based authentication and signing using Camenisch and Lysyanskaya's Idemix [2]. It's currently heavily focused towards The Netherlands, where citizens can obtain attributes such as name, home address and age. These attributes can then be selectively disclosed directly to a s…

> Shameless plug (but I hope that's okay, again) I find lots of cool shit on hn because people decide to share their side projects that I wouldn't otherwise have seen. It only becomes a problem when people don't disclose they have a bias or connection to a product when they should.

I wouldn't call it a side project - it's supported by the government and city of Nijmegen but very cool

Re: Apple Successfully Implements OpenID Connect with Sign in with Apple

#97
Apple's online credential/auth* user experience is terrible.

I can't wait till Apple fixes their account auto-lock feature. On weekly basis I have to unlock my account because someone is trying to login with my email. I contacted the customer service to see if something could be done to avoid auto-locking. The only suggestion was to pick another email address that's not common.

Also in order for me to unlock I have to supply my password along with answers to my 3 secret questions. Additionally my recovery email cannot be the same as my account email.

Why Apple's online is terrible compared to their hardware/software?

Re: Apple Successfully Implements OpenID Connect with Sign in with Apple

#98

Apple's online credential/auth* user experience is terrible. I can't wait till Apple fixes their account auto-lock feature. On weekly basis I have to unlock my account because someone is trying to login with my email. I contacted the customer service to see if something could be done to avoid auto-locking. The only suggestion was to pick another email address that's not common. Also in order for me to unlock I have t…

To be honest I read all your complaints as a "screw Apple for protecting me".. pretty disrespectful. Their answer is expected. If your email is something like "john.smith@gmail.com" - there are like few hundred thousends of Smiths there.. And the complaint that recovery email cannot be the same as account email - so you want your account to be compromised without ANY way to recover it? Those seem like complaints of a completely "security oblivious" customer.

Re: Apple Successfully Implements OpenID Connect with Sign in with Apple

#99
post #57

Shameless plug (but I hope that's okay, again): IRMA Authentication is an open-source app [1] and protocol that offers privacy-friendly attribute based authentication and signing using Camenisch and Lysyanskaya's Idemix [2]. It's currently heavily focused towards The Netherlands, where citizens can obtain attributes such as name, home address and age. These attributes can then be selectively disclosed directly to a s…

Is IRMA still phone-only? IRMA can't meet its stated design goals if owning a smartphone is required.

Re: Apple Successfully Implements OpenID Connect with Sign in with Apple

#100
post #98

Apple's online credential/auth* user experience is terrible. I can't wait till Apple fixes their account auto-lock feature. On weekly basis I have to unlock my account because someone is trying to login with my email. I contacted the customer service to see if something could be done to avoid auto-locking. The only suggestion was to pick another email address that's not common. Also in order for me to unlock I have t…

To be honest I read all your complaints as a "screw Apple for protecting me".. pretty disrespectful. Their answer is expected. If your email is something like "john.smith@gmail.com" - there are like few hundred thousends of Smiths there.. And the complaint that recovery email cannot be the same as account email - so you want your account to be compromised without ANY way to recover it? Those seem like complaints of a…

very interesting idea
Post reply on HN