Live data from Hacker News

Why we won’t be supporting Sign in with Apple

blog.anylist.com

201–210 of 485 posts

Re: Why we won’t be supporting Sign in with Apple

#201

> One problem is that most Apple IDs are tied to an iCloud email address. So most accounts created via Sign in with Apple will use an iCloud email address. But many of those iCloud email addresses are unused and unchecked, because a customer’s “real” email account is their Gmail, Yahoo, or Hotmail account. Wow, this is a really good point. I just checked and yup -- my AppleID is directly linked to my icloud email, an…

My Apple ID was initially tied to my gmail address, and then at some point Apple forced me to change it, so I use my yahoo address. I never check that address, since I only use it for my Apple ID.

That has never been an issue.

Re: Why we won’t be supporting Sign in with Apple

#202

Earlier quoted context omitted.

I cope with this confusion by avoiding third-party login whenever possible. Why volunteer additional information about myself to Google or Facebook?

Because you can frequently avoid account creation, setting a new password etc if you click “sign in with google.” It’s a tradeoff but if you don’t see any value in it you maybe haven’t used it- it’s convenient.

With a password manager though, I avoid having tradeoffs in the first place. I get some amount of anonymity by separating my accounts, and it's trivial to login to sites with the same amount of clicks as with third party sso.

Re: Why we won’t be supporting Sign in with Apple

#204

Earlier quoted context omitted.

I cope with this confusion by avoiding third-party login whenever possible. Why volunteer additional information about myself to Google or Facebook?

Because you can frequently avoid account creation, setting a new password etc if you click “sign in with google.” It’s a tradeoff but if you don’t see any value in it you maybe haven’t used it- it’s convenient.

It's convenient right up to the point where I need to get back into an account but forgot if I used it or not - which is exactly the point of the parent.

I too have struggled to remember which third party sign-on I used (or if I used a native sign in), so now I avoid them every time, too.

They're literally only convenient if I want to have an account that I'm happy to 'throw away' or, to accidentally create duplicate accounts for the service.

For anything where I'm actually paying, they're a nightmare. Oh, did I sign into this with one of my google accounts? Was I crazy enough to use facebook? Or which of my emails did I use?

Re: Why we won’t be supporting Sign in with Apple

#206

Earlier quoted context omitted.

>My password manager is usually pretty good at letting me know if I've got a "normal" account with user/password, but it doesn't do anything to remind me if I ought to log in with one of the other services. Doesn't it somewhat defeat the purpose of using a password manager if you use one account to sign into multiple sites? Sign on services from main accounts seem like security flaws. If you use one main account reso…

> Doesn't it somewhat defeat the purpose of using a password manager if you use one account to sign into multiple sites? Yes. Password managers exist to solve the problem of credential reuse; third-party login exists to implement credential reuse. They are fundamentally opposed.

The credentials are at least not in multiple databases and stand some chance of being more secure, so it’s not as bad as with direct credential reuse, but yes, if you do compromise that one identity provider you’re in big trouble.

Re: Why we won’t be supporting Sign in with Apple

#207

> Furthermore, if there are platforms where AnyList doesn’t support Sign in with Apple, like Android, and someone wants to log into their account, they’d have to know their privaterelay.appleid.com email address. (And that certainly won’t be easy to find if you no longer have an iOS device.) And then they’d have to create a password with us, since they wouldn’t be able to sign in using Sign in with Apple. The easy an…

I agree in principal, but in practice this isn't as easy as one would hope. Each IdP has slightly different requirements and parameters for connecting clients. There may be significant code non-overlap across providers, not to mention across platforms.

Facebook, for instance, doesn't actually implement OpenID Connect, but has a custom layer on top of OAuth. Their recommended method of connecting is a client SDK for each platform.

Re: Why we won’t be supporting Sign in with Apple

#208

As they point out at the very bottom, all their arguments apply to all third-party sign-ons, so they're removing Facebook as well. So there's nothing specifically against Apple, despite the title seeming to imply it -- just that they're taking the move right now because of Apple's new policy coming into effect. I've got to say, I really wish there were a way to know whether I already used Facebook, Google, or Apple t…

Having had this same problem multiple times, I actually made it a point to save a “login” for those sites that when I autofill it reminds me which auth service I’ve used. Username: Log in with FB Password:

Neat trick. Some websites don't even bother giving you any choice for traditional username/password input though.

Re: Why we won’t be supporting Sign in with Apple

#209

Worth noting that AnyList automatically subscribed me to a marketing list without double opt-in or any kind of consent, which is exactly the kind of behaviour that makes me not want apps to have my real email address.

Having any kind of subscription payment massively increases complexity and support requirements in your app.

Re: Why we won’t be supporting Sign in with Apple

#210

Earlier quoted context omitted.

It’s not any transaction. It’s any digital transaction. You can sell physical goods and services either without giving Apple any cut, or by using Apple Pay and Apple just gets your standard credit card processing fee. Does Walmart let you sell your product in their store and say you can look at it there but get it cheaper from Amazon?

My app is not the App Store. The user has already paid to download my app from the App Store and Apple has gotten 30% of the cut. What users do on my App after that is none of Apple's business, though of course Apple would like to claim otherwise. Similarly, once I have bought something from Walmart I can use it as I wish. Our business transaction ends there, so your analogy isn't really apt. > Does Walmart let you s…

> once I have bought something from Walmart I can use it as I wish.

Not if it's a movie, music, or video game. I.e. anything with digital content.

Post reply on HN