Live data from Hacker News

Why we won’t be supporting Sign in with Apple

blog.anylist.com

281–290 of 485 posts

Re: Why we won’t be supporting Sign in with Apple

#281
post #279

Developer should just ask for user's email after new sign up using third party provider. Even Facebook does not require email for user to sign up. They should separate the email used for the account & the email used for third party sign in. Because 1 user can have multiple third party sign in, all with different email. I think they did not need to care about customer who did not check the reply email from support, be…

What's to stop someone signing up with a fake email and sharing it on a forum so that many people can sign in with it?

Yes, I know that there are ways to reduce this by scanning IPs and so on, but by using third party auth you offload that onto the auth providers.

Re: Why we won’t be supporting Sign in with Apple

#282

A lot of the points they make here are real points, and I think AnyList has validity in their actions. I also think it’s not as unmanageable as it seems. Let’s analyze this quote, from the article, as it highlights what I imagine are a big crux of this issue: > with the “Hide My Email” option, your spouse or friends obviously won’t know your privaterelay.appleid.com email address, so when they enter your email addres…

In a perfect world people would share things with you without entering your private email address in other people's systems. I don't want to be in the database of whatever app or system my friends decided to join, nor I want to receive spam from these companies. Many of the objections come from wanting to do things the old way, without privacy and responsible handling of private data.

Can you elaborate on "private email address"? I'd be offended if someone were careless with a more intimate identifier like my personal cell phone number, but I've always considered arms-length interactions with businesses and institutions I'm not fully on board with to be the whole point of email.

Re: Why we won’t be supporting Sign in with Apple

#283
post #171

Earlier quoted context omitted.

Yes! Especially once you start juggling multiple accounts for different companies and projects. Becomes a guessing game, and each wrong guess creates another account magically. Infuriating

Time to create a new service to unify all your SSO accounts! One single SSO!

If only there was a decentralized option that has already solved this... We could call it OpenID or something like that... Oh, wait..

Re: Why we won’t be supporting Sign in with Apple

#284

Earlier quoted context omitted.

There's two kinds of "obfuscation" at play with Sign In With Apple. One is true obfuscation - "hide my email". That would be a poor choice for use with any app you hope to have an ongoing relationship with, I'd think. The other is just the use of iCloud email addresses, detailed in the post, which seemed like a very good and concerning point. It's also much less likely to be a problem with FB or Google login.

I can have an ongoing relationship with an app without that app’s developer having an ongoing relationship with my inbox.

Sure you can. But they explain why it's not applicable for their use case.

And I would literally blow up at Apple, if they forced this on TripIt... Sharing trip information is done using registered email. And iCloud email is crap.

Re: Why we won’t be supporting Sign in with Apple

#285
post #171

Earlier quoted context omitted.

Yes! Especially once you start juggling multiple accounts for different companies and projects. Becomes a guessing game, and each wrong guess creates another account magically. Infuriating

Time to create a new service to unify all your SSO accounts! One single SSO!

OpenID would have done it, but Facebook and Google neutered it in favour of OAuth so they could cement themselves as primary players.

Re: Why we won’t be supporting Sign in with Apple

#286

Earlier quoted context omitted.

Having had this same problem multiple times, I actually made it a point to save a “login” for those sites that when I autofill it reminds me which auth service I’ve used. Username: Log in with FB Password:

Neat trick. Some websites don't even bother giving you any choice for traditional username/password input though.

Some places require no additional info from you.

There are good use cases where third party logins are good enough.

Re: Why we won’t be supporting Sign in with Apple

#287

Worth noting that AnyList automatically subscribed me to a marketing list without double opt-in or any kind of consent, which is exactly the kind of behaviour that makes me not want apps to have my real email address.

This.

The blog post was long and winded. And it brought up some very desperate arguments, like the bug bounty offered to hackers when they report security vulnerabilities.

They want people's email addresses, period.

They say that no email breaks the sharing feature. True. But that's something that can be offered later when someone actually does share something with you. They say that the emails will go to the a seldom checked account. True. But users can change email addresses. They say it breaks support service for looking up accounts without email addresses. Again true. But what's another way of looking up accounts? Username. What is another? Apple ID.

They are email network harvesters. Plain and simple. And this is their business model.

Re: Why we won’t be supporting Sign in with Apple

#288
I seriously hope I'll see the day when OpenID takes off. It doesn't seem to be going the right way, but it would solve most of our login problems.

One way to sign in, used everywhere, decentralized, set up 2FA for everything in one place, switch providers with ease or be your own provider.

Apple could promote a decentralized solution instead of forcing the sign in with apple shit on people, but clearly they want all your data so they can lock you in.

Re: Why we won’t be supporting Sign in with Apple

#289

Earlier quoted context omitted.

I can have an ongoing relationship with an app without that app’s developer having an ongoing relationship with my inbox.

Sure you can. But they explain why it's not applicable for their use case. And I would literally blow up at Apple, if they forced this on TripIt... Sharing trip information is done using registered email. And iCloud email is crap.

Sharing trip information is done using registered email.

Could you provide any details? How is such "registered" email different than any other email?

Re: Why we won’t be supporting Sign in with Apple

#290

As they point out at the very bottom, all their arguments apply to all third-party sign-ons, so they're removing Facebook as well. So there's nothing specifically against Apple, despite the title seeming to imply it -- just that they're taking the move right now because of Apple's new policy coming into effect. I've got to say, I really wish there were a way to know whether I already used Facebook, Google, or Apple t…

"all their arguments apply to all third-party sign-ons" No they don't. Other sign-on options don't obfuscate the email address. They are likely removing FB login as otherwise their next app update will be rejected by Apple for supporting third party login but not Apple login.

That may be a reason in the future, but they did specifically mention a couple really good reasons to dump Facebook login now:

> "That’s become even more true as time goes on, since Facebook constantly seems to be upping the ante with creepy privacy practices. We use the Facebook SDK to provide login functionality, and every new release of the SDK seems to add new tracking options that are turned on by default, which we have to take action to disable. Furthermore, the Facebook SDK has quality problems, and recently caused a huge number of iOS apps to crash due to a misconfigured server."

Post reply on HN