Live data from Hacker News

Why we won’t be supporting Sign in with Apple

blog.anylist.com

381–390 of 485 posts

Re: Why we won’t be supporting Sign in with Apple

#381

Earlier quoted context omitted.

As explained in the article a lot of people use the iCloud mail for their apple account and they don’t check it because they use another provider main mail address. Furthermore if they contact them from their email for support they have no way to associate it with the mail registered in the system, so they can’t help them. If you ask me they seem both very valid points.

Do you have a number for “a lot of people”? I am very skeptical of this data point. This email address is used for a lot of communication with Apple, e.g. receipts from App Store.

Receipts from the app store go to my gmail account.

I bought my iMac on the Apple store, and the receipt was also sent to my personal account.

Re: Why we won’t be supporting Sign in with Apple

#383

Earlier quoted context omitted.

I agree with the sibling in that defaults are powerful. However, I've never built anything directly used "by the public", nor am I very familiar with how Apple Sign in works. So I'm wondering, as the developer of a trustworthy app, what's the drawback in the user giving an obfuscated address? Is it not possible for you to contact the user using this address? Does the user have to manually allow getting mail to this a…

As explained in the article a lot of people use the iCloud mail for their apple account and they don’t check it because they use another provider main mail address. Furthermore if they contact them from their email for support they have no way to associate it with the mail registered in the system, so they can’t help them. If you ask me they seem both very valid points.

Can't they just ask the user to open the app and send them some identifying number they can find in the ui?

Re: Why we won’t be supporting Sign in with Apple

#384

Earlier quoted context omitted.

It used to be true that during a Facebook Connect session the user was asked if they wanted to share their email or not. I faintly remember you could even choose a proxy fb e-mail aka "fake email". Did they remove that feature?

A party in OAuth authentication can request some obligatory information, and if email is part of it, you won't be able to deselect it. In general, sites use email as an indication of a unique, real person. I imagine most of them do not really care about it afterwards, which is why the SSO systems even work (though, they can demand an email too).

It was not that Facebook allowed the user to deselect the e-mail address from what would be shared. Rather, it allowed them to randomly generate an e-mail address to share with the other party. I think messages sent to this address were forwarded to the user's Facebook inbox.

And to answer scarlac's question, yes, they removed this feature a very long time ago.

Re: Why we won’t be supporting Sign in with Apple

#385

Earlier quoted context omitted.

With a password manager though, I avoid having tradeoffs in the first place. I get some amount of anonymity by separating my accounts, and it's trivial to login to sites with the same amount of clicks as with third party sso.

Registering a new site on PC browser with password manager is fine but on mobile with password manager is bother. It won't register new ID/password automatically.

Chrome on Android is persistently annoying about wanting to save new IDs, and will also try to save logins for apps. That gets turned off fairly quickly, as I use Bitwarden, which _also_ prompts to add new accounts when I sign up or log in.

It's not foolproof, but given I'm generating the password in Bitwarden anyway, it's not the end of the world if it doesn't catch it.

Re: Why we won’t be supporting Sign in with Apple

#386

Worth noting that AnyList automatically subscribed me to a marketing list without double opt-in or any kind of consent, which is exactly the kind of behaviour that makes me not want apps to have my real email address.

That's exactly what I'm thinking! Further I can't find the EULA of the app on the internet - maybe I'll find it later. But I could bet that they sell the data for marketing purposes. And I could also bet that they removed Facebook not because they don't want to use it but because they had to implement Sign in with Apple which would result in the Data being not so valuable because the standard option is to obfuscate the mail address.

Re: Why we won’t be supporting Sign in with Apple

#387

As they point out at the very bottom, all their arguments apply to all third-party sign-ons, so they're removing Facebook as well. So there's nothing specifically against Apple, despite the title seeming to imply it -- just that they're taking the move right now because of Apple's new policy coming into effect. I've got to say, I really wish there were a way to know whether I already used Facebook, Google, or Apple t…

I don't support social login anymore. It's better for the customer.

Re: Why we won’t be supporting Sign in with Apple

#388
post #269

Earlier quoted context omitted.

Your primary iCloud email address is meant to just be your main email address, including non-Apple email addresses.

"Meant to" doesn't mean "is", and even if 99% of people do what they are "meant to", that still leaves millions of people doing it the "wrong" way.

Yep. I rarely run into people who use their iCloud email, and that goes for both the technically inclined and the average users.

Locking things down like this seems to have some serious negatives that Apple needs to reconsider their approach for.

Re: Why we won’t be supporting Sign in with Apple

#390

Earlier quoted context omitted.

This is where their article lost credibility with me. Their decision to base their sharing and addressing system on email was their mistake, and Apple is just the first to force them to face their mistake. I don't want to share my spam email with all my friends to get them to share with me. And I don't want to give my primary email to an app that will spam me. If I want to share something, I'll send a link and the re…

It's not a mistake, by any means. It's dead clear that you don't work with consumers. Your technical bias shows what you care about and you're(an me) are an utter minority. If you want security, btw - you should have multiple passwords for different things. And ideally not even use a password manager.

Why should he not use a password manager?
Post reply on HN