Live data from Hacker News

Why we won’t be supporting Sign in with Apple

blog.anylist.com

411–420 of 485 posts

Re: Why we won’t be supporting Sign in with Apple

#411

Earlier quoted context omitted.

I cope with this confusion by avoiding third-party login whenever possible. Why volunteer additional information about myself to Google or Facebook?

Because you can frequently avoid account creation, setting a new password etc if you click “sign in with google.” It’s a tradeoff but if you don’t see any value in it you maybe haven’t used it- it’s convenient.

I use third party identity providers for all webservices I offer. Not that many because I am not web dev. People love it but I wouldn't use it myself. Of course the identity provider could extract information about the services you use, I wouldn't like that for most platforms to be honest not for the net as a whole.

Account creation sucks, but I prefer it to letting an ID provider know about it. Although I would trust real third party ones like auth0 more than Facebook or Apple, even if they have a more focused business model.

Re: Why we won’t be supporting Sign in with Apple

#412
post #339

Earlier quoted context omitted.

It's also likely that 99% of users have no reason to share their email with you. Also, your app is extremely untrustworthy. It sounds like a random app you find by searching for key words. You're not Microsoft or Google, you have no reputation or credibility. They have no relationship with you, they don't know you, they likely have never interacted with your company before this. If I need an email to verify I'm not a…

> If I need an email to verify I'm not a bot, that's fine. But if a trusted 3rd party can verify I'm not a bot, then the only reason you would want my email is to do something unethical with it: namely, use my data in a way that I never intended gave you permission to use it. This was addressed in the article. If the service provider does not have your email address, they are severely hampered with regards to custome…

> If the service provider does not have your email address, they are severely hampered with regards to customer support.

No, they're not. They're just relying on email as a user verification methods as it's the easiest approach. Other methods are possible.

Re: Why we won’t be supporting Sign in with Apple

#413
post #4

This makes perfect sense from their standpoint - especially since they've had similar problems to what they outline with Facebook sign-in and are now dropping that as well. This is also a win for Apple & end-user privacy, as there's one less app using FB's login feature now. I think Sign in with Apple is a great step forward even if all it does is eliminate apps that require Facebook and/or Google accounts to log in.…

For my last two companies (both B2B), I implemented login via Google accounts only. Google login has a number of advantages: 1) Identity is an email address. If I wanted to rip out Google, or Google kicked me off the platform, all I need to do is add passwords and put a "forgot my password" link and my customers continue business as usual. 2) It's not a google-specific email address. You can create Google accounts fo…

#1 is only sort-of true. You can get access to their current email, yes, but the email can change and you should be keying by the Google account ID really.

Re: Why we won’t be supporting Sign in with Apple

#414

Earlier quoted context omitted.

In a perfect world people would share things with you without entering your private email address in other people's systems. I don't want to be in the database of whatever app or system my friends decided to join, nor I want to receive spam from these companies. Many of the objections come from wanting to do things the old way, without privacy and responsible handling of private data.

Can you elaborate on "private email address"? I'd be offended if someone were careless with a more intimate identifier like my personal cell phone number, but I've always considered arms-length interactions with businesses and institutions I'm not fully on board with to be the whole point of email.

I have a private email address and a catch all address for a variety of websites.

{app_name}@example.com goes to the same place, but it is easy for me to see if they sell/lose my email. And if it gets lost I'm done with them I can just block that specific address.

The added benefit is no one can assume that {my_name}@example.com is my bank email address or my email login.

I used to have a standard {username}@gmail.com for a while, but now it is on 20+ breached site lists. Best case? Copious amounts of spam. Worst case? I may have been reusing a password prior to switching to a password manager.

Now, I can just block the email from receiving anything. Two, if I accidentally reuse a password the username is at least different.

Re: Why we won’t be supporting Sign in with Apple

#415
post #412

Earlier quoted context omitted.

> If I need an email to verify I'm not a bot, that's fine. But if a trusted 3rd party can verify I'm not a bot, then the only reason you would want my email is to do something unethical with it: namely, use my data in a way that I never intended gave you permission to use it. This was addressed in the article. If the service provider does not have your email address, they are severely hampered with regards to custome…

> If the service provider does not have your email address, they are severely hampered with regards to customer support. No, they're not. They're just relying on email as a user verification methods as it's the easiest approach. Other methods are possible.

Verification is only one part of the problem. The other is communication.

If I can't contact my customers, how do I support them (e.g. report a security problem)? If my customers can't communicate which account is theirs, how do we help solve problems? Email addresses and/or phone numbers make this a lot easier.

Re: Why we won’t be supporting Sign in with Apple

#416

Earlier quoted context omitted.

Because you can frequently avoid account creation, setting a new password etc if you click “sign in with google.” It’s a tradeoff but if you don’t see any value in it you maybe haven’t used it- it’s convenient.

It's convenient right up to the point where I need to get back into an account but forgot if I used it or not - which is exactly the point of the parent. I too have struggled to remember which third party sign-on I used (or if I used a native sign in), so now I avoid them every time, too. They're literally only convenient if I want to have an account that I'm happy to 'throw away' or, to accidentally create duplicate…

I don't have any metrics to back this up, but I would assume most websites that use these third-party login systems, still pull down your email address and create an account for you based on that. So it stands to reason, you if you used the same email for all Facebook, Google, Apple, you could sign in with any of them and maintain one account.

I suppose that's a huge assumption, but that's how I would do it if I was developing against them. That said, it doesn't help w/ the "Hide my Email" or the default icloud.com email addresses people don't realize they're using.

Re: Why we won’t be supporting Sign in with Apple

#417
post #318

Worth noting that AnyList automatically subscribed me to a marketing list without double opt-in or any kind of consent, which is exactly the kind of behaviour that makes me not want apps to have my real email address.

The article says "When you provide us with your email address, it is never sold, shared, or used to invade your privacy." So, one of you is lying. I don't have the means to determine who, but I don't see what your motivation for lying would be, but can see what theirs may be. And to extend that, if they are a spammy company, that would be exactly why they would be complaining about SIWAI.

It wasn't sold or shared, the emails came from them. But they were pure marketing, not transactional, and I certainly didn't agree to it or want it.

Re: Why we won’t be supporting Sign in with Apple

#418
post #277
post #228

Earlier quoted context omitted.

Obfuscation of the email address is an explicit choice by the user when using Sign in with Apple. It’s not something forced by the service. If users are choosing to do that, it says something about the lack of trust the users have with whatever they’re signing up for.

Not necessarily. I have an app with 1,000 users, and about 99% of them choose to obfuscate. My app isn’t untrustworthy at all either. It’s an experimental app which attempts to let users create an iOS app on iOS. My suspicion is that people choose to obfuscate because it’s what’s selected by default.

Why do you need my email address? I wouldn't give it to you just so you can have bad database security and then have my email dumped somewhere.

Re: Why we won’t be supporting Sign in with Apple

#420

Earlier quoted context omitted.

Why should Apple be allowed to dictate if an app asks for an email address? They should not become the defacto law makers of our society

That ship sailed long ago. Apple basically has apps and app-developers by the balls, not to mention the 30% extortion money they try to get not just for app purchases but any transaction done within the app, so much as even banning an app from telling the user that they can do the transaction elsewhere. It makes my blood boil but from the discussions I see on HN about it, most people here seem to be more or less ok w…

It hasn't sailed yet. We'll have to see what comes out of the antitrust litigations in the EU and, if I'm not mistaken, also in the US.
Post reply on HN